Location
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Riyadh
About the Role
As a Senior Consultant/Manager specializing in Cyber Operate Governance and PMO, you will be integral in shaping and maintaining the cybersecurity governance framework and leading program management for large-scale initiatives. You will design vital policies, oversee governance bodies, and ensure quality assurance across deliverables while meeting compliance standards such as NCA ECC and ISO/IEC 27001.
Responsibilities
You will demonstrate and develop capabilities in the following areas:
-
Design and Maintain the Governance Framework
- Design the cybersecurity governance framework, including governance structure, decision rights, roles, and RACI across the CISO office, IT, OT, risk, legal, procurement, and business units.
- Write and maintain the cybersecurity policy framework, ensuring alignment with NCA ECC-2:2024 and applicable controls.
- Manage the document lifecycle, including drafting, stakeholder review, approval, publication, communication, periodic review, and version control.
- Maintain the ISMS governance components toward ISO/IEC 27001:2022.
- Define and keep current the cybersecurity roles and responsibilities matrix required by NCA ECC.
-
Run Governance Bodies
- Establish and manage the cybersecurity steering committee and working groups, including charters, memberships, meeting schedules, agendas, and decision tracking.
- Prepare focused documents for executives and ensure timely follow-up on decisions and actions.
-
Run the Programme Management Office
- Build and maintain the integrated programme plan with milestones, dependencies, and critical paths.
- Manage the RAID log (risks, assumptions, issues, dependencies) and escalate blockers with potential solutions.
- Oversee change control for scope, schedule, and resources.
- Track resources, onboarding, timesheets, and budgets against the programme plans.
- Provide status reporting through dashboards and executive summaries for leadership.
- Coordinate with various offices to ensure smooth workflows across the programme.
-
Assure Quality and Delivery
- Set programme standards for deliverables, including templates, quality review processes, and acceptance criteria.
- Conduct quality reviews and manage the submission and formal acceptance of deliverables.
- Maintain a comprehensive programme document repository for audits and regulators.
Leadership Capabilities
- Builds understanding of our purpose and values; identifies opportunities for impact.
- Demonstrates commitment to personal learning and development and acts as a brand ambassador attracting talent.
- Maintains accountability for performance tracking.
- Focuses on developing effective communication and relationship-building skills.
- Connects daily work to broader team and business priorities.
Qualifications
- 5-10 years of experience in relevant roles.
- Bachelor's degree in cybersecurity, IT, business, or a related field.
- Experience designing or updating cybersecurity governance frameworks or policy suites.
- Proven programme management experience in large, multi-workstream programmes, including planning, RAID, change control, and status reporting.
- Knowledge of NCA ECC, ISO/IEC 27001, and NIST CSF 2.0.
- Strong skills in stakeholder management and executive reporting.
- Excellent written communication skills in English.
- Experience setting up and running steering committees in Saudi government or large private entities.
- Proficiency with planning tools (MS Project, Primavera, Smartsheet) and Power BI dashboards.
- Experience coordinating with service management (ITIL) functions.
- Consulting background is preferred.
- Arabic language proficiency is a plus.
- At least one of the following certifications is preferred: PMP, CISM, CGEIT.
- Valued certifications include: PgMP, PRINCE2 / MSP, ISO/IEC 27001 Lead Implementer, COBIT.
Contracts and Travel
Travel requirements and contract specifics will be outlined upon engagement. Expect potential travels depending on project needs and client locations.