Apply Edge Start your job search

Manager - GRC

CPX · Abu Dhabi Emirate, United Arab Emirates

Apply & track with Apply Edge

The Manager – Cyber Consulting Services is a techno-functional leadership role responsible for the high-quality, hands-on delivery of Governance, Risk and Compliance (GRC) advisory and GRC technology enablement engagements for a leading government regulatory entity and its regulated sector. The role leads the on-the-ground design, implementation, configuration, and operationalization of enterprise GRC (eGRC/IRM) platforms and GRC transformation initiatives, ensuring that functional GRC requirements are effectively translated into automated, sustainable, and compliant technology solutions. Operating within a healthcare regulatory environment, the role holder is expected to align delivery with the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and applicable UAE regulatory requirements, while managing project teams, mentoring staff, supporting business development, and ensuring adherence to enterprise and Sub-Business Unit (SBU) policies.

Key Responsibilities

-Act as the technical single point of contact for assigned GRC and technology enablement engagements, or as part of a team of managers, senior managers, and consultants. Lead the hands-on, on-the-ground delivery of high-quality deliverables covering the design, deployment, configuration, integration, and operationalization of eGRC/IRM platforms and GRC transformation initiatives. Work closely with the delivery team, project managers, and the client to ensure project risks and issues are understood and effectively managed, key milestones are met, quality standards are upheld, and customer satisfaction is exceeded.Translate functional GRC requirements into automated technology solutions by analysing, designing, and enabling governance, risk, and compliance processes across the organization and its regulated sector. Advise on and operationalize risk management, compliance management, policy management, internal / external audit, third-party/vendor risk, and business continuity workflows, ensuring alignment with the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard, ISO/IEC 27001, ISO 27701, and applicable UAE regulatory and information security requirements.Lead the end-to-end implementation, configuration, and administration of enterprise GRC (eGRC/IRM) platforms, including requirements gathering, solution design, workflow and use-case build, data migration, integrations, testing, deployment, and post-go-live support. Configure risk registers, control libraries, assessment workflows, dashboards, and reporting to meet functional GRC and regulatory needs, and provide ongoing platform optimization, automation, and operational support to ensure sustainable, high-value outcomes.Support the business function leadership and enterprise pre-sales team with proposal development within the GRC and technology enablement domain. Contribute to thought leadership by writing blogs, case studies, or whitepapers that support marketing drives relating to the service portfolio.Mentor more junior staff on projects to foster growth, positive morale, and a healthy business culture, and may hold direct people-management responsibilities. These responsibilities include: setting performance objectives to facilitate lateral and vertical growth; providing fair and constructive performance evaluations; implementing training and development plans for staff; managing and resolving project team conflicts; fostering a culture of effective stakeholder and expectation management; and supporting other Sub-Business Units with resources when needed, where possible.Skills/Certifications (Technical & Non-Technical)Strong techno-functional understanding of GRC processes, control frameworks, risk assessment methods, and compliance monitoring practices, combined with hands-on expertise in implementing, configuring, and managing enterprise GRC (eGRC/IRM) platforms. Technical certifications in leading GRC/IRM and privacy platforms (e.g., Archer, ServiceNow IRM/GRC, MetricStream, OneTrust, BigID) are strongly preferred. In-depth, working knowledge of the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard and its application, together with familiarity with UAE healthcare regulatory and information security requirements, is mandatory. Preferred certifications: ISO/IEC 27001 Lead Implementer or Lead Auditor; ISO/IEC 27701 Lead Implementer or Lead Auditor; ISO 22301 Lead Implementer or Lead Auditor; Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); Certified Information Systems Auditor (CISA); Certified in Risk and Information Systems Control (CRISC); CIPP/CIPM. Project management certifications (e.g., PMP, PRINCE2) and other industry certifications are a plus.Techno-Functional GRC Acumen; eGRC/IRM Platform Configuration; Risk-Based Thinking; Solution Design and Delivery; Project and Team Management; Policy and Documentation; Analytical Skills; Stakeholder and Expectation Management; Communication; Mentoring and People Leadership; Attention to Detail; Integrity and Confidentiality.Minimum Work Experience & Education : -Minimum of 10 years of Information Security and GRC experience, with a specific focus on the deployment, implementation, configuration, and operations of enterprise GRC (eGRC/IRM) platforms and GRC transformation initiatives. include client-facing cyber consulting experience across topics such as enterprise, operational, and information security risk management, compliance management, data privacy, internal audit, and business continuity management. A substantial and demonstrable portion of this experience must be within the UAE healthcare sector or a healthcare regulatory environment, including hands-on experience implementing, assessing, or advising against the Abu Dhabi Healthcare Information and Cyber Security (ADHICS) Standard. Prior experience in a project or team leadership capacity is required.Bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a Business-related field, or an equivalent qualification (a Diploma with additional relevant experience may be considered). An MBA or Master’s degree in Computer Science, Engineering, or Information Security is preferable