Data Security Manager Jobs in Riyadh

More than 10 Data Security Manager Jobs in Riyadh. Explore detailed job descriptions, salaries, and locations. Apply and get hired today!


Category
Contract Type
Nationality

img
Data Security Manager

Data Security Manager

📣 Job AdNew

HSBC

Full-time

About the Role

HSBC Saudi Arabia is seeking a Data Security Manager to join its team in Riyadh. This role is integral to developing, implementing, and monitoring information security policies and procedures across HSBC Saudi Arabia's business operations. The Data Security Manager will be responsible for fostering awareness of security risks and potential fraud, and will play a key role in Business Continuity Risk Management (BCM) and SMART IT Segregation, with a specific focus on Data Security.

This position involves overseeing all aspects of Information Security Risk for HSBC Saudi Arabia, encompassing Data Security, Threat & Incident Management, Business Controls, Third Party Security, and Technical Security. The role holder will contribute to the design and execution of the Cyber Security strategy, providing essential support to the CISO and CRO, and advising on the management and operations of security controls for critical HSBC Saudi Arabia services. The ideal candidate will possess a deep technical understanding of security controls, a hands-on technical background, strong stakeholder management skills, and a commitment to continuous learning and development.

Key Responsibilities

  • Own and lead the implementation, operation, and continuous improvement of data security controls, ensuring the confidentiality, integrity, and availability of organizational data across all environments.
  • Operate and manage data security technologies and platforms, including Data Loss Prevention (DLP), data classification, encryption, discovery, and monitoring tools, ensuring their configuration, tuning, enhancement, and ongoing optimization.
  • Monitor, detect, and trigger responses to data security incidents, ensuring timely escalation, investigation, coordination with Security Operations Center (SOC)/Incident Response (IR) teams, and post-incident analysis in alignment with incident management processes.
  • Develop, generate, and enhance data security reporting and dashboards, providing actionable insights, risk analysis, trends, and control effectiveness metrics for technical teams and senior management.
  • Ensure alignment of data security controls with applicable standards, regulatory requirements, and internal policies, driving compliance and audit readiness across business units.
  • Lead data security governance activities, including control ownership, risk assessments, exception handling, control uplift initiatives, and continuous maturity improvement.
  • Review, update, and maintain data security policies, standards, and procedures, ensuring alignment with business operations, emerging risks, and global best practices.
  • Act as a primary liaison with global and cross-functional teams, including IT, Security Operations, Legal, Compliance, and business stakeholders, to embed data security requirements into business processes.
  • Translate technical data security risks and findings into business-focused insights, clearly presenting analysis, recommendations, and remediation plans to senior management and executive stakeholders.
  • Drive continuous improvement initiatives, including control uplift, reporting enhancements, tool capability expansion, and operational process optimization.
  • Support strategic data security initiatives by bridging hands-on technical execution with governance, policy, and management-level oversight.
  • Develop information security policies and procedures in accordance with HSBC group standards and industry standards such as ISO and COBIT to ensure up-to-date information security and integration solutions at HSBC Saudi Arabia.
  • Supervise the implementation and oversee adherence to agreed policies and compliance practices to create a secure environment for HSBC Saudi Arabia’s business operations.
  • Review, collate, and analyze monthly Business Risk Information Officer (BIRO) Reports to identify policy-related risks within respective business units.
  • Maintain a close awareness of best practices and industry standards in Information Security, assess potential security threats and risks to HSBC Saudi Arabia IT infrastructure, systems, network, and data, and recommend improvements in policies.
  • Enforce appropriate security standards for access control functions and IT Security, and monitor all exceptions closely.
  • Implement and manage the BIRO program for HSBC Saudi Arabia, ensuring all risk assessment activities are undertaken within assigned BIRO areas, and work directly with staff to explain the risk assessment process, risk identification, measurement, and mitigation/elimination actions.
  • Support general information security/risk oversight and awareness programs implemented across the business, including town hall meetings, marketing initiatives, and informal meetings addressing information security topics.
  • Involve in Cyber Security projects and create Engineering solutions in the Data Security Area.
  • Configure and run DLP solutions and data scanning tooling.
  • Provide production support to Data Security tooling (such as Symantec, McAfee, MIP).
  • Utilize Confluence and Jira for Project and Production support tasks.
  • Manage stakeholder relationships, including business communication and audit management.

Qualifications and Requirements

  • Typically educated to degree level.
  • 4 to 5 years of experience in Data Security Engineering.
  • Experience with DLP products such as Symantec DLP and SkyHigh DLP, with hands-on experience deploying data discovery tools.
  • Demonstrable experience in Data in Motion and/or Data at Rest Security.
  • Experience in Agile Methodology and project planning & management.
  • Experience in Data Incident Management.

