Company logo hidden

Consultant - Manager | Cyber Operate | Third-Party Risk Assessor | KSA

Unlock employer Saudi Arabia Direct to Company 1 hour ago · 08 Oct 2026

Financial

  • Estimate: $50k - $100k*
  • Zero income tax location

Accessibility

  • Visa Provided

Requirements

  • Experience: Intermediate
  • English: Professional
  • Arabic: Preferred

Position

About the Role / About the Job
Join us as a Consultant – Manager where you will contribute to the third-party risk management (TPRM) framework. You will have the responsibility of designing and maintaining the framework, ensuring organizational protection against cybersecurity risks associated with third-party engagements. This position requires a blend of technical acumen and strategic thinking to effectively assess, manage, and mitigate risks throughout the lifecycle of third-party relationships.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Key Responsibilities
Design and Maintain the TPRM Framework

  • Design the third-party and supply chain cybersecurity risk management framework, encompassing scope, roles, and responsibilities (RACI) across various teams.
  • Develop and maintain the third-party cybersecurity policy and associated processes across all lifecycle stages: intake, tiering, due diligence, contracting, onboarding, monitoring, reassessment, issue management, exceptions, and offboarding.
  • Create a supporting toolkit that includes tiered questionnaires, evidence checklists, assessment templates, standard contract clauses, and security requirements schedules for suppliers.
  • Integrate TPRM steps into procurement and contract management processes to ensure that high-risk suppliers undergo necessary cybersecurity assessments before onboarding.
  • Define key performance indicators (KPIs) and key risk indicators (KRIs), maintaining regular updates to the framework in line with new regulatory requirements and lessons learned.

Run the Third-Party Risk Lifecycle

  • Tier third parties based on inherent risk, considering data sensitivity, system access, service criticality, and geographic location.
  • Conduct due diligence prior to onboarding and before contract renewals, proportionate to the tier risk.
  • Manage periodic reassessments and ensure secure offboarding of third parties, including access removal and data handling protocols.

Assess Third Parties

  • Issue and evaluate security questionnaires, critically assessing responses against supporting evidence rather than taking them at face value.
  • Review essential security evidence including ISO/IEC 27001 certificates, SOC 2 reports, penetration test summaries, policies, and incident histories to identify gaps and vulnerabilities.
  • Conduct on-site and remote assessments of high-risk suppliers, focusing on their data protection measures.
  • Assess cloud and SaaS providers against regulatory standards and cybersecurity best practices.
  • Evaluate contractors with access to IT and OT systems and review their adherence to security standards.

Manage Supply Chain Cybersecurity Risk

  • Map critical supply chains and identify single points of failure and concentration risks related to suppliers.
  • Establish secure development requirements for software supply chains and hardware delivered by vendors.
  • Collaborate with suppliers to ensure their preparedness for incident responses and business continuity measures.
  • Coordinate organizational responses to supplier breaches and vulnerabilities following recognized frameworks.

Make Contracts Protect the Organization

  • Define and integrate cybersecurity requirements into contracts in collaboration with Procurement and Legal teams.
  • Assess contracts and statements of work for high-risk suppliers to ensure compliance with documented risk findings.

Track, Monitor and Report

  • Track remediation actions and escalate cases where suppliers lack adequate responses.
  • Continuously monitor critical suppliers for potential breaches and performance issues.
  • Maintain the third-party inventory and risk register and report findings related to third-party risk to management.

Leadership Capabilities

  • Pursue an understanding of organizational purpose and values, exploring impact opportunities.
  • Demonstrate commitment to personal development while acting as a brand ambassador.
  • Exhibit personal accountability and effective relationship-building skills.

Qualifications

  • 2-8 years of relevant experience.
  • Bachelor’s degree in IT, cybersecurity, or a related field.
  • Practical experience assessing vendor cybersecurity against established standards (e.g., ISO/IEC 27001, NIST, NCA).
  • Experience designing or updating TPRM frameworks and related policies/procedures.
  • Ability to critically analyze SOC 2 reports and relevant security documentation.
  • Knowledge of supply chain risks and associated cybersecurity threats.
  • Understanding of technical controls related to cloud data protection and access management.
  • Familiarity with TPRM platforms and security rating services.
  • Proficiency in written English for reports and supplier communications.
  • Experience in IT audit or procurement risk analysis is a plus.
  • Preferred certifications include CTPRP, CISA, ISO/IEC 27001 Lead Auditor, with additional certifications valued including CTPRA, CRISC, CCSK, and CDPSE.
  • Familiarity with NCA ECC third-party and cloud requirements, and related cybersecurity frameworks.
Apply Direct

Jobs you might like   View all jobs

About Business Consulting and Services Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct