Manager – Cybersecurity & Technology Risk Advisory
Grant Thornton Advisory Ethiopia Addis Ababa · Addis Ababa Posted 1h ago
About this role
About the company:
Grant Thornton Ethiopia is part of the global Grant Thornton network, one of the world’s leading organizations of independent assurance, tax, and advisory firms. We are committed to helping dynamic organizations unlock their potential for growth by providing tailored, forward-thinking solutions.
Grant Thornton Ethiopia is looking for a highly motivated and experienced Manager – Cybersecurity & Technology Risk Advisory to join our Advisory practice and play a key role in building and growing our cybersecurity advisory capabilities in Ethiopia.
The successful candidate will combine cybersecurity expertise, technology risk knowledge, client advisory skills, and business development capability to help organizations understand and manage their cyber and technology risks, strengthen governance and controls, and build cyber resilience.
Requirements
Key responsibilities
- Cybersecurity Advisory & Engagement Delivery
- Lead and deliver cybersecurity and technology risk advisory engagements from planning through completion.
- Conduct cybersecurity risk and maturity assessments using recognized frameworks and industry good practices.
- Deliver ISO 27001, NIST CSF, CIS Controls and related cybersecurity assessments and readiness reviews.
- Assess cybersecurity governance, policies, processes, controls and operating models.
- Develop practical cybersecurity strategies, roadmaps and improvement plans.
- Perform IT risk, cybersecurity controls and technology risk assessments.
- Conduct third-party/vendor cybersecurity risk assessments.
- Support cloud, Microsoft 365, IAM/PAM, data security and security architecture assessments.
- Support clients in developing incident response, cyber resilience and crisis-readiness capabilities.
- Lead cybersecurity tabletop exercises and awareness activities for management and key stakeholders.
- Prepare high-quality reports, presentations and recommendations for senior management and Boards.
- Practice Development & Business Development
- Support the development and growth of Grant Thornton Ethiopia's Cybersecurity & Technology Risk Advisory practice.
- Identify cybersecurity opportunities across existing and prospective clients.
- Work closely with Audit, Advisory, Tax and other Grant Thornton teams to identify and develop cross-service opportunities.
- Lead or contribute to RFPs, proposals, statements of work and client presentations.
- Develop cybersecurity service offerings, methodologies, tools, templates and thought leadership materials.
- Build strong relationships with CIOs, CISOs, CROs, CFOs, Internal Audit leaders and other senior executives.
- Support the development of new cybersecurity propositions relevant to the Ethiopian and wider African market.
- Team & Practice Leadership
- Manage and coach consultants and junior team members.
- Provide technical and quality oversight across cybersecurity engagements.
- Contribute to recruitment, capability development and performance management within the cybersecurity team.
- Maintain professional standards, engagement quality and risk management requirements.
- Collaborate with Grant Thornton's global cybersecurity and technology risk network to bring specialist expertise and capabilities to clients where required.
Key Service Areas
The role will initially focus on:
- Cybersecurity Strategy & Roadmap
- Cybersecurity Maturity & Risk Assessments
- Cybersecurity Governance & Operating Model
- ISO 27001 / NIST / CIS Assessments
- Cybersecurity Controls & Gap Assessments
- IT & Technology Risk Advisory
- Third-Party Cyber Risk
- Cloud & Microsoft 365 Security Advisory
- IAM / PAM Advisory
- Data Security & Protection
- Cyber Resilience & Incident Readiness
- Cybersecurity Policies, Standards & Procedures
- Cybersecurity Awareness & Executive Advisory
Candidate Profile
We are looking for a practice-builder and trusted advisor, not only a technical cybersecurity specialist.
The ideal candidate will have:
- 8–12+ years of relevant professional experience, with significant experience in cybersecurity, technology risk, IT risk, information security or related advisory services.
- Proven experience leading cybersecurity or technology risk consulting engagements.
- Strong understanding of cybersecurity frameworks and standards, including NIST CSF, ISO 27001 and CIS Controls.
- Experience in cybersecurity governance, risk management, controls assessment and compliance.
- Good understanding of cloud security, IAM/PAM, data security, application security and cyber resilience.
- Demonstrated ability to manage client relationships and communicate effectively with C-suite and senior management.
- Experience preparing and presenting proposals, RFP responses and client deliverables.
- Strong report-writing, presentation and analytical skills.
- Experience managing and developing consulting teams.
- Commercial awareness and the ability to identify and develop new business opportunities.
- Strong project management and stakeholder management skills.
- Excellent written and verbal English communication skills.
- Equivalent combinations of professional experience, qualifications and certifications will also be considered.
Professional Certifications
Relevant professional certifications will be highly desirable, including:
- CISSP
- CISM
- CRISC
- CISA
- CCSP
- ISO 27001 Lead Auditor / Lead Implementer
What We Are Looking For
- The successful candidate should demonstrate:
- Strong consulting and advisory mindset
- Commercial and business development orientation
- Ability to translate complex cybersecurity issues into clear business risks and practical recommendations
- Strong client relationship and stakeholder management skills
- Ability to work independently and lead engagements
- Strong problem-solving and analytical capability
- Commitment to quality and professional ethics
- Willingness to continuously develop cybersecurity knowledge and capabilities
- Ability to collaborate effectively with Grant Thornton teams locally and internationally
Why Join Grant Thornton Ethiopia?
This is an opportunity to join at an exciting stage of the development of our Cybersecurity & Technology Risk Advisory practice. The successful candidate will have the opportunity to:
- Help build and shape a new cybersecurity advisory capability in Ethiopia.
- Work with a diverse portfolio of organizations and senior decision-makers.
- Develop and lead high-value cybersecurity advisory engagements.
- Collaborate with Grant Thornton's international network and specialist teams.
- Develop new cybersecurity solutions and market propositions.
- Grow professionally within a leading global professional services organization
Never miss a role
New jobs land on Telegram first
Every opening we aggregate is posted to @ethio_tech_jobs within minutes — join the channel and be the first to apply.