
Closed
Posted
Paid on delivery
I need an experienced Cybersecurity Governance / GRC consultant to overhaul our entire documentation set so it truly mirrors the way we operate today. We run our program primarily on the SAMA Cybersecurity Framework (CSF) and must also respect the Saudi PDPL, yet I want every policy, standard, and procedure you touch to map cleanly to ISO/IEC 27001 and recognised industry best practice as well. Your first task will be to read through the existing material, speak with the relevant stakeholders if clarification is needed, and mark anything that is outdated, redundant, or simply no longer implemented. Once the gaps are clear, rewrite the texts: tighten language, unify structure, eliminate conflicts, and—because I selected “Yes” to including new controls—recommend and weave in additional safeguards that strengthen our posture even if they are not yet live in production. The final language must remain practical and proportionate to our environment; I do not want theoretical controls that no one can maintain. Deliverables expected from you: • A fully updated set of cybersecurity policies, standards, and procedures, professionally formatted and ready for board approval. • A review log or comment matrix that shows what you changed, what you removed, and why. • A concise recommendations document highlighting any new controls you propose, mapped to SAMA CSF, ISO/IEC 27001, PDPL and, where helpful, NIST CSF for future reference. I will consider the engagement complete once every control listed in the documents can be traced back to an actual practice in our environment (or is marked as a recommended future control), and the formatting across the full suite is consistent. If you have successfully led similar governance clean-ups and can start soon, let’s talk.
Project ID: 40606573
14 proposals
Remote project
Active 4 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
14 freelancers are bidding on average $149 USD for this job

Hello, I hold a BSc degree in Computer Science and a Ph.D. in cyber security, with extensive experience in cybersecurity governance, GRC documentation, compliance, and policy development. I can review and modernize your cybersecurity documentation to accurately reflect your current operating environment while aligning with SAMA CSF, Saudi PDPL, ISO/IEC 27001, and relevant NIST CSF controls. My approach includes: • Reviewing existing policies, standards, and procedures to identify outdated, conflicting, or redundant content. • Revising documentation into a consistent, board-ready format with practical, maintainable controls. • Mapping every control to SAMA CSF, ISO/IEC 27001, PDPL, and NIST CSF where appropriate. • Preparing a comprehensive change log detailing additions, revisions, removals, and rationale. • Recommending future-state controls that strengthen governance while clearly distinguishing them from implemented practices. I focus on producing clear, audit-ready documentation that supports compliance without introducing unnecessary operational burden. I value accuracy, stakeholder collaboration, and timely delivery, and I am available to begin immediately. I look forward to discussing your governance framework and supporting this documentation overhaul.
$40 USD in 3 days
4.8
4.8

Hey, I have experience in cybersecurity governance, GRC documentation, and compliance frameworks including ISO/IEC 27001, NIST CSF, and regulatory standards. I can review your existing policies, identify outdated or missing controls, align the documentation with your current practices, and update everything to map clearly with SAMA CSF, Saudi PDPL, and ISO/IEC 27001 while maintaining practical, audit-ready documentation. My strength is producing clear, consistent, and board-ready governance documents with full traceability, gap analysis, and actionable recommendations for future controls. Your satisfaction is my guarantee! Just message me & consider your project is done. Thanks.
$100 USD in 3 days
3.6
3.6

Hello, I am working for cybersecurity company in PL, that takes care of GRC docs. Please send me the existing material, so I can pass it to our company's specialist to review it and send back the quote for the whole thing. Thank you, Dawid R.
$249 USD in 7 days
0.0
0.0

THIS IS A GREAT MATCH. I have just handled a comprehensive overhaul of cybersecurity documentation for a financial institution, aligning with ISO/IEC 27001 and NIST CSF. You need clear, practical policies that reflect your unique operations while meeting compliance requirements. I’ll meticulously review your existing materials, identifying outdated sections and ensuring new controls are practical and maintainable. I’ll also unify the language and structure for clarity. The process will be straightforward and transparent, keeping you in the loop every step of the way. REACH OUT, LET'S SEE IF WE ARE A GOOD FIT. Regards, Stefan.
$150 USD in 14 days
0.0
0.0

I appreciate the opportunity to assist with your cybersecurity GRC documentation revamp. Your focus on aligning with the SAMA Cybersecurity Framework, Saudi PDPL, and ISO/IEC 27001 is crucial for a robust governance structure. I HAVE RECENTLY COMPLETED A SIMILAR PROJECT where I successfully overhauled documentation for a cybersecurity program, ensuring alignment with industry standards and best practices. I understand your primary goal is to create clear, actionable policies that reflect your current operations while addressing any outdated or redundant content. Failing to properly manage this could lead to compliance issues, security vulnerabilities, and operational inefficiencies. With extensive experience in cybersecurity governance, I specialize in writing concise, practical policies that ensure maintainability and relevance. My approach includes thorough stakeholder engagement, meticulous documentation review, and structured updates that enhance your security posture without introducing impractical controls. Even if you decide to work with another freelancer, I’m happy to offer a free consultation to help you navigate common pitfalls. I’d love to discuss this project further. What is your timeline for starting the revamp? I'm available to begin soon.
$150 USD in 7 days
0.0
0.0

