2. الغرض الوظيفي
يتولى مدير أمن المعلومات وإدارة المخاطر قيادة وظيفة أمن المعلومات والمخاطر السيبرانية في المؤسسة. سيتولى تصميم برنامج الأمن السيبراني وتنفيذه وصيانته، وإدارة مخاطر الأمن المعلوماتي للمؤسسة، وضمان الامتثال للمتطلبات التنظيمية والصناعية السعودية ذات الصلة، وتعزيز ثقافة واعية بالأمن عبر المؤسسة.
يقدم الدور قيادة استراتيجية وتشغيلية عبر حوكمة أمن المعلومات، وإدارة المخاطر والامتثال (GRC)، وعمليات الأمن، والاستجابة للحوادث، وحماية البيانات، والتوعية الأمنية.
3. المسؤوليات الرئيسية والتسليمات
سيتحمل الدور مسؤولية تطوير وتنفيذ والتحسين المستمر لـ:
- استراتيجية أمن المعلومات وخارطة طريق الأمن السيبراني
- سياسات أمن المعلومات والمعايير والإجراءات والإرشادات
- نظام إدارة أمن المعلومات (ISMS)
- سجل مخاطر تكنولوجيا المعلومات والأمن السيبراني للمؤسسة
- تقارير تقييم مخاطر أمن المعلومات
- خطط معالجة المخاطر والتخفيف منها
- تقارير الامتثال الأمني، بما في ذلك ISO 27001 والمتطلبات التنظيمية ذات الصلة
- إطار عمل تحكم الأمن وتقارير فعالية الضوابط
- تقارير تقييم الثغرات واختبار الاختراق (VAPT)
- تقارير الأمن السيبراني وتحليل السبب الجذري (RCA)
- مراقبة الأمن ولوحات مخاطر تهديدات
- لوحات KPI وKRI للأمن السيبراني
- سياسات وبنى وصول وهوية (IAM)، ونماذج ومصفوفات الوصول
- تصنيف البيانات وإطار حماية البيانات
- تقارير وتوثيق التدقيق الداخلي والخارجي ومستودع الأدلة
- نتائج التدقيق وتتبع التخفيف
- التوافق الأمني لاستمرارية الأعمال والتعافي من الكوارث (BCP/DR)
- برامج وتقارير التوعية والتدريب الأمني
- التقييمات التنظيمية، والتقديمات، وأدلة الامتثال
4. المسؤوليات الرئيسية أ. استراتيجية الأمن المعلوماتي والحوكمة
- تعريف وتطوير وتنفيذ استراتيجية أمن المعلومات وخارطة الطريق للأمن السيبراني للمؤسسة.
- الملكية والارتقاء المستمر لنظام إدارة أمن المعلومات (ISMS).
- تطوير والحفاظ على سياسات أمن المعلومات والمعايير والإجراءات والإرشادات.
- إنشاء أطر حوكمة سيبرانية فعالة متوافقة مع أهداف العمل.
- تقديم تقارير دورية حول موقف الأمن السيبراني، وتعرض المخاطر، والامتثال، وأداء برنامج الأمن إلى CTO والقيادة التنفيذية.
- إرساء ومتابعة مؤشرات الأداء الأمني، ومقاييس KRIs وأداء الأداء.
- التأكد من دمج متطلبات الأمن المعلوماتي في المبادرات التكنولوجية والمشاريع والعمليات التجارية.
- دعم الاختبار والتحسين المستمر لإجراءات التعافي المرتبطة بالأمن.
5. المؤهلات والخبرة الحد الأدنى من المؤهلات
- درجة البكالوريوس في تكنولوجيا المعلومات، علوم الحاسوب، الأمن السيبراني، أمن المعلومات، أو تخصص ذي صلة.
- شهادة CISSP أو CISM مطلوبة.
- يفضّل شهادة ISO/IEC 27001 Lead Implementer أو Lead Auditor.
- يفضّل اعتماد أو شهادة متعلقة بالأمن السيبراني من NCA.
الحد الأدنى من الخبرة
- 8-10 سنوات من الخبرة المهنية في أمن المعلومات / الأمن السيبراني.
