Information Technology Security Manager
Cenomi Retail · Riyadh, Saudi Arabia
قدّم وتابع مع أبلاي إيدجOverview:Founded in 1990 as Fawaz Alhokair Fashion Retail Co., Cenomi Retail has introduced more than 80 international retail and F&B brands to the Kingdom of Saudi Arabia. These include some of the world’s most loved including Zara, Mango, Aldo, Cinnabon, Subway and more. Cenomi Retail operates more than 1,600 stores across 100 shopping centers in 11 countries. We are dedicated to growth and breaking down boundaries to offer a truly unique brand partnership proposition.Position - IT Security ManagerReporting To - IT DirectorJob Role:The primary job goal for an IT Security Manager is ensuring the confidentiality, integrity, and availability of the organization's information and systems, leading the organization's IT Security strategy, fostering team growth, managing third-party risks, ensuring regulatory compliance, and continuously monitoring performance for effective safeguarding.Key Responsibilities:Collaborate in the execution of the organization's IT Security strategy to safeguard critical assets and data.Sets the overarching strategy for third-party risk management and ensures alignment with organizational security standards.Define the organization's physical security strategy, ensuring integration with broader security goals.Direct the strategic vision and ensures alignment of the organization's network security initiatives with overarching IT Security goals.Determine the strategic approach to data protection, ensuring alignment with regulatory requirements.Establishes the IT Security incident management framework and strategy, ensuring organizational preparedness.Consider IT Security requirements in all outsourcing contracts.Evaluate and assess security risks associated with third-party vendors and service providers to protect the organization's data and assets.Sets the direction for Vulnerability Assessment and Penetration Testing(VAPT) initiatives, ensuring thorough coverage and regulatory compliance.Oversee the monitoring and logging of all administrative activities, implement stringent privileged access controls, and periodically conduct comprehensive access reviews to ensure adherence to IT Security protocols.Establish key performance indicators (KPIs) to measure the effectiveness of security initiatives and track progress toward security goals.Develop and deliver security training and awareness programs.Stay abreast of emerging threats and technologies.Provide leadership and guidance to a team of IT Security professionals, fostering their growth and ensuring effective security practices.Technical Skills (Preferred)Cloud Security: Experience securing cloud environments such as Microsoft Azure, Amazon Web Services (AWS), and Oracle Cloud Infrastructure (OCI).Microsoft Security Stack: Hands-on experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Microsoft Intune, and Microsoft 365 Security solutions.Security Information and Event Management (SIEM): Experience implementing, monitoring, and managing SIEM platforms for threat detection, incident analysis, and security monitoring.Security Orchestration, Automation and Response (SOAR): Experience with security automation, playbook development, and incident response orchestration.Data Loss Prevention (DLP): Knowledge of enterprise DLP technologies and data protection policies to safeguard sensitive information.Zero Trust Security Architecture: Understanding and implementation of Zero Trust principles, including continuous verification, least privilege, and micro-segmentation.Identity & Access Management (IAM): Experience with identity governance, privileged access management (PAM), multi-factor authentication (MFA), single sign-on (SSO), role-based access control (RBAC), and lifecycle management.Academic Qualifications and Certification:Bachelor’s degree in information technology, information systems, computer science or related field (required)Master’s degree in information technology, information systems, computer science or related field (optional)Certified Information Systems Security Professional (CISSP) (optional)Certified Information Security Manager (CISM) (optional)Certified Ethical Hacker (CEH) (optional)CompTIA Security+ (optional)Other IT/Cyber Security-recognized certifications (optional)Job Specific Skills:Industry Specific: Deep understanding of IT Security regulations, standards, best practices, and trends within the retail industry.Data-Driven: Ability to analyze complex issues, make data-driven decisions for proper tracking and optimizing of IT Security processes.Ethics and Integrity: Ethical and committed to upholding the highest standards in IT Security.Regulatory Expert: Strong understanding of IT Security regulatory requirements and applicable laws and regulations in the Kingdom of Saudi Arabia.Technical Knowledge: Excellent knowledge in IT Security tools, methodologies, and frameworks.Analytical: Strong analytical and problem-solving skills, and the ability to define and track key performance indicators (KPIs) for IT Security efforts.Leadership Skills: Demonstrated leadership abilities in managing and motivating teams focused on IT Security matters.Communication Skills: Ability to work collaboratively across departments and with external stakeholders.Required Prior Experience:7-9 years of relevant experience in IT Security or a related role, with a demonstrated track record of leading successful security initiatives.Proven experience in managing third-party risks and ensuring compliance with industry regulations and standards.Strong background in developing and executing IT Security strategies.Experience in responding to and managing security incidents.Strong understanding of firewalls, VPNs, IDS/IPS, and other network security technologies.Knowledge of secure coding practices, web application security, and vulnerability assessment & Penetration Testing(VAPT).Previous experience in team leadership and people management, with a focus on promoting team growth and ensuring effective security practices.Track record of successful collaboration with cross-functional teams to integrate security measures effectively.Preferred certifications:CISSPCISMCEHSecurity+ISO 27001 Lead ImplementerCCSP