Here it is, trimmed to 200 words: Thank you for considering me for this engagement. I bring over 22 years of experience in cybersecurity consulting, having led governance programmes aligned with ISO/IEC 27001, the SAMA Cybersecurity Framework, NIST CSF, Saudi PDPL, GDPR, ISO/IEC 27701, and SOC 2. My approach is practical — every document is aligned with the organisation's actual operating model and existing technical controls, not written as a theoretical exercise. For this engagement, I would: Conduct a detailed review of your existing policies, standards, and procedures. Identify outdated, duplicate, conflicting, or non-implemented controls. Hold stakeholder discussions where needed to ensure documentation reflects actual practice. Rewrite and standardise the full suite with consistent structure and approval-ready format. Map all applicable controls to SAMA CSF, ISO/IEC 27001, Saudi PDPL, and NIST CSF. Recommend additional controls based on best practice, clearly separating future-state recommendations from implemented ones. Keep the documentation practical and maintainable for daily use. Deliverables would include the updated documentation suite, a review matrix showing all changes and their rationale, and a recommendations report mapped across frameworks. I would be glad to share references and sample deliverables from similar engagements, and to discuss scope and timelines. I remain available to start promptly
$140 USD in 7 days
0.0
0.0

Hi, The part that caught my attention was this: "I do not want theoretical controls that no one can maintain." That's exactly the problem I run into most often when reviewing existing documentation, policies written for auditors, not for the people who have to follow them. I've spent 4 years rewriting and maintaining governance documentation across ISO 27001, SOC 2, NIST CSF and PCI-DSS in regulated environments. SAMA CSF is built on the same foundation as ISO 27001, so the overlap is significant and I'll be straight with you about the PDPL pieces where I'll need to get up to speed. I'd start by going through what you have, marking what's stale or disconnected from how you actually operate, and rebuilding from there. No fluff. When's a good time to talk?
$170 USD in 7 days
0.0
0.0

Hi, I have hands-on experience in Cybersecurity Governance, GRC, and compliance documentation, including aligning policies with ISO/IEC 27001, NIST CSF, and regulatory frameworks. I can review your existing documentation, identify gaps, rewrite and standardize policies, and ensure they accurately reflect your current practices while mapping to SAMA CSF and Saudi PDPL requirements. I deliver practical, audit-ready documentation with clear traceability, change logs, and actionable recommendations. I'm available to start immediately and can ensure a consistent, board-ready document set. Looking forward to discussing your project.
$140 USD in 7 days
0.0
0.0

As an accomplished AI Automation Engineer and Business Analyst, I'm uniquely positioned to revamp your Cybersecurity Governance Documentation. For four years now, I have assisted counterparts in streamlining systems, automating processes, and ensuring efficient QA delivery. My knowledge of Python/Flask backend, SQL databases, ETL/data pipelines, and system design will greatly aid in unifying structure across your documents while my expertise in BRD/SRS will guarantee the final documentation is both practical and proportionate to your environment. I have studied CCNA and did Penetration testing using burpsuite and other tools and did custom ethical hacking tools brute-forcing to test and verify the security standards .. so when needed i can be in action. Moreover, my strong QA automation background using tools like Selenium will provide an extra edge to ensure all controls listed in your documentation can be directly attributed to actual practices in your existing operations or marked as recommended future controls. From leveraging SAMA CSF to ISO/IEC 27001 and PDPL mappings, trust me to provide a concise recommendations document that considers recognized industry best practices and reserves NIST CSF for future reference if helpful
$200 USD in 7 days
0.0
0.0

Riyadh, Saudi Arabia
Member since Aug 9, 2019
$30-250 USD
$30-250 USD
$30-250 USD
$30-250 USD
$20-50 USD
₹12500-37500 INR
£20-250 GBP
₹100-400 INR / hour
₹1500-12500 INR
$650-5000 USD / hour
₹400-750 INR / hour
$250-750 USD
$250-750 USD
$10-30 USD
$25-50 USD / hour
₹1500-12500 INR
₹600-1500 INR
$40-80 USD
£250-500 GBP
₹1500-12500 INR
₹750-1250 INR / hour
$25-50 USD / hour
$10-50 USD
₹750-1250 INR / hour