Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
CPX in Abu Dhabi seeks a Lead Consultant – Cyber Consulting Services to own and drive GRC and Information Security initiatives for a government regulator and its sector, ensuring alignment with ADHICS and UAE requirements. This senior contributor leads workstreams, sets technical direction, and serves as the main client liaison.
You will mentor juniors, guide consultants, plan programs, and monitor delivery quality while maintaining regulatory and industry best practices.
The Lead Consultant – Cyber Consulting Services is a senior individual-contributor and delivery-lead role responsible for owning and driving the definition, enforcement, and monitoring of Governance, Risk and Compliance (GRC) and Information Security initiatives for a leading government regulatory entity and its regulated sector. The role holder leads GRC workstreams end-to-end, sets the technical direction and quality standards for deliverables, and acts as the senior point of contact with the client and regulatory stakeholders. Operating within a healthcare regulatory environment, the role ensures compliance with, and continuous improvement of, the Information Security maturity of the organization and its wider regulated sector in alignment with the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and applicable UAE regulatory requirements. The role holder is expected to independently plan and execute programs, guide and quality-assure the work of consultants, and mentor junior team members, without carrying full people-management accountability.
Skills/Certifications (Technical & Non-Technical)
Advanced understanding of GRC processes, control frameworks, risk assessment methods, and compliance monitoring practices, with a proven ability to lead workstreams and quality-assure deliverables. In-depth, working knowledge of the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and its application, together with familiarity with UAE healthcare regulatory and information security requirements, is mandatory. Preferred certifications: Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); Certified Information Systems Auditor (CISA); Certified in Risk and Information Systems Control (CRISC); ISO/IEC 27001 Lead Implementer or Lead Auditor; ISO 31000 Risk Manager or equivalent; Certified in the Governance of Enterprise IT (CGEIT).
Workstream and Delivery Leadership; Risk-Based Thinking; Quality Assurance and Review; Policy and Documentation; Analytical Skills; Stakeholder and Expectation Management; Mentoring and Coaching; Communication; Attention to Detail; Integrity and Confidentiality.
Minimum of 9 years of experience in governance, risk, compliance, and Information Security, including demonstrable experience leading GRC workstreams or teams and quality-assuring deliverables. A substantial and demonstrable portion of this experience must be within the UAE healthcare sector or a healthcare regulatory environment, and must include cybersecurity, technology risk, regulatory compliance, or audit management activities, along with hands-on experience implementing, assessing, or advising against the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard.
Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business Administration, or a related field. A Master’s degree or relevant postgraduate qualification is preferable.