GRC Specialist (NCSA Certification Support)
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 hours ago
- Work mode
- In office
- Education
- Bachelor’s degree in information security, Cybersecurity or relevant field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Accenture
Accenture empowers leading global enterprises by transforming their digital core and harnessing AI to accelerate value creation across various industries. Our mission is to be the preferred partner for reinvention, driving safe and widespread AI adoption, while fostering a client-centric, AI-enabled, and excellent work environment. With around 786,000 professionals worldwide, proprietary technologies, and extensive industry expertise, we deliver comprehensive solutions that produce measurable results at scale. We serve roughly 9,000 clients and generated close to $70 billion in revenue in FY25.
About Accenture Security
Accenture Security enhances organizations’ capabilities in managing cyber threats by combining deep sector insights, advanced security techniques, and state-of-the-art technologies to safeguard essential assets, comply with regulations, and build robust security frameworks.
Key Duties
Governance
- Create cybersecurity frameworks, policies, procedures, guidelines, and associated documentation.
- Collaborate with stakeholders to review current and proposed cybersecurity policies and documentation.
- Build reporting metrics, key performance indicators, and dashboards to track cybersecurity performance.
- Oversee the consistent application of cybersecurity policies throughout planning and management activities.
- Ensure cybersecurity workforce management practices comply with legal and organizational standards.
- Interpret and implement relevant laws and regulations within cybersecurity policies.
- Offer policy-related guidance to security teams and users.
Risk Management
- Effectively communicate cybersecurity risks and organizational posture to executive leadership.
- Formulate risk mitigation strategies aligned with the organization’s risk appetite.
- Apply sound risk management principles in all cybersecurity decisions.
- Conduct risk analyses for major changes to applications or systems.
- Contribute to the development of risk management frameworks and documentation.
- Identify and manage cybersecurity risks through established governance processes.
- Perform cybersecurity risk assessments and maintain an ongoing risk management program.
- Assign roles responsible for executing the Risk Management Framework.
- Develop and implement organizational risk management strategies, including risk tolerance determination.
- Conduct initial and continuous risk assessments of stakeholder assets.
- Use continuous monitoring tools to maintain situational risk awareness.
- Utilize tools like eGRC and monitoring systems to assess risks effectively.
- Devise methods to monitor and measure risk, compliance, and assurance initiatives.
- Document and assess supply chain risks for critical systems where applicable.
Compliance and Regulation
- Evaluate cybersecurity policies and system configurations to ensure regulatory compliance.
- Detect patterns of non-compliance and identify improvements for documentation and policies.
- Periodically review cybersecurity strategies and policies to align with current laws and regulations.
- Collaborate with stakeholders to address cybersecurity incidents and vulnerabilities.
- Develop processes and audits to ensure third-party service compliance with cybersecurity standards.
- Maintain up-to-date knowledge of relevant legislation, regulations, and accreditation standards.
- Coordinate with regulatory bodies during compliance reviews or investigations.
Qualifications and Skills
- Excellent verbal and written communication and strong interpersonal skills.
- Analytical and creative problem-solving abilities.
- Willingness to travel as required.
- Strong consulting experience with effective stakeholder engagement and relationship management.
- Fluency in both Arabic and English.
- Adept at translating threat environment insights into improved risk management practices.
- Capability to collaborate with leadership to establish a comprehensive cyber risk and compliance approach.
- Experienced in developing and maintaining cybersecurity policies ensuring compliance with legal and contractual obligations.
- Ability to tailor technical communications to various stakeholder understanding levels.
- Knowledgeable in risk assessment, mitigation, and treatment methodologies.
- Familiarity with legal and ethical cybersecurity requirements related to privacy.
- Understanding of cybersecurity threats from emerging technologies and malicious actors.
- Awareness of operational impacts resulting from cybersecurity breaches.
- Familiarity with national cybersecurity regulations such as SAMA CSF, NCA ECC, and globally recognized standards like ISO 27001/27002, NIST, PCI DSS, and ITIL.
Preferred Credentials
- Bachelor’s degree in information security, cybersecurity, or a related field.
- Over five years of relevant experience in similar roles.
- Professional certifications such as CRISC, GRCP, ISO 27001 Lead Implementer, or equivalent.
Minimum education
Bachelor's Degree
Industry
Management Consulting