Cybersecurity Risk Analyst

ASMO
السعودية, السعودية دوام كامل
نشر: 1448/2/3 | 2026/07/17 ينتهي: 1448/3/3 | 2026/08/16 ✨ وصف بالذكاء الاصطناعي
تقدم للوظيفة الآن

الوصف الوظيفي

Objective

The Cybersecurity Risk Analyst plays a pivotal role in establishing and maintaining robust quality assurance standards across ASMO’s Technology function. This position is instrumental in monitoring and evaluating information technology standards, ensuring strict compliance with internal policies and regulatory requirements. By developing and implementing a comprehensive Information Security Risk Management Framework, the role holder will proactively identify, assess, and mitigate information security risks to safeguard ASMO’s digital assets and operational integrity.

Key Responsibilities

  • Risk Management Framework Development: Design and execute information security risk programs, aligning them with internal policies, industry standards, and regulatory mandates to ensure a resilient security posture.
  • Risk Identification and Treatment: Conduct thorough assessments of information security risks in accordance with the established framework, developing and maintaining Key Risk Indicators (KRIs) to monitor critical assets. Track remediation efforts and update the information security risk register to reflect evolving threats and mitigation progress.
  • Cross-Functional Collaboration: Partner with all ASMO departments to integrate risk mitigation strategies into business operations, fostering a culture of security awareness and accountability across the organization.
  • Policy and Procedure Development: Create, refine, and enforce Information Security policies and procedures that meet ASMO’s standards and regulatory obligations, ensuring seamless integration of security solutions into the Technology infrastructure.
  • Compliance and Counter-Risk Measures: Implement and enforce counter-risk strategies while adhering to established policies and compliance frameworks, thereby creating a secure operational environment for ASMO’s Technology business functions.
  • Risk Reporting and Analysis: Develop, review, and analyze monthly business risk information reports to identify policy-driven risks and recommend strategic improvements to enhance security resilience.
  • System Monitoring and Incident Response: Conduct continuous monitoring of system activities, perform spot checks, and analyze security incidents to inform policy adjustments and drive necessary system modifications in collaboration with relevant departments.
  • Security Assessments and Integration: Lead security assessments for new software and infrastructure, define security standards, and oversee the integration of security requirements into the Technology Infrastructure to ensure adherence to policies and procedures.
  • Project Guidance and Security Controls: Provide expert Information Security guidance to Technology department projects, embedding risk-based security measures and ensuring the implementation of adequate controls to achieve optimal protection levels.
  • Threat Awareness and Policy Enhancement: Stay abreast of industry best practices and emerging threats, conducting regular assessments of ASMO’s IT infrastructure, systems, networks, and data to recommend policy improvements and mitigate vulnerabilities.
  • Incident and Observation Management: Address all Information Security-related observations and incidents promptly, ensuring corrective actions are taken to minimize potential impacts.
  • Stakeholder Engagement and Awareness: Collaborate closely with end users to explain security risks, emphasize the role of business units in preventing security fraud, and drive initiatives to raise awareness about Information Security best practices. Design and deliver informative sessions to sensitize stakeholders on critical security risks and mitigation strategies.

Qualifications and Experience

To excel in this role, candidates must possess a Bachelor’s degree in Information Technology or an equivalent field. A certification such as Certified Data Privacy Solutions Engineer (CDPSE) is highly desirable. The ideal candidate will have a minimum of five years of experience in Information Technology, Data Solutions, Networking, or Cybersecurity. Strong proficiency in both oral and written English is essential to effectively communicate complex security concepts and collaborate across global teams.

يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.

المصدر: لينكد إن ↗ • 16 مشاهدة

وظائف مشابهة

تقدم للوظيفة الآن