img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

Qiddiya is seeking a Senior Manager, Third Party Security to lead and manage its Third-Party Security Risk Management program. This full-time position is based in Riyadh and focuses on ensuring that vendors, partners, consultants, and service providers comply with cybersecurity requirements. The role aims to prevent unacceptable risks to Qiddiya's information assets, systems, and operations, aligning with industry best practices for cybersecurity risk management and third-party oversight.

Role Purpose and Context

The Senior Manager will be responsible for establishing security assessment frameworks, overseeing vendor security reviews, and driving the remediation of identified risks. This involves a strategic approach to managing cybersecurity risks introduced by external entities, ensuring Qiddiya's operational integrity and security posture are maintained.

Key Responsibilities

  • Develop and maintain the Third-Party Security Risk Management (TPSRM) framework.
  • Conduct cybersecurity due diligence and risk assessments for vendors and suppliers.
  • Review security requirements during procurement, RFP, and contract stages.
  • Assess cloud providers, SaaS platforms, managed service providers, and strategic partners.
  • Define vendor security controls aligned with NCA ECC, ISO 27001, NIST, and Qiddiya cybersecurity standards.
  • Establish vendor risk classification and assessment methodologies.
  • Monitor remediation plans and track closure of identified security gaps.
  • Collaborate with Procurement, Legal, Compliance, Enterprise Risk, and Technology teams.
  • Lead periodic reassessments of critical vendors.
  • Report third-party cyber risks, trends, and KPIs to senior management.
  • Manage external security audits, questionnaires, and assurance activities.
  • Lead and develop the Third-Party Security team.

Qualifications and Experience

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, or a related field.
  • 8-12 years of experience in cybersecurity.
  • A minimum of 4 years of experience in Third-Party Security, Vendor Risk Management, Cybersecurity Risk Management, or GRC.
  • Experience within large enterprises, giga projects, banking, telecom, government, or critical infrastructure environments.
  • Demonstrated experience in managing teams and engaging with stakeholders at senior levels.

Work Environment

This role operates within a dynamic environment, requiring collaboration with various internal departments and external partners to uphold Qiddiya's cybersecurity standards. The position is based in Riyadh and is a full-time commitment.

Application Process

Candidates meeting the specified requirements are encouraged to apply for this role to contribute to Qiddiya's security framework.


Requirements

  • Requires 5-10 Years experience

Similar Jobs