Job Summary
Knowledge Compass Consulting (KCC) seeks a Senior GRC Engineer to deliver Governance, Risk, Compliance, Information Security, Data Privacy, and Business Continuity consulting engagements. The role involves assessing compliance requirements, identifying gaps and risks, developing governance frameworks and policies, and supporting organizations in achieving alignment with international standards and regulatory requirements.
Responsibilities
- Lead and support GRC consulting engagements including gap assessments, risk assessments, compliance reviews, and implementation projects.
- Support implementation and maintenance of management systems based on ISO/IEC 27001, ISO/IEC 27701, ISO 22301, ISO 31000, and ISO/IEC 42001.
- Conduct information security, privacy, operational, and compliance risk assessments and develop risk treatment plans.
- Develop and review policies, procedures, standards, guidelines, risk registers, Statements of Applicability, and compliance documentation.
- Assess client environments against applicable regulatory and contractual requirements.
- Support compliance with data protection and privacy regulations including Jordanian Personal Data Protection requirements and GDPR where applicable.
- Conduct internal audits, compliance assessments, maturity assessments, and control effectiveness reviews.
- Prepare professional assessment reports, executive summaries, dashboards, and client deliverables.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Engineering, Information Systems, or a related discipline.
- Minimum 4–6 years of relevant experience in Governance, Risk, Compliance, Information Security, cybersecurity consulting, or a related field.
- Strong knowledge of ISO/IEC 27001 and information security risk management.
- Practical experience conducting gap assessments, risk assessments, internal audits, or compliance implementation projects.
- Good understanding of security governance, policies, controls, risk treatment, and compliance management.
- Experience with one or more additional frameworks or standards such as ISO 22301, ISO/IEC 27701, ISO 31000, ISO/IEC 42001, NIST CSF, COBIT, PCI DSS, or regional cybersecurity regulations is highly desirable.
- Professional certifications such as ISO/IEC 27001 Lead Implementer, Lead Auditor, CISA, CRISC, CISM, CISSP, or equivalent are preferred.
- Strong analytical, documentation, and report-writing skills.
- Excellent communication and stakeholder-management skills.
- Strong command of English and Arabic, both written and spoken.
We refresh listings regularly, but some roles close early on the source platform.
Country: Jordan
City: Amman
Job Category: Consulting
Job Type: Full Time
Company Name: Knowledge Compass Consulting (KCC)
Seniority level: Mid-Senior level

