Company logo hidden

Consultant – Manager| Cyber Operate | Cybersecurity Risk Specialist | KSA

Unlock employer Saudi Arabia Direct to Company 1 hour ago · 08 Oct 2026

Financial

  • Estimate: $30k - $60k*
  • Zero income tax location

Accessibility

  • Visa Provided

Requirements

  • Experience: Intermediate
  • English: Professional
  • Arabic: Preferred

Position

Location
Riyadh

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

About the Role
As a Consultant – Manager in Cybersecurity Risk Management, you will play a crucial role in defining and implementing a robust cybersecurity risk management framework. Your expertise will guide the organization's efforts in assessing and mitigating cyber risks while aligning with regulatory requirements and industry standards. You will work closely with business and technology leaders to ensure that risks are identified and treated effectively to safeguard information and assets.

Responsibilities

  • Define the Risk Framework

    • Design the cybersecurity risk management framework and methodology, including risk taxonomy, asset and impact criteria, likelihood scales, risk matrix and scoring rules.
    • Define risk appetite and tolerance statements for cyber risk with leadership, aligned with the enterprise risk management (ERM) framework and ISO 31000.
    • Write the risk management policy, procedures, and templates, including risk acceptance, exceptions, and escalation thresholds.
    • Align the framework with NCA ECC risk management requirements, ISO/IEC 27005, and NIST SP 800-30.
  • Assess Cyber Risk

    • Identify and assess the organization’s top cyber risks and scenarios (e.g., ransomware, data breach, payment fraud, service outage, OT disruption) at the enterprise level with business and technology leaders.
    • Conduct risk assessments for critical systems, new projects, and major changes prior to go-live and agree on treatment with respective owners.
    • Assess the adoption risks of new technologies such as cloud services, AI, and IoT platforms, recommending conditions for their safe use.
    • Integrate findings from vulnerability management, penetration testing, OT security, third-party risk, and threat intelligence into a holistic risk view.
    • Facilitate risk workshops that encourage honest input from business owners, challenging optimistic or vague risk ratings.
  • Treat and Monitor Risk

    • Maintain the cyber risk register, including owners, ratings, treatment plans, due dates, and status updates.
    • Track treatment plans to completion, re-assess residual risk, and escalate overdue or rising risks appropriately.
    • Manage the risk acceptance and exception process, ensuring proper justification, timely approval, and limits on acceptances.
    • Define key risk indicators (KRIs) and thresholds, monitoring them in collaboration with the Performance Management team.
  • Report and Advise

    • Generate clear risk reports and heat maps for management and the risk committee, articulating changes, significance, and required decisions.
    • Introduce quantitative risk analysis (e.g., FAIR) for top risks to express exposure in financial terms.
    • Configure and operate risk workflows in the GRC platform (e.g., Archer, ServiceNow IRM, MetricStream).

Leadership Capabilities

  • Develop a strong understanding of the organization’s purpose and values, exploring opportunities for impact.
  • Exhibit commitment to personal learning and development, serving as a brand ambassador to attract top talent.
  • Demonstrate personal accountability for keeping performance on track.
  • Focus on cultivating effective communication and relationship-building skills.
  • Understand how daily work contributes to team and business priorities.

Qualifications

  • Experience: 4-8 years total experience.
  • Education: Bachelor's in cybersecurity, IT, risk management, or a related field.
  • Proven experience in designing or significantly improving a cyber or IT risk methodology (Senior level), or managing end-to-end risk assessments (Mid level).
  • Strong knowledge of cybersecurity threats and controls, enabling credible assessment of technical risk.
  • Familiarity with ISO/IEC 27005, NIST SP 800-30, ISO 31000, and NCA ECC guidelines.
  • Proficient in written English for management and risk committee reporting.
  • Experience with a GRC platform (Archer, ServiceNow IRM, MetricStream, or similar) is preferred.
  • Quantitative risk analysis experience (FAIR) is an asset.
  • Experience in linking cyber risk to enterprise risk management in a large organization is preferred.
  • Background in large-scale development, hospitality, financial services, or critical infrastructure is advantageous.
  • Proficiency in Arabic is preferred.
  • Certifications: At least one of the following is preferred: CRISC, ISO/IEC 27005 Risk Manager, CISM; other valuable certifications include Open FAIR, CISSP, ISO 31000 Risk Manager.

Frameworks & Standards

  • NCA ECC-2:2024
  • ISO/IEC 27005:2022
  • ISO 31000:2018
  • NIST SP 800-30 Rev 1
  • NIST SP 800-37 Rev 2
  • NIST CSF 2.0 (Govern – Risk Management)
  • FAIR
Apply Direct

Jobs you might like   View all jobs

About Business Consulting and Services Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct