—
• Lead GRC engagements including risk assessments, compliance gap analyses, and governance framework design for public and private sector clients.
• Design and implement GRC frameworks aligned to international standards (ISO 27001, NIST CSF, COBIT, NCA ECC, SAMA).
• Advise clients on regulatory compliance requirements across MENA jurisdictions and support remediation roadmap development.
• Lead internal audit reviews and third-party risk assessments; present findings to executive steering committees.
• Mentor junior team members and manage engagement workplans, budgets, and client relationships.
• Bachelor's or Master's degree in Information Security, Law, Business Administration, or related field.
• 7-10 years of GRC consulting or in-house risk/compliance experience.
• Professional certification required: CISM, CISA, CRISC, CIA, or ISO 27001 Lead Auditor/Implementer.
• Deep knowledge of MENA regulatory landscape (NCA, SAMA, PDPL, ADSIC) is a strong differentiator.
• Demonstrated experience presenting to C-suite and board-level audiences.
• Competitive salary and performance-based bonus scheme.
• Flexible and hybrid working arrangements.
• Continuous learning budget and access to Yellomind Academy programmes.
• Health and wellness coverage.
• International exposure through cross-border client engagements across MENA & Africa.
• Clear career progression framework with mentorship support.
• Dynamic, collaborative team culture driven by innovation and excellence.