Information Security Risk Assessment Manager
SAB · Riyadh, Saudi Arabia
Apply & track with Apply EdgeJob Title: Information Security Risk Assessment ManagerDivision: Cybersecurity / RiskLocation: RiyadhWorking Hours: 8:00 AM to 5:00 PM (Sunday to Thursday)Role:Cybersecurity Risk Management to support in managing the enterprise-wide cybersecurity risk management program. This position is responsible for conducting threat modeling, developing and maintaining risk assessment methodologies under the risk management team, Also play a critical role in protecting the organization’s information assets by identifying, assessing cybersecurity risks.Key ResponsibilitiesCybersecurity Risk Assessment: Conduct detailed and risk-based Cybersecurity Risk Assessment, meeting SLA commitments during IT and cybersecurity engagements.Maintains a close awareness of best practices and industry standards in Information Security assesses potential policy gaps and/or loopholes and responding risks to SAB IT infrastructure, systems, network and data and recommends any improvements in policies.Liaises closely with end users, explains Cybersecurity risks and the business role in preventing Cybersecurity risks and drives initiatives to sensitize end-users on Cybersecurity risks.Advise IT and business on the optimal way of dealing the identified Cybersecurity risks and mitigation.Final Cybersecurity Risk Assessment: Execute comprehensive Cybersecurity Risk Assessment before go-live.Conduct detailed Cybersecurity Threat ModelingThreat Modeling & Risk Assessments: Conduct detailed cybersecurity risk assessments and threat modeling for IT projects and systems – at early project stages, before major changes, for new technologies, and periodically for existing assets. Identify threats, vulnerabilities, and controls for critical information assets and document these risks in a centralized risk register.Cybersecurity Risk Assessment Validation: Review, analyze, and validate Cybersecurity Risk Assessment results to align the result with Cybersecurity issues raised by other Cybersecurity teams.Raise application security related defectEnhance Cybersecurity pattern during engagements, periodic assessments or Ad-Hoc assessments by highlighting new risks to domain ownersAll engaged/assigned engagements, periodic assessments or Ad-Hoc assessments should be assessed in accordance to the Cybersecurity Risk Management Methodology, Cybersecurity Risk Pattern and Cybersecurity Change Review and Engagement Process and within the agreed timeline (SLA)Cybersecurity Risk Assessment platform Tuning: Customize and fine-tune Cybersecurity risk assessment platform for optimal compatibility and accuracy.Cybersecurity Risk Management Maturity:Enhance the existing Risk Management process and documentationReview and update the existing Cybersecurity Risk Management documentation (methodology, FIM section, standards, guidelines)Ensure that both Cybersecurity Risk Management process and documentation are aligned with Group latest practices, regulatory practice/framework such as NCA , SAMA CSF …etcCybersecurity Risk Management Policy and Design: Ensure all Cybersecurity Risk Management design documents are maintained and aligned with regulators and internal policies.Cybersecurity Risk Management domain Ownership: Develop, unify, and maintain the cybersecurity risk management methodology and procedures, aligned with enterprise risk management and regulatory requirements. Regularly review and update risk management policies, design documents, and tools to reflect changes in the threat landscape or laws. Ensure that risk treatment plans (mitigation, transfer, acceptance, avoidance) are in place and tracked through completion.Periodic Cybersecurity Risk and Crown Jewels assessment: Ensure all required IT Services assessed as per the annual planCybersecurity Assessment Plan: manage periodic cybersecurity assessment plan. Ensure critical systems and services undergo regular security reviews. Document review findings, identified risks, and recommended actions. Coordinate independent cybersecurity teams.Cybersecurity Risk Management Reporting: Provide quarter report about all Cybersecurity risks by highlighting priority risks to be actioned with IT and Cybersecurity Management including:Cybersecurity Risk Management KPIs and KRIs: Calculate required KPIs and KRIs to highlight related risksCybersecurity Risk Management Escalation: Establish escalation matrix for outstanding risks to be followed for all Cybersecurity RisksQualifications and Experience :Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Information Security, or a related discipline.Minimum of 3 years of professional experience in cybersecurity risk management, governance, IT audit, or a related field, preferably in the financial or banking sector.Experience in roles involving compliance with SAMA CSF and NCA ECC.