GRC Consultant
Listed on 2026-06-26
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Experience
Required:
5+ Years
Employment Type:
Full-Time
Ebryx is a leading cybersecurity services and solutions company helping organizations across the globe strengthen their security posture and achieve compliance with international standards. With deep expertise in Governance, Risk & Compliance (GRC), Managed Security Services, Threat Detection & Response, Cloud Security, and Security Engineering, Ebryx partners with enterprises to address evolving cyber risks and regulatory requirements.
Our team consists of highly skilled cybersecurity professionals who work with cutting‑edge technologies and globally recognized security frameworks. At Ebryx, you’ll have the opportunity to work on challenging projects, collaborate with industry experts, and contribute to securing some of the region’s most critical organizations.
Position OverviewWe are seeking an experienced GRC Consultant to join our team in Riyadh, Saudi Arabia. The ideal candidate will have extensive experience in cybersecurity governance, risk management, compliance assessments, policy development, and implementation of international security frameworks and standards.
The consultant will work closely with clients to assess security maturity, identify risks, implement compliance programs, and support regulatory and certification initiatives.
Key Responsibilities- Conduct Governance, Risk, and Compliance (GRC) assessments for clients across various industries.
- Perform risk assessments, gap analyses, and security maturity evaluations.
- Develop and maintain information security policies, procedures, standards, and guidelines.
- Support organizations in implementing and maintaining compliance with international standards and frameworks.
- Assist clients in achieving certifications and regulatory compliance requirements.
- Conduct internal audits and readiness assessments.
- Develop risk treatment plans and track remediation activities.
- Facilitate risk workshops and stakeholder meetings.
- Prepare executive‑level reports, presentations, and compliance dashboards.
- Provide advisory services on cybersecurity governance and best practices.
- Support security awareness and compliance training initiatives.
- Coordinate with technical security teams to address identified compliance gaps.
- Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field.
- Minimum 5 years of hands‑on experience in Governance, Risk & Compliance (GRC).
- Strong understanding of cybersecurity governance principles and risk management methodologies.
- Experience conducting compliance assessments and security audits.
- Excellent report writing and client communication skills.
- Ability to engage with senior management and business stakeholders.
Hands‑on experience with one or more of the following:
- ISO/IEC 27001
- ISO 22301
- NIST Cybersecurity Framework (CSF)
- PCI DSS
- SAMA Cybersecurity Framework
One or more of the following certifications are highly desirable:
- CISA
- CRISC
- CISSP
- CISM
- CGRC (formerly CAP)
- PCI QSA (preferred)
- Strong analytical and problem‑solving skills.
- Strong grip on NCA compliances, strong grip on compliance audits/assessments, experience in compliance management.
- Excellent documentation and presentation abilities.
- Client‑facing consulting experience.
- Ability to manage multiple projects simultaneously.
- Strong stakeholder management and communication skills.
- Fluency in English;
Arabic language skills are a plus.
- Work with a leading cybersecurity company serving global and regional clients.
- Exposure to large‑scale cybersecurity and compliance programs.
- Opportunity to work alongside highly experienced cybersecurity professionals.
- Career growth and continuous learning opportunities.
- Competitive compensation and benefits package.
- Be part of a culture that values innovation, excellence, and professional development.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).