Cyber Security Specialist
AA Consultant Group · Saudi Arabia
Apply & track with Apply EdgePosition OverviewWe are looking for a GRC Security Specialist to join our Cyber Security Services (MSSP) cluster part of Infrastructure (INFRA) Services Division.Start date: October 2026Duration: 12-18 months & Extendable Working model: full-time, remote, Working hours / time zone: Egypt, KSA, or UAE, with a preference for EgyptLanguages: English + Arabic or English + FrenchKey Responsibilities
- Develop, review, and maintain information security policies, procedures, standards, and guidelines in alignment with business goals and regulatory requirements.
- Promote security awareness across the organization and assist in designing training programs.
- Coordinate and facilitate internal and external security audits (e.g., SOC 2, ISO 27001, PCI-DSS, HIPAA, GDPR).
- Conduct regular internal assessments to identify compliance gaps and drive remediation efforts with technical teams.
- Perform security risk assessments on internal systems, business processes, and infrastructure.
- Manage the third-party/vendor risk management program by evaluating the security posture of critical vendors and SaaS tools.
- Maintain the IT/Security Risk Register, ensuring all identified risks are documented, tracked, and remediated or formally accepted.Job Requirement:
- Experience: 3–5 years of experience in information security, IT audit, or a GRC-specific role.
- Knowledge Base: Strong understanding of security frameworks and regulations (e.g., NIST CSF, ISO/IEC 27001, SOC 2, CIS Controls, GDPR).
- Certifications (Preferred): CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control), CISM (Certified Information Security Manager), or CompTIA Security+.Preferred Qualifications
- Technical cybersecurity knowledge or prior experience in SOC.
- Understanding of enterprise IT workplace environments, TCP/IP networks also with available security controls (technical & process control) for respective layers.
- Certification like CISM, CRISC, CGEIT, CISSP or similar.
- Up to date with NIS2 directive or/and course/training completion in this direction.