Senior Consultant - Tech Consulting - Cybersecurity - GRC - Cairo
EY Cairo, Cairo, Egypt
Professional Services · 10,001+ employees
About the role
You will deliver cybersecurity and technology risk consulting engagements while assessing governance structures and compliance against industry standards. Additionally, you will facilitate stakeholder workshops, develop remediation roadmaps, and mentor junior team members to ensure high-quality project delivery.
What they look for
Requirements
Candidates must hold a bachelor's or master's degree in IT or cybersecurity and possess 3-8 years of relevant experience in risk, compliance, or consulting. Strong communication skills and familiarity with frameworks like NIST and ISO 27001 are essential for this role.
Benefits
Full description
As part of our Cyber Technology Consulting practice, you will support the delivery of cybersecurity governance, technology risk and regulatory compliance programs for leading organizations across the Middle East. You will work closely with other senior consultants, managers and client stakeholders to identify regulatory obligations, perform compliance assessments and support governance initiatives.
The opportunity
We’re looking for consultant/ senior consultant/ assistant manager with strong consulting background and hands-on expertise in implementing enterprise cyber risk and governance programs. This is an exceptional opportunity to work with senior leadership across industries and influence strategic cybersecurity decision-making at the highest levels.
Your key responsibilities
- Deliver cybersecurity and technology risk consulting engagements across various industries.
- Conduct cybersecurity and technology risk assessments covering applications, infrastructure, cloud environments, and business processes. Ability to develop risks, controls, compliance requirements and implementation guidance
- Ability to review regulatory circulars, notices, standards and guidelines and identify applicable technology and cybersecurity obligations
- Perform cybersecurity governance, compliance, maturity, and control effectiveness assessments against industry standards and regulatory requirements.
- Assess and enhance governance structures, risk management frameworks, and cybersecurity operating models.
- Develop and review cybersecurity policies, standards, procedures, and supporting governance documentation.
- Support clients in establishing and improving compliance monitoring, risk management, and assurance programs.
- Conduct gap assessments and develop remediation roadmaps aligned with leading frameworks and regulations.
- Support resilience initiatives including business continuity, disaster recovery, and operational resilience assessments.
- Identify risks, evaluate controls, analyze findings, and provide practical recommendations to improve security and risk posture.
- Develop detailed reports, executive presentations, and management summaries tailored to both technical and business audiences.
- Facilitate stakeholder workshops, interviews, and working sessions with technology, security, risk, and business teams.
- Manage multiple engagements, ensuring timely delivery, quality assurance, and adherence to leading practices.
- Mentor and coach junior team members, contributing to capability development and knowledge sharing across the practice.
- Stay updated on emerging cyber threats, technology trends, regulatory changes, and industry best practices
Skills and attributes for success
- Strong understanding of cybersecurity governance, cybersecurity and technology risk management as well as risk assessment methodologies.
- Experience conducting technology, cybersecurity, and operational risk assessments.
- Knowledge of industry frameworks and standards such as ISO 27001, NIST CSF, NIST 800-53, CIS Controls, COBIT, and ITIL.
- Familiarity with cybersecurity regulations and regulatory compliance requirements across regional (MENA) and international jurisdictions.
- Experience developing and reviewing cybersecurity policies, procedures, standards, and governance documentation.
- Understanding of cyber resilience, business continuity, disaster recovery, and third-party risk management concepts.
- Ability to analyze complex technical and business issues and communicate findings clearly to stakeholders.
- Experience working within consulting environments and managing multiple stakeholder groups.
- Strong analytical, problem-solving, and critical-thinking skills.
- Excellent written, verbal, and presentation skills.
- Ability to work independently while collaborating effectively within multidisciplinary teams.
To qualify for the role, you must have
- A bachelor's or master’s degree in information technology, cyber security etc.
- Excellent communication skills with a consulting mindset.
- 3-8 years of experience in cybersecurity, technology risk, IT risk, compliance, governance, resilience, or consulting services
- A valid passport for travel.
- Excellent communication skills with a consulting mindset.
Ideally, you’ll also have
- Industry-recognized certifications such as CISSP, CRISC, CISM ISO 27001 LA/LI
- Experience working with GRC platforms (e.g., Archer, ServiceNow GRC etc.).
- Familiarity with cloud security, privacy, operational resilience, or third-party risk management programs
- Experience supporting clients in highly regulated sectors such as financial services or government
- Knowledge of regional frameworks and regulations within the Middle East
What we offer
We offer a competitive compensation package where you’ll be rewarded based on performance and recognized for the value you bring to our business. Plus, we offer:
- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
If you can demonstrate that you meet the criteria above, please contact us as soon as possible.
The exceptional EY experience. It’s yours to build.
EY | Shape The Future With Confidence
Similar roles
-
Senior Security Engineer
Commonwealth Bank Bengaluru, Karnataka, India
-
Security Engineer, Vulnerability Management (ACAS/Tenable.sc) - Secret clearance
PGTEK Ogden, Utah, United States · $130K–$160K/yr
-
Security Engineer, GKE
Google Seattle, Washington, United States · $174K–$252K/yr
-
Cybersecurity Incident Response Triage Analyst
Accenture Federal Services Careers Marketplace Arlington, Virginia, United States · $57K–$109K/yr
-
Cybersecurity Incident Response Triage Analyst
Accenture Federal Services Arlington, Virginia, United States · $57K–$109K/yr
-
Information Security Engineer
EverBank Jacksonville, Florida, United States