IT & Cybersecurity Auditor
📣 إعلان| نوع العقد | دوام كامل | |
| طبيعة الوظيفة | بالموقع | |
| الموقع | الرياض |
وصف الوظيفة
About the Role
OptiClaim Business Solutions is seeking an IT & Cybersecurity Auditor on behalf of a client in Riyadh, Saudi Arabia. This full-time role involves supporting IT and cybersecurity audit engagements, assessing IT infrastructure, cybersecurity controls, IT General Controls (ITGC), technology risks, and governance processes. The auditor will evaluate the effectiveness of security controls, identify risks and gaps, and recommend improvements to the organization's cybersecurity posture and compliance.
Key Responsibilities
- Plan and execute IT and cybersecurity audit engagements using risk-based audit methodologies.
- Evaluate the design and operating effectiveness of ITGC, including logical access, privileged access, password controls, change management, backup/recovery, logging, monitoring, and IT operations.
- Assess cybersecurity controls across network, endpoint, server, database, cloud, and infrastructure environments.
- Review Identity and Access Management (IAM), Privileged Access Management (PAM), Multi-Factor Authentication (MFA), and access governance processes.
- Assess vulnerability management, patch management, security monitoring, incident response, threat detection, and Security Operations Center (SOC) capabilities.
- Review network security architecture, including firewalls, segmentation, remote access, VPNs, email security, and secure configuration.
- Evaluate cloud security controls across Azure, AWS, Microsoft 365, GCP, and hybrid environments.
- Perform technology risk assessments to identify control deficiencies and improvement opportunities.
- Assess compliance with internal policies, regulatory requirements, and cybersecurity frameworks.
- Prepare audit working papers, risk assessments, reports, and executive presentations.
- Monitor and validate remediation actions and verify the closure of audit observations.
- Collaborate with IT, Information Security, Risk Management, Internal Audit, and business stakeholders.
Qualifications and Experience
- A minimum of 10 years of experience in a relevant field.
- Consulting background preferred, ideally with a Big 4 firm.
- Strong grounding in IT audit methodologies and risk-based auditing.
- Hands-on ITGC review experience.
- Strong knowledge across IAM, PAM, network/endpoint/server/OS security, cloud security, SOC, vulnerability & patch management, SIEM, incident response, backup/DR, data protection & encryption.
- Experience auditing on-premise, cloud, and hybrid environments.
- Familiarity with Azure, AWS, Microsoft 365, Active Directory, Microsoft Entra ID, and VMware is preferred.
Relevant Frameworks and Standards
The role requires familiarity with various cybersecurity and IT governance frameworks, including:
- NCA ECC & DCC
- SAMA CSF
- PDPL
- ISO/IEC 27001
- NIST CSF
- COBIT
- CIS Controls
- PCI DSS
متطلبات الوظيفة
- تتطلب ٥-١٠ سنوات خبرة
وظائف مشابهة
قد يعجبك أيضاً
- وظائف ذات صلة بـ IT & Cybersecurity Auditor
- وظائف أخصائي تسويق في الرياض
- وظائف موظف استقبال في الرياض
- وظائف بائع في الرياض
- وظائف أخصائي تسويق إلكتروني في الرياض
- وظائف Key Account Manager في الرياض
- مجالات وظيفية أخرى في الرياض
- وظائف أخصائي تسويق في الرياض
- وظائف موظف استقبال في الرياض
- وظائف بائع في الرياض
- وظائف أخصائي تسويق إلكتروني في الرياض
- وظائف Key Account Manager في الرياض
- وظائف Guest Experience Expert في الرياض
- وظائف Safety Engineer في الرياض
- وظائف Sales Supervisor في الرياض
- وظائف GIS Specialist في الرياض
- وظائف Planning Engineer في الرياض
- استكشف الوظائف في أنحاء المملكة
- وظائف مدير أشغال ومرافق عامة في ابها
- وظائف مشرف تنظيف وتدبير في تنومة
- وظائف أخصائي تسويق في الرياض
- وظائف محامي في المدينة المنورة
- وظائف معلم مرحلة متوسطة لغة عربية في حفر الباطن
- وظائف كاتب محتوى في الرياض
- وظائف فني هندسة مدنية في الخرج
- وظائف مدير عام في الطائف
- وظائف كهربائي مباني في الرياض
- وظائف أخصائي مستودعات في الرياض