Required Skills

  • Data Security
  • Threat & Incident Management
  • Business Controls
  • Third Party Security
  • Technical Security
  • Infrastructure Security
  • Application Security
  • Access Management
  • Cyber Security Strategy
  • Security Controls
  • DLP (Data Loss Prevention)
  • Data Classification
  • Encryption
  • Data Discovery
  • Data Incident Management
  • Risk Management
  • Agile Methodology
  • Project Planning & Management
  • Stakeholder Management
  • Business Communication
  • Audit Management
  • Symantec DLP
  • SkyHigh DLP
  • Data in Motion Security
  • Data at Rest Security
  • Jira
  • Confluence
  • ISO Standards
  • COBIT Standards
  • Information Security
  • IT Security
  • Risk Assessment
  • Communication
  • Leadership

Work Environment and Additional Information

This is a full-time position based in Riyadh, Saudi Arabia. Industry qualifications such as CISSP, CISA, or CISM are preferred but not essential.

breifcase2-5 years

locationRiyadh

about 2 hours ago
Cybersecurity Delivery Manager

Cybersecurity Delivery Manager

📣 Job Ad

FNRCO

Full-time

About the Role

FNRCO is seeking a results-oriented Cybersecurity Delivery Manager to lead the end-to-end delivery of managed security services. This role ensures the consistent, high-quality, and risk-aware delivery of services, acting as the primary interface between the security operations team and senior stakeholders. The successful candidate will be instrumental in maintaining compliance with Service Level Agreements (SLAs), Key Performance Indicators (KPIs), governance requirements, and overall business expectations within the cybersecurity landscape of Riyadh, Saudi Arabia. This full-time position requires a strategic thinker with a proven track record in managing complex cybersecurity operations and driving service excellence, overseeing a 24x7 managed security service environment.

Key Responsibilities

  • Lead the end-to-end delivery of 24x7 managed security services across multiple domains, including Security Operations Center (SOC), Security Information and Event Management (SIEM), Incident Response, and Vulnerability Management.
  • Ensure strict adherence to all defined SLAs, KPIs, and service quality standards, proactively identifying and addressing any deviations.
  • Oversee all aspects of incident management, continuous monitoring, and operational performance, ensuring timely and effective resolution of security events.
  • Drive continuous improvement initiatives and implement strategies to enhance operational efficiency and effectiveness within the security services delivery.
  • Serve as the primary point of contact for senior stakeholders, fostering strong relationships and ensuring clear communication regarding service performance and strategic alignment.
  • Lead regular service review meetings, providing comprehensive performance reports and insights to stakeholders.
  • Effectively manage escalations, critical incidents, and all service-related issues, ensuring swift and appropriate resolution.
  • Ensure that all delivered security services are aligned with and support the overarching business objectives and strategic goals.
  • Guarantee compliance with all relevant security standards, internal policies, and external regulatory requirements.
  • Implement and actively monitor robust risk management frameworks and security controls to mitigate potential threats.
  • Support audit readiness activities and ensure accurate and timely compliance reporting.
  • Track and report on key operational metrics, including performance indicators and response times, to measure and improve service delivery.
  • Lead, coordinate, and mentor cross-functional cybersecurity teams, fostering a collaborative and high-performing environment.
  • Manage resource planning, effective workload distribution, and overall team performance to optimize delivery capabilities.
  • Coordinate effectively across internal and external delivery teams to ensure seamless service provision.
  • Manage budgets, forecasts, and cost optimization initiatives related to cybersecurity service delivery.
  • Ensure that all service delivery activities align with financial and contractual commitments.
  • Identify and support opportunities for service improvement and business growth within the cybersecurity domain.
  • Define, evolve, and execute the roadmap for managed security services, adapting to emerging threats and technologies.
  • Drive automation, efficiency gains, and maturity enhancements across all service delivery processes.
  • Align cybersecurity delivery strategies and operations with the overall business and security strategy of the organization.

Qualifications and Experience

  • A Bachelor’s degree in Cybersecurity, Information Technology, or a related technical field.
  • A minimum of 8 years of progressive experience in the cybersecurity or IT sector.
  • At least 3 to 5 years of experience in a dedicated service delivery or leadership role within a cybersecurity context.
  • Demonstrated experience in managing managed security services (MSS) and operating within enterprise-level environments.
  • A strong understanding of the security operations and incident response lifecycle.
  • Proven experience with a range of security technologies, including SIEM, endpoint security solutions, Identity and Access Management (IAM), and network security technologies.
  • Exceptional stakeholder management and communication skills, with the ability to engage effectively with both technical teams and senior leadership.
  • Expertise in delivery governance and performance management frameworks.
  • The ability to effectively manage complex technical environments and lead during critical incidents.
  • Professional certifications such as CISSP, CISM, CCSP, or ITIL are highly regarded.
  • Project Management Professional (PMP) certification is preferred.

