Title: Cyber Security Technical GRC
Company Name: Info Stream
Vacancy: 1
Age: Na
Job Location: Anywhere in Bangladesh
Salary: Negotiable
Experience: --
Published: 2026-10-05
Application Deadline: 2026-11-04
Education:
Requirements: --
Skills Required:
Additional Requirements:
Responsibilities & Context:
Role Summary
We are looking for a Cyber Security GRC Consultant who combines governance and compliance expertise with hands-on technical skills in penetration testing and vulnerability assessment. You will lead compliance engagements from gap assessment to audit readiness. You will also validate controls technically and produce clear, audit-ready documentation and reports for both executive and technical readers.
This role suits someone who writes as well as they hack: able to turn a complex finding or control requirement into a precise, defensible document.
Key Responsibilities
Compliance consulting and delivery
Lead and deliver PCI DSS (v4.0.x) engagements: scoping, CDE identification, network segmentation review, gap assessment, remediation roadmaps, and readiness for QSA assessment, SAQ or ROC.
Implement and assess compliance with ISO/IEC 27001:2022, including risk assessment, Statement of Applicability, internal audits and certification readiness.
Perform gap assessments and implementation support against NCA ECC, Aramco CCC (Third-Party Cybersecurity Standard) and the SAMA Cyber Security Framework, and cross-map controls across frameworks to avoid duplicated effort.
Support clients through external audits, certification and regulator assessments.
Governance, risk and documentation
Develop and review policies, standards, procedures, risk registers, asset inventories, incident response plans, BCP/DR documentation and evidence repositories.
Run risk assessments and maintain treatment plans aligned to client business context.
Build compliance matrices, control mappings, dashboards and management reports.
Technical security assessment
Conduct or technically oversee vulnerability assessments (network, systems, cloud, applications) and penetration tests (internal, external, web, API, wireless).
Validate the technical controls behind compliance requirements, such as segmentation, hardening, logging and monitoring, access control, encryption and patch management.
Review firewall, endpoint and network security configurations (e.g., Fortinet, Palo Alto, Cisco, Sophos, CrowdStrike, SentinelOne, Microsoft Defender).
Translate technical findings into risk-ranked, actionable remediation guidance, and re-test fixes.
Reporting and client engagement
Produce high-quality reports in English: executive summaries, technical findings, compliance gap reports and remediation plans.
Present findings and progress to CISOs, IT leads, compliance officers and board-level stakeholders.
Act as a trusted advisor throughout the engagement, and support pre-sales activities such as scoping, proposals and technical solution input.
Internal contribution
Help build InfoStream's GRC methodology, templates, toolkits and reusable documentation.
Mentor junior consultants and security analysts.
Keep current with changes in Saudi regulations (NCA, SAMA, CST, SDAIA/PDPL) and international standards.
Required Qualifications
Bachelor's degree in Cyber Security, Information Security, Computer Science, IT or a related field.
5+ years of experience in cyber security GRC, with at least 2 years in hands-on technical security testing (VA/PT).
Proven delivery of PCI DSS and ISO 27001 projects, with working knowledge of at least two of NCA ECC, SAMA CSF and Aramco CCC.
Strong command of VA/PT methodology and tools (e.g., Nessus, Qualys, Burp Suite, Nmap, Metasploit, Kali toolset) and frameworks such as OWASP, PTES and NIST SP 800-115.
Exceptional written communication: policy drafting, audit evidence handling and technical report writing, with a portfolio or sample reports you can discuss (anonymised).
Strong understanding of network, cloud, identity and endpoint security fundamentals.
Fluent professional English.
Preferred Certifications
At least one from each category is expected, and more is a strong advantage.
Area Certifications
GRC / audit / management CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer / Lead Auditor
Payment security PCI Professional (PCIP), PCI ISA, or QSA-qualified (a major plus)
Offensive / technical OSCP, GPEN, CEH, CompTIA PenTest+, eJPT/eCPPT
Other relevant CCSP, GRCP, CDPSE, CompTIA Security+ (entry-level baseline)
Desirable Skills
Experience in banking, fintech, government, oil and gas, or critical infrastructure environments in Saudi Arabia or the GCC.
Knowledge of PDPL, CST Cloud Cybersecurity Controls, and the NCA CCC/OTCC/DCC family.
Familiarity with GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust, Vanta/Drata-type tools).
Scripting ability (Python, PowerShell, Bash) for automation and evidence collection.
Experience in a consulting or professional-services environment with multiple concurrent client engagements.
Key Competencies
Meticulous attention to detail and strong analytical judgement
Structured, audit-ready documentation discipline
Clear communication with both technical and non-technical audiences
Ownership, client focus and ability to manage deadlines across parallel projects
Integrity and discretion when handling sensitive client data