IT Security Lead
الوصف الوظيفي
Position Overview
We are seeking a seasoned and strategic IT Security Lead to spearhead the development, implementation, and continuous improvement of our enterprise-wide information security program. This critical role is responsible for safeguarding our digital infrastructure, systems, and sensitive data against evolving cyber threats while ensuring full compliance with global and regional regulatory frameworks. The ideal candidate will possess deep expertise in enterprise security architecture, cloud security, and operational technology, with a strong focus on securing SAP S/4HANA environments, Microsoft platforms, and hybrid cloud infrastructures. Reporting to senior leadership, this position plays a pivotal role in shaping our security posture, driving risk mitigation initiatives, and fostering a culture of security awareness across the organization.
Key Responsibilities
The IT Security Lead will be accountable for the following core functions:
- Security Strategy & Governance: Develop and execute a comprehensive information security strategy aligned with business objectives, ensuring alignment with the B-ITSC governance framework. Establish, maintain, and continuously refine security policies, standards, and procedures to reflect industry best practices and regulatory requirements.
- Risk Management & Compliance: Conduct annual information security risk assessments and maintain a dynamic enterprise security risk register, including treatment plans and remediation tracking. Ensure strict adherence to regulatory mandates such as the Saudi Personal Data Protection Law (PDPL), General Data Protection Regulation (GDPR), and the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) framework. Oversee compliance initiatives and prepare for external audits and certifications, including NCA ECC, ISO 27001, and ZATCA requirements.
- Incident Response & Threat Management: Lead the organization’s incident response efforts by owning and maintaining the Incident Response Plan and playbooks for high-priority (P1/P2) cybersecurity events. Collaborate closely with the Security Operations Centre (SOC) to monitor threats, analyze alerts, and coordinate response actions. Manage threat intelligence feeds and prioritize vulnerability remediation based on risk exposure, ensuring timely patching and mitigation.
- Security Assessments & Testing: Oversee and conduct regular penetration testing, red team exercises, and security assessments across all critical systems. Validate and remediate findings within defined service-level agreements (SLAs) to maintain a robust security posture.
- SAP S/4HANA & Application Security: Define, implement, and govern the security architecture for SAP S/4HANA, including role-based access control, segregation of duties (SoD), and comprehensive audit logging. Review and validate security design deliverables produced by system integrators, ensuring alignment with ASD’s stringent security standards. Conduct SoD conflict analysis during user acceptance testing (UAT) and prior to go-live, enforcing remediation before production deployment. Additionally, manage security requirements for key applications such as SalesBuzz, SalesCode, Shelfr, SO99, and third-party SaaS solutions.
- Identity & Access Management (IAM): Lead the AFG Identity and Access Management (IAM) program, including Privileged Access Management (PAM) and Zero Trust implementation. Govern user provisioning, de-provisioning, and access certification processes across all systems, with a focus on SAP and Microsoft 365. Define and enforce least-privilege access principles and role segregation policies to minimize risk exposure.
- Cloud & Endpoint Security: Manage and secure cloud infrastructure, including Microsoft Azure Active Directory / Entra ID, with a focus on multi-factor authentication (MFA), conditional access policies, Privileged Identity Management (PIM), and identity protection. Oversee endpoint detection and response (EDR) using Microsoft Defender for Endpoint across all corporate devices to detect and mitigate advanced threats.
- Business Continuity & Disaster Recovery: Develop, maintain, and test Business Continuity Planning (BCP) and Disaster Recovery (DR) strategies specifically tailored for cyber event scenarios, ensuring minimal disruption to critical operations.
- Security Awareness & Training: Design, deliver, and monitor a comprehensive, organization-wide security awareness and training program. Track completion rates, conduct phishing simulations, and foster a security-conscious culture through ongoing education and engagement initiatives.
- Third-Party & Supply Chain Security: Conduct rigorous security risk assessments for third-party vendors and supply chain partners. Integrate robust security requirements into vendor contracts and maintain ongoing oversight to mitigate associated risks.
- Reporting & Stakeholder Engagement: Produce and present quarterly security risk reports to the IT Operations Manager and executive leadership, highlighting key risks, trends, and mitigation progress. Develop and maintain monthly security metrics dashboards that provide visibility into the threat landscape, vulnerability posture, and compliance status across the enterprise.
Qualifications & Experience
To excel in this role, candidates must meet the following criteria:
- Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a closely related field.
- Certifications: Certified Information Security Manager (CISM) is required; Certified Information Systems Auditor (CISA) is preferred. Additional advantageous certifications include Microsoft SC-200 (Security Operations Analyst) or SC-300 (Identity and Access Administrator).
- Professional Experience: Minimum of 5–8 years in information security, with at least 3 years in a leadership or managerial capacity. Proven track record in securing SAP environments, including role design, SoD analysis, and SAP security audits. Hands-on experience with cloud security platforms such as Azure Security Center / Defender for Cloud, AWS GuardDuty, or Google Cloud Security Command Center (SCC) is highly desirable.
- Regulatory Knowledge: In-depth understanding of Saudi regulatory requirements, particularly PDPL and NCA ECC, with the ability to interpret and apply these frameworks effectively across the organization.
- Technical & Soft Skills: Strong analytical, problem-solving, and communication skills. Ability to translate complex security concepts into actionable strategies for technical and non-technical stakeholders. Demonstrated leadership in driving security initiatives, managing cross-functional teams, and influencing organizational change.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.