CISO
الوصف الوظيفي
Chief Information Security Officer (CISO)
The CISO is a pivotal role responsible for driving the enterprise's information security vision, strategy, and program to safeguard information assets and technologies. This leader oversees the security of both Information Technology (IT) and Operational Technology (OT) environments, ensuring alignment with Saudi Vision 2030 digital transformation goals and compliance with National Cybersecurity Authority (NCA) regulations.
- Strategy & Governance: Develop and implement a comprehensive cybersecurity strategy that aligns with operational goals and safety standards. Ensure full compliance with NCA regulations, including Essential Cybersecurity Controls (ECC) and Critical Systems Cybersecurity Controls (CSCC). Establish and enforce security policies, standards, and procedures for both corporate and industrial networks. Regularly report the state of cybersecurity to the Board of Directors and Executive Committee.
- IT/OT Convergence & Critical Infrastructure Protection: Oversee the protection of Industrial Control Systems (ICS), signaling systems, and rolling stock operational data. Bridge the gap between IT and Engineering/Operations teams to ensure a unified security posture. Conduct regular threat modeling for critical infrastructure to prevent cyber-physical attacks.
- Risk Management & Incident Response: Manage the Cyber Security Operations Center (CSOC) for 24/7 threat monitoring. Lead the Incident Response Team (IRT) in case of a breach to minimize operational downtime and reputational damage. Conduct regular vulnerability assessments and penetration testing on booking systems, mobile apps, and control networks.
- Data Privacy & Vendor Management: Ensure compliance with the Saudi Personal Data Protection Law (PDPL) regarding passenger and employee data. Oversee Third-Party Risk Management (TPRM) to ensure supply chain partners meet security standards.
Requirements include a minimum of 10 years of experience in Information Security, with at least 4 years in a leadership role. Proven experience managing OT/ICS security environments and any 2 of the following certifications: CISSP, CISM, CISA, or GICSP. Deep understanding of NCA frameworks, Cloud Security (Azure/AWS), and IoT security. Saudi Nationals are strongly preferred due to the critical nature of the role and alignment with Vision 2030 and Nitaqat requirements.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.