Manager – Cybersecurity GRC & Advisory
Location: Dubai, UAE – Hybrid with regular client site work in Saudi Arabia, Kuwait, GCC
Employment: Full-time
Business: Axon Technologies – Cybersecurity Advisory
Axon Technologies is expanding its Cybersecurity Advisory team and is looking for an experienced
Manager – Cybersecurity GRC & Advisory to deliver client engagements across Saudi Arabia and the wider GCC.
This is a hands-on, client-facing role for someone who combines deep governance, risk and compliance expertise with security architecture literacy, strong writing skills and the confidence to advise CISOs, architects and executive stakeholders directly.
At Axon, we are outcome-led. We help financial institutions, government entities and critical-infrastructure organisations understand their risk, meet regulatory expectations and build security capabilities that last. Our work spans cybersecurity strategy, virtual CISO services, regulatory compliance (such as NCA, SAMA, ISO 27001), security assessments, SOC and threat-intelligence operating models, and enterprise security architecture.
The opportunity
As a Manager, you will own client deliverables from day one on live engagements with a leading Saudi bank, a major real-estate and smart-city developer and an engineering consultancy. You will act as virtual CISO, lead security and business-impact assessments, author SOC and CTI operating documentation, and contribute to enterprise security architecture built on SABSA and TOGAF.
The role offers direct exposure to CISOs, chief architects and executive stakeholders, the chance to shape Axon's growing advisory practice in Saudi Arabia, and a clear path toward practice leadership for high-performing individuals.
Key responsibilities
- Deliver cybersecurity advisory engagements from mobilisation through to client sign-off.
- Act as a trusted advisor and virtual CISO to clients, including CISOs, security architects, SOC leads, risk, compliance and business stakeholders.
- Plan and run stakeholder interviews and workshops for business impact assessments, risk assessments and security architecture reviews.
- Develop cybersecurity strategies, roadmaps, risk registers and leadership reporting.
- Assess security posture and control maturity against NCA ECC/CSCC, SAMA CSF, ISO 27001 and NIST, and build practical remediation plans.
- Author and review SOC and threat-intelligence policies, procedures, playbooks, runbooks, KPIs and operating-model documentation.
- Contribute to enterprise security reference architectures, business attribute taxonomies and architecture deliverables aligned to SABSA and TOGAF.
- Design and deliver cybersecurity awareness programmes for client staff and leadership.
- Translate regulatory requirements and complex findings into clear, client-ready documents and presentations.
- Manage workplans, deliverable trackers, document request registers, risks and client expectations across parallel engagements.
- Contribute to proposals, RFP responses, thought leadership and the continued development of Axon's advisory services.
- Mentor junior consultants and improve Axon's delivery templates and accelerators.
What we are looking for
- Approximately 7-12 years of experience** in cybersecurity, with at least 5 years in GRC or advisory consulting.
- Demonstrable experience delivering consulting engagements in Saudi Arabia or the wider GCC for government, financial-services or critical-infrastructure clients.
- Strong working knowledge of regional and international regulation and framework like NCA ECC and CSCC, the SAMA Cybersecurity Framework, ISO 27001 and NIST CSF / 800-53.
- Experience acting as vCISO, security manager or equivalent: risk registers, roadmaps and board-level reporting.
- Hands-on experience with business impact assessments and risk assessments run through stakeholder interviews.
- Enough SOC and CTI understanding to write and review operating procedures, playbooks and KPIs credibly.
- Exposure to security architecture documentation and familiarity with SABSA and/or TOGAF.
- Excellent technical writing; able to produce polished Word, Excel and PowerPoint deliverables without supervision.
- Strong workshop facilitation and stakeholder management skills at CISO and architect level.
- CISSP or CISM certification.
- Strong written and verbal communication skills in English.
- Willingness to travel regularly to Riyadh and work to the Saudi business week.
Desirable experience
- Previous experience with a Big Four firm, a global systems integrator or a specialist cybersecurity consultancy.
- ISO 27001:2022 ISMS implementation as lead consultant, and ISO 27001 Lead Auditor or Lead Implementer certification.
- PCI DSS compliance or remediation programmes, ideally in banking.
- NCA OTCC reviews and other OT / critical-infrastructure security work.
- Third-party and vendor security assessments, maturity and gap assessments, and cybersecurity KPI framework development.
- GRC pre-sales experience: service portfolio development, proposal writing and effort estimation.
- SABSA SCF, TOGAF, CRISC, CISA or PMP certifications
- A technical foundation in network security and SIEM tooling (e.g. Nessus, Nipper, AlienVault, McAfee ESM) to hold credible conversations with SOC engineers.
- Arabic language skills.
What Axon offers
- A senior, highly visible delivery role in a rapidly growing specialist consultancy.
- Immediate ownership of live engagements with tier-one clients in Saudi Arabia.
- Direct exposure to CISO, chief-architect and executive-level stakeholders.
- The opportunity to help build and shape Axon's cybersecurity advisory practice in across the GCC region.
- Rapid progression for high-performing individuals.
- Competitive compensation with meaningful performance-related upside.
- A flexible hybrid working model across GCC and Dubai.
- The opportunity to work across Axon's wider cybersecurity, anti-fraud and operational resilience services.
This role is suited to someone who wants more than a traditional consulting position — someone who wants to own client outcomes, work at the intersection of governance and architecture, and play a meaningful role in the growth of a specialist firm.
To apply: Please submit your CV through LinkedIn, together with a short note outlining your relevant GRC advisory and client delivery experience in the GCC. Immediate availability is a strong advantage.