- على الأقل ثلاث سنوات من الخبرة في دور قيادي/إداري في الأمن السيبراني أو أمن المعلومات.
- خبرة مثبتة في إدارة برامج الأمن السيبراني على مستوى المؤسسة وفرق الأمن.
- خبرة مثبتة في GRC، إدارة المخاطر، عمليات الأمن، والاستجابة للحوادث.
- خبرة مثبتة في العمل مع الامتثال التنظيمي، التدقيق، وأطر الأمن السيبراني.
6. المهارات التقنية والمهنية
ينبغي أن يظهر المرشح الناجح ما يلي:
- معرفة قوية بأطر الأمن السيبراني والمعايير وأفضل الممارسات.
- فهم عميق لـ NCA، PDPL، NDMO، ISO 27001، ومتطلبات حماية البيانات ذات الصلة.
- خبـرة قوية في الحوكمة والمخاطر والامتثال (GRC).
- خبرة في عمليات SOC ومنصات SIEM مثل Microsoft Sentinel، Splunk، أو ما يعادلها.
- فهم قوي لإدارة الثغرات واختبار الاختراق.
- فهم قوي للاستجابة للحوادث وخطط استجابة الحوادث السيبرانية (CIRP).
- فهم قوي لإدارة الهوية والسيطرة والوصول (IAM).
- معرفة بحماية البيانات، وتصنيف البيانات، وحوكمة البيانات.
- فهم قوي للهندسة الآمنة وضبط الضوابط الأمنية.
- القدرة على تطوير ومراقبة مؤشرات KPI وKRI للأمن السيبراني.
- خبرة تدقيق وتقييم تنظيمية قوية.
- القدرة على تقييم وتوصيل مخاطر الأمن السيبراني من حيث أثرها على الأعمال.
- قدرة تفكير استراتيجية واتخاذ قرارات عالية المستوى.
- قيادة متميزة ومهارات إدارة الأفراد.
- القدرة على إدارة فرق متعددة الوظائف وأصحاب مصالح تحت الضغط.
- مهارات اتصال وعرض وتقديم تقارير قوية.
- ثنائية اللغة بالعربية والإنجليزية.
7. كفاءات القيادة
- التفكير الاستراتيجي
- قيادة الأمن السيبراني
- اتخاذ القرار بناءً على المخاطر
- إدارة أصحاب المصالح
- التواصل التنفيذي
- قيادة الفريق والتطوير
- حل المشكلات
- إدارة الأزمات والحوادث
- الحوكمة والمسائلة
- التحسين المستمر
- فهم العمل
- إدارة التغيير
المتطلبات الخاصة
- القدرة على العمل بفاعلية في بيئة سريعة الإيقاع وديناميكية.
- القدرة على إدارة الحوادث السيبرانية والمواقف الأمنية الحرجة.
- الاستعداد للمشاركة في استجابة ورفع الحوادث الأمنية عند الحاجة.
- الالتزام بالسرية والنزاهة المهنية.
- القدرة على العمل بشكل تعاوني مع القيادة التنفيذية، وتكنولوجيا المعلومات، ووظائف الأعمال، والمدققين، وأصحاب المصلحة التنظيميين.
الملف المرشح المرغوب
2. Job Purpose
The Information Security & Risk Manager is responsible for leading the organization s Information Security and Cyber Risk function. The role will design, implement, and maintain the cybersecurity program, manage enterprise information security risks, ensure compliance with applicable Saudi regulatory and industry requirements, and promote a strong security-aware culture across the organization.
The role provides strategic and operational leadership across Information Security Governance, Risk & Compliance (GRC), Security Operations, Incident Response, Data Protection, and Security Awareness.
