Cybersecurity Advisory & Assurance Lead
Company Description
CNS is a technology company that powers the future by providing digital solutions essential to support all enterprise and human development. While growing and managing a robust pool of supplier-partners for the benefit of our clients has always been a priority, we are constantly re-inventing ourselves.
Founded in 1987 with more than 30 years of experience, CNS employs over 320 employees including more than 250 certified engineers. We offer in-depth expertise and a range of best-in-class products that support the digital transformation of all major industries. With offices in three countries, we have an extensive reach into, and regional knowledge of the Middle East markets.
A shift into levering our many years of experience to develop pioneering software in-house will add yet another dimension to our highly innovative solutions-portfolio.
Job Description
The Cybersecurity Advisory & Assurance Lead is a senior, hands-on cybersecurity professional responsible for leading complex cybersecurity assessments, advisory engagements and transformation programmes for enterprise and government customers.The role independently leads comprehensive, framework-based assessments (NIST CSF, NIST SP 800-series, ISO/IEC 27001, CIS Controls and applicable UAE/GCC regulatory requirements), taking engagements from initial customer workshops and evidence collection through technical assessment, control testing, maturity evaluation, gap analysis, risk identification, target-state design, remediation planning and executive presentation.Drawing on broad expertise across defensive security, offensive security, governance, risk and compliance (GRC), security architecture and security operations, the jobholder acts as a technically credible adviser to CISOs, SOC, infrastructure, cloud and architecture teams, and senior management.
DUTIES & RESPONSIBILITIES:
- Lead enterprise-wide cybersecurity maturity and capability assessments, including NIST CSF-based current-state and target-state assessments covering governance and the Identify, Protect, Detect, Respond and Recover functions.
- Conduct control design and operating-effectiveness assessments, evaluating whether technical controls are effectively implemented rather than relying solely on policy documentation.
- Review cybersecurity policies, standards, procedures and operating models, and evaluate them against NIST CSF, NIST SP 800-series, ISO/IEC 27001/27002, CIS Critical Security Controls, UAE Information Assurance requirements, UAE/GCC cybersecurity regulations, PCI DSS, SWIFT CSP, cloud security frameworks and sector-specific requirements.
- Assess and advise on defensive security and SOC capabilities, including SOC operating models, SIEM and security monitoring, EDR/XDR, detection engineering, threat intelligence, threat hunting, security logging, incident response, vulnerability management, IAM/PAM, network, endpoint, email and web security, ransomware resilience, cyber crisis management, and business continuity and cyber recovery.
- Assess security architecture across enterprise infrastructure, cloud and hybrid environments, network, identity, endpoint, data, application security, security monitoring and, where applicable, OT/ICS environments.
- Assess the effectiveness and maturity of cybersecurity processes, including asset, risk, vulnerability, patch and change management, identity lifecycle and privileged access management, security monitoring, incident response, third-party risk, secure development, threat management, security architecture governance, data protection, business continuity and cyber recovery.
- Scope, challenge and interpret penetration-testing and red-team assessments; review vulnerability and penetration-testing results and assess vulnerability management and remediation processes.
- Validate whether technical findings represent material business risks and work with offensive-security specialists to translate them into risk and remediation programmes, supporting purple-team and control-validation activities where required.
- Conduct cybersecurity governance and cyber-risk assessments, assess governance structures and accountability, evaluate cyber-risk management methodologies, support regulatory and compliance readiness, and map controls across multiple regulatory frameworks.
- Identify security gaps, risks, control weaknesses and capability deficiencies, and develop prioritised remediation roadmaps and cybersecurity improvement programmes.
- Develop maturity models, heatmaps, risk registers and management dashboards, and produce executive, management and detailed technical assessment reports.
- Present findings and recommendations to CISOs, CIOs, executives and governance committees, translating highly technical issues into business-risk language and practical remediation recommendations.
- Lead customer workshops and stakeholder interviews; define assessment methodologies and evidence requirements, and maintain evidence traceability between findings and conclusions.
- Manage assessment workstreams and guide junior consultants, challenging customer assumptions professionally and constructively.
- Support proposals, RFP responses, statements of work and customer presentations, and assist Account Managers in identifying follow-on cybersecurity opportunities.
Qualifications
Education
Required:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems or Engineering (Electronics, Computer or Telecom).
Desirable:
- Master's degree such as an MSc in Cybersecurity or Information Security, or an MBA with a technology focus. For a lead role this is a plus, not usually a must.
- Professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor / Lead Implementer, CISA, CCSP, GIAC or NIST-related training/certification
- Technical/offensive certifications such as OSCP, PNPT or CEH (or equivalent practical experience)
Experience
Required:
- 8 years of cybersecurity experience spanning multiple disciplines
- Demonstrable experience leading enterprise cybersecurity assessments
- Experience conducting stakeholder interviews and evidence-based assessments
- Experience producing executive-level reports and presenting to senior customer stakeholders
Desirable:
- 12+ years of cybersecurity experience
- Experience in government, critical infrastructure, financial services, aviation, energy or other highly regulated sectors
Additional Information
Skills & Abilities
Required:
- Strong practical knowledge of NIST CSF, ISO 27001 and cybersecurity control frameworks
- Strong understanding of SOC/security operations, security architecture and enterprise controls
- Working knowledge of offensive-security methodology
- Understanding of major cybersecurity technology categories
- Excellent report writing, workshop facilitation and executive communication
- Ability to work independently and move between technical, operational and governance discussions
Desirable:
- Knowledge of UAE Information Assurance and GCC cybersecurity regulations
- Experience with PCI DSS, SWIFT CSP and cloud security frameworks
- Exposure to OT/ICS security assessments
Compliance with policies and procedures based on the ISO standards adopted by CNS.