Director - Cyber Consulting Services (CPX)
Date: 30 Sept 2026
Location: MBZ City, Abu Dhabi, AE
Company: G Forty Two General Trading LLC
Overview:
The Director – GRC Services leads the governance, risk and compliance advisory practice, holding overall accountability for service delivery, client relationships, commercial performance and people leadership across the practice. The role sets the strategic direction for GRC offerings, oversees the quality of engagements delivered to clients across regulated and unregulated sectors, and acts as the senior point of escalation on technical, commercial and risk matters. Reporting to the Executive Director – CCS, the Director translates the firm’s growth strategy into a high-performing, profitable and scalable GRC service line.
Responsibilities:
- Define and execute the strategy, service portfolio and go-to-market plan for the GRC Services line in alignment with the firm’s overall advisory strategy.
- Own the practice profit-and-loss, including revenue targets, utilization, margin, pricing and resource planning.
- Identify emerging regulatory, governance and risk themes (e.g. ESG, data protection, AI governance) and shape new propositions and methodologies in response. Represent the firm and the GRC practice in the market through thought leadership, industry forums, regulator engagement and speaking opportunities
- Build and maintain trusted-advisor relationships with C-suite, board and audit-committee stakeholders across client organizations.
- Lead origination and conversion of new business, including proposals, pitches, scoping and commercial negotiation.
- Drive cross-selling across other advisory and assurance service lines and manage a portfolio of strategic accounts.
- Hold ultimate delivery accountability for GRC engagements, including governance reviews, enterprise risk management, regulatory compliance, internal controls, policy frameworks and risk transformation programmes.
- Review and approve key deliverables, ensuring technical accuracy, methodological rigor and alignment with applicable standards and regulations (e.g. ISO 31000, COSO ERM, ISO 27001, Central Bank of the UAE, DFSA/DIFC, FSRA/ADGM, SCA requirements).
- Serve as the senior escalation point for complex technical issues, delivery risks and client concerns.
- Lead, mentor and develop managers and consultants, setting performance objectives and supporting career progression.
- Build the capability and capacity of the practice through recruitment, training, knowledge management and succession planning.
Skills :-
• NIST Cybersecurity Framework (CSF), ISO/IEC 27001, ISO/IEC 27005, and CIS Controls.
• UAE Information Assurance (UAE IA) Standards and applicable UAE Cybersecurity Council guidance.
• TDRA cybersecurity guidelines and other relevant UAE sectoral regulations.
• Cyber maturity models and quantitative cyber risk methodologies (e.g., FAIR).
• Excellent executive stakeholder management, influencing, negotiation and business-development skills.
• Strong technical command across governance, enterprise risk and regulatory compliance.
• Excellent written and verbal communication, including board-level reporting and presentation.
Qualifications:
Tools Experience : -
• GRC platforms (e.g. ServiceNow GRC, RSA Archer or equivalent).
• Enterprise reporting and BI tools (e.g. Power BI, Tableau) for executive and board reporting.
• Risk and compliance management, audit and workpaper tooling.
• Standard productivity and collaboration suites (Microsoft 365 or equivalent).
Education & Minimum Work Experience : -
• Minimum 12 years of relevant experience in governance, risk and/or compliance, including significant experience in a professional service / consulting environment.
• Minimum 5 years in a leadership role with delivery, P&L and business-development accountability.
• Demonstrated track record of leading and growing a practice or large engagements across regulated sectors.
• Experience advising on or delivering national / sector-wide cyber governance and assurance programmes — such as the National Cybersecurity Index Program — is strongly preferred..Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Data Analytics, or a related field.
• Master’s degree preferred.