img
Contract TypeFull-time
Workplace typeOn-site
LocationJeddah

Job Description

About the Role

Masharah Advisory is seeking a dedicated Cyber Security Specialist to join our team. This full-time position, based in Jeddah, Makkah, Saudi Arabia, involves taking ownership of the company’s cybersecurity requirements, security architecture, risk management, and overall security posture. The successful candidate will serve as the technical security authority and primary security representative when engaging with external cybersecurity, infrastructure, network, and technology service providers.

The role requires identifying security risks and gaps, defining necessary security controls, evaluating and selecting appropriate solutions, leading technical discussions with service providers, overseeing implementation, and validating that the delivered environment meets the company’s security requirements.

Key Responsibilities

  • Continuously assess and manage the company’s overall cybersecurity and infrastructure security posture.
  • Conduct security assessments to identify gaps, risks, vulnerabilities, and areas for improvement.
  • Define cybersecurity requirements, security controls, and technical security standards.
  • Develop and review security architecture across various domains, including Network Security, Firewalls/NGFW, Network Segmentation, DMZ/WAF, VPN/ZTNA, Servers & Virtualization, Identity & Access Management, EDR/XDR, SIEM/SOC, Backup & Disaster Recovery, and Application & Data Security.
  • Develop cybersecurity and infrastructure security requirements for external service providers.
  • Identify, evaluate, and recommend appropriate cybersecurity technologies and solutions.
  • Lead technical meetings and discussions with cybersecurity, network, infrastructure, and other service providers.
  • Evaluate and challenge vendors’ proposed architectures, technologies, configurations, and security recommendations.
  • Review security architecture, HLDs, LLDs, technical proposals, BoQs, and implementation plans.
  • Oversee security implementation and ensure correct application of agreed security requirements and controls.
  • Validate and test security controls prior to accepting implemented solutions.
  • Establish and oversee vulnerability management and remediation processes, including coordinating penetration testing.
  • Define and oversee security monitoring, logging, SIEM/SOC, EDR/XDR, and alerting requirements.
  • Establish incident response, containment, recovery, and security incident-handling requirements.
  • Define and review IAM, MFA, RBAC, PAM, privileged access, and network access-control requirements.
  • Ensure appropriate security hardening and secure configuration of infrastructure and security systems.
  • Review GitHub, CI/CD, DevSecOps, and application security practices where applicable.
  • Review backup, disaster recovery, business continuity, RTO/RPO, and ransomware-resilience requirements.
  • Assess data protection, data residency, and cross-border data-transfer considerations.
  • Identify applicable Saudi cybersecurity and data protection requirements and support compliance efforts.
  • Maintain cybersecurity policies, standards, risk registers, security architecture, and technical documentation.
  • Provide management with regular updates on security risks, gaps, priorities, and remediation progress.

Qualifications and Experience

  • 3–5+ years of professional experience in Cybersecurity, Infrastructure Security, Network Security, Security Engineering, or a closely related field.
  • Strong practical understanding of cybersecurity principles and security architecture.
  • Demonstrated experience conducting security assessments and identifying security gaps and risks.
  • Strong knowledge of network security, including Firewalls/NGFW, IPS/IDS, Network segmentation, VLANs, DMZ, VPN/ZTNA, and secure remote access.
  • Good understanding of server, virtualization, endpoint, and infrastructure security.
  • Knowledge of IAM, MFA, RBAC, PAM, and privileged-access management.
  • Experience or strong understanding of EDR/XDR, SIEM, SOC, security monitoring, and centralized logging.
  • Understanding of WAF and web/application security.
  • Knowledge of vulnerability management and penetration-testing processes.
  • Understanding of backup, disaster recovery, business continuity, RTO/RPO, and ransomware resilience.
  • Familiarity with GitHub, CI/CD, DevSecOps, and application security is an advantage.
  • Ability to review, evaluate, and challenge technical architectures, security designs, configurations, and vendor proposals.
  • Strong experience communicating with technical stakeholders, vendors, and service providers.
  • Strong analytical and problem-solving skills.
  • Ability to work independently and take ownership of cybersecurity requirements and decisions.
  • Strong written and verbal communication skills in English.
  • Arabic communication skills are a plus.

Preferred Certifications

The following certifications are considered a strong advantage:

  • CISSP / CISM
  • Security+
  • CCNA / CCNP
  • Palo Alto Networks certifications
  • Fortinet certifications
  • ISO 27001-related certifications
  • Other relevant cybersecurity or infrastructure security certifications

Candidate Profile

We are looking for a professional who can effectively manage cybersecurity from the company’s perspective, moving beyond mere vendor coordination. The ideal candidate should be capable of driving the security lifecycle from identification to continuous improvement:

  • Identify → Assess → Design → Recommend → Lead → Implement → Validate → Improve

You should be comfortable navigating discussions ranging from management-level strategic planning to detailed technical exchanges with cybersecurity and infrastructure engineers. The role requires the ability to independently assess proposed solutions, identify security gaps, challenge vendors when necessary, and ensure that the company’s security requirements are consistently met.

Work Type and Compensation

This is a full-time position based in Jeddah, Makkah, Saudi Arabia. The salary for this role will be discussed during the interview process.


Requirements

  • No experience required

Similar Jobs