img
Contract TypeFull-time
Workplace typeOn-site
LocationAl Jubail

Job Description

About the Role

ArcelorMittal Tubular Products Al-Jubail is seeking a Sr. Specialist IT Security to join their team in Al Jubail, Eastern region. This full-time role involves implementing, administering, and maintaining the organization's enterprise security technologies to ensure the confidentiality, integrity, and availability of information systems and data. The position requires 5-10 years of experience in IT security.

Role Overview

The Senior Specialist, IT Security provides advanced technical expertise across security operations, threat monitoring, incident response, vulnerability management, access governance, and compliance. This role enforces corporate security standards aligned with international frameworks such as ISO/IEC 27001 and NIST, as well as Saudi national regulations (NCA ECC and OTCC). Collaboration with Infrastructure, Network, Cloud, Application, Service Desk, Cybersecurity, and Audit teams is essential to strengthen the organization's cyber resilience.

Key Responsibilities

  • Develop and maintain IT security reference architectures aligned with ISO/IEC 27001, NIST SP 800-53, COBIT 2019, and applicable Saudi regulations (NCA ECC and OTCC).
  • Implement, administer, and maintain enterprise security technologies including endpoint protection (EDR), next-generation firewalls, IDS/IPS, anti-malware, email and web security gateways, DLP, vulnerability scanners, and SIEM solutions.
  • Continuously monitor security alerts, logs, and events; perform triage, investigation, escalation, and remediation of threats and incidents.
  • Lead and support security incident response and forensic investigations, including containment, eradication, recovery, and root-cause analysis.
  • Conduct risk assessments, vulnerability scans, and configuration reviews across systems, endpoints, networks, and cloud workloads; track findings through to closure.
  • Collaborate with IT Infrastructure, Network, Applications, Cloud, and Service Desk teams to embed security-by-design principles into projects, systems, and patch management processes.
  • Apply security baselines, configuration hardening, and patch-management policies across servers, endpoints, and cloud environments (*, CIS Benchmarks).
  • Administer identity and access governance, including access provisioning, privileged access management (PAM), and periodic user access reviews.
  • Ensure secure deployment and configuration of firewalls, network security layers, proxies, and security appliances.
  • Develop, enforce, and maintain security policies, standards, and procedures aligned with enterprise governance.
  • Support internal and external audits (*, ISO 27001, SOC 2, NCA compliance) through evidence collection, access reviews, and remediation tracking with Audit and Compliance teams.
  • Maintain and periodically test disaster recovery and business continuity plans for security systems.
  • Advise IT leadership on risk-mitigation strategies, emerging threats, and control improvements.
  • Participate in cross-functional projects to embed security-by-design into business systems and processes.
  • Maintain accurate documentation, runbooks, and knowledge-base articles, and drive continuous improvement of security operations.

Experience Required

  • 5-10 years of experience in IT security.

Work Type and Location

This is a full-time position based in Al Jubail, Eastern region.

Application Information

Salary details for this position will be disclosed during the application process.


Requirements

  • Requires 5-10 Years experience

Similar Jobs