Cybersecurity Risk Specialist
الوصف الوظيفي
About the Role
We are seeking a seasoned Cybersecurity Risk Specialist to lead and support critical cybersecurity risk management initiatives across both IT and OT environments. In this pivotal role, you will be responsible for conducting comprehensive cybersecurity risk assessments, maintaining accurate risk registers, facilitating vulnerability assessments, and contributing to robust enterprise cybersecurity governance programs. Your expertise will be instrumental in identifying, evaluating, and mitigating cyber risks to safeguard our organization’s digital and operational assets.
Key Responsibilities
- Risk Assessment Leadership: Conduct thorough cybersecurity risk assessments in alignment with ISO/IEC 27005 standards, ensuring a systematic approach to identifying and evaluating potential threats and vulnerabilities.
- Risk Register Management: Maintain and update organizational risk registers to provide real-time visibility into cybersecurity risks, enabling proactive decision-making and resource allocation.
- Vulnerability and Risk Evaluations: Perform detailed vulnerability assessments and cybersecurity risk evaluations to identify weaknesses in IT and OT systems, recommending mitigation strategies to enhance resilience.
- Reporting and Analytics: Develop and deliver comprehensive risk reports, Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and Global Risk Prediction Reports to stakeholders at all levels, ensuring transparency and accountability.
- Remediation Tracking: Monitor and track penetration testing findings and remediation activities to ensure timely resolution of identified vulnerabilities and adherence to security policies.
- Vendor Risk Management: Conduct rigorous vendor risk assessments to evaluate third-party security posture and mitigate potential supply chain risks.
- Governance Support: Provide active support to NCA (National Cybersecurity Authority) cybersecurity risk and governance initiatives, ensuring compliance with regulatory requirements and industry best practices.
Requirements
- Educational Background: Bachelor’s degree in Information Security, Information Technology, Computer Science, or a closely related field.
- Professional Experience: Minimum of 5–7 years of hands-on experience in Cybersecurity Risk Management, with a proven track record in vulnerability assessment and exposure to both IT and OT environments.
- Industry Expertise: Demonstrated experience within high-risk sectors such as Energy, Oil & Gas, Manufacturing, Utilities, Industrial (OT/ICS), or Government, where cybersecurity resilience is paramount.
- Certifications: One or more of the following industry-recognized certifications: CRISC (Certified in Risk and Information Systems Control), CISM (Certified Information Security Manager), or ISO/IEC 27005 Risk Manager.
- Language Proficiency: Professional fluency in both Arabic and English, enabling effective communication and collaboration in diverse and international environments.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.