GRC Specialist (NCSA Certification Support)

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity

In short

Accenture is seeking a GRC Specialist in Doha to provide NCSA Certification Support. This role involves developing cyber frameworks, policies, and processes, managing risks, and ensuring compliance with relevant regulations and standards.

Responsibilities

  • Develop cyber frameworks, policies, processes, procedures, guidelines, and related documentation.
  • Review existing and proposed policies and related documentation with stakeholders.
  • Develop reporting metrics, KPIs, and dashboards.
  • Monitor the effective implementation of cybersecurity policies, principles, and practices.
  • Ensure cybersecurity workforce management policies and processes comply with legal and organizational requirements.
  • Interpret and apply applicable laws, statutes, and regulatory documents to cybersecurity policies.
  • Provide policy guidance to cybersecurity management, staff, and users.
  • Effectively communicate Cybersecurity risks and posture to senior management.
  • Develop risk mitigation strategies aligned with organizational risk appetite.
  • Ensure Cybersecurity decisions are based on sound risk management principles.
  • Perform risk analysis for major application or system changes.
  • Provide input to the risk management framework and related documentation.
  • Ensure Cybersecurity risks are identified and managed through the organization's risk governance process.
  • Carry out Cybersecurity risk assessments.
  • Work with others to implement and maintain a Cybersecurity risk management program.
  • Identify and assign individuals to specific roles for Risk Management Framework execution.
  • Establish a risk management strategy including risk tolerance determination.
  • Conduct and update initial risk assessments of stakeholder assets.
  • Work with organizational officials to ensure continuous monitoring tool data provides situational awareness of risk levels.
  • Use risk management tools such as eGRC and monitoring tools to assess risks.
  • Develop methods to effectively monitor and measure risk, compliance, and assurance efforts.
  • Determine and document supply chain risks for critical system elements.
  • Analyze the organization's Cybersecurity policies and configurations for compliance with regulations and frameworks.
  • Recognize patterns of non-compliance to improve documentation.
  • Periodically review Cybersecurity strategy, policies, and documents for compliance with legislation and regulation.
  • Work with stakeholders to resolve Cybersecurity incidents and vulnerability compliance issues.
  • Develop specifications to ensure risk, compliance, and assurance efforts conform with Cybersecurity requirements.
  • Monitor and evaluate a system's compliance with Cybersecurity, resilience, and dependability requirements.
  • Develop Cybersecurity compliance processes and audits for third-party services.
  • Maintain knowledge of applicable legislation, regulation, and accreditation standards.
  • Cooperate with relevant regulatory agencies and legal entities in compliance reviews or investigations.

Requirements

  • Excellent communication (written and oral) and interpersonal skills.
  • Ability to work creatively and analytically in a problem-solving environment.
  • Flexibility to travel.
  • Consulting, stakeholder engagement and relationship management skills.
  • Fluent in Arabic and English language.
  • Ability to effectively communicate insights relating to an organization’s threat environment to improve its risk management posture.
  • Ability to work with organization’s leadership to provide a comprehensive, organization-wide approach to address Cybersecurity risk and compliance.
  • Ability to work with organization’s leadership to develop a risk management strategy to address Cybersecurity related risks.
  • Ability to develop and maintain Cybersecurity policies, standards and related documentation to support business strategy and maintain compliance with legislative, regulatory, and contractual obligations.
  • Ability to communicate technical and planning information at the same level as a stakeholder’s understanding.
  • Knowledge and understanding of risk assessment, mitigation, and treatment methods.
  • Knowledge of relevant Cybersecurity aspects of legislative and regulatory requirements, relating to ethics and privacy.
  • Knowledge of Cybersecurity threats and vulnerabilities posed by new technologies and malicious actors.
  • Knowledge and understanding of risk assessment, mitigation, and management methods.
  • Knowledge of the likely operational impact on an organization of Cybersecurity breaches.
  • Knowledge of national Cybersecurity laws and regulations such as SAMA CSF, NCA ECC, etc.
  • Knowledge of common information security standards, such as: ISO 27001/27002, NIST, PCI DSS, ITIL, etc.

Desired Qualifications

  • Bachelor’s degree in information security, Cybersecurity or relevant.
  • 5+ years of experience in a similar position.
  • Certified in CRISC, GRCP, ISO 27001 LI or equivalent certifications.

Benefits

  • Opportunities to keep skills relevant through certifications, learning, and diverse work experiences.
  • Well-being support (physical, mental, financial).
#GRC#Cybersecurity#NCSA#Certification Support#Risk Management#Governance#Compliance#Doha

Company

Accenture

Job Posted

1 week ago

Employment Type

Full Time

WorkMode

On Site

Experience Level

Mid-Senior

Locations

Doha, Qatar

Qualification

Bachelor

Applicants

Be an early applicant