img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

The General Authority for Competition (الهيئة العامة للمنافسة) in Riyadh is seeking a Cybersecurity Executive Director. This full-time role involves overseeing cybersecurity governance and risk activities, leading compliance and audit operations, and directing cybersecurity operations including defense, incident management, and threat response. Additionally, the role leads the Data Office and supervises data management and governance activities.

Strategic Planning and Objectives

  • Oversee the development of annual operational plans for cybersecurity and data office units in alignment with the Authority's strategic plan and guide implementation.
  • Develop goals and performance indicators for cybersecurity and the Data Office based on approved Authority objectives, and continuously monitor progress towards achieving these goals.
  • Establish the annual budget for cybersecurity and the Data Office in line with plans and needs, ensuring effective utilization.

Cybersecurity Governance, Risk, and Compliance

  • Ensure that IT cybersecurity requirements align with the Authority's cybersecurity strategy.
  • Manage cybersecurity decisions in a manner consistent with fundamental risk management principles.
  • Oversee and participate in the results of cybersecurity risk assessments.
  • Review prevention and mitigation plans to ensure all vulnerabilities and gaps are properly addressed.
  • Manage the cybersecurity risk register and key risk indicators, and define controls to protect access to information and technical assets to ensure effective risk management.
  • Supervise the implementation of cybersecurity training and awareness programs.
  • Review non-compliance reports, identify, and follow up on the implementation of necessary measures to mitigate potential and resulting risks.

Cybersecurity Operations

  • Oversee the design of the cybersecurity architecture to ensure alignment with the Authority's needs and objectives.
  • Review proactive information, cybersecurity threats, and security vulnerabilities in the Authority's systems and solutions, and identify necessary measures to address them and counter cyberattacks.
  • Oversee the results of security vulnerability scanning and penetration testing operations.
  • Ensure appropriate actions are taken to address risk when a cybersecurity incident occurs.
  • Supervise the handling of cybersecurity incidents, which involves collecting, analyzing, examining, and processing evidence.
  • Follow up on the implementation of change requests and technical requirements related to business continuity and disaster recovery.
  • Review periodic reports documenting encountered incidents, threat trends, and corrective measures taken, and recommend improvement actions.
  • Keep senior management informed with periodic reports and important changes.

Data Office Responsibilities

  • Facilitate collaboration and communication with the National Data Management Office (NDMO).
  • Ensure that data management and governance policies and strategy align with the Authority's strategy.
  • Review the governance framework, policies, procedures, and guidelines for data classification, storage, and protection.
  • Oversee the implementation of the data management roadmap, tools, and key performance indicators.
  • Supervise data governance activities and ensure compliance with approved standards and policies, highlighting gaps and vulnerabilities to ensure they are addressed.
  • Monitor and evaluate data management performance, identify areas for improvement, and implement corrective actions.

Requirements

  • No experience required

Similar Jobs