Cybersecurity Policy officer- KSA
الوصف الوظيفي
About the Role
We are seeking a highly motivated and experienced Cybersecurity Policy Officer to join our team in the Kingdom of Saudi Arabia. In this critical role, you will be responsible for developing, implementing, and maintaining robust cybersecurity policies, standards, and procedures to safeguard our organization against evolving threats. Your expertise will ensure compliance with industry-leading frameworks, including the NIST Cybersecurity Framework (CSF), while fostering a culture of security awareness across the enterprise. This position offers an opportunity to play a pivotal role in strengthening our cybersecurity governance and protecting our digital assets in a dynamic and fast-paced environment.
Key Responsibilities
- Policy Development and Maintenance: Lead the creation, review, and continuous improvement of cybersecurity policies, standards, procedures, and guidelines to align with organizational goals and regulatory requirements.
- Framework Compliance: Ensure adherence to the NIST Cybersecurity Framework (CSF) and other relevant cybersecurity frameworks, standards, and best practices to maintain a resilient security posture.
- Risk Assessment and Management: Conduct comprehensive cybersecurity risk assessments to identify vulnerabilities, evaluate threats, and recommend mitigating security controls to minimize risk exposure.
- Collaboration and Implementation: Work closely with IT, business, and operational teams to implement, monitor, and enforce security policies and controls effectively across the organization.
- Audit and Compliance Support: Facilitate internal and external security audits, assessments, and compliance initiatives to demonstrate adherence to regulatory and industry standards.
- Threat Intelligence and Policy Updates: Stay abreast of emerging cybersecurity threats, regulatory changes, and industry trends to ensure policies remain current, relevant, and effective.
- Governance and Continuous Improvement: Drive continuous improvement in cybersecurity governance by identifying gaps, recommending enhancements, and implementing best practices to strengthen the organization’s security posture.
- Reporting and Documentation: Prepare detailed reports, documentation, and presentations to communicate cybersecurity governance status, risks, and compliance metrics to stakeholders at all levels.
- Security Awareness and Training: Promote a culture of security awareness by providing guidance, training, and support to employees on cybersecurity policies, best practices, and their roles in maintaining a secure environment.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field (or equivalent practical experience).
- Fluency in English with exceptional written and verbal communication skills to articulate complex security concepts to diverse audiences.
- Professional certification in at least one of the following:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CRISC (Certified in Risk and Information Systems Control)
- CISA (Certified Information Systems Auditor)
Required Skills & Experience
- In-depth knowledge and hands-on experience with the NIST Cybersecurity Framework (CSF) and related cybersecurity standards.
- Proven expertise in cybersecurity governance, policy development, risk management, and compliance within a corporate or enterprise environment.
- Strong analytical skills with the ability to conduct thorough risk assessments and recommend appropriate security controls to mitigate identified risks.
- Solid understanding of information security principles, security frameworks, and regulatory compliance requirements (e.g., GDPR, ISO 27001, local regulations).
- Excellent documentation, reporting, and stakeholder communication skills to engage with technical and non-technical audiences effectively.
- Experience collaborating with cross-functional teams, including IT, legal, HR, and business units, to implement and maintain cybersecurity policies and controls.
Preferred Qualifications
- Experience with additional security frameworks such as ISO/IEC 27001, COBIT, or PCI DSS, and familiarity with their implementation and auditing processes.
- Knowledge of IT risk management methodologies, audit processes, and information security governance frameworks.
- Prior experience working in regulated industries, including banking, finance, healthcare, telecommunications, or government sectors, is highly advantageous.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.