Required Skills

  • Security Operations
  • Incident Response
  • SIEM (Security Information and Event Management)
  • Endpoint Security
  • IAM (Identity and Access Management)
  • Network Security
  • Stakeholder Management
  • Communication
  • Delivery Governance
  • Performance Management
  • Complex Environments Management
  • Critical Incident Management

Work Environment and Details

This is a full-time position based in Riyadh, Saudi Arabia. The role requires a minimum of 10 years of experience, with a significant portion dedicated to cybersecurity delivery and leadership within enterprise environments.

breifcase+10 years

locationRiyadh

8 days ago
OT Cybersecurity Program Manager

OT Cybersecurity Program Manager

📣 Job AdNew

Accenture Middle East

Full-time

About the Role

Accenture Middle East is seeking an experienced OT Cybersecurity Program Manager to join our team in Riyadh, Saudi Arabia. This role is essential for managing and delivering complex OT/ICS cybersecurity projects throughout their lifecycle, ensuring the security and resilience of critical industrial control systems for our clients in the region. As a key member of our cybersecurity practice, you will serve as the primary point of contact for client project teams, fostering strong relationships with OT managers, control system engineers, and IT security leads. You will play a significant role in shaping and executing cybersecurity strategies to protect operational technology environments.

Key Responsibilities

  • Manage and deliver OT/ICS cybersecurity projects from initial scoping and assessment through architecture design, implementation, and close-out.
  • Act as the main liaison with client project teams, cultivating robust working relationships with OT managers, control system engineers, and IT security leads.
  • Conduct and oversee comprehensive OT risk and vulnerability assessments, ICS network reviews, and compliance gap analyses against industry standards such as IEC 62443 and NCA OT-CCC.
  • Design and document robust OT security architectures, including network segmentation strategies, DMZ designs, secure remote access solutions, and asset inventory frameworks.
  • Lead and mentor cybersecurity analysts and consultants during engagements, providing technical direction and ensuring deliverable quality.
  • Contribute to proposal development and business development initiatives, supporting senior leadership in solution design, bid writing, and client presentations.
  • Maintain up-to-date knowledge of OT threat intelligence, emerging vulnerabilities, and evolving regulatory landscapes within Saudi Arabia and the broader GCC region.

Qualifications and Requirements

  • A minimum of 8-11 years of overall experience in cybersecurity, with at least 4 years dedicated to OT/ICS/SCADA security within sectors such as energy, utilities, oil & gas, water, or manufacturing.
  • Proven experience in a client-facing delivery role within a management consulting firm, system integrator, or professional services organization.
  • Hands-on proficiency with key OT security frameworks and standards, including IEC 62443, NIST CSF, ISA/IEC, and NCA ECC/OT-CCC.
  • Practical knowledge of industrial control systems and major ICS vendors such as Honeywell, Siemens, Rockwell Automation, Schneider Electric, ABB, or Emerson.
  • A solid understanding of OT network protocols, including Modbus, DNP3, Profinet, and OPC-UA, and their associated security implications.
  • Experience utilizing OT-specific security tools.
  • Strong report writing capabilities and excellent client communication skills, with the ability to articulate technical findings into clear risk narratives for both operational and executive audiences.
  • Relevant cybersecurity certifications such as GICSP, CISM, CISSP, CompTIA Security+, or equivalent are highly desirable.
  • Arabic language proficiency is strongly preferred; fluent English is essential.

Required Skills

  • OT/ICS Cybersecurity Project Management
  • OT Risk and Vulnerability Assessment
  • ICS Network Review and Analysis
  • Compliance Gap Analysis
  • OT Security Architecture Design
  • Network Segmentation
  • DMZ Design
  • Secure Remote Access Solutions
  • Asset Inventory Frameworks
  • OT Threat Intelligence
  • Emerging Vulnerability Analysis
  • Regulatory Development Monitoring (KSA/GCC)
  • OT/ICS/SCADA Security Expertise
  • Client-Facing Delivery
  • OT Security Frameworks (IEC 62443, NIST CSF, ISA/IEC, NCA ECC/OT-CCC)
  • Industrial Control Systems (ICS) Knowledge
  • Major ICS Vendor Familiarity (Honeywell, Siemens, Rockwell Automation, Schneider Electric, ABB, Emerson)
  • OT Network Protocols (Modbus, DNP3, Profinet, OPC-UA)
  • OT-Specific Security Tools
  • Report Writing
  • Client Communication
  • Risk Narrative Development
  • Leadership and Mentorship
  • Business Development Support

Work Environment and Location

This is a full-time position based in Riyadh, Saudi Arabia. The role involves working within Accenture Middle East's cybersecurity practice.

breifcase+10 years

locationRiyadh

Remote Job
2 days ago
Information Security Risk & Assurance

Information Security Risk & Assurance

📣 Job Ad

The Saudi National Bank - SNB

Full-time

About the Role

The Saudi National Bank (SNB) is seeking an Information Security Risk & Assurance professional to join its team in Riyadh, Saudi Arabia. This role is integral to supporting SNB's Information Security Risk and Assurance programs by identifying and addressing security weaknesses, gaps, vulnerabilities, and failures through the execution of departmental initiatives. The position contributes to maintaining the bank's robust security posture and ensuring compliance with regulatory standards.

