Logo for MENA CONSULTANCY

Senior Cybersecurity Risk & Resilience Consultant - 2-Year Engagement

Role overview

Qualifications

  • 8–10 total years of experience
  • Proven experience in cybersecurity risk and resilience consulting
  • Strong experience conducting cybersecurity and technology risk assessments
  • Knowledge of NCA ECC, SAMA requirements, and ISO 27001

Responsibilities

  • Assist with planning and delivering Risk & Resilience engagements
  • Perform cybersecurity, technology, and enterprise risk assessments
  • Create, maintain, and improve risk registers
  • Develop, track, and report on risk treatment plans

Key facts

Hard skills

About the company

MENA CONSULTANCY logo

MENA CONSULTANCY

Business Consulting & Services

MENA Consultancy is a multi-jurisdictional corporate services firm headquartered in Dubai, UAE, with offices in Doha, Qatar and Nairobi, Kenya. Established in 2011 and with over 2,000 corporate and private client structures to our name, we advise entrepreneurs, family offices and corporations at every stage of their business lifecycle, from company formation and initial market entry through to ongoing operations and compliance. Our experienced team guides clients through every requirement their jurisdiction demands: incorporation, licensing, immigration, local labour law, accounting and tax filing. Our core services include: Bespoke Entity Formation, Licensing & Structuring - SPVs, holding companies, trusts, foundations and operational entities, across mainland, free zone, financial free zone and offshore jurisdictions; Regulatory, Compliance & Governance - corporate secretarial services, statutory filings, beneficial ownership registration, economic substance compliance, policy frameworks and corporate records maintenance; Corporate Legal Advisory - legal counsel supporting business operations and corporate matters; Residency & Visa Solutions - immigration and labour services support and residency planning for individuals and corporate personnel; Business Support Services - HR administration, payroll processing, corporate tax registration and filing, VAT registration and compliance, bookkeeping and accounting support; Company Liquidation - end-to-end support for the voluntary liquidation and dissolution of entities, managing the full process from regulatory notifications through to the cancellation of licences and final deregistration; Twice recognised at the MEA Markets UAE Business Awards 2025 - Most Client-Focused Business Set-Up Consultancy and Client Service Excellence Award, we combine regional insight with international standards to deliver results that are cost-effective, practical, compliant and built for long-term success.

Company details

Company typeTPE
IndustryBusiness Consulting & Services
Company size2 - 10

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Location: remote.
Years of Experience: 8-10 years.
Project Duration: 2 years.
Language Requirements: Fluency in Arabic & English (written and spoken).

We are seeking a Senior Cybersecurity Risk & Resilience Consultant with 8–10 years of experience to deliver cybersecurity and technology risk assessments and advise on risks across systems, cloud environments, digital initiatives, and third-party services. The consultant will manage risk registers, treatment plans, and exception processes; strengthen risk management frameworks; and provide clear reporting to senior stakeholders. The role requires knowledge of NCA ECC, SAMA requirements, and ISO 27001.

   

Key Requirements

  • 8–10 total years of experience.
  • Proven experience in cybersecurity risk and resilience consulting.
  • Strong experience conducting cybersecurity and technology risk assessments across systems, digital services, cloud environments, and technology projects.
  • Hands-on experience managing risk registers and the full risk lifecycle, including assessment, treatment, acceptance, exceptions, and ongoing monitoring.
  • Experience developing and tracking risk treatment and remediation plans, including evaluation of control gaps and compensating controls.
  • Ability to advise on risks related to infrastructure, cloud security, third parties, secure software development, and data protection.
  • Experience developing or improving cybersecurity risk frameworks, methodologies, risk appetite statements, and key risk indicators (KRIs).
  • Knowledge of applicable frameworks and regulations, particularly NCA ECC, SAMA requirements, and ISO 27001.

Key Responsibilities

  • Assist with planning and delivering Risk & Resilience engagements in line with approved methodologies, project plans, and timelines.

  • Perform cybersecurity, technology, and enterprise risk assessments covering customer systems, platforms, digital services, and technology initiatives, as well as regulatory-driven assessments, including NCA compliance activities, and ad hoc risk reviews.

  • Create, maintain, and improve risk registers, tracking risks from identification and assessment through treatment, acceptance, and ongoing monitoring.

  • Develop, track, and report on risk treatment plans, mitigation initiatives, and remediation activities to support timely closure of identified risks and control gaps.

  • Coordinate risk acceptance and exception management processes, including impact assessments, evaluation of compensating controls, stakeholder engagement, approvals, and periodic revalidation.

  • Assess major technology changes, cloud deployments, digital transformation initiatives, third-party services, and strategic projects to identify emerging risks and recommend appropriate risk responses.

  • Deliver risk advisory services across enterprise infrastructure, cloud security, cybersecurity controls, secure software development, digital platforms, data protection, and emerging technologies.

  • Help maintain and continuously improve the customer’s cybersecurity risk management framework, methodologies, standards, templates, and governance processes.

  • Contribute to developing and periodically updating cybersecurity risk strategies, risk roadmaps, risk appetite statements, and risk mitigation priorities in alignment with business objectives.

  • Work with business, technology, cybersecurity, and project teams to offer actionable risk recommendations and enable informed, risk-based decisions.

  • Track key risk indicators (KRIs), risk trends, emerging threats, and overdue remediation actions, providing insights for proactive risk management.

  • Prepare and present risk reports, dashboards, management updates, and executive-level insights to relevant stakeholders and governance forums.

  • Encourage a risk-aware culture through stakeholder engagement, awareness activities, workshops, and advisory sessions across customer business units.

  • Ensure alignment with applicable internal policies, regulatory requirements, and industry standards, including NCA ECC, SAMA requirements, ISO 27001, and other relevant frameworks.

If you would like to know more about the Global Consulting Bootcamp Visit: https://caseinpointco.com/global-consultant-bootcamp/
If you would like to know more about the MC Club Visit: https://menaconsultant.com/mc-club/

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cybersecurity Consultant Related jobs

Other jobs at MENA CONSULTANCY

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.