Description
Summary:
Onyx IT Consulting seeks an IT Security Compliance Officer to manage GRC, security audit cycles, corporate data defense, and regulatory alignments for premier institutions.
Highlights:
1. Lead continuous digital risk assessments and technical compliance audits
2. Act as primary technical interface for external regulatory reviews
3. Structuralize and execute rigorous security maturity reviews
Onyx IT Consulting is currently extending an immediate, permanent career track for an IT Security Compliance Officer to step into our high\-vigilance data protection unit based in Ghubra North, Muscat 130\. This full\-time engagement secures a tax\-free monthly compensation of OMR 2,020, paired with a robust benefits structure encompassing executive residential provisions, commuter transport subsidies, and comprehensive private health coverage.
Our firm orchestrates advanced digital transformations and enterprise cloud architecture protection for premier financial institutions, ministerial networks, and corporate entities across the Sultanate of Oman. As the technical anchor for governance, risk, and compliance (GRC), you will assume total ownership of our security audit cycles, corporate data defense frameworks, and regulatory alignments.
Scope of Professional Accountability
* **Framework Integrity:** Systematically design, implement, and monitor internal security control frameworks to guarantee absolute alignment with ISO 27001, NIST, and Omani National Certified Security Standards.
* **Vulnerability \& Risk Auditing:** Lead continuous digital risk assessments and technical compliance audits across complex enterprise networks, cloud landscapes, and software application pipelines.
* **Regulatory Liaison:** Act as the primary technical interface for external data protection regulatory reviews, security certifications, and compliance inspections executed by national telecom and digital ministry bodies.
* **Incident Response Blueprinting:** Author and periodically update corporate data breach response playbooks, coordinating forensic root\-cause analysis documentation following any internal or client\-side security exception.
* **Third\-Party Risk Governance:** Structuralize and execute rigorous security maturity reviews for all external technology partners, vendors, and supply chain software channels to eliminate incoming vector vulnerabilities.
Technical \& Professional Vetting Criteria
We are seeking a highly analytical cyber risk professional who offers a minimum of 4 to 6 years of progressive experience handling enterprise IT security compliance, data privacy management, or corporate IT auditing inside a dedicated technology consulting firm, financial enterprise, or multinational operation.
A formal bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a closely allied quantitative field is an absolute prerequisite. Possession of active, verifiable professional credentials—specifically **CISA (Certified Information Systems Auditor), CRISC, or CISM**—will immediately distinguish an application. Your software toolkit must feature deep familiarity with modern GRC automation platforms and network scanning diagnostic readouts. Flawless technical English reporting literacy is required to draft legally binding policy documentation and C\-suite threat assessments.
How to Apply
Review of applications will commence immediately upon the submission of a chronological CV. To guarantee early\-stage technical review, please ensure your submission details a specific corporate compliance deficit or audit vulnerability you successfully identified and remediated, highlighting the long\-term protection it provided the organization.
الراتب المدفوع: ﷼٢٬٠٢٠٫٠٠٠ لكل شهر
موقع العمل: بشكل شخصي