أبلاي إيدج ابدأ البحث عن عمل

Cybersecurity Manager

Al Majed Oud.co · Riyadh, Saudi Arabia

قدّم وتابع مع أبلاي إيدج
Job Objective:To lead and develop the comprehensive cybersecurity strategy, govern the protection of digital infrastructure and technical assets, ensure compliance with the National Cybersecurity Authority (NCA) regulations, manage risks and budgets, and build capacities for Al Majed Oud Company.Scope of Responsibilities and Key Duties:1. Leadership, Strategy, and Digital Asset ProtectionLeads and approves the comprehensive cybersecurity strategy in alignment with the company’s general directives and digital transformation strategy.Defines and adopts cybersecurity requirements and controls for infrastructure, networks, servers, and cloud environments, and monitors their implementation in coordination with the Operations and Infrastructure Department.Approves response plans for cyber incidents, emergencies, and technical crises to ensure business continuity and mitigate risks.Directs the execution of vulnerability assessments and periodic penetration testing for digital infrastructure and applications, and approves remediation plans.Governs and oversees the securing of digital supply chains, technology service provider contracts, and external company systems.Supervises the Security Operations Center (SOC) and monitors 24/7 early warning and threat detection indicators.Approves cybersecurity architecture requirements in coordination with the Enterprise Architecture team.2. Governance, Risk Management, and Cyber ComplianceGoverns and ensures full compliance with the National Cybersecurity Authority (NCA) controls, such as Essential Cybersecurity Controls (ECC) and Critical Systems Cybersecurity Controls (CSCC).Approves and updates the corporate cyber risk register and endorses treatment strategies and operational/technical risk mitigation plans.Endorses internal security policies, standards, and controls, and oversees their dissemination and implementation across all sectors of the company.Directs and oversees cybersecurity awareness programs and phishing simulation campaigns to elevate employees' security awareness.Coordinates with regulatory bodies, authorities, and independent auditors, and approves periodic compliance and cyber audit reports.Monitors and evaluates personal data protection and commercial transaction confidentiality projects to ensure alignment with approved regulations.3. Budget Management and Financial ControlPrepares the annual estimated budget for the Cybersecurity Department, including license costs, security software, and security infrastructure.Oversees the regulation and tracking of operational and capital expenditures (OPEX/CAPEX) for security projects to ensure strict compliance with the approved budget.Evaluates the technical and financial feasibility of targeted security solutions and tools to maximize the return on investment (ROI) in digital asset protection.4. People ManagementLeads and directs the cybersecurity team and monitors the achievement of operational goals.Sets SMART individual goals and Key Performance Indicators (KPIs) for subordinates, and approves annual performance evaluations and training needs.Directs and ensures the creation of succession plans, development of technical talents, and preparation of second-line cyber leaders.Fosters a culture of compliance and security vigilance, and promotes a motivating work environment that supports outstanding performance and corporate alignment.5. Policies, Operations, and ProceduresMonitors the implementation of policies, processes, standard operating procedures (SOPs), identity management controls, and access privileges.Leads developmental initiatives to automate incident response and continuously improve cyber defense and analysis tools.Qualifications and Requirements:Experience:8 to 12 years of specialized practical experience in cybersecurity, digital infrastructure protection, and governance, including at least 3 years in a supervisory or leadership role.Previous experience as an ISO 27001 Lead Implementer / Lead Auditor is preferred.Educational Qualifications:Bachelor’s degree in Cybersecurity, Computer Engineering, Computer Science, Information Technology, or an equivalent field.Professional Certifications:Mandatory: CISM or CISSPPreferred: CRISCSkills:High leadership and strategic ability to manage and direct the cybersecurity and digital transformation ecosystem.Superior competence in formulating and approving cyber governance frameworks, policies, and national compliance standards.Exceptional skill in preparing and managing estimated budgets for cybersecurity, and controlling license and project costs.Deep experience in the security architecture of networks, cloud systems, and e-commerce platforms.Mastery of cyber risk management, building risk registers, and treatment strategies.Ability to lead cyber incident response operations, crisis management, and disaster recovery.Comprehensive knowledge of the National Cybersecurity Authority (NCA) regulations and international digital security standards.High-level strategic communication and coordination skills with executive management and regulatory authorities.