IT Security Lead
Al Safi Danone | الصافي دانون · Riyadh, Saudi Arabia
قدّم وتابع مع أبلاي إيدجRole Purpose:The IT Security Lead is responsible for implementing and managing ASD’s enterprise information security programme to protect its systems, data, and digital assets from cyber threats and ensure regulatory compliance. The role establishes and matures the organization's security posture through policy, technology, and awareness — with a specific focus on securing the SAP S/4HANA programme environment, Microsoft platforms, cloud infrastructure, and operational technology. The Security Lead operates within the B-ITSC governance framework and reports on security risk to executive leadership and the board.Key Accountabilities:Own ASD’s information security strategy, policy framework, and security roadmap.Coordinate and maintain information security policies, standards, and procedures.Produce quarterly security risk reports for the IT Operations Manager. Conduct annual information security risk assessments; maintain the enterprise security risk register and treatment plans.Ensure compliance with applicable regulations including PDPL (Saudi Personal Data Protection Law), GDPR, and NCA ECC framework.Collaborate with the Security Operations Centre (SOC) function, monitoring and alerting.Lead incident response activities; own the Incident Response Plan and Playbooks for P1/P2 cyber security events.Manage threat intelligence feeds and vulnerability management programme; prioritize patching based on risk exposure.Conduct regular penetration testing, red team exercises, and security assessments; remediate findings within agreed SLAs.Oversee endpoint detection and response (EDR) using Microsoft Defender for Endpoint across all ASD devices.Manage Business Continuity Planning (BCP) and Disaster Recovery (DR) for cyber event scenarios.Define and govern the SAP S/4HANA security architecture including role-based access control, segregation of duties (SoD), and audit logging.Review SAP security design deliverables produced by the system integrator; validate against ASD’s security standards.Conduct SoD conflict analysis during UAT and prior to go-live; ensure remediation before production cutover.Manage security requirements for all application systems: SalesBuzz, SalesCode, Shelfr, SO99, and third-party SaaS.Collaborate with AFG, ASD’s Identity and Access Management (IAM) programme including Privileged Access Management (PAM) and Zero Trust implementation.Govern user provisioning, de-provisioning, and access certification processes across all systems including SAP and M365.Manage Azure Active Directory / Entra ID security configuration: MFA, Conditional Access, PIM, and identity protection.Define and enforce least-privilege access principles and role segregation policies across IT and business systems.Conduct quarterly access reviews and user entitlement audits; report exceptions to the IT Operations Manager.Deliver the organisation-wide security awareness and training programme; track completion rates and phishing simulation outcomes.Manage third-party and supply chain security risk assessments; include security requirements in vendor contracts.Liaise with Internal Audit on security-related audit findings; develop and track remediation action plans.Prepare for and support external regulatory audits and certifications, including NCA ECC, ISO 27001, and ZATCA security requirements.Produce monthly security metrics dashboards covering threat landscape, vulnerability posture, and compliance status.Qualifications:Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field.CISM (Certified Information Security Manager) — required or CISA — preferred.Microsoft SC-200 (Security Operations Analyst) or SC-300 — advantageous.5–8 years of experience in information security, with at least 3 years in a security leadership role.Proven experience securing SAP environments including role design, SoD analysis, and SAP security audit.Experience with cloud security: Azure Security Center / Defender for Cloud, AWS GuardDuty, or GCP SCC.Knowledge of Saudi Arabia regulatory requirements: PDPL and NCA ECC cybersecurity framework — strongly preferred.Strong incident response and forensic investigation experience; crisis communication skills.GCC or FMCG industry experience is an advantage.Excellent risk communication skills; experience presenting security risk to executive and board audiences.