Security Consulting Consultant

Accenture


Date: 2 weeks ago
City: Riyadh
Contract type: Full time

Role Title: Cybersecurity Strategy and GRC

Location: Riyadh, Saudi Arabia


About Accenture

Accenture is a global professional services company with leading capabilities in digital, cloud and security. Combining unmatched experience and specialized skills across more than 40 industries, we offer Strategy and Consulting, Song, Technology and Operations services — all powered by the world’s largest network of Advanced Technology and Intelligent Operations centers. Our 744,000 people deliver on the promise of technology and human ingenuity every day, serving clients in more than 120 countries. We embrace the power of change to create value and shared success for our clients, people, shareholders, partners and communities. Visit us at www.accenture.com.

About Accenture Security

Join Accenture Security to pioneer security solutions that blend risk strategy, digital identity, cyber defense, application security and managed services. Using the coolest next-gen tech, you’ll have every chance to stay one step ahead of cybercrime and out-hack the hackers.

Accenture Security provides comprehensive security services – from security strategy development, to business transformation, to managed security services – on demand and at a global scale to help mitigate risks and take full advantage of advanced technologies and proven risk management models. Our experienced team of global security professionals helps businesses understand their risks and build resilience from the inside out, giving them the confidence to focus on what matters most: innovation and business growth.


Responsibilities and Accountabilities:

Risk Management:

  • Effectively communicate Cybersecurity risks and posture to senior management.
  • Develop risk mitigation strategies to effectively manage risk in accordance with organizational risk appetite
  • Ensure that decisions relating to Cybersecurity are based on sound risk management principles
  • Perform risk analysis whenever an application or system undergoes a major change
  • Provide input to the risk management framework and related documentation
  • Ensure Cybersecurity risks are identified and managed appropriately through the organization's risk governance process.
  • Carry out a Cybersecurity risk assessments
  • Work with others to implement and maintain a Cybersecurity risk management program
  • Identify and assign individuals to specific roles associated with the execution of the Risk Management Framework
  • Establish a risk management strategy for the organization that includes a determination of risk tolerance
  • Conduct an initial risk assessment of stakeholder assets and update the risk assessment on an ongoing basis
  • Work with organizational officials to ensure continuous monitoring tool data provides situation awareness of risk levels
  • Use risk management related tools such as eGRC and monitoring tools to assess risks
  • Develop methods to effectively monitor and measure risk, compliance, and assurance efforts.
  • Determine and document supply chain risks for critical system elements, where they exist.

Compliance & Regulation:

  • Analyze the organization's Cybersecurity policies and configurations to evaluate compliance with regulations and organization compliance frameworks
  • Recognize patterns of non-compliance with Cybersecurity policies and related documentation to identify ways to improve the documentation
  • Periodically review Cybersecurity strategy, policies, and related documents to maintain compliance with applicable legislation and regulation
  • Work with stakeholders to resolve Cybersecurity incidents and vulnerability compliance issues
  • Develop methods to effectively monitor and measure risk, compliance, and assurance efforts
  • Develop specifications to ensure that risk, compliance, and assurance efforts conform with Cybersecurity requirements.
  • Monitor and evaluate a system's compliance with Cybersecurity, resilience, and dependability requirements
  • Develop Cybersecurity compliance processes and audits for services provided by third parties
  • Maintain knowledge of applicable legislation, regulation, and accreditation standards and regularly review these to ensure continued organizational compliance
  • Cooperate with relevant regulatory agencies and other legal entities in any compliance reviews or investigations.

Skills and Qualifications:

  • Excellent communication (written and oral) and interpersonal skills
  • Ability to work creatively and analytically in a problem-solving environment
  • Flexibility to travel
  • Consulting, stakeholder engagement and relationship management skills.
  • Fluent in Arabic and English language
  • Ability to effectively communicate insights relating to an organization’s threat environment to improve its risk management posture.
  • Ability to work with the organization's leadership to provide a comprehensive, organization wide approach to address Cybersecurity risk and compliance.
  • Ability to work with the organization's leadership to develop a risk management strategy to address Cybersecurity related risks.
  • Ability to develop and maintain Cybersecurity policies, standards and related documentations to support business strategy and maintain compliance with legislative, regulatory, and contractual obligations.
  • Ability to communicate technical and planning information at the same level as a stakeholder’s understanding.
  • Knowledge and understanding of risk assessment, mitigation, and treatment methods.
  • Knowledge of relevant Cybersecurity aspects of legislative and regulatory requirements, relating to ethics and privacy.
  • Knowledge of Cybersecurity threats and vulnerabilities posed by new technologies and malicious actors.
  • Knowledge and understanding of risk assessment, mitigation, and management methods.
  • Knowledge of the likely operational impact on an organization of Cybersecurity breaches.
  • Knowledge of Cybersecurity authentication, authorization, and access control methods.
  • Knowledge of vulnerabilities in applications and their likely impact.
  • Knowledge of national Cybersecurity laws and regulations such as SAMA CSF, NCA ECC, etc.
  • Knowledge of common information security standards, such as: ISO 27001/27002, NIST, PCI DSS, ITIL, etc.

Preferred Qualifications:

  • Bachelor’s degree in information security, Cybersecurity or relevant.
  • 5+ years of experience in similar position
  • Should be Certified in CRISC, GRCP, ISO 27001 LI or equal certifications

Why join us?

  • We offer a transparent, fast paced approach career progression, with a focus on your strengths and continuous coaching from senior colleagues
  • You will benefit from working alongside Accenture experts who are solving some of the biggest industry challenges with innovative thinking and pioneering tools
  • Flexible work arrangements and a range of benefits including competitive rewards
  • You will have access to state-of-the-art technology that will give you the opportunity to deepen your existing skills even as you help create the latest business trends
  • You will also have opportunities to make a difference to the communities in which we work and live

Next Steps

If this sounds like the ideal role, career and company for you, click below to apply.
To learn more about life @AccentureMiddleEast, follow us on social media and keep up with our latest news.
Accenture Middle East: LinkedIn, Instagram, Facebook, Twitter, YouTube

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

Project Manager

MENA Consultant, Riyadh
16 hours ago
Location: Riyadh, KSA.Years of Experience: 4-6 years.Working Arrangement: on-site.Language Requirements: Fluency in Arabic & English (written and spoken).We are seeking a Project Manager with 4 to 6 years of experience to lead and manage projects within government or large enterprise environments. The ideal candidate will have expertise in project planning, risk management, and scheduling, with a strong ability to track...

Senior Management Consultant

Palladium: Make It Possible, Riyadh
1 day ago
Project Overview And RolePrimary Duties and Responsibilities: Purpose of PositionPalladium is currently recruiting for a Senior Consultant to join our dynamic team in Saudi Arabia focused on delivery of advisory services to government and private sector entities. Senior consultants are integral to every delivery team by taking responsibility for the execution of key workstreams and management of related team members....

AutoCAD Designer

FrontLine Solutions, Riyadh
1 day ago
We are looking to hire AutoCAD Operator with experience in preparation and design of Electrical Drawings, shop drawings, As-built, SLDs, Schematics etc. with minimum 2-3 Years’ experience.Must travel inside kingdom. Need Driving Licenses and Transferable Iqama.