Key Responsibilities

  • Implement approved Information Security Risk IAM governance and compliance policies, processes, procedures, and instructions, monitoring adherence to ensure controlled work execution.
  • Adhere to the Bank's AML/CTF policy, guidelines, and all SAMA regulations pertaining to account opening, KYC, and Customer Due Diligence.
  • Comply with the Bank's Cyber Security policies and all SAMA regulations, supporting SNB's compliance with internal, national, and international Cyber Security controls and regulations.
  • Support the execution of attack simulations to validate the effectiveness of SNB's detection and response capabilities.
  • Assess the strength of security controls and incident response processes against real-world attack scenarios.
  • Support purple teaming efforts by ensuring active collaboration between red and blue teams to enhance the overall security posture and threat detection.
  • Conduct compromise assessments to identify indicators of past or ongoing breaches and ensure timely containment and remediation.
  • Support the vulnerability management program, including the identification, risk analysis, prioritization, and tracking of vulnerabilities across the environment.
  • Coordinate regular penetration testing of applications, networks, and infrastructure to uncover and validate security weaknesses.
  • Support the implementation and results of SAST and DAST tools to ensure secure software development practices and identify code-level vulnerabilities.
  • Review configurations across systems, applications, and network devices, ensuring compliance with internal baselines and industry best practices.

Qualifications and Requirements

  • Must be a Saudi national.
  • Hold a Bachelor's degree in Computer Science, Information Technology, Information Security, or a related field; or an acceptable educational level accompanied by strong banking experience.
  • Possess a minimum of 3 years of experience in Information Security Management or a related field.
  • Demonstrate a strong understanding of enterprise security architecture and layered defense principles.
  • Exhibit deep knowledge of MITRE ATT&CK and threat actor TTPs.
  • Show a deep understanding of secure development lifecycle (SDLC) integration.
  • Be skilled in threat modeling and risk-based security assessments.

Required Skills

  • Information Security Risk IAM governance
  • AML/CTF policy adherence
  • SAMA regulations compliance
  • Cyber Security policies implementation
  • Attack simulations and validation
  • Detection and response capabilities enhancement
  • Security controls assessment
  • Incident response processes evaluation
  • Purple teaming collaboration
  • Threat detection improvement
  • Compromise assessments and remediation
  • Vulnerability management lifecycle
  • Penetration testing coordination
  • SAST and DAST tool support
  • Secure software development practices
  • Enterprise security architecture principles
  • Layered defense strategies
  • MITRE ATT&CK framework knowledge
  • Threat actor Tactics, Techniques, and Procedures (TTPs) understanding
  • Secure Development Lifecycle (SDLC) integration
  • Threat modeling expertise
  • Risk-based security assessments

Work Environment and Location

This is a full-time position based in Riyadh, Saudi Arabia. The role requires 2-5 years of experience in a relevant field.

breifcase2-5 years

locationRiyadh

11 days ago
Manager Cloud Security

Manager Cloud Security

📣 Job Ad

Riyadh Air

Full-time

About the Role

Riyadh Air, a new national airline headquartered in Riyadh, Saudi Arabia, is establishing itself as a digitally native carrier connecting the Kingdom to over 100 destinations. The airline is seeking a Manager Cloud Security to define and embed security practices across its operations. This role is instrumental in shaping how security is designed, implemented, and governed throughout the organization, contributing to a resilient and trusted digital future.

Key Responsibilities

  • Define the organizational approach to security design, embedding, and governance.
  • Enforce cloud security standards by strengthening baselines and configurations across compute, storage, networking, identity, and container services.
  • Establish and maintain a robust cloud security governance framework.
  • Align security policies and baselines with recognized industry standards, including CIS Benchmarks, NIST CSF, ISO 27001, and CSA CCM.
  • Lead cloud security reviews for new initiatives, migrations, and third-party integrations.
  • Provide clear architectural guidance for cloud security initiatives.
  • Act as a key approval gate for cloud security-related decisions.
  • Guide and mentor cloud and security teams, setting expectations and encouraging best practices.
  • Foster a strong security-first culture across the organization.
  • Present executive-level insights on cloud security posture, risk trends, and program maturity to senior leadership and board-level committees.

Qualifications and Requirements

  • Degree qualified.
  • Minimum of 7 years of experience in Cybersecurity.
  • At least 3 years of experience specializing in Cloud Security.
  • Proven, hands-on experience securing cloud environments across one or more major platforms, including AWS, Microsoft Azure, and Google Cloud Platform.
  • Strong experience with CSPM / CNAPP tools.
  • Strong experience with Infrastructure-as-Code (IaC).
  • Solid expertise in network security fundamentals such as firewalls, WAF, VPNs, and Zero Trust architectures.
  • Proven track record designing enterprise-scale cloud security architectures.
  • Proven track record designing enterprise-scale cloud security governance frameworks.
  • Proven track record designing enterprise-scale cloud security baseline standards.

