Security inspector Jobs in Egypt
4848 Jobs Found
<ul><li><p>Develop, implement, and monitor <strong>security policies, procedures, and site security plans</strong>.</p></li><li><p>Manage security operations across construction sites, offices, warehouses, and project facilities.</p></li><li><p>Conduct regular <strong>security risk assessments</strong> and identify potential threats and vulnerabilities.</p></li><li><p>Ensure effective control of <strong>site access, personnel, visitors, vehicles, and materials</strong>.</p></li><li><p>Manage and supervise security guards and security supervisors.</p></li><li><p>Develop security manpower plans, duty rosters, and shift schedules.</p></li><li><p>Monitor compliance with security procedures and take corrective action when required.</p></li><li><p>Coordinate with <strong>Project Managers, Site Management, HR, HSE, and other departments</strong> regarding security matters.</p></li><li><p>Coordinate with external security service providers and evaluate their performance.</p></li><li><p>Investigate security incidents, theft, unauthorized access, property damage, and other violations.</p></li><li><p>Prepare security incident reports and recommend appropriate corrective and preventive actions.</p></li><li><p>Support emergency response and crisis-management procedures.</p></li></ul><ul><li><p>Monitor the movement and protection of company assets, equipment, materials, and vehicles.</p></li><li><p>Coordinate with relevant authorities and emergency services when required.</p></li><li><p>Conduct regular security inspections and audits across project sites.</p></li><li><p>Maintain accurate security records, reports, logs, and incident documentation.</p></li><li><p>Ensure security teams are properly trained and understand site procedures and emergency protocols.</p></li></ul><p></p><p><strong>Requirements</strong></p><ul><li><p><strong>9–15 years of relevant security experience</strong>, including experience in a managerial/supervisory position.</p></li><li><p><strong>Strong experience in construction companies and construction project sites is required/preferred.</strong></p></li><li><p>Proven experience managing security operations across <strong>multiple construction sites</strong>.</p></li><li><p>Experience managing security guards, supervisors.</p></li><li><p>Strong knowledge of <strong>site access control, asset protection, incident management, and security risk assessment</strong>.</p></li><li><p>Experience dealing with security incidents, investigations, and emergency situations.</p></li><li><p>Good knowledge of <strong>CCTV, access-control systems, alarms, and other security technologies</strong>.</p></li><li><p>Strong communication, leadership, and decision-making skills.</p></li><li><p>Ability to work under pressure and respond effectively to emergencies.</p></li><li><p>Willingness to travel between construction project sites as required.</p></li></ul><p></p>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>Establish and maintain the organization’s Cyber Defense methodology in line with security regulations and requirements.<br> Obtain senior management endorsement for security policies, standards, and procedures by clearly articulating their benefits.<br> Investigate cybersecurity incidents and violations, reporting findings and recommendations to the CISO.<br> Respond rapidly and effectively to cybersecurity incidents in line with incident management processes.<br> Prepare periodic performance reports based on analysis and correlation of security events.<br> Oversee projects and deployments of security tools to ensure an effective security posture.<br> Lead the Security Operations Center (SOC) team, including shift planning and operational tool implementation.<br> Manage the Cyber Defense Centre and its resources to ensure operational effectiveness.<br> Maintain the security of corporate information against all internal and external threats.<br> Provide security input into the organization’s strategic planning process and enterprise-level decisions.<br> Implement and maintain the organization’s information security program in alignment with business objectives.<br> Raise major cybersecurity incidents directly to the CISO.<br> Bachelor’s degree in Computer Science, Information Systems, or related field.<br> 12+ years of experience in Cyber Defense.<br> Proven experience managing SOC teams and cyber defense operations.<br> Strong knowledge of incident response, threat detection, and security monitoring.<br> Hands-on expertise with SIEM, endpoint protection, and enterprise security tools.<br> Relevant certifications (CISSP, CISM, CISA, or equivalent) preferred.<br> Strong analytical, leadership, and communication skills.<br></span> </div>
Job Purpose:Administration:Leads the administration of SOAR (Security Orchestration and Response solution) solutions within the Cyber Defense Center, enhancing the efficiency and effectiveness of an organization’s security operations through the use of automation and orchestration. This role involves working closely with the security operations team to develop automated workflows, integrate various security tools, and respond to security incidents efficiently SOAR Manager effectively streamlines security operations, improve incident response times, and enhance overall cybersecurity resilience<br>Key Result Areas:Technical Proficiency: Deep understanding of security technologies, including SOAR (Security Orchestration and Response solution) platforms, threat intelligence platforms, SIEM solutions and other cyber monitoring tools and technologies. Design, implement, optimize security workflows, Create automated playbooks and ensure proper orchestration between multiple security tools and systems Automation and Scripting: Proficiency in scripting languages such as Python, Power Shell, or Bash to automate repetitive tasks and integrate different security tools. Incident Response: Strong knowledge of incident response processes and frameworks, including the ability to coordinate response efforts during security incidents. Analytical Skills: Ability to analyze complex security data, identify patterns, and make informed decisions to enhance security operation. Project Management: Experience in managing projects, including planning, execution, and monitoring of SOAR implementations and improvements.