
Closed
Posted
Paid on delivery
I need an experienced Cybersecurity Governance / GRC consultant to overhaul our entire documentation set so it truly mirrors the way we operate today. We run our program primarily on the SAMA Cybersecurity Framework (CSF) and must also respect the Saudi PDPL, yet I want every policy, standard, and procedure you touch to map cleanly to ISO/IEC 27001 and recognised industry best practice as well. Your first task will be to read through the existing material, speak with the relevant stakeholders if clarification is needed, and mark anything that is outdated, redundant, or simply no longer implemented. Once the gaps are clear, rewrite the texts: tighten language, unify structure, eliminate conflicts, and—because I selected “Yes” to including new controls—recommend and weave in additional safeguards that strengthen our posture even if they are not yet live in production. The final language must remain practical and proportionate to our environment; I do not want theoretical controls that no one can maintain. Deliverables expected from you: • A fully updated set of cybersecurity policies, standards, and procedures, professionally formatted and ready for board approval. • A review log or comment matrix that shows what you changed, what you removed, and why. • A concise recommendations document highlighting any new controls you propose, mapped to SAMA CSF, ISO/IEC 27001, PDPL and, where helpful, NIST CSF for future reference. I will consider the engagement complete once every control listed in the documents can be traced back to an actual practice in our environment (or is marked as a recommended future control), and the formatting across the full suite is consistent. If you have successfully led similar governance clean-ups and can start soon, let’s talk.
Project ID: 40570465
17 proposals
Remote project
Active 14 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
17 freelancers are bidding on average $184 USD for this job

Hi, I have experience working on GRC documentation, cybersecurity policy frameworks, compliance mapping, risk management, control assessments, and security governance improvements. My approach focuses on creating documentation that is practical, operationally realistic, and aligned with how organizations actually manage security not generic compliance templates. My approach will include: Review of the existing cybersecurity policies, standards, and procedures. Identification of outdated, duplicated, conflicting, or non-implemented controls. Stakeholder discussions where clarification is required to validate current practices. Complete rewriting and restructuring of documents for consistency, clarity, and board-level presentation. Mapping existing and recommended controls against: SAMA Cybersecurity Framework ISO/IEC 27001 controls Saudi PDPL requirements NIST Cybersecurity Framework (where beneficial) Deliverables: Updated cybersecurity policy and procedure suite Change/review matrix documenting updates, removals, and rationale Recommendations report for additional security controls and future improvements Professionally formatted documents ready for governance review and approval I will ensure every control is either traceable to an existing practice or clearly marked as a future-state recommendation, maintaining a balance between compliance requirements and operational feasibility. Best regards, Aqsa
$150 USD in 7 days
3.6
3.6

Hello, With extensive experience in Cybersecurity GRC, policy development, and compliance frameworks, I can help modernize your cybersecurity documentation to align with SAMA CSF, ISO/IEC 27001, PDPL, and industry best practices. What I will deliver: * Review and update of cybersecurity policies, standards, and procedures. * Removal of outdated content and alignment of documentation with actual practices. * Control mapping to SAMA CSF, ISO 27001, PDPL, and NIST CSF where relevant. * Recommendations for practical new controls and security improvements. * Change log and recommendations report for review and approval. I have experience creating clear, audit-ready governance documentation that is practical, consistent, and aligned with regulatory requirements. Regards, Moiz
$100 USD in 2 days
3.2
3.2

Hi, I understand you're looking for an experienced GRC consultant to align your cybersecurity documentation with your current operational practices while ensuring compliance with the SAMA Cybersecurity Framework, Saudi PDPL, ISO/IEC 27001, and industry best practices. I can help deliver a well-structured, audit-ready documentation suite that is practical, consistent, and easy to maintain. Here’s what I’ll do: • Review your existing documentation and identify outdated, redundant, or missing controls. • Update policies, standards, and procedures to reflect your current environment. • Map controls to SAMA CSF, ISO/IEC 27001, PDPL, and reference NIST CSF where applicable. • Deliver a change log, recommendations report, and professionally formatted, board-ready documents. I have experience working on governance, compliance, and documentation projects that require meticulous reviews, structured writing, and alignment with recognized security frameworks. My focus is on producing clear, practical documentation that supports compliance while remaining realistic and sustainable for day-to-day operations. Let’s chat and discuss this in more detail. Regards, Neha
$500 USD in 7 days
2.0
2.0

