IT & Cybersecurity Auditor
📣 Job Ad| Contract Type | Full-time | |
| Workplace type | On-site | |
| Location | Riyadh |
Job Description
About the Role
OptiClaim Business Solutions is seeking an IT & Cybersecurity Auditor on behalf of a client in Riyadh, Saudi Arabia. This full-time role involves supporting IT and cybersecurity audit engagements, assessing IT infrastructure, cybersecurity controls, IT General Controls (ITGC), technology risks, and governance processes. The auditor will evaluate the effectiveness of security controls, identify risks and gaps, and recommend improvements to the organization's cybersecurity posture and compliance.
Key Responsibilities
- Plan and execute IT and cybersecurity audit engagements using risk-based audit methodologies.
- Evaluate the design and operating effectiveness of ITGC, including logical access, privileged access, password controls, change management, backup/recovery, logging, monitoring, and IT operations.
- Assess cybersecurity controls across network, endpoint, server, database, cloud, and infrastructure environments.
- Review Identity and Access Management (IAM), Privileged Access Management (PAM), Multi-Factor Authentication (MFA), and access governance processes.
- Assess vulnerability management, patch management, security monitoring, incident response, threat detection, and Security Operations Center (SOC) capabilities.
- Review network security architecture, including firewalls, segmentation, remote access, VPNs, email security, and secure configuration.
- Evaluate cloud security controls across Azure, AWS, Microsoft 365, GCP, and hybrid environments.
- Perform technology risk assessments to identify control deficiencies and improvement opportunities.
- Assess compliance with internal policies, regulatory requirements, and cybersecurity frameworks.
- Prepare audit working papers, risk assessments, reports, and executive presentations.
- Monitor and validate remediation actions and verify the closure of audit observations.
- Collaborate with IT, Information Security, Risk Management, Internal Audit, and business stakeholders.
Qualifications and Experience
- A minimum of 10 years of experience in a relevant field.
- Consulting background preferred, ideally with a Big 4 firm.
- Strong grounding in IT audit methodologies and risk-based auditing.
- Hands-on ITGC review experience.
- Strong knowledge across IAM, PAM, network/endpoint/server/OS security, cloud security, SOC, vulnerability & patch management, SIEM, incident response, backup/DR, data protection & encryption.
- Experience auditing on-premise, cloud, and hybrid environments.
- Familiarity with Azure, AWS, Microsoft 365, Active Directory, Microsoft Entra ID, and VMware is preferred.
Relevant Frameworks and Standards
The role requires familiarity with various cybersecurity and IT governance frameworks, including:
- NCA ECC & DCC
- SAMA CSF
- PDPL
- ISO/IEC 27001
- NIST CSF
- COBIT
- CIS Controls
- PCI DSS
Requirements
- Requires 5-10 Years experience
Similar Jobs
You may also like
- Related IT & Cybersecurity Auditor Opportunities
- Courier Jobs in Riyadh
- Gift Wrapper Jobs in Riyadh
- Administrative Assistant Jobs in Riyadh
- Social Media Management Specialist Jobs in Riyadh
- Secretary Jobs in Riyadh
- Other Job Fields in Riyadh
- Courier Jobs in Riyadh
- Gift Wrapper Jobs in Riyadh
- Administrative Assistant Jobs in Riyadh
- Social Media Management Specialist Jobs in Riyadh
- Secretary Jobs in Riyadh
- Marketing Manager Jobs in Riyadh
- Site Engineer Jobs in Riyadh
- Sales Representative Jobs in Riyadh
- Hotel Receptionist Jobs in Riyadh
- Sales Supervisor Jobs in Riyadh
- Explore Jobs Across Saudi Arabia
- Civil Engineer Jobs in Khamis Mushayt
- HVAC Mechanic Jobs in Dammam
- Optician Jobs in Arar
- Dentist Jobs in Jeddah
- Private Car Driver Jobs in Jeddah
- Commercial Manager Jobs in Riyadh
- Environmental Engineer Jobs in Al Khobar
- Human Resources Specialist Jobs in Dammam
- Financial Accountant Jobs in Riyadh
- Host Jobs in Riyadh