Cyber Grc Framework Design & Development

 

Description:

We are looking for a skilled Cyber GRC Framework Design & Development professional with expertise in cybersecurity governance, policy development, and compliance framework design. The ideal candidate will have experience creating cybersecurity policies, standards, procedures, and control frameworks aligned with global security standards.

Key Responsibilities
• Design, develop, and maintain cybersecurity policies, standards, procedures, and guidelines.
• Develop and manage enterprise Cyber GRC frameworks and control libraries.
• Map security controls to ISO 27001, NIST CSF, NIST 800-53, CIS Controls, COBIT, and regulatory requirements.
• Conduct policy gap assessments and recommend remediation strategies.
• Create control objectives, testing procedures, evidence requirements, and maturity models.
• Collaborate with IT, Security, Risk, Compliance, and Business teams to develop governance documentation.
• Maintain policy lifecycle, version control, review schedules, and approval workflows.
• Support internal audits, regulatory assessments, and compliance initiatives.
• Develop awareness materials and facilitate policy review workshops.
• Configure and support governance documentation within eGRC platforms.

Required Skills
• 4–6 years of experience in Cybersecurity Governance, Risk & Compliance (GRC).
• Hands-on experience developing cybersecurity policies, standards, procedures, and frameworks.
• Strong knowledge of ISO 27001/27002, NIST CSF, NIST 800-53, CIS Controls, and COBIT.
• Experience with policy mapping, control frameworks, and traceability matrices.
• Excellent technical writing and documentation skills.
• Understanding of Identity & Access Management, Network Security, Cloud Security, Data Protection, Incident Management, Business Continuity, and Third-Party Risk.
• Experience with SharePoint, Microsoft Office, and eGRC platforms is preferred.
Preferred Certifications
• CISM
• ISO 27001 Lead Implementer / Lead Auditor
• CRISC
• COBIT Foundation
• CompTIA Security+
Preferred Industry Experience
• Financial Services & Banking
• Insurance
• Government & Public Sector
• Telecommunications & Critical Infrastructure
• Healthcare & Life Sciences
• Energy & Utilities

Organization ZIVENTRA
Industry IT / Telecom / Software Jobs
Occupational Category Cyber GRC Framework Design and Development
Job Location Doha,Qatar
Shift Type Morning
Job Type Full Time
Gender No Preference
Career Level Experienced Professional
Experience 4 Years
Posted at 2026-07-21 2:08 pm
Expires on 2026-10-19