GRC & Cloud Security Analyst
Listed on 2026-01-13
-
IT/Tech
Cybersecurity
Established in the region for 40 years, PwC has around 12,000 people in 12 countries across the region:
Bahrain, Egypt, Iraq, Jordan, Kuwait, Lebanon, Libya, Oman, the Palestinian territories, Qatar, Saudi Arabia and the United Arab Emirates.
Our regional team operates across the Middle East bringing international experience delivered within the context of the region and its culture. We can bring the collective knowledge and experience of more than 370,000 people across the entire global PwC network in advisory, assurance and tax to help you find the value you are looking for.
A career in our Cyber technology services will allow you to work under the supervision of cyber cybersecurity leadership within the Cyber business unit consulting practice. Use strategic business consulting skills to work with clients through all stages of strategy‑based transformation projects. Provide support on client assignments that help to develop a strategy and then refocus an organisation on making that strategy a reality.
We are a growing team and looking for dynamic, flexible, proactive and hardworking consultants who have a passion for shaping cybersecurity positively in the GCC over the coming years. We have a strong pipeline of large, transformational opportunities with our clients which will provide great opportunities for all our people to step up and play significant and rewarding roles in an entrepreneurial and innovation‑driven environment.
As a Senior Associate, you’ll work as part of a team of problem solvers, helping to solve complex business issues from strategy to execution. PwC Professional skills and responsibilities for this management level include but are not limited to:
Work under the supervision of cybersecurity leadership within the Cyber & Digital Trust business unit consulting practice.
Support in the design and development of cybersecurity programs in different domains including the development of strategy, GRC, architecture, identity and access management and cybersecurity solutions based on leading practices such as NIST, CIS, ISO
27001 and others.
Support the development and implementation of cybersecurity governance, risk and compliance frameworks aligned with NIST CSF, ISO 27001, CIS Controls, and local GCC regulatory requirements (e.g., NCA, SAMA, NESA, TDRA, NDMO).
Conduct cybersecurity risk assessments, maturity assessments, and gap analyses to benchmark client capabilities against industry standards and regulatory expectations.
Develop and refine cybersecurity policies, procedures, standards, and guidelines ensuring alignment with business objectives, compliance mandates and leading practices.
Support audit readiness and certification efforts for frameworks such as ISO 27001 and other related standards.
Design of cybersecurity strategies and roadmaps that balance risk management, business enablement, and digital transformation goals.
Work closely with cross‑functional teams to define target operating models for cybersecurity functions, including governance structures, roles, and performance indicators.
Develop and execute cybersecurity awareness and culture programmes. This includes designing tailored awareness campaigns, executive briefings, training programmes, and behaviour‑change initiatives to foster a culture of digital trust and resilience.
Assist in the design of target technical security architecture for clients with deep understanding and analysis of emerging cybersecurity solutions including, but not limited to, threat intelligence, anti‑advanced persistent threats, DLP, SIEM, next generation firewalls, analytics, enterprise incident response and others.
Support in the implementation of cybersecurity solutions at client premises and be able to work closely with security vendors and system integrators.
Communicate effectively (both verbal and writing) with executives, IT personnel, executives, and business users communities, translating complex cybersecurity concepts into actionable insights.
Support in coordinating, facilitating, and making presentations.
Support in business development activities, including preparation of technical and financial proposals…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).