IT Security Lead

Al Safi Danone | الصافي دانون
الرياض, الرياض دوام كامل
نشر: 1448/2/22 | 2026/08/05 ينتهي: 1448/3/22 | 2026/09/04 ✨ وصف بالذكاء الاصطناعي
تقدم للوظيفة الآن

الوصف الوظيفي

IT Security Lead – Safeguarding Digital Assets and Driving Enterprise Security Excellence

In this pivotal role as **IT Security Lead**, you will spearhead the development and execution of ASD’s comprehensive enterprise information security strategy, ensuring robust protection of systems, data, and digital assets against evolving cyber threats. Reporting directly to executive leadership and the board, you will establish and mature ASD’s security posture through a disciplined blend of policy, cutting-edge technology, and proactive awareness initiatives. With a critical focus on securing the **SAP S/4HANA programme environment, Microsoft platforms, cloud infrastructure, and operational technology**, you will align security efforts with regulatory compliance while fostering a culture of resilience and risk mitigation.

As the guardian of ASD’s cybersecurity framework, you will drive the organization’s security vision by designing and implementing a **scalable, future-proof security roadmap** that balances innovation with risk reduction. Your leadership will be instrumental in shaping **information security policies, standards, and procedures**, ensuring they evolve in tandem with emerging threats and business needs. Through **quarterly security risk assessments** and the maintenance of an enterprise-wide security risk register, you will provide actionable insights to stakeholders, enabling informed decision-making at the highest levels.

Core Responsibilities

Your role encompasses a broad spectrum of security disciplines, demanding both strategic foresight and hands-on execution:

  • Strategic Leadership: Own the development and governance of ASD’s **information security strategy**, ensuring alignment with global regulations such as **PDPL (Saudi Personal Data Protection Law), GDPR, and the NCA ECC framework**. Define and champion the security roadmap, translating business objectives into actionable security initiatives.
  • Risk Management and Compliance: Conduct **annual security risk assessments** and produce **quarterly risk reports** for executive review. Maintain a dynamic **security risk register** and treatment plans, prioritizing vulnerabilities based on impact and likelihood. Oversee compliance audits, including **ISO 27001, ZATCA security requirements, and external regulatory assessments**, ensuring ASD meets all legal and operational mandates.
  • Incident Response and Threat Mitigation: Lead ASD’s **Incident Response Plan (IRP) and playbooks**, ensuring rapid and effective containment of **P1/P2 cybersecurity events**. Collaborate closely with the **Security Operations Centre (SOC)** to monitor threats, manage alerting systems, and implement proactive countermeasures. Oversee **threat intelligence feeds** and **vulnerability management**, prioritizing patching efforts to mitigate high-risk exposures.
  • Technical Governance: Define and enforce **SAP S/4HANA security architecture**, including **role-based access control (RBAC), segregation of duties (SoD), and audit logging**. Review and validate security design deliverables from system integrators, ensuring adherence to ASD’s stringent standards. Conduct **penetration testing, red team exercises, and security assessments**, remediating findings within agreed SLAs. Manage **endpoint detection and response (EDR)** using **Microsoft Defender for Endpoint** across all ASD devices.
  • Identity and Access Management (IAM): Collaborate with ASD’s IAM programme to govern **Privileged Access Management (PAM) and Zero Trust initiatives**. Oversee **user provisioning, de-provisioning, and access certification** processes across SAP, M365, and other systems. Define and enforce **least-privilege access principles**, conducting **quarterly access reviews** and audits to mitigate unauthorized entitlements.
  • Cloud and Application Security: Secure **Azure Active Directory / Entra ID configurations**, including **Multi-Factor Authentication (MFA), Conditional Access, and Privileged Identity Management (PIM)**. Manage security requirements for all critical applications, including **SalesBuzz, SalesCode, Shelfr, SO99, and third-party SaaS platforms**. Ensure **Business Continuity Planning (BCP) and Disaster Recovery (DR)** protocols are robust against cyber event scenarios.
  • Third-Party and Supply Chain Security: Conduct **vendor security risk assessments** and integrate security requirements into procurement contracts. Liaise with **Internal Audit** to address security-related findings, developing and tracking remediation action plans.
  • Security Awareness and Training: Design and deliver an **organization-wide security awareness programme**, including phishing simulations and training modules. Track completion rates and outcomes to measure effectiveness and drive continuous improvement.
  • Metrics and Reporting: Develop and maintain **monthly security metrics dashboards**, providing visibility into the **threat landscape, vulnerability posture, and compliance status**. Present actionable insights to leadership, enabling data-driven security investments.

This role is ideal for a **seasoned security professional** with a proven track record in **enterprise security leadership**, particularly within complex SAP and cloud environments. Your expertise will be instrumental in elevating ASD’s security posture, ensuring resilience against cyber threats, and fostering a culture of security excellence across the organization.

يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.

المصدر: لينكد إن ↗ • 1 مشاهدة

ℹ️ إخلاء مسؤولية توظيف:

موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.

وظائف مشابهة

تقدم للوظيفة الآن