Required Skills

  • Cloud Security
  • Cybersecurity
  • AWS
  • Microsoft Azure
  • Google Cloud Platform
  • CSPM
  • CNAPP
  • Infrastructure-as-Code (IaC)
  • Network Security
  • Firewalls
  • WAF
  • VPNs
  • Zero Trust Architectures
  • Cloud Security Architectures
  • Governance Frameworks
  • Baseline Standards
  • Leadership
  • Mentoring
  • Communication

Work Environment and Details

This is a full-time position based in Riyadh, Saudi Arabia. The role requires a professional with over 10 years of experience in the field, with a significant portion dedicated to cloud security leadership and strategy.

breifcase+10 years

locationRiyadh

8 days ago
Chief Information Security Officer - Cloud Security - Saudi Arabia

Chief Information Security Officer - Cloud Security - Saudi Arabia

📣 Job AdNew

ByteDance

Full-time

About the Role

ByteDance is seeking a Chief Information Security Officer (CISO) to lead its cloud security initiatives in Saudi Arabia. This executive role is responsible for the organization's overall cybersecurity posture, ensuring robust security assurance for enterprise businesses and the underlying cloud platform. The CISO will be instrumental in establishing and maintaining compliance with all applicable cybersecurity laws, regulations, and frameworks, including the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC) within the Kingdom of Saudi Arabia (KSA).

This position offers the opportunity to shape strategic outcomes, reduce risk exposure, and drive secure innovation across complex ecosystems. The CISO will collaborate closely with senior executives, providing independent oversight across cybersecurity governance, risk management, and security operations. The ideal candidate will be a pragmatic, business-oriented leader with deep expertise in cybersecurity, cloud security, and modern technology environments, capable of aligning cybersecurity risks with the organization's risk appetite and regulatory expectations.

Key Responsibilities

  • Establish and maintain enterprise-wide cybersecurity governance in line with SAMA CSF and NCA ECC requirements.
  • Ensure clear ownership, accountability, and segregation of duties across all cybersecurity functions.
  • Advise executive management on cybersecurity risks, emerging threats, and the effectiveness of existing controls.
  • Integrate cybersecurity considerations into corporate governance and enterprise risk management processes.
  • Own and oversee the cybersecurity risk management framework, ensuring its continuous effectiveness.
  • Ensure ongoing compliance with all applicable cybersecurity regulations and industry best practices.
  • Oversee the timely remediation of audit findings and regulatory observations.
  • Serve as the primary point of accountability for cybersecurity matters in interactions with regulatory bodies.
  • Oversee cybersecurity operations, including security monitoring, detection, vulnerability management, Identity and Access Management (IAM), and incident response.
  • Ensure the implementation of effective prevention, detection, response, and recovery capabilities for security incidents.
  • Govern the selection, implementation, and operation of cybersecurity technologies.
  • Champion security by design principles across infrastructure, applications, cloud, and data platforms.
  • Ensure effective incident response and cyber crisis management processes are in place.
  • Lead executive coordination and communication during material cybersecurity incidents.
  • Ensure alignment of cybersecurity incident response with business continuity and disaster recovery plans.
  • Oversee post-incident reviews to identify lessons learned and drive continuous improvement.
  • Ensure third-party cybersecurity risks are identified, assessed, and effectively managed.
  • Verify that vendors and partners comply with regulatory and contractual cybersecurity obligations.
  • Oversee outsourced and managed security services to ensure they meet ByteDance's security standards.
  • Establish and maintain a compliant cybersecurity operating model.
  • Develop national cybersecurity talent in alignment with Saudization initiatives.
  • Promote a strong cybersecurity awareness and culture throughout the organization.
  • Ensure adequate resourcing and ongoing training for the cybersecurity team.
  • Define and enforce cybersecurity policies and standards across the enterprise.
  • Escalate significant risks and incidents to executive management in a timely manner.
  • Approve or reject cybersecurity risk acceptances based on established criteria.

Qualifications and Requirements

  • A bachelor's degree in Computer Science, Computer Engineering, Information Technology, or a closely related field.
  • A minimum of 5 years of relevant experience in security strategy, cybersecurity governance, risk management, or related domains.
  • Proven executive leadership experience in cybersecurity governance, risk management, and regulatory compliance.
  • Strong experience engaging with Boards of Directors, regulatory bodies, and senior executives on critical cybersecurity matters.
  • The ability to translate complex cybersecurity risks into clear business and risk implications for executive stakeholders.
  • Demonstrated leadership in building and developing high-performing cybersecurity teams, including fostering national talent.

Required Skills

  • Security Architecture
  • Software Development Life Cycle (SDLC) Security
  • Vulnerability Management
  • Security Incident Response
  • Security Compliance
  • Cybersecurity Governance
  • Risk Management
  • Security Operations
  • Cloud Security
  • OWASP
  • SANS CWE Top 25
  • ISO 27001
  • PCI DSS
  • NIST Frameworks
  • SAMA CSF
  • NCA ECC
  • Identity and Access Management (IAM)
  • Cyber Resilience
  • Business Continuity
  • Disaster Recovery
  • Executive Leadership
  • Communication

Work Environment and Location

This is a full-time position based in Riyadh, Saudi Arabia. The role is with ByteDance, a company operating in the technology sector.

breifcase2-5 years

locationRiyadh

2 days ago
Associate Principal Job

Associate Principal Job

📣 Job Ad

Elm Company

Full-time

About the Associate Principal Role

Elm Company is seeking a highly skilled Associate Principal to join its team in Riyadh, Saudi Arabia. This role is integral to enhancing the organization's governance, control effectiveness, and overall security posture through independent assurance and advisory services. The Associate Principal will conduct and support risk-based information security audits, with a focus on critical areas including cybersecurity, access controls, data privacy, and the protection of sensitive data.

