img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About Qiddiya

Qiddiya is seeking an Associate Director Cybersecurity Risk and Compliance to join their team in Riyadh, Saudi Arabia. This full-time role is crucial for managing and enhancing the cybersecurity posture across both IT and OT environments within the organization.

Role Overview

The Associate Director Cybersecurity Risk and Compliance will be responsible for leading cybersecurity risk assessments, ensuring compliance with relevant standards, and governing third-party cybersecurity risks. The role involves a strong focus on both Information Technology (IT) and Operational Technology (OT) environments, requiring expertise in identifying, assessing, and mitigating cybersecurity threats.

Key Responsibilities

  • Conduct periodic and ad hoc cybersecurity risk assessments across IT and OT environments, including OT-specific assets like PLCs, HMIs, RTUs, and engineering systems.
  • Identify and document OT-relevant risk scenarios such as control system disruption, unauthorized access, and safety manipulation.
  • Coordinate risk reviews for major IT/OT changes, reassess risk posture following incidents or regulatory updates, and validate existing controls to prioritize treatment actions.
  • Support the integration of assessment outcomes into control design, zoning, segmentation, and system deployment, tracking risk treatment progress and escalating high-priority items.
  • Define and monitor Key Risk Indicators (KRIs) in coordination with performance management to proactively track changes in cybersecurity risk exposure.
  • Maintain the cybersecurity risk register, including OT-specific entries, capturing identified risks, likelihood and impact ratings, treatment plans, ownership, and status.
  • Coordinate and execute internal cybersecurity compliance assessments across all relevant domains and functions, serving as the lead interface for external audits and regulatory inspections.
  • Conduct periodic compliance assessments of OT environments, including SCADA, DCS, PLCs, and associated network infrastructure.
  • Maintain an inventory of compliance-relevant OT assets, map them to applicable control requirements, and monitor adherence to cybersecurity policies.
  • Track and manage remediation plans for compliance gaps and audit findings, validating the effectiveness of implemented controls before closure.
  • Review and validate configuration baselines for OT systems to ensure alignment with compliance standards.
  • Report OT and IT cybersecurity compliance status and risks to leadership and cybersecurity governance.
  • Maintain a centralized compliance register covering both IT and OT, mapping regulatory requirements to policies, controls, responsible teams, and evidence sources.
  • Govern third-party cybersecurity risk by maintaining standardized assessment processes, due diligence criteria, and remediation tracking.
  • Coordinate and conduct third-party cybersecurity assessments across IT and OT suppliers to ensure alignment with internal policies and regulatory requirements.
  • Review vendor-supplied OT systems and documentation to ensure inclusion of security controls and compliance with applicable standards (*, NCA OTCC, IEC 62443).
  • Ensure third-party risk findings are documented, risk-rated, and tracked through resolution, including acceptance or application of compensating controls.
  • Collaborate with procurement, legal, and compliance to embed cybersecurity requirements into third-party agreements, including OT-specific clauses.

Qualifications and Requirements

  • A minimum of 10-12 years of cybersecurity experience.
  • Strong experience in cybersecurity risk management, compliance, assessments, and assurance.

Work Environment

This is a full-time position based in Riyadh, Saudi Arabia, offering an opportunity to contribute to a dynamic and evolving cybersecurity landscape within Qiddiya.

Application Process

Candidates who meet the specified requirements and are interested in this role are encouraged to apply.


Requirements

  • Requires 5-10 Years experience

Similar Jobs