Associate Director Cybersecurity Risk and Compliance📣 إعلان
| نوع العقد | دوام كامل | |
| طبيعة الوظيفة | بالموقع | |
| الموقع | الرياض |
وصف الوظيفة
About Qiddiya Investment Company
Qiddiya Investment Company (شركة قدية الاستثمارية) is seeking a dedicated professional to join its team in Riyadh, Riyadh Province. This full-time position offers an opportunity to contribute to a significant organization within the region.
The Role of Associate Director - Cybersecurity Risk and Compliance
The Associate Director - Cybersecurity Risk and Compliance will lead cybersecurity risk and compliance activities across both Information Technology (IT) and Operational Technology (OT) environments. This role is critical for ensuring adherence to internal policies, industry standards, and regulatory requirements through comprehensive assessments, risk management, and audit coordination.
Cybersecurity Risk Assessment and Management
- Conduct periodic and ad hoc cybersecurity risk assessments across IT and OT environments, including specific OT assets such as PLCs, HMIs, RTUs, and engineering systems.
- Identify and document OT-relevant risk scenarios, including control system disruption, unauthorized access, and safety manipulation.
- Coordinate risk reviews for major IT/OT changes and reassess risk posture following significant changes, incidents, or regulatory updates.
- Review and validate existing controls to calculate residual risk and prioritize treatment actions.
- Provide standardized tools and guidance to support self-assessments by IT, OT, and business teams.
- Track risk treatment progress, escalate overdue or high-priority items, and coordinate the definition and monitoring of Key Risk Indicators (KRIs).
- Maintain the cybersecurity risk register, including OT-specific entries, capturing identified risks, likelihood and impact ratings, treatment plans, ownership, and status.
Compliance and Audit Oversight
- Coordinate and execute internal cybersecurity compliance assessments across all relevant domains and functions.
- Serve as the primary interface for external audits and regulatory inspections, managing preparation, execution, and response.
- Conduct periodic compliance assessments of OT environments, including SCADA, DCS, PLCs, and associated network infrastructure.
- Maintain an inventory of compliance-relevant OT assets and map them to applicable control requirements and standards.
- Monitor adherence to cybersecurity policies, escalate non-compliance, and coordinate corrective actions with relevant teams.
- Track and manage remediation plans for compliance gaps, non-conformities, and audit findings through closure, validating the effectiveness of implemented controls.
- Report OT and IT cybersecurity compliance status and risks to leadership and cybersecurity governance.
- Maintain a centralized compliance register covering both IT and OT, mapping regulatory requirements to policies, controls, responsible teams, and evidence sources.
Third-Party Cybersecurity Risk Governance
- Govern third-party cybersecurity risk by maintaining standardized assessment processes, due diligence criteria, and remediation tracking.
- Coordinate and conduct third-party cybersecurity assessments across IT and OT suppliers to ensure alignment with internal policies and regulatory requirements.
- Review vendor-supplied OT systems and supporting documentation to ensure inclusion of security controls and compliance with applicable standards (*, NCA OTCC, IEC 62443).
- Ensure third-party risk findings are documented, risk-rated, and tracked through resolution, including acceptance or application of compensating controls.
- Maintain a register of assessed vendors, associated risks, control gaps, and remediation status for ongoing oversight and reporting.
- Collaborate with procurement, legal, and compliance to embed cybersecurity requirements into third-party agreements, including OT-specific clauses where applicable.
Candidate Profile and Requirements
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field. A Master's degree is preferred.
- 10-12+ years of progressive experience in cybersecurity.
- Strong experience in cybersecurity risk management, compliance, assessments, and assurance.
متطلبات الوظيفة
- تتطلب اكثر من ١٠ سنوات خبرة
وظائف مشابهة
قد يعجبك أيضاً
- وظائف ذات صلة بـ Associate Director Cybersecurity Risk and Compliance
- وظائف موظف استقبال في الرياض
- وظائف Waiter في الرياض
- وظائف مشرف تطوير أعمال في الرياض
- وظائف سكرتير في الرياض
- وظائف مدير العمليات التنفيذي في الرياض
- مجالات وظيفية أخرى في الرياض
- وظائف موظف استقبال في الرياض
- وظائف Waiter في الرياض
- وظائف مشرف تطوير أعمال في الرياض
- وظائف سكرتير في الرياض
- وظائف مدير العمليات التنفيذي في الرياض
- وظائف مهندس إدارة مشاريع في الرياض
- وظائف معلم ابتدائي إجتماعيات ولغة عربية وإسلاميات في الرياض
- وظائف بائع في الرياض
- وظائف فني هندسة كهربائية في الرياض
- وظائف مسوق عقاري في الرياض
- استكشف الوظائف في أنحاء المملكة
- وظائف مسؤول تجارة الكترونية في الرياض
- وظائف مدرب مهني في جدة
- وظائف فني هندسة ميكانيكية في ضبا
- وظائف فني كهروميكانيك في سكاكا
- وظائف Training Officer في رابغ
- وظائف مساعد طبيب أسنان في الخبر
- وظائف Store Keeper في تبوك
- وظائف فني شبكات اتصالات في حفر الباطن
- وظائف Showroom Sales Representative في الرياض
- وظائف فني صيانة ميكانيكية في مكة المكرمة