Key Responsibilities

  • Define and execute the Information Security audit plan, covering cybersecurity, access controls, and the protection of sensitive data.
  • Evaluate and prioritize security-related risks to identify high-priority audit engagements.
  • Provide assurance and consultancy on information security governance, policies, procedures, and regulatory compliance.
  • Recommend improvements to information security controls to address vulnerabilities and strengthen defense mechanisms.
  • Ensure compliance with applicable security standards to guarantee data confidentiality, integrity, and availability.
  • Conduct or oversee compromise assessment and penetration testing activities to evaluate security defenses, detect potential breaches, and validate remediation efforts.
  • Perform formal audits and gap assessments against national, regional, and industry security standards.
  • Audit data privacy, governance, and protection mechanisms to ensure adherence to applicable laws and internal policies.
  • Evaluate the AI lifecycle, from data acquisition to deployment, to ensure fairness, transparency, and compliance with ethical and regulatory requirements.
  • Assess controls that influence user trust, service reliability, and the organization's overall security posture.
  • Monitor the implementation of information security-related corrective actions to ensure timely and effective resolution.
  • Develop and review periodic information security audit metrics to monitor performance, risk coverage, and control effectiveness.
  • Undertake special security-related audit assignments as requested by management.
  • Issue concise reports detailing risk-ranked findings, root causes, and actionable recommendations, and brief management or committees accordingly.
  • Adhere to all relevant departmental policies, processes, standard operating procedures, and instructions.
  • Comply with all relevant safety, quality, and environmental management policies, procedures, and controls.
  • Ensure the implementation of various information security practices and standards to comply with relevant policies and protect ELM data and information.

Qualifications and Experience

Candidates are expected to possess a strong understanding and practical experience in the areas outlined in the responsibilities and skills sections. A proven track record in performing comprehensive information security audits and providing strategic advisory services is essential. The role requires 5-10 years of experience.

Required Skills

  • Information Security Audits
  • Cybersecurity
  • Access Controls
  • Data Privacy
  • Risk Management
  • Governance
  • Compliance
  • Penetration Testing
  • AI Ethics

Work Environment and Details

This is a full-time position based in Riyadh, Saudi Arabia. The role is with Elm Company.

breifcase5-10 years

locationRiyadh

11 days ago
Data & Technology Director

Data & Technology Director

📣 Job Ad

Bayt Al-Tawabel

Full-time

About the Role

Bayt Al-Tawabel is seeking an experienced Data & Technology Director to lead the organization's comprehensive data strategy, enterprise systems, IT infrastructure, cybersecurity, and digital technology roadmap. This role is designed to ensure that technology and data serve as business enablers, driving operational efficiency, enhancing guest experience, supporting scalability, ensuring reporting accuracy, and fostering long-term growth across a multi-location business.

The ideal candidate will possess strong leadership experience across key technology domains including POS, ERP, integrations, data platforms, analytics, cybersecurity, infrastructure, and technology operations. This individual will oversee critical technology functions, manage vital systems and vendors, improve system reliability, strengthen cybersecurity governance, and empower data-driven decision-making.

Key Responsibilities

  • Lead the overall data, technology, IT infrastructure, cybersecurity, and enterprise systems strategy for the organization.
  • Own and manage the technology roadmap, encompassing POS systems, ERP, digital ordering, integrations, automation, data platforms, and various business applications.
  • Manage and enhance critical systems across all locations to guarantee reliability, availability, performance, and scalability.
  • Spearhead the organization's data strategy by centralizing data sources, improving reporting capabilities, and enabling more informed business decision-making.
  • Develop and refine dashboards, analytics tools, reporting models, and data visibility for key stakeholders.
  • Oversee all technology operations, including infrastructure, networks, systems, support, cybersecurity, data governance, and analytics functions.
  • Lead the integration architecture between core systems such as POS, ERP, CRM, ordering platforms, finance systems, and reporting tools.
  • Manage technology vendors, contracts, service providers, implementation partners, Service Level Agreements (SLAs), and support agreements.
  • Ensure the proper implementation of cybersecurity controls, policies, risk management, incident response, and access management processes.
  • Maintain compliance with relevant data protection, cybersecurity, and local regulatory requirements.
  • Support digital transformation initiatives aimed at improving guest experience, operational efficiency, automation, and overall business growth.
  • Establish and maintain technology policies, governance frameworks, documentation, and standard operating procedures.
  • Monitor system uptime, project delivery, cybersecurity incidents, vendor performance, and key technology performance indicators (KPIs).
  • Lead, develop, and manage technology and data teams, establishing clear accountability and performance expectations.
  • Prepare technology performance reports, roadmap updates, risk assessments, and strategic recommendations for senior leadership.

