Cyber Security

Il y a 10 heures

Casablanca, Casablanca-Settat, Maroc LimberSecurity Temps plein


About us
We are a team of cybersecurity practitioners who help organisations in industry and government design, govern and transform their security programmes. What sets us apart is the practical implementation of threat-informed defense: we start from the adversaries and techniques that actually target our clients, map them to controls, and build strategies, governance and transformation roadmaps around what matters most, rather than around a generic checklist. Our values are simple: do the right thing, dig deeper, and move with velocity. The opportunityWe are expanding our Cybersecurity practice in Casablanca and Rabat and are hiring Senior Consultants with 3 to 5 years of experience in cybersecurity strategy, GRC and security transformation. You will deliver, and progressively lead, engagements for clients in industry and government, in Morocco and internationally: security strategies, maturity assessments, governance frameworks, GRC tooling and automation, and multi-year transformation programmes. Depending on your experience, you will also help shape our go-to-market and service offerings in this domain. You are joining a new, growing team: there is real room to shape your role around your interests, whether that is deeper GRC engineering, leading transformation programmes, or building the practice itself. Your

key responsibilities
Depending on your experience, you will either deliver workstreams, act as subject matter expert, or lead a small team to an excellent client outcome. Across engagements you will: Cyber strategy
• Understand the client's threat landscape and risk exposure, and translate them into a cybersecurity strategy that leadership can fund and act on.
• Assess the maturity of the client's security programme (ISO 27001, NIST CSF 2.0, DNSSI or client-specific frameworks) and identify priority gaps.
• Build prioritised, costed roadmaps of investments and organisational changes, and measure whether delivered initiatives have actually improved the security posture. GRC engineering
• Design and implement governance frameworks: policies, standards, procedures and control catalogues aligned with regulatory and contractual requirements.
• Operationalise GRC through tooling and automation: control mapping, risk registers, continuous compliance monitoring, evidence collection and dashboards (e.g. ServiceNow IRM, Archer, OneTrust, Drata/Vanta, or scripted integrations with cloud and IT platforms).
• Build or improve Information Security Management Systems (ISMS) and Business Continuity Management Systems (BCMS), from design to certification readiness. Cyber transformation
• Run or support transformation programmes: plan workstreams, track progress, manage risks and dependencies, and keep sponsors and stakeholders informed.
• Support client security teams as a deputy or interim team member (security officer, cybersecurity manager, PMO) when needed.
• Build trusted relationships with client staff from technical teams to executives, and communicate security matters in business language. Practice development
• Help identify and develop new business opportunities and contribute to proposals.
• Stay current on threats, regulation and industry trends relevant to our clients, and bring that knowledge into our methods and offerings.

Your profile
Must have
• 3 to 5 years of experience in cybersecurity consulting or in an internal security, GRC or risk function.
• A Bachelor's or Master's degree in IT, engineering, information security or a related field.
• Hands-on experience assessing or implementing security governance: at least one ISMS or BCMS implementation, maturity assessment or framework rollout you can describe end to end.
• Working knowledge of ISO 27001:2022 / 27002 / 27005 and NIST CSF 2.0, plus at least one of ISO 22301, COBIT 2019, CIS Controls or MITRE ATT&CK.
• Experience operationalising controls through tooling, scripting or integration with IT or cloud environments (Microsoft 365, Azure, AWS), not only through documentation.
• Ability to explain security risks and priorities clearly to both technical teams and business leaders.
• Full working proficiency in French and English, written and spoken. Nice to have
• Knowledge of the Moroccan regulatory landscape: DGSSI / DNSSI requirements, Law 05-20 on cybersecurity, Law 09-08 and CNDP on personal data protection.
• Exposure to EU regulation relevant to international clients (NIS2, DORA, GDPR).
• Experience with a GRC platform (ServiceNow IRM, Archer, OneTrust, Drata, Vanta) or with policy-as-code and compliance-as-code approaches.
• A certification such as ISO 27001 Lead Implementer or Lead Auditor, CISM, CRISC, CISSP or CISA.