Hello there, I have strong experience in cybersecurity GRC, policy development, compliance mapping, and governance frameworks including ISO/IEC 27001, NIST, and regulatory requirements. I can review, restructure, and enhance your cybersecurity documentation with clear mappings to SAMA CSF and PDPL while introducing practical, maintainable controls aligned with your operations. I will deliver board-ready policies, change matrices, and recommendations that improve governance maturity without adding unnecessary complexity.
$88 USD in 1 day
2.1
2.1

Hello There! I’m Md Toriqul Islam, and I’m excited to partner with you. I’m an experienced Cybersecurity GRC specialist with expertise in security documentation, compliance frameworks, risk management, and governance improvements. I understand you want to revamp your cybersecurity policies, standards, and procedures to align with SAMA Cybersecurity Framework, Saudi PDPL, ISO/IEC 27001, and industry best practices. I have experience reviewing existing documentation, identifying gaps, restructuring policies, mapping controls, and creating practical governance documents ready for stakeholder approval. I am skilled in Cybersecurity GRC, ISO 27001, SAMA CSF, NIST CSF, risk assessment, security policies, control mapping, compliance documentation, and audit preparation. I’m ready to start immediately and would be happy to review your current documentation, discuss requirements, and create a structured improvement roadmap. Looking forward to hearing from you. Best regards, Md Toriqul Islam
$100 USD in 3 days
1.8
1.8

Hi there, We can help overhaul your Cybersecurity GRC documentation so it reflects current operations while mapping clearly to SAMA CSF, Saudi PDPL, and ISO/IEC 27001. We will review the existing policies, standards, and procedures, identify outdated or redundant controls, and rewrite them into a consistent, board-ready structure with a practical review log and recommendations matrix. Our initial assumption is that current stakeholder input and document versions will be available for validation. Best Regards, 8veer
$223 USD in 7 days
0.0
0.0

Hi, I wanted to reach out directly before submitting a proposal. I specialise in ISO 27001:2022 — I hold both Lead Auditor and Lead Implementer certifications, along with CISM, PCI-DSS Lead Implementer, and ISO 31000. I have spent three years as Compliance Officer at a SaaS company owning the ISMS end-to-end through certification and the 2022 migration.I noticed the engagement spans SAMA CSF, PDPL, ISO 27001, and NIST CSF. Rather than claim the full scope, I wanted to ask whether you would consider splitting the engagement — with me taking ownership of the ISO 27001 stream, including gap review, policy rewrite, control mapping, change log, and NIST CSF cross-referencing.I would rather deliver one piece to a genuinely high standard than stretch across frameworks where my experience is thinner. Happy to jump on a scoping call this week if this works for you.
$140 USD in 7 days
0.0
0.0

I help businesses save time, automate repetitive work, and build professional websites and software that help them grow. Whether you need a Virtual Assistant, custom web application, WordPress website, CRM management, or business automation, I deliver reliable, high-quality solutions on time. * 7+ years customer service * 99% accuracy in data entry * 100+ automation workflows * 5000+ customer interactions * Managed logistics operations * Built multiple business websites With expertise in Cybersecurity Governance and GRC, I am well-equipped to overhaul your cybersecurity documentation set. By aligning your policies, standards, and procedures with SAMA CSF, ISO/IEC 27001, and industry best practices, I will enhance your security posture. My approach includes identifying outdated content, recommending new controls, and ensuring practicality in implementation. Deliverables include updated documentation, a review log, and concise recommendations mapped to relevant frameworks. Let's elevate your cybersecurity practices together.
$150 USD in 7 days
0.0
0.0

"Hi there. This is an interesting project. Before anything else, one area I'd pay particularly close attention to is ensuring that the cybersecurity policies align seamlessly with SAMA CSF, ISO/IEC 27001, and PDPL, maintaining practicality throughout. The critical task involves not only updating documentation but also recommending additional safeguards for enhanced security posture. To mitigate any implementation risks, I propose a phased approach: first, conducting a thorough review and stakeholder discussions to identify gaps, then aligning policies with the required frameworks. My experience in cybersecurity governance aligns well with your project needs. One key consideration is how we can ensure seamless traceability of controls to operational practices. Could you provide insights into the current process for tracking control effectiveness within your environment?" Looking forward to engaging. Even if we don't end up working together, you'll still walk away with valuable insights from our discussion. Regards, Riyaaz
$100 USD in 7 days
0.0
0.0