Qualifications and Requirements

  • Bachelor's degree in Computer Science, Information Technology, Engineering, Data Science, Business Technology, or a closely related field.
  • A minimum of 10 years of progressive experience in technology, IT, data, digital transformation, systems, or enterprise applications.
  • A minimum of 5 years of experience in a technology leadership role, managing multiple technology functions or teams.
  • Experience within the F&B, retail, hospitality, restaurant, or multi-location business sectors is strongly preferred.
  • Demonstrated strong experience with POS systems, ERP systems, digital ordering platforms, integrations, and various business applications.
  • A solid understanding of IT infrastructure, networks, cloud platforms, cybersecurity principles, system administration, and business continuity planning.
  • Proven experience leading data strategy development, data governance implementation, analytics, reporting, and dashboard creation.
  • In-depth knowledge of cybersecurity governance, risk management, incident response protocols, access control mechanisms, and compliance standards.
  • Familiarity with local data protection and cybersecurity regulations is advantageous.
  • Proven track record of successfully managing technology vendors, contracts, SLAs, implementation partners, and support providers.
  • Exceptional leadership skills with the ability to effectively manage both technical teams and diverse business stakeholders.
  • Strong project management capabilities, including roadmap planning, prioritization, and execution.
  • The ability to translate complex business needs into practical and effective technology and data solutions.
  • Excellent analytical thinking, problem-solving, and decision-making skills.
  • Outstanding communication, reporting, and presentation skills.
  • A strong command of both Arabic and English languages.

Required Skills

  • Data Strategy
  • Enterprise Systems
  • IT Infrastructure
  • Cybersecurity
  • Digital Technology Roadmap
  • POS Systems
  • ERP Systems
  • Integrations
  • Data Platforms
  • Analytics
  • Technology Operations
  • Digital Ordering
  • Automation
  • Business Applications
  • Networks
  • Cloud Platforms
  • System Administration
  • Business Continuity Planning
  • Data Governance
  • Reporting
  • Dashboard Development
  • Risk Management
  • Incident Response
  • Access Control
  • Compliance
  • Digital Transformation
  • Project Management
  • Roadmap Planning
  • Prioritization
  • Execution
  • Analytical Thinking
  • Problem-Solving
  • Decision-Making
  • Communication
  • Presentation Skills
  • Leadership

Work Environment and Location

This is a full-time position based in Riyadh, Saudi Arabia, with Bayt Al-Tawabel. The role requires a minimum of 10 years of experience, with a significant portion in leadership positions.

breifcase+10 years

locationRiyadh

8 days ago
OT Cybersecurity Program Senior Manager

OT Cybersecurity Program Senior Manager

📣 Job AdNew

Accenture Middle East

Full-time

About the Role

Accenture Middle East is seeking an experienced OT Cybersecurity Program Senior Manager to join its team in Riyadh, Saudi Arabia. This role will lead end-to-end Operational Technology (OT) / Industrial Control Systems (ICS) cybersecurity engagements, serving as a trusted advisor to senior client stakeholders across major Saudi and regional organizations. The position is instrumental in shaping and executing Accenture's OT cybersecurity go-to-market strategy for Saudi Arabia, aligning with Vision 2030 and national cyber resilience priorities.

This opportunity involves driving business development, building and mentoring a high-performing team with a focus on developing Saudi national talent, and overseeing critical OT/IT convergence security programs. The role also contributes to Accenture's global OT Security practice through sharing KSA market insights and shaping global offerings.

Key Responsibilities

  • Lead end-to-end OT / ICS cybersecurity engagements, including assessments, architecture and roadmaps, large-scale programs, and managed security services.
  • Act as a trusted advisor to senior client stakeholders, including CISOs, COOs, plant leadership, and executive committees across major Saudi and regional organizations.
  • Drive business development by originating, shaping, and closing OT security opportunities across the energy, utilities, manufacturing, chemicals, and critical infrastructure sectors.
  • Define and execute Accenture’s OT cybersecurity go-to-market strategy for Saudi Arabia, ensuring alignment with Vision 2030 and national cyber resilience priorities.
  • Build, mentor, and lead a high-performing OT cybersecurity team, with a strong focus on developing Saudi national talent.
  • Oversee OT/IT convergence security programs, encompassing industrial network segmentation, secure remote access, asset discovery and visibility, SOC integration, and incident preparedness.
  • Contribute to Accenture's global OT Security practice by sharing KSA market insights and shaping global offerings, methodologies, accelerators, and assets.