3. Key Accountabilities & Deliverables
The role will be accountable for the development, implementation, and continuous improvement of:
- Information Security Strategy and Cybersecurity Roadmap
- Information Security policies, standards, procedures, and guidelines
- Information Security Management System (ISMS)
- Enterprise IT and Cybersecurity Risk Register
- Information Security Risk Assessment Reports
- Risk Treatment and Remediation Plans
- Security Compliance Reports, including ISO 27001 and applicable regulatory requirements
- Cybersecurity Control Framework and Control Effectiveness Reports
- Vulnerability Assessment and Penetration Testing (VAPT) Reports
- Cybersecurity Incident Reports and Root Cause Analysis (RCA)
- Security Monitoring and Threat Dashboards
- Cybersecurity KPI and KRI Dashboards
- Identity and Access Management (IAM) Policies, Models, and Access Matrices
- Data Classification and Data Protection Framework
- Internal and External Audit Reports and Evidence Repository
- Audit Findings and Remediation Tracking
- Business Continuity and Disaster Recovery (BCP/DR) Security Alignment
- Security Awareness and Training Programs and Reports
- Regulatory Assessments, submissions, and compliance evidence
4. Key Responsibilities A. Information Security Strategy & Governance
- Define, develop, and execute the organization s Information Security Strategy and cybersecurity roadmap.
- Own and continuously improve the Information Security Management System (ISMS).
- Develop and maintain information security policies, standards, procedures, and guidelines.
- Establish effective cybersecurity governance frameworks aligned with business objectives.
- Provide regular reporting on cybersecurity posture, risk exposure, compliance, and security program performance to the CTO and executive leadership.
- Establish and monitor security KPIs, KRIs, and performance metrics.
- Ensure information security requirements are incorporated into technology initiatives, projects, and business processes.
- Support testing and continuous improvement of security-related recovery procedures.
5. Qualifications & Experience Minimum Qualifications
- Bachelor s degree in Information Technology, Computer Science, Cybersecurity, Information Security, or a related discipline.
- CISSP or CISM certification Mandatory.
- ISO/IEC 27001 Lead Implementer or Lead Auditor certification preferred.
- NCA-related cybersecurity accreditation or certification is preferred.
Minimum Experience
- 8 10 years of professional experience in Information Security / Cybersecurity.
- At least 3 years of experience in a cybersecurity or information security management/leadership role.
- Proven experience managing enterprise cybersecurity programs and security teams.
- Proven experience in GRC, risk management, security operations, and incident response.
- Proven experience working with regulatory compliance, audits, and cybersecurity frameworks.
6. Technical & Professional Skills
The successful candidate should demonstrate:
- Strong knowledge of cybersecurity frameworks, standards, and best practices.
- Deep understanding of NCA, PDPL, NDMO, ISO 27001, and applicable data protection requirements.
- Strong expertise in Governance, Risk, and Compliance (GRC).
- Experience with SOC operations and SIEM platforms such as Microsoft Sentinel, Splunk, or equivalent.
- Strong understanding of vulnerability management and penetration testing.
- Strong knowledge of Incident Response and Cybersecurity Incident Response Plans (CIRP).
- Strong understanding of IAM and access governance.
- Knowledge of data protection, data classification, and data governance.
- Strong understanding of secure architecture and security controls.
- Ability to develop and monitor cybersecurity KPIs and KRIs.
- Strong audit and regulatory assessment experience.
- Ability to assess and communicate cybersecurity risks in terms of business impact.
- Strong strategic thinking and high-level decision-making capability.
- Excellent leadership and people-management skills.
- Ability to manage cross-functional teams and stakeholders under pressure.
- Strong communication, presentation, and reporting skills.
- Bilingual proficiency in Arabic and English.
7. Leadership Competencies
- Strategic Thinking
- Cybersecurity Leadership
- Risk-Based Decision Making
- Stakeholder Management
- Executive Communication
- Team Leadership & Development
- Problem Solving
- Crisis and Incident Management
- Governance & Accountability
- Continuous Improvement
- Business Acumen
- Change Management
Special Requirements
- Ability to work effectively in a fast-paced and dynamic environment.
- Ability to manage cybersecurity incidents and critical security situations.
- Willingness to participate in security incident response and escalation activities when required.
- Strong confidentiality and professional integrity.
- Ability to work collaboratively with executive leadership, IT, business functions, auditors, and regulatory stakeholders.
Desired Candidate Profile