Hello, I can support the end-to-end review and revamp of your cybersecurity governance documentation, ensuring it reflects actual operating practices while mapping clearly to SAMA CSF, Saudi PDPL, ISO/IEC 27001 and relevant NIST CSF practices. My approach will be: • Review the current policy, standard and procedure suite and identify outdated, redundant or conflicting content. • Conduct a practical gap assessment against SAMA CSF, PDPL and ISO/IEC 27001. • Rewrite and standardize the documents for clarity, consistency, ownership, review cycles and board approval. • Create a change/review matrix explaining updates, removals and rationale. • Provide a prioritized recommendations document for future controls, clearly separating implemented controls from recommended improvements. I have experience in cybersecurity GRC, ISO 27001, risk assessments, policy development, audit readiness, cloud security governance and compliance programs. I focus on practical, maintainable controls rather than generic template language. I can start promptly and will confirm the document inventory, stakeholder inputs and final delivery plan at kickoff. Regards, Keerthy
$180 USD in 10 days
0.0
0.0

I am an IT and Cybersecurity professional with hands-on experience in SOC monitoring, Linux administration, networking, and cloud technologies. My technical background enables me to create accurate, well-structured, and user-friendly documentation tailored to both technical and non-technical audiences. I have experience working with tools such as Wazuh, Wireshark, Burp Suite, Git/GitHub, and AWS services. This practical knowledge helps me explain complex concepts in a clear, concise, and actionable manner. I stay updated with industry best practices and emerging technologies, ensuring that the content I create remains relevant and valuable. My strengths include technical research, documentation writing, process guides, troubleshooting manuals, and knowledge base articles. I focus on creating content that is easy to understand, properly formatted, and organized with clear headings, code examples, and diagrams where needed. I am committed to delivering high-quality, original work that meets project requirements and passes plagiarism checks. I value clear communication and actively incorporate client feedback to ensure the final deliverable aligns with project goals. My goal is to create documentation that not only explains technical processes accurately but also helps users learn, troubleshoot, and work with confidence. I am dedicated to professionalism, timely delivery, and providing maximum value to every client.
$140 USD in 7 days
0.0
0.0

Hi, I'd like to start with a small initial phase to review your current documentation before committing to the full rewrite. What I'll do: Read through your existing policies, standards, and procedures Talk to relevant stakeholders if anything needs clarifying Flag what's outdated, redundant, or no longer implemented Map current docs against SAMA CSF, ISO/IEC 27001, and PDPL to show where gaps are Give you a short summary + a proposed plan and price for the full rewrite Why this way: You get clarity on the real scope before paying for the full overhaul, and I get to properly understand your environment first. My background: Done PDPL vs. GDPR comparative analysis (scope, breach notification, data subject rights, cross-border transfer) Built ISO 27001 ISMS documentation (policies, risk register) ISO 9001 QMS Internal Auditor — comfortable with document control and audit trails Regulated-industry background, so I focus on controls teams can actually maintain I'm being upfront: this would be my first project at this scale, which is why I'm proposing the smaller review phase first — you can judge my work before scaling up. Happy to hop on a call to discuss your framework first. Best regards, Muhammad Umer Shahzad
$500 USD in 15 days
0.0
0.0

Cybersecurity GRC consultant with 6 years' experience, including Big 4 tenure, specializing in SAMA CSF-aligned documentation overhauls. I'll audit your current policy suite, mark outdated/redundant content, rewrite it into a unified board-ready set, and map every control to SAMA CSF, ISO/IEC 27001, PDPL, and NIST CSF. Deliverables include the full revised documentation, a change/review log, and a recommendations report for new controls sized to your environment — nothing theoretical, everything traceable to real practice.
$140 USD in 8 days
0.0
0.0

Riyadh, Saudi Arabia
Payment method verified
Member since Aug 9, 2019
$30-250 USD
$30-250 USD
$30-250 USD
₹1500-12500 INR
₹12500-37500 INR
$2-8 USD / hour
₹37500-75000 INR
₹1500-12500 INR
₹600-1500 INR
₹12500-37500 INR
$30-250 SGD
£250-750 GBP
₹5000-8000 INR
₹750-1250 INR / hour
₹1500-12500 INR
₹750-1250 INR / hour
$3000-5000 USD
$10-30 CAD
$30-250 USD
$250-750 USD
$8-15 USD / hour
$250-750 USD
₹750-1250 INR / hour