Lead Consultant- GRC

CPX

Abu Dhabi

On-site

AED 300,000 - 460,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

CPX in Abu Dhabi seeks a Lead Consultant – Cyber Consulting Services to own and drive GRC and Information Security initiatives for a government regulator and its sector, ensuring alignment with ADHICS and UAE requirements. This senior contributor leads workstreams, sets technical direction, and serves as the main client liaison.

You will mentor juniors, guide consultants, plan programs, and monitor delivery quality while maintaining regulatory and industry best practices.

Qualifications

  • Minimum 9 years in governance, risk, compliance and information security.
  • Experience leading GRC workstreams within UAE healthcare or regulatory sector.
  • Knowledge of ADHICS standard and UAE regulatory requirements.
  • Bachelor's degree in related field; Master's preferred.

Responsibilities

  • Own end-to-end GRC and information security workstreams and serve as senior client liaison.
  • Develop, implement and improve information security policies aligned to ADHICS and ISO standards.
  • Lead risk management programs, coordinate with assurance activities, and report findings.
  • Engage with regulators and stakeholders to ensure timely, compliant engagements.

Skills

GRC processes
Control frameworks
Risk assessment
Compliance monitoring
ADHICS Standard
Stakeholder management
Mentoring and coaching

Education

Bachelor's degree in IT/Cybersecurity/CS
Master's degree preferred

Tools

ISO/IEC 27001
ISO 31000
CISSP
CISM
CISA
CRISC
CGEIT

Job description

The Lead Consultant – Cyber Consulting Services is a senior individual-contributor and delivery-lead role responsible for owning and driving the definition, enforcement, and monitoring of Governance, Risk and Compliance (GRC) and Information Security initiatives for a leading government regulatory entity and its regulated sector. The role holder leads GRC workstreams end-to-end, sets the technical direction and quality standards for deliverables, and acts as the senior point of contact with the client and regulatory stakeholders. Operating within a healthcare regulatory environment, the role ensures compliance with, and continuous improvement of, the Information Security maturity of the organization and its wider regulated sector in alignment with the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and applicable UAE regulatory requirements. The role holder is expected to independently plan and execute programs, guide and quality-assure the work of consultants, and mentor junior team members, without carrying full people-management accountability.

Key Responsibilities
  • Own and lead the end-to-end delivery of assigned GRC and Information Security workstreams for the organization and its regulated sector, acting as the senior point of contact with the client and regulatory stakeholders. Plan and sequence activities, set technical direction and quality standards for deliverables, manage workstream risks, dependencies, and timelines, and ensure that milestones are met and outcomes exceed stakeholder expectations
  • Lead the development, implementation, and continuous improvement of Information Security policies, standards, procedures, guidelines, and templates for the organization and its regulated sector, aligned to legal, regulatory, and international best practices, including the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and ISO/IEC 27001.
  • Lead and mature the Information Security Risk Management Program for the organization and its regulated sector; drive risk identification, assessment, treatment, and monitoring, and coordinate with mission assurance programs to manage Information Assurance, Information Security, and Cyber Security risks, escalating significant risks with clear remediation recommendations.
  • Define and execute compliance management initiatives and lead Information Security audits for the organization and its regulated sector. Establish measures to assess operational capabilities, determine compliance and control effectiveness levels, and coordinate audits with internal and external agencies, tracking findings through to closure.
  • Serve as a senior liaison with internal business functions, local and international sector stakeholders, and regulatory bodies on Information Security matters, deviations, exemptions, and incidents, ensuring timely, well-informed, and professionally represented engagement on behalf of the organization.
  • Guide, review, and quality-assure the work of consultants and junior team members within assigned workstreams, providing technical direction, coaching, and constructive feedback. Mentor junior staff to foster growth and a healthy delivery culture, and support resource and knowledge-sharing across the team, without carrying full line-management accountability.
  • Provide expert advisory by reviewing contracts, MoUs, agreements, and documents, and represent Information Security on relevant committees and forums. Define and report performance, deviations, challenges, and risks with remedial proposals, and elevate matters to the Information and Cyber Security Office Leadership as required.

Skills/Certifications (Technical & Non-Technical)

Advanced understanding of GRC processes, control frameworks, risk assessment methods, and compliance monitoring practices, with a proven ability to lead workstreams and quality-assure deliverables. In-depth, working knowledge of the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and its application, together with familiarity with UAE healthcare regulatory and information security requirements, is mandatory. Preferred certifications: Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); Certified Information Systems Auditor (CISA); Certified in Risk and Information Systems Control (CRISC); ISO/IEC 27001 Lead Implementer or Lead Auditor; ISO 31000 Risk Manager or equivalent; Certified in the Governance of Enterprise IT (CGEIT).

Workstream and Delivery Leadership; Risk-Based Thinking; Quality Assurance and Review; Policy and Documentation; Analytical Skills; Stakeholder and Expectation Management; Mentoring and Coaching; Communication; Attention to Detail; Integrity and Confidentiality.

Minimum Work Experience & Education

Minimum of 9 years of experience in governance, risk, compliance, and Information Security, including demonstrable experience leading GRC workstreams or teams and quality-assuring deliverables. A substantial and demonstrable portion of this experience must be within the UAE healthcare sector or a healthcare regulatory environment, and must include cybersecurity, technology risk, regulatory compliance, or audit management activities, along with hands-on experience implementing, assessing, or advising against the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard.

Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business Administration, or a related field. A Master’s degree or relevant postgraduate qualification is preferable.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Consultant –GRC
Consultant –GRC

CPX • Abu Dhabi

On-site
AED 180,000 - 240,000
Manager - GRC
Manager - GRC

CPX • Abu Dhabi

On-site
AED 350,000 - 480,000
Senior GRC & Information Security Delivery Lead
Senior GRC & Information Security Delivery Lead

CPX • Abu Dhabi

On-site
AED 300,000 - 460,000
Senior Consultant Information Security GRC
Senior Consultant Information Security GRC

Paramount Computer Systems • Dubai

On-site
AED 300,000 - 600,000
Senior Consultant – Information Security (GRC)
Senior Consultant – Information Security (GRC)

Paramount Computer System • Dubai

On-site
AED 350,000 - 500,000
Cybersecurity Consultant
Cybersecurity Consultant

Mada Media • Dubai

On-site
AED 300,000 - 600,000
Senior Consultant – Information Security (GRC)
Senior Consultant – Information Security (GRC)

Paramount Computer Systems • Dubai

On-site
AED 300,000 - 420,000
Cybersecurity Consultant
Cybersecurity Consultant

Dubai Careers - A Smart Dubai Initiative • Dubai

On-site
AED 300,000 - 420,000
Healthcare GRC & InfoSec Consultant (ADHICS)
Healthcare GRC & InfoSec Consultant (ADHICS)

CPX • Abu Dhabi

On-site
AED 180,000 - 240,000
Information Security Consultant
Information Security Consultant

United Al Saqer Group • Abu Dhabi

On-site
AED 180,000 - 260,000