About the Role
The company Security helps organizations prepare for, prevent, detect, respond to, and recover from cyber threats. This role involves developing and enhancing cybersecurity frameworks, policies, and strategies to protect critical assets. You will work with clients to ensure compliance with regulatory requirements and to build resilient security programs that effectively manage risks.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities:
Governance:
- Develop cyber frameworks, policies, processes, procedures, guidelines, and related documentation.
- Review existing and proposed policies and related documentation with stakeholders.
- Develop reporting metrics, KPIs, and dashboards.
- Monitor the effectiveness of cybersecurity policies, principles, and practices in planning and management services delivery.
- Ensure compliance of cybersecurity workforce management policies and processes with legal and organizational requirements.
- Interpret and apply applicable laws, statutes, and regulatory documents to ensure they are reflected in cybersecurity policies.
- Provide policy guidance to cybersecurity management, staff, and users.
Risk Management:
- Effectively communicate cybersecurity risks and posture to senior management.
- Develop risk mitigation strategies aligned with the organizational risk appetite.
- Ensure decisions related to cybersecurity are based on sound risk management principles.
- Perform risk analysis during major changes to applications or systems.
- Contribute to the risk management framework and related documentation.
- Ensure cybersecurity risks are identified and managed through the organization's risk governance process.
- Conduct cybersecurity risk assessments.
- Collaborate with others to implement and maintain a cybersecurity risk management program.
- Identify and assign individuals to specific roles associated with the Risk Management Framework execution.
- Establish a risk management strategy, including determination of risk tolerance.
- Conduct initial risk assessments and continually update these assessments.
- Ensure continuous monitoring tool data provides awareness of risk levels.
- Utilize risk management tools like eGRC and monitoring tools for risk assessment.
- Develop methods for monitoring and measuring risk, compliance, and assurance efforts.
- Document supply chain risks for critical system elements.
Compliance & Regulation:
- Analyze and evaluate the organization’s cybersecurity policies and configurations against regulations and compliance frameworks.
- Identify patterns of non-compliance and recommend improvements.
- Periodically review cybersecurity strategy and policies to maintain regulatory compliance.
- Collaborate with stakeholders on cybersecurity incidents and vulnerability compliance.
- Develop specifications for compliance efforts related to cybersecurity requirements.
- Monitor and evaluate systems for compliance with cybersecurity, resilience, and dependability requirements.
- Create compliance processes and audits for third-party services.
- Stay updated on relevant legislation and standards for organizational compliance.
- Cooperate with regulatory agencies during compliance reviews or investigations.
Skills and Qualifications:
- Excellent written and oral communication skills.
- Strong analytical and problem-solving capabilities.
- Willingness to travel as needed.
- Experience in consulting, stakeholder engagement, and relationship management.
- Proficiency in Arabic and English.
- Ability to effectively communicate insights regarding the threat environment to enhance risk management.
- Experience collaborating with leadership to devise a comprehensive organizational approach to cybersecurity risk and compliance.
- Knowledge of cybersecurity policies, standards, and documentation.
- Understanding of risk assessment, mitigation, and treatment methods.
- Familiarity with the operational impacts of cybersecurity breaches.
- Knowledge of national cybersecurity laws and regulations (e.g., SAMA CSF, NCA ECC).
- Understanding of common information security standards (e.g., ISO 27001/27002, NIST, PCI DSS, ITIL).
Preferred Qualifications:
- Bachelor’s degree in Information Security, Cybersecurity, or a relevant field.
- 5+ years of experience in a similar position.
- Relevant certifications such as CRISC, GRCP, ISO 27001 LI, or equivalent.