Qualifications and Experience

  • A minimum of 13 years of overall cybersecurity experience.
  • At least 7 years of specialized experience in OT / ICS / SCADA environments within sectors such as energy, utilities, oil & gas, or manufacturing.
  • A strong background in management consulting or professional services, with proven experience leading complex client-facing advisory and delivery engagements.
  • Deep expertise in OT security standards and frameworks, including IEC 62443 / ISA-IEC standards, NIST Cybersecurity Framework, Saudi NCA ECC, OT-CCC, and local regulatory requirements. Experience within KSA is strongly preferred.
  • Proven experience delivering large-scale OT security programs, including risk assessments, secure architectures, SOC integration, and incident response.
  • Demonstrated ability to engage and influence senior client stakeholders within complex organizations.
  • Hands-on familiarity with leading OT / ICS vendors such as Honeywell, Siemens, Rockwell Automation, Schneider Electric, ABB, and Emerson.
  • Relevant professional certifications such as GICSP, CISSP, CISM, or equivalent OT/ICS cybersecurity credentials.
  • Excellent English communication skills are essential.
  • Arabic language proficiency is strongly preferred.

Required Skills and Expertise

  • OT / ICS cybersecurity engagements, assessments, architecture and roadmaps, large-scale programs, and managed security services.
  • Trusted advisor capabilities and business development acumen for OT security opportunities.
  • Expertise across energy, utilities, manufacturing, chemicals, and critical infrastructure sectors.
  • Developing and executing OT cybersecurity go-to-market strategies, with an understanding of Vision 2030 and national cyber resilience priorities.
  • Team leadership, mentoring, and talent development, with a focus on Saudi national talent.
  • OT/IT convergence security programs, including industrial network segmentation, secure remote access, asset discovery and visibility, SOC integration, and incident preparedness.
  • Contribution to global practice development, including sharing market insights and shaping offerings.
  • Proficiency with OT security standards and frameworks (IEC 62443, NIST CSF, Saudi NCA ECC, OT-CCC).
  • Experience with OT/ICS vendors (Honeywell, Siemens, Rockwell Automation, Schneider Electric, ABB, Emerson).
  • Professional certifications (GICSP, CISSP, CISM, or equivalent).
  • Strong client engagement and stakeholder influence skills.
  • Excellent English communication skills.

Work Location and Type

This is a full-time position based in Riyadh, Saudi Arabia.

breifcase+10 years

locationRiyadh

Remote Job
2 days ago
AI Security Manager

AI Security Manager

📣 Job Ad

Accenture Middle East

Full-time

About the Role

Accenture Middle East is seeking an experienced AI Security Manager to join its Cybersecurity practice in Riyadh, Saudi Arabia. This role is central to defining and delivering secure architectures for Artificial Intelligence (AI) and agentic systems within enterprise environments. The position involves close collaboration with client leadership to translate complex AI security requirements into scalable, production-ready designs, ensuring the secure adoption of emerging technologies while maintaining resilience and trust.

This opportunity offers a significant role in assisting organizations with the operationalization of secure and responsible AI. The focus is on embedding security into AI architectures from the initial design phase through to deployment, thereby enabling innovation at scale.

Key Responsibilities

  • Design end-to-end security architectures for AI/ML and agentic systems, covering data pipelines, model development and hosting, inference layers, identity management, and associated security controls.
  • Adapt Accenture's AI Security frameworks into practical, implementable architectures tailored to specific client environments and business needs.
  • Lead comprehensive threat modeling and risk assessment activities for AI workloads, defining clear mitigation strategies and robust secure design patterns.
  • Evaluate and recommend secure AI solutions and platforms, including guardrails, runtime protection mechanisms, AI Security Posture Management (AI-SPM), model scanning tools, and Large Language Model (LLM) gateways.
  • Provide strong technical leadership on client engagements, setting strategic direction for delivery teams and guiding consultants to ensure high-quality outcomes.
  • Collaborate directly with client architects, security leaders, and Chief Information Security Officers (CISOs) to validate designs and support their implementation into production environments.
  • Contribute to shaping the security strategy and architecture for AI transformation programs across various industries.

Required Qualifications

  • A strong background in security architecture across cloud, identity, network, and data domains, with deep expertise in at least one major cloud platform.
  • A practical understanding of AI/ML systems, including common architectures and key security challenges throughout their lifecycle.
  • Knowledge of the secure AI tooling landscape, with the ability to objectively assess and align solutions to client requirements.
  • Proven experience in leading technical workstreams and mentoring team members within complex delivery environments.
  • Strong stakeholder management skills, with a demonstrated ability to engage and influence senior client leaders effectively.
  • The ability to translate complex technical concepts into clear architectural guidance and actionable recommendations.

Skills and Experience

  • Security Architecture
  • Cloud Security
  • Identity Security
  • Network Security
  • Data Security
  • AI/ML Systems
  • Threat Modeling
  • Risk Assessment
  • AI Security Tooling
  • Technical Leadership
  • Stakeholder Management
  • Large Language Models (LLMs)
  • Agentic Systems
  • AI-enabled Applications

Additional Information

This is a full-time position based in Riyadh, Saudi Arabia. The ideal candidate will have 5-10 years of relevant experience.

Bonus points if you possess:

  • Certifications in cybersecurity or cloud architecture (*, CISSP, CCSP, cloud security certifications).
  • Hands-on experience securing LLMs, agentic systems, or AI-enabled applications.
  • Experience delivering projects within the GCC region or similar markets.

breifcase5-10 years

locationRiyadh

8 days ago