A complete application in a minute — tailored resume and cover letter, ready to send.
Accenture Security is seeking a cybersecurity governance and risk professional to help develop and implement framework-mandating policies across governance, risk, and compliance.” The role emphasizes stakeholder collaboration, regulatory alignment, and continuous improvement in security programs. The position involves travel and close coordination with clients to ensure robust cyber risk posture.
The candidate should have 5+ years in related roles, strong communication, and knowledge of
Accenture helps the world’s leading enterprises reinvent by building their digital core and unleashing the power of AI to create value at speed for organizations across industries. Our strategy is to be the reinvention partner of choice for our clients and lead in the safe, widespread adoption of AI, and to be the most client-focused, AI-enabled, great place to work in the world. We bring together the talent of our approximately 786,000 people with proprietary assets and platforms, deep process and industry expertise, and leading ecosystem relationships to deliver end-to-end solutions and measurable outcomes at scale. Through our Reinvention Services, we offer broad expertise across Cybersecurity, Digital Core, Finance, Industry and Enterprise, Song, Supply Chain and Engineering, and Talent, with advanced capabilities in AI and Data, Industry and Process, and Technology. We serve approximately 9,000 clients and generated approximately $70 billion in FY25 revenue. Visit us at accenture.com.
Accenture Security helps organizations prepare for, prevent, detect, respond to, and recover from cyber threats. We bring together deep industry knowledge, advanced security capabilities, and cutting-edge technology to help our clients protect their most critical assets, comply with regulatory requirements, and build resilient security programs.
Developcyber frameworks, policies, processes, procedures, guidelines, and related documentation.
Review existing and proposed policies and related documentation with stakeholders.
Develop reporting metrics,KPIs, anddashboards.
Monitor how effectively cybersecurity policies, principles and practices are implemented in the delivery of planning and management services.
Ensure that cybersecurity workforce management policies and processescomply withlegal and organizational requirements.
Interpret and apply applicable laws,statutesand regulatory documents to ensure they are reflected inthe cybersecuritypolicies.
Providepolicy guidance to cybersecurity management,staffand users.
Effectively communicateCybersecurityrisks and posture to senior management.
Develop risk mitigation strategies to effectively manage riskin accordance withorganizational risk appetite.
Ensure that decisions relating toCybersecurityare based on sound risk management principles.
Perform risk analysis whenever an application or system undergoes a major change.
Provide input to the risk management framework and related documentation.
EnsureCybersecurityrisks areidentifiedand managed appropriately through the organization’s risk governance process.
Carry out aCybersecurityriskassessments.
Work with others to implement andmaintainaCybersecurityrisk management program
Identifyand assign individuals to specific roles associated with the execution of the Risk Management Framework
Establish a risk management strategy for the organization that includes a determination of risk tolerance
Conductan initialrisk assessment of stakeholder assets and update the risk assessment on an ongoing basis
Work with organizational officials to ensure continuous monitoring tool data provides situationawareness of risk levels
Userisk management related tools such aseGRCandmonitoring tools to assess risks
Develop methods to effectivelymonitorand measure risk, compliance, and assurance efforts.
Determineand document supply chain risks for critical system elements, where they exist.
Analyze the organization’sCybersecuritypolicies and configurations to evaluate compliance with regulationsand organization compliance frameworks
Recognize patterns of non-compliance withCybersecuritypolicies and related documentation toidentifyways to improve the documentation
Periodically reviewCybersecuritystrategy, policies, and related documents tomaintaincompliance with applicable legislation and regulation
Work with stakeholders to resolveCybersecurityincidents and vulnerability compliance issues
Develop methods to effectivelymonitorand measure risk, compliance, and assurance efforts
Develop specifications to ensure that risk, compliance, and assurance efforts conform withCybersecurityrequirements.
Monitor and evaluate a system’s compliance withCybersecurity, resilience, and dependability requirements
DevelopCybersecuritycompliance processes and audits for services provided by third parties
Maintain knowledge of applicable legislation, regulation, and accreditation standards and regularly review these to ensure continued organizational compliance
Cooperate with relevant regulatory agencies and other legal entities in anycompliancereviews or investigations.
Excellent communication (written and oral) and interpersonal skills
Ability to work creatively and analytically in a problem-solving environment
Flexibility to travel
Consulting, stakeholderengagementand relationship management skills.
Fluent in Arabic and English language
Ability to effectively communicate insights relating to an organization’s threat environment to improve its risk management posture.
Ability to work with the organization’s leadership to provide a comprehensive, organization wide approach to addressCybersecurityriskand compliance.
Ability to work with the organization’s leadership to develop a risk management strategy to addressCybersecurityrelated risks.
Ability to developandmaintainCybersecuritypolicies,standardsand related documentationsto support business strategy andmaintaincompliance with legislative, regulatory, and contractual obligations.
Ability to communicate technical and planning information at the same level as a stakeholder’s understanding.
Knowledge and understanding of risk assessment, mitigation, andtreatmentmethods.
Knowledge of relevantCybersecurityaspects of legislative and regulatory requirements, relating to ethics and privacy.
Knowledge ofCybersecuritythreatsandvulnerabilitiesposed bynew technologiesand malicious actors.
Knowledge and understanding of risk assessment, mitigation, and management methods.
Knowledge of thelikely operationalimpact on an organization ofCybersecuritybreaches.
Knowledge of nationalCybersecuritylaws and regulationssuch as SAMA CSF, NCA ECC, etc.
Knowledge of common information security standards, such as: ISO 27001/27002, NIST, PCI DSS, ITIL,etc.
Bachelor’s degree in information security,Cybersecurityor relevant.
5+years of experience in similar position
Should be Certified inCRISC,GRCP,ISO 27001 LIor equal certifications.
Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.
Visit us at www.accenture.com
We believe that no one should be discriminated against because of their differences.All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, sexual orientation, gender identity or expression, marital status, citizenship status or any other basis as protected by applicable law.Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities.