img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About the Role

Qiddiya is seeking a Senior Manager, Third Party Security to lead and manage its Third-Party Security Risk Management program. This full-time position, based in Riyadh, is responsible for ensuring that vendors, partners, consultants, and service providers adhere to cybersecurity requirements and do not introduce unacceptable risks to Qiddiya's information assets, systems, and operations. The role involves establishing security assessment frameworks, overseeing vendor security reviews, and driving the remediation of identified risks, aligning with industry best practices for cybersecurity risk management and third-party oversight.

Key Responsibilities

  • Develop and maintain the Third-Party Security Risk Management (TPSRM) framework.
  • Conduct cybersecurity due diligence and risk assessments for vendors and suppliers.
  • Review security requirements during procurement, RFP, and contract stages.
  • Assess cloud providers, SaaS platforms, managed service providers, and strategic partners.
  • Define vendor security controls aligned with NCA ECC, ISO 27001, NIST, and Qiddiya cybersecurity standards.
  • Establish vendor risk classification and assessment methodologies.
  • Monitor remediation plans and track closure of identified security gaps.
  • Collaborate with Procurement, Legal, Compliance, Enterprise Risk, and Technology teams.
  • Lead periodic reassessments of critical vendors.
  • Report third-party cyber risks, trends, and KPIs to senior management.
  • Manage external security audits, questionnaires, and assurance activities.
  • Lead and develop the Third-Party Security team.

Qualifications and Experience

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, or a related field.
  • 8-12 years of cybersecurity experience.
  • Minimum 4 years of experience specifically in Third-Party Security, Vendor Risk Management, Cybersecurity Risk Management, or GRC.
  • Experience within large enterprises, giga projects, banking, telecom, government, or critical infrastructure environments.
  • Proven experience managing teams and engaging with stakeholders at senior levels.

Work Environment and Type

This is a full-time position located in Riyadh. The role requires a professional with experience in managing teams and collaborating across various departments within complex organizational structures.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة