Manager - Cyber Security - GRC Specialist
EY
Date: 1 week ago
City: Abu Dhabi
Contract type: Full time

Manager - Cyber Security- GRC Specialist
As part of our Cyber Technology Consulting team, you will handle leading and managing Cyber Governance, Risk, and Compliance (GRC) engagements for clients across the MENA region. You will collaborate closely with stakeholders to assess, develop, and enhance cybersecurity governance frameworks, risk management practices, and compliance programs in line with global standards and regulatory requirements. The client base spans diverse sectors and includes collaboration with other teams across Advisory services.
The opportunity
We’re looking manager with strong consulting background and hands-on expertise in implementing enterprise cyber risk and governance programs. This is an exceptional opportunity to work with senior leadership across industries and influence strategic cybersecurity decision-making at the highest levels.
Your Key Responsibilities
We offer a competitive compensation package where you’ll be rewarded based on performance and recognized for the value you bring to our business. Plus, we offer:
The Exceptional EY Experience. It’s Yours To Build.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform, and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.
As part of our Cyber Technology Consulting team, you will handle leading and managing Cyber Governance, Risk, and Compliance (GRC) engagements for clients across the MENA region. You will collaborate closely with stakeholders to assess, develop, and enhance cybersecurity governance frameworks, risk management practices, and compliance programs in line with global standards and regulatory requirements. The client base spans diverse sectors and includes collaboration with other teams across Advisory services.
The opportunity
We’re looking manager with strong consulting background and hands-on expertise in implementing enterprise cyber risk and governance programs. This is an exceptional opportunity to work with senior leadership across industries and influence strategic cybersecurity decision-making at the highest levels.
Your Key Responsibilities
- Lead and deliver end-to-end cyber GRC engagements, including policy and framework development, control assessments, regulatory compliance, and cyber risk assessments.
- Design and implement cybersecurity governance models, risk management processes, and third-party risk programs aligned with leading standards (e.g., ISO 27001, NIST CSF, COBIT, CSA).
- Assess client readiness for local and global regulations such as NCA ECC, SAMA, UAE IA, GDPR, and sector-specific guidelines.
- Manage enterprise cyber risk assessments, maturity assessments, and business impact analyses (BIAs).
- Advise on the implementation and enhancement of GRC tools and technologies (e.g., eGRC platforms).
- Support business development by identifying client needs, preparing proposals, and managing relationships.
- Mentor and coach team members, ensuring professional growth and knowledge sharing across the practice.
- Develop detailed reports, articulate technical findings, and deliver actionable recommendations to both technical teams and executive stakeholders.
- Manage multiple engagements, ensuring timely delivery, quality assurance, and adherence to industry best practices.
- Stay updated with emerging cyber threats, vulnerabilities, and offensive security techniques, and incorporate these insights into client engagements
- Strong understanding of cybersecurity and risk governance principles, regulatory landscapes, and compliance obligations.
- Experience designing and implementing enterprise-wide GRC programs and policies.
- In-depth knowledge of control frameworks (e.g., ISO 27001/2, NIST CSF, NIST 800-53, COBIT, PCI DSS, SWIFT CSCF).
- Familiarity with sector-specific standards (e.g., NCA ECC/SAMA CSF for KSA, UAE IA/NESA, or energy and financial sector mandates).
- Ability to conduct technology and cybersecurity risk assessments for applications, infrastructure and network assets
- Collaborating with other members of the engagement team to plan the engagement and develop work program timelines, risk assessments and other documents/templates.
- Mentor and coach team members, ensuring professional growth and knowledge sharing across the practice.
- Ability to interpret complex technical results and present insights to business stakeholders.
- Strong analytical, problem-solving, and critical-thinking skills.
- Excellent communication and collaboration skills
- A bachelor's or master’s degree in information technology, cyber security etc.
- Excellent communication skills with a consulting mindset.
- 6-7 years of experience in GRC and cyber security assessments
- A valid passport for travel.
- Excellent communication skills with a consulting mindset.
- Industry-recognized certifications such as CISSP, CISM, CRISC, ISO 27001 LA
- Experience working with GRC platforms (e.g., Archer, ServiceNow GRC etc.).
- Familiarity with data privacy regulations (e.g., GDPR, DPD, PDPL).
- Understanding of cyber risk quantification methods (e.g., FAIR, Monte Carlo simulations).
We offer a competitive compensation package where you’ll be rewarded based on performance and recognized for the value you bring to our business. Plus, we offer:
- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
The Exceptional EY Experience. It’s Yours To Build.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform, and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Sales Support Specialist for Refining Catalysts
Ketjen Corporation,
Abu Dhabi
9 hours ago
Are you ready to move your career forward and help shape our company’s and customers’ futures?If you aspire to challenge yourself, work with the best in the industry and join a successful team where you can make a meaningful contribution, then we invite you to join us at Ketjen Corporation, a provider of advanced catalyst solutions to leading producers in...

IT Operations
Dicetek LLC,
Abu Dhabi
16 hours ago
Monitoring critical systems Knowledge in 1st level Troubleshooting Knowledge in payment systems knowledge in Azure or other cloud platforms ATM/ CCDM Knowledge knows how to escalate Issues, coordinate between teams and to maintain reports for management MicroFocus Monitoring Comvault Backup

Senior HR Advisor
Damen,
Abu Dhabi
1 day ago
We offer you an Ocean of Possibilities. Join our family.DAMEN MIDDLE EAST SHARED SERVICESDamen Shipyards Group is established in 1927 and is a 100% Dutch family-owned international group of companies which operates 34 shipbuilding and repair yards, employing 10,000 people worldwide from a divisional structure with 7 divisions and a holding.Damen Middle East Shared Services located in UAE is part...
