img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About the Role

Al Safi Danone is seeking an experienced IT Security Lead to join our team in Riyadh, Saudi Arabia. This full-time role is central to implementing and managing the enterprise information security programme, ensuring the protection of systems, data, and digital assets from cyber threats, and maintaining regulatory compliance. The Security Lead will be instrumental in establishing and maturing the organization's security posture across SAP S/4HANA, Microsoft platforms, cloud infrastructure, and operational technology, operating within the B-ITSC governance framework.

Key Responsibilities

  • Own and maintain the information security strategy, policy framework, and security roadmap.
  • Coordinate and maintain information security policies, standards, and procedures.
  • Conduct annual information security risk assessments and manage the enterprise security risk register and treatment plans.
  • Ensure compliance with applicable regulations, including PDPL (Saudi Personal Data Protection Law), GDPR, and the NCA ECC framework.
  • Lead incident response activities, owning the Incident Response Plan and Playbooks for P1/P2 cyber security events.
  • Manage threat intelligence feeds and the vulnerability management programme, prioritizing patching based on risk exposure.
  • Conduct regular penetration testing, red team exercises, and security assessments, ensuring remediation of findings within agreed SLAs.
  • Oversee endpoint detection and response (EDR) using Microsoft Defender for Endpoint across all devices.
  • Manage Business Continuity Planning (BCP) and Disaster Recovery (DR) for cyber event scenarios.

Technical Security Management

  • Define and govern the SAP S/4HANA security architecture, including role-based access control, segregation of duties (SoD), and audit logging.
  • Review SAP security design deliverables from system integrators and validate against security standards.
  • Manage security requirements for all application systems, including SalesBuzz, SalesCode, Shelfr, SO99, and third-party SaaS.
  • Collaborate with the Identity and Access Management (IAM) programme, including Privileged Access Management (PAM) and Zero Trust implementation.
  • Govern user provisioning, de-provisioning, and access certification processes across all systems, including SAP and M365.
  • Manage Azure Active Directory / Entra ID security configuration, including MFA, Conditional Access, PIM, and identity protection.
  • Define and enforce least-privilege access principles and role segregation policies across IT and business systems.
  • Deliver the organization-wide security awareness and training programme.
  • Manage third-party and supply chain security risk assessments, integrating security requirements into vendor contracts.

Reporting and Audit Liaison

  • Produce quarterly security risk reports for the IT Operations Manager.
  • Conduct SoD conflict analysis during UAT and prior to go-live, ensuring remediation before production cutover.
  • Conduct quarterly access reviews and user entitlement audits, reporting exceptions to the IT Operations Manager.
  • Liaise with Internal Audit on security-related audit findings, developing and tracking remediation action plans.
  • Prepare for and support external regulatory audits and certifications, including NCA ECC, ISO 27001, and ZATCA security requirements.
  • Produce monthly security metrics dashboards covering threat landscape, vulnerability posture, and compliance status.
  • Report on security risk to executive leadership and the board.

Qualifications and Experience

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field.
  • CISM (Certified Information Security Manager) — required, or CISA — preferred.
  • Microsoft SC-200 (Security Operations Analyst) or SC-300 — advantageous.
  • 5–8 years of experience in information security, with at least 3 years in a security leadership role.
  • Proven experience securing SAP environments, including role design, SoD analysis, and SAP security audit.
  • Experience with cloud security platforms such as Azure Security Center / Defender for Cloud, AWS GuardDuty, or GCP SCC.
  • GCC or FMCG industry experience is an advantage.

Required Skills and Knowledge

  • Knowledge of Saudi Arabia regulatory requirements, including PDPL and the NCA ECC cybersecurity framework — strongly preferred.
  • Strong incident response and forensic investigation experience.
  • Demonstrated crisis communication skills.
  • Excellent risk communication skills, with experience presenting security risk to executive and board audiences.

متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة