Cyber Security Specialist
Yaqeen Capital · Riyadh, Riyadh, Saudi Arabia
Apply & track with Apply EdgeCompany Description Yaqeen Capital is a Saudi investment company listed on the Saudi Exchange and licensed by the Capital Market Authority under license number (37-06020). The firm provides a comprehensive range of financial services, including brokerage, asset management, investment banking, custody, and advisory services. Yaqeen Capital serves both individual and institutional clients, offering tailored investment solutions aligned with regulatory standards. The company is committed to high levels of professionalism, transparency, and client service in the Saudi capital market.Role Description The Cyber Security Specialist is a full-time role based in Riyadh. This role is responsible for monitoring, analyzing, and improving the organization’s security posture across applications, networks, and information systems. Daily tasks include assessing vulnerabilities, responding to security incidents, implementing security controls, and ensuring compliance with relevant security standards and regulations. The specialist will collaborate with IT, operations, and business teams to design secure solutions, develop security policies and procedures, and conduct security awareness activities. The role also involves continuous evaluation of emerging threats and technologies to strengthen Yaqeen Capital’s cyber resilience.Responsibilities· Develop and implement the organization’s cyber security strategy and governance aligned with CMA, NCA, and Tadawul requirements.· Establish and maintain cyber security policies, procedures, and guidelines.· Ensure compliance with relevant laws and regulations (e.g., NCA ECC, CMA, PDPL)· Identify and manage cybersecurity risks through regular assessments, threat modeling, and mitigation actions. · Monitor key risk indicators (KRIs) and performance indicators (KPIs); report to executive management. · Promote cybersecurity awareness and conduct organization-wide training. · Develop, test, and maintain incident response and business continuity plans. · Manage and monitor cybersecurity controls (firewalls, WAF, SIEM, EDR, DLP, etc.). · Oversee the investigation, containment, and reporting of cybersecurity incidents. · Ensure continuous compliance with internal and external audits· Conduct third-party, outsourcing, and cloud risk assessments and ensure their compliance with CMA and Tadawul requirements. · Report cybersecurity posture, compliance status, and incidents to executive management and the Information Security Steering Committee. · Liaise with auditors and respond to security audits findings promptly· Drive continuous improvement of cybersecurity maturity in line with CMA and NCA expectations.Qualifications· Bachelor's degree in Computer Science, Information Systems, Cybersecurity or equivalent education · Understanding of relevant legislation, policies and procedures · 2+ years of relevant experience with at least one year experience in financial industries · Strong knowledge of NCA ECC, CMA, ISO27001, NIST, and PDPL frameworks. Saudi Nationality only يقين المالية شركة استثمارية سعودية مدرجة في السوق المالية السعودية ومرخّصة، تخضع لأنظمة هيئة السوق المالية بموجب الترخيص رقم (37-06020). تقدم خدمات الوساطة، إدارة الأصول، المصرفية الاستثمارية، الحفظ والمشورة الاستثمارية للأفراد والمؤسسات.المهام والمسؤوليات:· تطوير وتنفيذ استراتيجية وحوكمة الأمن السيبراني للمنشأة بما يتماشى مع متطلبات هيئة السوق المالية، والهيئة الوطنية للأمن السيبراني ، وتداول. · وضع وصيانة سياسات وإجراءات ومبادئ توجيهية خاصة بالأمن السيبراني. · ضمان الامتثال للقوانين واللوائح ذات الصلة (مثل ضوابط الأمن السيبراني الأساسية الصادرة عن NCA، ولوائح CMA، ونظام حماية البيانات الشخصية PDPL). · تحديد وإدارة مخاطر الأمن السيبراني من خلال التقييمات الدورية، ونمذجة التهديدات، وإجراءات الحد من المخاطر. · مراقبة مؤشرات المخاطر الرئيسية (KRIs) ومؤشرات الأداء الرئيسية (KPIs) ورفع التقارير بشأنها إلى الإدارة التنفيذية. · تعزيز الوعي بالأمن السيبراني وتنفيذ برامج تدريبية على مستوى المنشأة. · إعداد واختبار وتحديث خطط الاستجابة للحوادث واستمرارية الأعمال. · إدارة ومراقبة ضوابط الأمن السيبراني (مثل جدران الحماية، وجدران حماية تطبيقات الويب WAF، وأنظمة SIEM وEDR وDLP، وغيرها). · الإشراف على عمليات التحقيق في حوادث الأمن السيبراني واحتوائها وإعداد التقارير الخاصة بها. · ضمان الامتثال المستمر لمتطلبات التدقيق الداخلي والخارجي. · إجراء تقييمات المخاطر المتعلقة بالأطراف الثالثة، والخدمات الخارجية، والحوسبة السحابية، وضمان امتثالها لمتطلبات CMA وتداول. · رفع تقارير حول وضع الأمن السيبراني، وحالة الامتثال، والحوادث إلى الإدارة التنفيذية ولجنة توجيه أمن المعلومات. · التنسيق مع المدققين والاستجابة الفورية لنتائج وملاحظات عمليات التدقيق الأمني. · دفع عجلة التحسين المستمر لمستوى نضج الأمن السيبراني بما يتماشى مع توقعات CMA وNCA.المؤهلات: · درجة البكالوريوس في علوم الحاسب، أو نظم المعلومات، أو الأمن السيبراني، أو مؤهل تعليمي معادل· الإلمام بالتشريعات والسياسات والإجراءات ذات الصلة· خبرة عملية لا تقل عن سنتين في مجال ذي صلة، منها سنة واحدة على الأقل في القطاع المالي· معرفة قوية بأطر العمل والمعايير التالية: NCA ECC، وCMA، وISO27001، وNIST، وPDPL· الجنسية السعودية فقط