img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعمكة المكرمة

وصف الوظيفة

About ADFAR Tech and the Role

ADFAR Tech is seeking a Cybersecurity Specialist to join our team in Jeddah, Makkah, Saudi Arabia. This full-time role is open to candidates with 0-1 years of experience who are prepared to contribute to the protection of our systems, data, and infrastructure. The specialist will play a key role in ensuring compliance with the cybersecurity regulations of the Kingdom of Saudi Arabia and will be involved in the full cybersecurity lifecycle, from implementing controls to incident response.

Core Responsibilities: Compliance and Governance

  • Lead the implementation of the NCA regulatory frameworks — the Essential Cybersecurity Controls (ECC) and related control sets (CSCC, CCC, DCC, TCC, OTCC) — across all organizational domains.
  • Assess compliance with NCA controls: perform gap analyses, define remediation roadmaps, implement corrective actions, and test/validate control effectiveness on an ongoing basis.
  • Prepare and maintain the evidence required for NCA self-assessments, regulator reporting, and internal and external cybersecurity audits, acting as the technical counterpart during those engagements.
  • Define and maintain cybersecurity policies, standards, and procedures aligned with NCA requirements and international best practices (ISO/IEC 27001, NIST CSF, CIS).
  • Perform cybersecurity risk assessments for projects, systems, and third parties, and embed security requirements into procurement, development, and change management.
  • Review and govern identity and access management: privileged access (PAM), MFA enforcement, periodic access recertification, and least-privilege design.

Core Responsibilities: Security Operations and Testing

  • Run the vulnerability management program end to end: scheduled scanning, risk-based prioritization, coordinating and verifying remediation with system owners, and closing findings within defined SLAs.
  • Conduct security testing of systems and applications — penetration tests, configuration reviews, and secure-baseline (hardening) assessments — before go-live and periodically in production.
  • Operate and tune cybersecurity systems and platforms: SIEM, EDR/XDR, next-generation firewalls, IPS/IDS, WAF, email and web security, NAC, and data loss prevention.
  • Monitor, detect, and respond to cybersecurity incidents: triage alerts, contain and eradicate threats, perform root-cause analysis and forensics, and produce post-incident reports with lessons learned.
  • Deliver cybersecurity awareness activities and phishing simulations, and raise the security maturity of technical teams through guidance and training.
  • Track the threat landscape (threat intelligence, CVE advisories, NCA alerts) and proactively drive protective measures before threats materialize.

Essential Skills and Attributes

  • Strong analytical and investigative mindset, with the discipline to trace an alert or a finding to its root cause.
  • Clear written and verbal communication in Arabic and English; able to brief executives, regulators, auditors, and technical teams.
  • High integrity, confidentiality, and sound judgment when handling sensitive information and incidents.
  • Ownership mindset — drives findings from discovery through verified closure, and works to prevent recurrence.
  • Calm and structured under pressure, especially during live security incidents.
  • Collaborative influence: builds security into projects by working with, not against, IT and business teams.
  • Continuous learner who keeps pace with the evolving threat landscape and regulatory requirements.

Qualifications and Experience

Candidates should possess 0-1 years of experience in cybersecurity or a related technical field. Proficiency in both Arabic and English is required for effective communication across all levels of the organization and with external stakeholders.

Work Environment

This is a full-time position based in Jeddah, Makkah, Saudi Arabia. The role operates within a dynamic environment focused on maintaining robust cybersecurity defenses and fostering a security-first culture.


متطلبات الوظيفة

  • لا تتطلب خبرة

وظائف مشابهة