Information Security Manager (KSA National)
Maximus KSA | ماكسيموس السعودية · Riyadh, Saudi Arabia
قدّم وتابع مع أبلاي إيدجWe are looking for an experienced Information Security Manager to join our team in Riyadh.This is a key governance role responsible for the independent oversight, risk management and assurance of our cybersecurity and information security framework. Working closely with senior leadership, IT, Internal Audit, Legal and external regulators, you will help ensure that our security environment remains robust, compliant and aligned with Saudi regulatory requirements.What you'll be responsible for:Developing and maintaining the organisation's cybersecurity strategy and roadmap.Leading the Information Security Management Framework, aligned with ISO 27001, NCA ECC and relevant Saudi regulatory requirements.Owning cybersecurity governance, policies, standards and the Cybersecurity Risk Register.Leading cybersecurity risk assessments across technology projects, cloud solutions, new systems and third-party engagements.Overseeing security compliance, control reviews and independent cybersecurity audits.Tracking audit findings and remediation activities and reporting key risks to senior management.Providing independent oversight of cybersecurity incident governance and response arrangements.Managing third-party security and vendor risk.Acting as a key liaison with regulators, auditors and external assessors.Partnering with Legal and other stakeholders on Saudi PDPL and data protection requirements.What we're looking for:You'll bring 7–10 years' experience in information security, cybersecurity governance or IT governance, including at least three years in a managerial or governance-focused role.We're particularly interested in candidates with:Strong experience with NCA ECC and Saudi cybersecurity regulatory frameworks.Knowledge of Saudi PDPL and SDAIA requirements.Strong ISO/IEC 27001 experience, including leading audits.Experience in cybersecurity governance, risk, compliance and assurance.Strong policy development, reporting and senior stakeholder management skills.A relevant bachelor's degree.Professional certifications such as CISM, CISA, ISO 27001 Lead Implementer/Auditor or COBIT 2019.Fluent English; Arabic Essential If you have strong information security governance experience and understand the Saudi cybersecurity regulatory landscape, we'd be interested in hearing from you.Apply via LinkedIn to join our team in Riyadh.#InformationSecurity #CyberSecurity #GRC #InformationSecurityManager #CyberSecurityJobs #RiyadhJobs #SaudiArabiaJobs #ISO27001 #NCA #RiskManagement