About the Role
Petromin Corporation is seeking a highly motivated and technically adept Cybersecurity Manager to establish and lead its cybersecurity function from the ground up. This is a critical, hands-on role where you will be instrumental in defining the cybersecurity strategy, governance, risk management, and operational security for the organization. As the cybersecurity team is new and lean, the manager will be expected to take ownership of a broad range of responsibilities, leveraging approved AI and automation tools to enhance efficiency, quality, and visibility across all cybersecurity activities. This position offers an opportunity to build a robust cybersecurity program within a dynamic organization. The ideal candidate will be a technical leader with a proven ability to develop and implement comprehensive security solutions, manage risks effectively, and foster a security-aware culture.
Key Responsibilities
- Build and lead Petromin's cybersecurity function from its inception, including developing the strategic roadmap, operating model, policies, standards, governance forums, and reporting mechanisms.
- Serve as the hands-on technical lead for security architecture and core controls across identity, endpoints, networks, cloud environments, email systems, applications, branch offices, and digital platforms.
- Own the cybersecurity risk assessment process, identify control gaps, develop remediation plans, and prioritize security initiatives in collaboration with IT, Digital Transformation, operations, and business leadership.
- Design and supervise security operations, including SIEM/MSSP management, alert monitoring, incident response playbook development, threat intelligence analysis, and vulnerability management.
- Directly handle high-priority technical tasks, complex investigations, architecture reviews, and escalations when team capacity or specific expertise is limited.
- Manage security incidents from initiation to resolution, coordinating containment and recovery efforts, leading post-incident reviews, and maintaining crisis communication with senior management.
- Establish and maintain compliance and audit readiness, develop comprehensive security policies, conduct third-party risk reviews, implement data protection controls, and ensure evidence collection for applicable Saudi and corporate requirements.
- Develop and deliver cybersecurity awareness programs, conduct phishing exercises, provide executive briefings, and offer practical security guidance to employees and business units.
- Select, implement, and manage security tools and external partners, including MSSPs, security vendors, auditors, and consultants, ensuring value delivery, adherence to SLAs, and accountability.
- Develop and maintain dashboards, KPIs, risk registers, management reports, and provide recommendations for cybersecurity budget investments.
- Utilize approved AI and automation tools to enhance output, including alert summarization, threat research, vulnerability prioritization, drafting policies/SOPs, reporting, and workflow automation, while diligently controlling data exposure.
- Coach the Cybersecurity Specialist and future team members, create knowledge bases, and ensure operational continuity through comprehensive documentation and cross-training initiatives.
Qualifications and Requirements
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field. A Master's degree is preferred.
- A minimum of 5-12 years of progressive experience in cybersecurity, with at least 3 years in a leadership capacity, managing security initiatives, vendors, or teams.
- Must possess hands-on experience across security operations, security architecture, Governance, Risk, and Compliance (GRC), and incident response.
- Demonstrated ability to build a cybersecurity function from scratch, including developing roadmaps, policies, KPIs, budgets, and practical governance frameworks.
- Proven experience in managing security incidents, audits, third-party risk, MSSPs/vendors, and delivering executive-level reporting.
- Proficiency in using approved AI, automation tools, scripting, and workflow automation to maximize output with a lean team.
- Strong business communication, decision-making, confidentiality, and stakeholder management skills are essential.
Required Skills
- Cybersecurity Strategy and Governance
- Risk Management and Compliance
- Security Architecture and Design
- Security Operations and Monitoring
- Incident Response and Management
- Awareness Training and Development
- Vendor and MSSP Management
- Technical Execution and Leadership
- AI and Automation Tools
- Identity and Access Management (IAM)
- Microsoft Security Technologies
- Endpoint Security
- Network Security
- Cloud Security
- Email Security
- Vulnerability Management
- Roadmap and Policy Development
- KPI and Budget Management
- Governance Frameworks
- Audit and Third-Party Risk Management
- Executive Reporting
- Automation Scripting and Workflow Automation
- Business Communication
- Decision Making
- Confidentiality
- Stakeholder Management
Work Environment and Additional Information
This is a full-time position based in Jeddah, Makkah, Saudi Arabia. Professional English proficiency is required, and Arabic is preferred. Preferred professional certifications include CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor, CCSP, AZ-500, SABSA, PMP, or Agile certifications.