Company Overview:
Dar, the founding member of the Sidara group, is an international multidisciplinary consulting organization specializing in engineering, architecture, planning, environment, project management, facilities management, and economics. Sidara operates in 60 countries with 20,500 professionals, Dar connects people, places, and communities through innovative solutions to the world's most complex challenges. We deliver projects from inception through completion, embracing challenges to empower communities worldwide. Learn more at www.dar.com.
Our Vision and Values:
We aspire to be the chosen home of those with a gift for crafting solutions that empower people and an unwavering passion for learning and innovation. Our core values shape our culture and guide our decision-making. We are committed to:
- Excellence
- Responsibility
- Empowerment
- Connectivity
- Courage
Job Summary
The role will support the implementation and continuous improvement of Dar's Information Security Management System (ISMS) across all Dar offices, in alignment with ISO/IEC 27001:2022 and other applicable cybersecurity standards.
Responsibilities
- Implement, maintain, and improve Dar's ISMS across all offices.
- Develop and update cybersecurity policies, standards, procedures, and guidelines.
- Conduct cybersecurity risk assessments for projects, systems, SaaS solutions, clients, and suppliers.
- Maintain cybersecurity risk registers and track risk treatment and remediation plans.
- Support internal, external, certification, and surveillance audits.
- Conduct compliance and control assessments based on ISO 27001, ISO 27002, and CIS Controls.
- Perform third-party and supplier cybersecurity assessments.
- Track audit findings and corrective actions until closure.
- Prepare cybersecurity reports, KPIs, and management updates.
- Support cybersecurity awareness and training activities.
Qualifications
- Bachelor's degree in computer science, Engineering, Information Technology, Cybersecurity, or a related field.
- 5–10 years of cybersecurity experience, mainly in GRC.
- Good knowledge of ISO/IEC 27001, ISO/IEC 27002, CIS Controls, and cybersecurity risk management.
- Experience in security audits, risk assessments, policy development, and third-party assessments.
- Strong English communication, documentation, presentation, and organizational skills.
- Ability to work effectively with technical and business stakeholders.
- CISSP, CISM, CRISC, ISO 27001 certificates is a plus.
Required Skills
- Implement, maintain, and improve Dar's ISMS across all offices.
- Develop and update cybersecurity policies, standards, procedures, and guidelines.
- Conduct cybersecurity risk assessments for projects, systems, SaaS solutions, clients, and suppliers.
- Maintain cybersecurity risk registers and track risk treatment and remediation plans.
- Support internal, external, certification, and surveillance audits.
- Conduct compliance and control assessments based on ISO 27001, ISO 27002, and CIS Controls.
- Perform third-party and supplier cybersecurity assessments.
- Track audit findings and corrective actions until closure.
- Prepare cybersecurity reports, KPIs, and management updates.
- Support cybersecurity awareness and training activities.
Kind Note:
** While we carefully review all applications, only candidates who meet the specified requirements will be contacted for further consideration. We appreciate your understanding and thank you for your interest.