Information Technology Security Manager
الوصف الوظيفي
Information Technology Security Manager – Safeguarding Innovation at Cenomi Retail
Join Cenomi Retail, a dynamic and visionary retail leader, as we continue to redefine the retail landscape across the Middle East and beyond. Since 1990, we have pioneered the introduction of over 80 globally renowned brands—from fashion to fast-casual dining—into the Kingdom of Saudi Arabia and beyond, operating an expansive network of over 1,600 stores across 11 countries. As an Information Technology Security Manager, you will play a pivotal role in fortifying our digital infrastructure, ensuring the confidentiality, integrity, and availability of our critical assets, and driving a proactive security culture that aligns with our ambitious growth trajectory.
Reporting directly to the IT Director, this strategic position demands a forward-thinking leader with a deep expertise in cybersecurity, risk management, and compliance. You will spearhead our IT security initiatives, fostering a resilient security posture while empowering our team to deliver exceptional results. This is an opportunity to shape the future of cybersecurity at a company that values innovation, collaboration, and excellence.
Key Responsibilities
In this dynamic role, your responsibilities will be both strategic and operational, ensuring that Cenomi Retail remains at the forefront of cybersecurity excellence:
- Strategic Leadership: Collaborate with senior leadership to develop and execute a robust IT security strategy that safeguards our critical assets, data, and digital infrastructure against evolving threats. Align security initiatives with business objectives to drive sustainable growth while minimizing risk.
- Third-Party Risk Management: Establish and oversee a comprehensive third-party risk management framework, ensuring that all external vendors, partners, and service providers adhere to our stringent security standards. Conduct thorough risk assessments and due diligence to mitigate potential vulnerabilities in our supply chain.
- Physical and Network Security: Define and implement a cohesive physical security strategy that integrates seamlessly with our broader IT security framework. Lead the strategic vision for network security initiatives, ensuring alignment with organizational goals and regulatory requirements.
- Data Protection and Compliance: Develop and enforce a strategic approach to data protection that complies with international regulations, including GDPR, local data sovereignty laws, and industry-specific standards. Ensure that all data handling practices align with legal and ethical obligations.
- Incident Management and Resilience: Design and implement a robust IT security incident management framework, including response protocols, recovery plans, and continuous improvement mechanisms. Ensure that the organization is prepared to detect, respond to, and recover from security incidents with minimal disruption.
- Vendor and Contract Security: Embed IT security requirements into all outsourcing contracts and third-party agreements, ensuring that security considerations are prioritized from the outset. Conduct regular audits and evaluations to assess compliance and risk exposure.
- Vulnerability Assessment and Penetration Testing (VAPT): Lead VAPT initiatives to identify and mitigate security vulnerabilities across our systems, applications, and infrastructure. Ensure that testing methodologies are thorough, compliant with industry best practices, and aligned with regulatory requirements.
- Access Control and Monitoring: Oversee the implementation of stringent privileged access controls, administrative activity monitoring, and periodic access reviews. Utilize advanced logging and monitoring tools to detect and respond to suspicious activities in real time.
- Performance and KPI Development: Establish key performance indicators (KPIs) to measure the effectiveness of security initiatives, track progress toward security goals, and demonstrate the value of IT security investments to stakeholders.
- Security Awareness and Training: Develop and deliver engaging security training programs to educate employees at all levels about best practices, emerging threats, and their role in maintaining a secure organizational environment.
- Threat Intelligence and Innovation: Stay ahead of the curve by continuously monitoring emerging threats, advancements in cybersecurity technologies, and industry trends. Proactively recommend and implement innovative solutions to enhance our security posture.
- Team Leadership and Development: Provide visionary leadership to a high-performing IT security team, fostering a culture of continuous learning, collaboration, and professional growth. Mentor team members to ensure they are equipped with the skills and knowledge to excel in their roles.
Technical Expertise and Qualifications
To excel in this role, you will bring a blend of technical expertise, strategic acumen, and a passion for cybersecurity. While we value a diverse range of skills, the following technical proficiencies are highly preferred:
- Cloud Security: Extensive experience securing cloud environments, including Microsoft Azure, Amazon Web Services (AWS), and Oracle Cloud Infrastructure (OCI). A deep understanding of cloud-native security controls, compliance frameworks, and threat mitigation strategies.
- Microsoft Security Stack: Hands-on experience with Microsoft’s comprehensive security solutions, such as Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID (formerly Azure AD), Microsoft Purview, Microsoft Intune, and Microsoft 365 Security. Proficiency in leveraging these tools to enhance threat detection, incident response, and compliance monitoring.
- Security Information and Event Management (SIEM): Expertise in implementing, configuring, and managing SIEM platforms to centralize security monitoring, detect anomalies, and respond to incidents efficiently. Familiarity with tools like Splunk, IBM QRadar, or Microsoft Sentinel.
- Security Orchestration, Automation, and Response (SOAR): Experience with SOAR platforms to automate incident response workflows, streamline threat intelligence sharing, and enhance the overall efficiency of security operations. Knowledge of playbook development and integration with existing security tools.
- Data Loss Prevention (DLP): In-depth knowledge of enterprise DLP technologies and data protection policies to safeguard sensitive information. Ability to design and enforce DLP strategies that align with regulatory requirements and business needs.
- Zero Trust Security Architecture: A strong understanding of Zero Trust principles, including continuous verification, least privilege access, and micro-segmentation. Experience in designing and implementing Zero Trust frameworks to enhance security resilience.
- Identity and Access Management (IAM): Proficiency in IAM solutions, including identity governance, privileged access management (PAM), multi-factor authentication (MFA), single sign-on (SSO), role-based access control (RBAC), and identity lifecycle management. Experience in designing secure authentication and authorization frameworks.
We are seeking a candidate with a Bachelor’s degree in Information Technology, Information Systems, Computer Science, or a related field (required). While not mandatory, a Master’s degree in a relevant discipline or advanced certifications such as CISSP, CISM, CISA, or CEH will be highly advantageous. Additionally, a proven track record of driving security initiatives in a large-scale, multi-national organization will set you apart.
If you are a visionary leader passionate about cybersecurity and eager to contribute to a company that is shaping the future of retail, we invite you to be part of our journey. Join us in building a secure, innovative, and resilient digital future for Cenomi Retail.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.