IT & Cybersecurity Auditor
📣 Job Ad| Contract Type | Full-time | |
| Workplace type | On-site | |
| Location | Riyadh |
Job Description
About the Role
OptiClaim Business Solutions is seeking an IT & Cybersecurity Auditor on behalf of a client in Riyadh, Saudi Arabia. This full-time role involves supporting IT and cybersecurity audit engagements, assessing IT infrastructure, cybersecurity controls, IT General Controls (ITGC), technology risks, and governance processes. The auditor will evaluate the effectiveness of security controls, identify risks and gaps, and recommend improvements to the organization's cybersecurity posture and compliance.
Key Responsibilities
- Plan and execute IT and cybersecurity audit engagements using risk-based audit methodologies.
- Evaluate the design and operating effectiveness of ITGC, including logical access, privileged access, password controls, change management, backup/recovery, logging, monitoring, and IT operations.
- Assess cybersecurity controls across network, endpoint, server, database, cloud, and infrastructure environments.
- Review Identity and Access Management (IAM), Privileged Access Management (PAM), Multi-Factor Authentication (MFA), and access governance processes.
- Assess vulnerability management, patch management, security monitoring, incident response, threat detection, and Security Operations Center (SOC) capabilities.
- Review network security architecture, including firewalls, segmentation, remote access, VPNs, email security, and secure configuration.
- Evaluate cloud security controls across Azure, AWS, Microsoft 365, GCP, and hybrid environments.
- Perform technology risk assessments to identify control deficiencies and improvement opportunities.
- Assess compliance with internal policies, regulatory requirements, and cybersecurity frameworks.
- Prepare audit working papers, risk assessments, reports, and executive presentations.
- Monitor and validate remediation actions and verify the closure of audit observations.
- Collaborate with IT, Information Security, Risk Management, Internal Audit, and business stakeholders.
Qualifications and Experience
- A minimum of 10 years of experience in a relevant field.
- Consulting background preferred, ideally with a Big 4 firm.
- Strong grounding in IT audit methodologies and risk-based auditing.
- Hands-on ITGC review experience.
- Strong knowledge across IAM, PAM, network/endpoint/server/OS security, cloud security, SOC, vulnerability & patch management, SIEM, incident response, backup/DR, data protection & encryption.
- Experience auditing on-premise, cloud, and hybrid environments.
- Familiarity with Azure, AWS, Microsoft 365, Active Directory, Microsoft Entra ID, and VMware is preferred.
Relevant Frameworks and Standards
The role requires familiarity with various cybersecurity and IT governance frameworks, including:
- NCA ECC & DCC
- SAMA CSF
- PDPL
- ISO/IEC 27001
- NIST CSF
- COBIT
- CIS Controls
- PCI DSS
Requirements
- Requires 5-10 Years experience
Similar Jobs
You may also like
- Related IT & Cybersecurity Auditor Opportunities
- Marketing Specialist Jobs in Riyadh
- Receptionist Jobs in Riyadh
- Seller Jobs in Riyadh
- Digital Marketing Specialist Jobs in Riyadh
- Key Account Manager Jobs in Riyadh
- Other Job Fields in Riyadh
- Marketing Specialist Jobs in Riyadh
- Receptionist Jobs in Riyadh
- Seller Jobs in Riyadh
- Digital Marketing Specialist Jobs in Riyadh
- Key Account Manager Jobs in Riyadh
- Guest Experience Expert Jobs in Riyadh
- Safety Engineer Jobs in Riyadh
- Sales Supervisor Jobs in Riyadh
- Safety Officer Jobs in Riyadh
- GIS Specialist Jobs in Riyadh
- Explore Jobs Across Saudi Arabia
- Teacher Jobs in Tabuk
- Procurement Officer Jobs in Riyadh
- Oral and Maxillofacial Orthodontist Jobs in Al Qawz
- Supply Chain Manager Jobs in Makkah
- Cosmetics and Toiletries Seller Jobs in Jeddah
- Maintenance Supervisor Jobs in Al-Kharj
- Private Car Driver Jobs in Al Khobar
- Electrical Site Engineer Jobs in Makkah
- Logistics Coordinator Jobs in Riyadh
- Social Work Assistant Jobs in Makkah