img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

SAB is seeking an Information Security Risk Assessment Manager to join their team in Riyadh, Saudi Arabia. This full-time role focuses on Cybersecurity Risk Management, supporting the enterprise-wide cybersecurity risk management program. The position is responsible for conducting threat modeling, developing and maintaining risk assessment methodologies, and plays a critical role in protecting the organization’s information assets by identifying and assessing cybersecurity risks. The ideal candidate will have 2-5 years of relevant experience.

Key Responsibilities

  • Conduct detailed and risk-based Cybersecurity Risk Assessments, meeting SLA commitments during IT and cybersecurity engagements.
  • Maintain awareness of best practices and industry standards in Information Security, assess potential policy gaps, respond to risks to SAB IT infrastructure, systems, network, and data, and recommend policy improvements.
  • Liaise with end-users to explain Cybersecurity risks and their role in prevention, driving initiatives to sensitize end-users.
  • Advise IT and business on optimal ways to deal with identified Cybersecurity risks and mitigation strategies.
  • Execute comprehensive Cybersecurity Risk Assessments before go-live and conduct detailed Cybersecurity Threat Modeling.
  • Perform detailed cybersecurity risk assessments and threat modeling for IT projects and systems at early project stages, before major changes, for new technologies, and periodically for existing assets. Identify threats, vulnerabilities, and controls for critical information assets and document these risks in a centralized risk register.
  • Review, analyze, and validate Cybersecurity Risk Assessment results to align them with issues raised by other Cybersecurity teams.
  • Raise application security related defects and enhance Cybersecurity patterns during engagements by highlighting new risks to domain owners.
  • Ensure all engaged/assigned assessments are conducted in accordance with the Cybersecurity Risk Management Methodology, Cybersecurity Risk Pattern, and Cybersecurity Change Review and Engagement Process, and within agreed timelines.
  • Customize and fine-tune the Cybersecurity risk assessment platform for optimal compatibility and accuracy.

Cybersecurity Risk Management Maturity and Policy

  • Enhance the existing Risk Management process and documentation.
  • Review and update existing Cybersecurity Risk Management documentation, including methodology, FIM section, standards, and guidelines.
  • Ensure that both the Cybersecurity Risk Management process and documentation align with Group latest practices and regulatory frameworks such as NCA and SAMA CSF.
  • Maintain all Cybersecurity Risk Management design documents, ensuring alignment with regulators and internal policies.
  • Develop, unify, and maintain the cybersecurity risk management methodology and procedures, aligned with enterprise risk management and regulatory requirements.
  • Regularly review and update risk management policies, design documents, and tools to reflect changes in the threat landscape or laws.
  • Ensure that risk treatment plans (mitigation, transfer, acceptance, avoidance) are in place and tracked through completion.

Periodic Assessments and Reporting

  • Ensure all required IT Services are assessed as per the annual plan.
  • Manage the periodic cybersecurity assessment plan, ensuring critical systems and services undergo regular security reviews.
  • Document review findings, identified risks, and recommended actions, and coordinate independent cybersecurity teams.
  • Provide a quarterly report on all Cybersecurity risks, highlighting priority risks for action with IT and Cybersecurity Management.
  • Calculate required KPIs and KRIs to highlight related risks.
  • Establish an escalation matrix for outstanding Cybersecurity Risks.

Experience Required

Candidates should possess 2-5 years of experience in a relevant field.

Work Environment

This is a full-time position based in Riyadh, Saudi Arabia.


Requirements

  • Requires 2-5 Years experience

Similar Jobs