Resource Requirements (Primary Focus: L2 & L3) Nationality Requirement Must be a Saudi National Educational Background Bachelor's degree or higher in: o Cybersecurity o Information Systems o Computer Science o Computer Engineering o or a related field Professional Experience Minimum 4+ years of professional experience in Cybersecurity Governance, Risk, and Compliance (GRC) Preference for: o L2 Consultants: 5-8 years of experience o L3 Consultants: 9-12 years of experience (as per the attached resource level definitions) Knowledge of Cybersecurity Standards National Standards Strong practical experience with Saudi national cybersecurity frameworks and regulations, including but not limited to: o NCA Essential Cybersecurity Controls (ECC) o CSCC, DCC, CCC, OTCC o National Cybersecurity Strategy (NCS) o National Data Management Office (NDMO) o Personal Data Protection Law (PDPL) International Standards Good working knowledge of international frameworks and standards such as: o ISO/IEC 27001 o NIST o CIS Controls o PCI DSS o GDPR Certifications: One or more relevant certifications are preferred, including: o ISO/IEC 27001 Lead Auditor / Lead Implementer o GCCC o CISSP o CISM o CISA Candidates actively pursuing relevant certifications are also welcome. Communication & Professional Conduct Strong communication skills, with the ability to clearly articulate complex cybersecurity concepts to diverse stakeholders Proven ability to collaborate effectively within a multi stakeholder environment (e.g., SITE teams) High standards of professionalism, customer engagement, and confidentiality Ability to handle sensitive situations with discretion and diplomacy