Apply Edge Start your job search

Lead Consultant- GRC

CPX · Abu Dhabi Emirate, United Arab Emirates

Apply & track with Apply Edge

Job Purpose: -The Lead Consultant – Cyber Consulting Services is a senior individual-contributor and delivery-lead role responsible for owning and driving the definition, enforcement, and monitoring of Governance, Risk and Compliance (GRC) and Information Security initiatives for a leading government regulatory entity and its regulated sector. The role holder leads GRC workstreams end-to-end, sets the technical direction and quality standards for deliverables, and acts as the senior point of contact with the client and regulatory stakeholders. Operating within a healthcare regulatory environment, the role ensures compliance with, and continuous improvement of, the Information Security maturity of the organization and its wider regulated sector in alignment with the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and applicable UAE regulatory requirements. The role holder is expected to independently plan and execute programs, guide and quality-assure the work of consultants, and mentor junior team members, without carrying full people-management accountability.

Key Responsibilities

-Own and lead the end-to-end delivery of assigned GRC and Information Security workstreams for the organization and its regulated sector, acting as the senior point of contact with the client and regulatory stakeholders. Plan and sequence activities, set technical direction and quality standards for deliverables, manage workstream risks, dependencies, and timelines, and ensure that milestones are met and outcomes exceed stakeholder expectationsLead the development, implementation, and continuous improvement of Information Security policies, standards, procedures, guidelines, and templates for the organization and its regulated sector, aligned to legal, regulatory, and international best practices, including the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and ISO/IEC 27001.Lead and mature the Information Security Risk Management Program for the organization and its regulated sector; drive risk identification, assessment, treatment, and monitoring, and coordinate with mission assurance programs to manage Information Assurance, Information Security, and Cyber Security risks, escalating significant risks with clear remediation recommendations.Define and execute compliance management initiatives and lead Information Security audits for the organization and its regulated sector. Establish measures to assess operational capabilities, determine compliance and control effectiveness levels, and coordinate audits with internal and external agencies, tracking findings through to closure.Serve as a senior liaison with internal business functions, local and international sector stakeholders, and regulatory bodies on Information Security matters, deviations, exemptions, and incidents, ensuring timely, well-informed, and professionally represented engagement on behalf of the organization.Guide, review, and quality-assure the work of consultants and junior team members within assigned workstreams, providing technical direction, coaching, and constructive feedback. Mentor junior staff to foster growth and a healthy delivery culture, and support resource and knowledge-sharing across the team, without carrying full line-management accountability.Provide expert advisory by reviewing contracts, MoUs, agreements, and documents, and represent Information Security on relevant committees and forums. Define and report performance, deviations, challenges, and risks with remedial proposals, and escalate matters to the Information and Cyber Security Office Leadership as required.Skills/Certifications (Technical & Non-Technical) Advanced understanding of GRC processes, control frameworks, risk assessment methods, and compliance monitoring practices, with a proven ability to lead workstreams and quality-assure deliverables. In-depth, working knowledge of the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and its application, together with familiarity with UAE healthcare regulatory and information security requirements, is mandatory. Preferred certifications: Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); Certified Information Systems Auditor (CISA); Certified in Risk and Information Systems Control (CRISC); ISO/IEC 27001 Lead Implementer or Lead Auditor; ISO 31000 Risk Manager or equivalent; Certified in the Governance of Enterprise IT (CGEIT).Workstream and Delivery Leadership; Risk-Based Thinking; Quality Assurance and Review; Policy and Documentation; Analytical Skills; Stakeholder and Expectation Management; Mentoring and Coaching; Communication; Attention to Detail; Integrity and Confidentiality.Minimum Work Experience & Education: -Minimum of 9 years of experience in governance, risk, compliance, and Information Security, including demonstrable experience leading GRC workstreams or teams and quality-assuring deliverables. A substantial and demonstrable portion of this experience must be within the UAE healthcare sector or a healthcare regulatory environment, and must include cybersecurity, technology risk, regulatory compliance, or audit management activities, along with hands-on experience implementing, assessing, or advising against the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard.Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business Administration, or a related field. A Master’s degree or relevant postgraduate qualification is preferable.