Overview
Cyber Security Consultant Jobs in Kuwait City Metropolitan Area at Protiviti Middle East Member Firm
Title: Cyber Security Consultant
Company: Protiviti Middle East Member Firm
Location: Kuwait City Metropolitan Area
Consultant – ISMS & ISO 27001 Certification
Experience: 1–5 Year
sJob Summar
yWe are seeking an experienced Consultant – ISMS & ISO 27001 Certification to lead and support Information Security Management System (ISMS) implementation, maintenance, and certification initiatives. The role involves conducting gap assessments, developing security policies and procedures, managing risk assessments, coordinating audits, and ensuring compliance with ISO 27001 and related information security standards
.Key Responsibilitie
- sLead ISO 27001 ISMS implementation and certification projects for clients or internal stakeholders
- .Conduct gap assessments against ISO 27001 requirements and develop remediation plans
- .Design, implement, and maintain Information Security Management Systems (ISMS)
- .Perform information security risk assessments and facilitate risk treatment activities
- .Develop, review, and update security policies, standards, procedures, and guidelines
- .Conduct Statement of Applicability (SoA) reviews and control implementation assessments
- .Prepare organizations for certification, surveillance, and recertification audits
- .Coordinate with certification bodies, auditors, and business stakeholders during audits
- .Monitor compliance with ISO 27001 controls and regulatory requirements
- .Conduct internal ISMS audits and management review activities
- .Deliver awareness sessions and training programs on information security best practices
- .Support incident management, corrective actions, and continuous improvement initiatives
- .Assist in the implementation of security frameworks such as ISO 22301, NIST, CIS Controls, and GDPR where applicable
- .Prepare project documentation, reports, dashboards, and compliance status updates
.Required Qualification
- sBachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or a related field
- .Strong understanding of ISO/IEC 27001:2022 standards and ISMS frameworks
- .Experience in information security governance, risk management, and compliance
- .Hands-on experience in conducting risk assessments and internal audits
- .Knowledge of security controls, policies, procedures, and regulatory compliance requirements
- .Experience supporting certification audits and remediation activities
- .Excellent stakeholder management, communication, and documentation skills
.
Technical Skil
- lsISO 27001:2022 Implementation & Complian
- ceISMS Governan
- ceInformation Security Risk Manageme
- ntInternal & External Audit Manageme
- ntBusiness Continuity & Disaster Recovery Concep
- tsSecurity Policy Developme
- ntCompliance & Regulatory Framewor
- ksThird-Party Risk Manageme
- ntSecurity Awareness & Traini
ngKey Competenci
- esStrong analytical and problem-solving skil
- lsExcellent client-facing and consulting capabiliti
- esProject management and stakeholder coordinati
- onReport writing and documentation experti
- seAbility to work independently and manage multiple engagemen
tsPreferred Experien
- ceExperience working in consulting, cybersecurity, GRC, or compliance environment
- s.Exposure to ISO 22301 (Business Continuity), ISO 27701, NIST CSF, or SOC 2 frameworks is an advantag
- e.Experience managing end-to-end certification engagements across multiple industrie
s.