IT Security Engineer
الوصف الوظيفي
About the Role
We are seeking a motivated and detail-oriented IT Security Engineer to join our dynamic team. This position is ideal for a fresh graduate eager to develop expertise in cybersecurity while contributing to the protection of our organization’s critical IT systems, applications, and data. Under the mentorship of senior IT professionals, you will play a pivotal role in implementing security standards, monitoring threats, and ensuring compliance with Saudi cybersecurity regulations. This role offers a unique opportunity to build a strong foundation in security governance, vulnerability management, and secure infrastructure practices while fostering a culture of security awareness across the organization.
Key Responsibilities
- Security Governance & Compliance Support:
- Assist in the implementation of IT security standards and internal security policies to align with organizational and regulatory requirements.
- Support compliance activities related to Saudi cybersecurity regulations, including the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC), Personal Data Protection Law (PDPL), and ISO 27001 standards.
- Maintain security documentation, checklists, and audit evidence to ensure transparency and accountability in security operations.
- Collaborate with senior team members to track and follow up on required security actions and remediation efforts.
- Threat & Vulnerability Management:
- Monitor security alerts and escalate suspicious activities to senior IT team members for further investigation and resolution.
- Assist in vulnerability scanning, risk assessment, and remediation tracking to mitigate potential security threats.
- Support patch management and corrective actions by documenting findings and coordinating with relevant teams to ensure timely resolution.
- Maintain security incident logs and work closely with IT support and incident response teams to resolve security breaches efficiently.
- Application & Infrastructure Security:
- Secure all layers of applications and infrastructure, including web applications, backend systems, APIs, databases, and client applications.
- Perform basic code security scanning before deployments to identify and report potential vulnerabilities, ensuring adherence to secure coding practices.
- Implement robust access control mechanisms, authentication protocols, encryption standards, and secure configurations to protect sensitive data.
- Collaborate with DevOps and Infrastructure teams to integrate security best practices into deployment pipelines and ensure secure operational environments.
- Knowledge Management & Training:
- Develop and maintain security guidelines, Standard Operating Procedures (SOPs), and documentation to support consistent security practices across the organization.
- Conduct training sessions and workshops to raise security awareness among internal users, technical teams, and stakeholders, fostering a proactive security culture.
- Promote best practices in information security and ensure that all employees understand their roles in safeguarding organizational assets.
- Collaboration & Technical Delivery:
- Work closely with Infrastructure, DevOps, and Development teams to design and implement secure architectures and operational processes.
- Review and approve security measures for new tools, applications, and integrations to ensure they meet organizational and regulatory standards.
- Provide expert advice on security requirements for new projects, features, or customer integrations, ensuring alignment with security policies and industry best practices.
Job Relations
This role reports directly to the IT Infrastructure Lead or IT Manager. Internally, you will collaborate closely with DevOps Engineers, Infrastructure Engineers, Quality Assurance (QA) teams, Development Teams, and IT Support to ensure a cohesive and secure operational environment. Externally, you may liaise with regulators, auditors, and external vendors to facilitate security assessments, penetration tests, and certifications, as well as escalate critical security risks to IT leadership and management as needed.
Qualifications & Competencies
To thrive in this role, you should possess a Bachelor’s degree in Computer Engineering, Computer Science, Cybersecurity, Information Technology, or a related field. As a fresh graduate or professional with up to two years of experience in Information Security, Cybersecurity, or IT, you will have the opportunity to apply your foundational knowledge while expanding your expertise. Relevant certifications such as CompTIA Security+, Certified Ethical Hacker (CEH), or ISO 27001 Foundation are advantageous and demonstrate your commitment to the field.
You should have a basic understanding of security governance, risk management, and compliance concepts, along with knowledge of:
- Network and infrastructure security, including firewalls, VPNs, and Intrusion Detection/Prevention Systems (IDS/IPS).
- Application security principles for web, API, and mobile applications.
- Security monitoring tools and Security Information and Event Management (SIEM) platforms.
- Backup, Disaster Recovery (DR), and Business Continuity concepts to ensure resilience against security incidents.
- Secure Software Development Lifecycle (SSDLC) practices and security code scanning techniques.
- Awareness of Saudi cybersecurity regulations and frameworks, such as NCA ECC, PDPL, and ISO 27001, is preferred.
We value candidates who exhibit a willingness to learn, a risk-aware mindset, and a keen attention to detail. Strong collaboration and communication skills are essential to influence both technical and non-technical teams, while a proactive attitude toward security awareness, documentation, and continuous improvement will set you apart in this role.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.