<br>Key Principles:<br>Alignment with Business Priorities: Provide strategic direction and oversight for the SOAR process, ensuring alignment with organizational goals and objectives Ownership and Accountability: The SOAR Manager takes full responsibility for activities and the department’s, holding self and team accountable for their outcomes. Driving SOAR Maturity Enhancement: Proactively drives initiatives that enhance incident response and resilient cyber posture. Focus on Outputs and Impact: Focus on delivering outputs that create meaningful impact such as enhanced security culture and protection posture of the bank. Innovation and Automation: Continuously seek innovative solutions and automated processes for efficiency. Continuous Learning and Improvement: Committed to learning from experiences and continuously improving the processes and outcomes.<br>Operating Environment, Framework and Boundaries, Working Relationships:<br>HO (Head Office), Local CISOs, Regulators and Supervisors across the bank Cyber Security Standards and Industry best practices All business units including LOD 1-3 including LOD1 – Business, DPP, Technology, LOD-2 Group Compliance, Fraud Prevention, Risk Management and LOD-3 Internal Audit.<br>Problem Solving:<br>Analytical Thinking: The ability to break down complex problems into manageable parts and analyze them systematically is crucial for identifying security threats and vulnerabilities. Technical Proficiency: Deep understanding of security technologies, protocols, and tools is essential for designing and implementing SOAR solutions. Creativity: Innovative thinking helps in developing unique solutions to security challenges, especially when standard approaches are insufficient.<br>Decision Making Authority & Responsibility:<br>SOAR Manager is a SME role who has overall responsibility for SOAR processes withing the Security Incident Response domain and supporting the Head of Cyber Defense Center to achieve organization’s Information Security strategy and goals. Confirm adequacy of the process controls against Security Incident response policies, standards and applicable regulatory requirements.<br>Knowledge, Skills, and Experience:<br>Essential knowledge Have over 8+ years of rich experience in information security domain and at least 4-6 years of dedicated experience in Security Incident Response using SOAR solutions. Hands on experience in implementing and operationalizing SOAR tools preferably on Sentinel or Splunk SOAR, Palo Alto Cortex XSOAR, or IBM Resilient Familiarity with advanced SOC monitoring technologies, risk, threat and security measures. Knowledge across the SOC domains including governance, control frameworks, policies, compliance management, risk management and incident response etc. Preferably worked in BFSI domain with proven experience in SOC function. Knowledge of key security standards and regulations such as NIST 800-61, CERT/CC, PCI, ISO 27035 etc.<br>Skills and Application <br>Automate potential resilient security processes to ensure continuous compliance with security best practices. Maintaining up-to-date knowledge of security trends, threats, and countermeasures Assess and design security posture SOAR solutions, tools and methodologies Reviewing use cases/playbooks for SOAR tools Continuously monitor security hygiene and performance using tools and processes Collaborate with other IS teams, Ops and tech teams on enhancing security incident response resilience<br>Other<br>Sound knowledge of evolving advanced tech stacks and related control and risk universe from a SOC perspective. The ideal candidate will have a technical or computer science degree. Professional certifications: GCIH, CISSP, CEH etc.
Senior Consultant - Cyber Security, ISMS/ ISMS Implementation<br>Role Responsibilities Reviewing systems architecture / design to assess and improve information security Assess the current state security posture, envision future state and provide implementation roadmaps to our clients in IT security projects Provide enterprise security strategy and project manage IT security solution implementation Advise clients on ISO 27001 standards and manage ISO 27001 project implementation Perform risk assessment and advice on risk treatment plan Develop IT security policies, procedures and baseline standards Prepare, discuss and finalize IT security assessment reports Carry out application source code reviews Identify potential new business opportunities and assist in conversion of opportunities end-to-end Assisting in IT security practice management activities Maintain healthy relationship with all levels of the client personnel at all times Handle multiple assignments across various industries, etc. Desired Profiles Minimum of 2-4 years of experience of Hands-on experience in ISMS implementation and on IT security consulting, implementation and maintenance of IT security solutions such as Firewalls, Anti-Virus System, Security Management Systems, IDS / IPS and other similar solutions IT security consulting experience or worked in industry with the primary responsibility of managing IT security solutions Worked / used various IT security tools, scripts, programs to carry out penetration tests and risk assessments Exposure to a well-structured risk assessment techniques Strong oral and written communication skills Team player and management skills Exceptional skills in client relationship management Preference will be given to those candidates who have IT security product certifications. Academic qualifications: BE / B. Tech or any graduation Preferred professional qualifications: CISA / CISSP / CISM / CEH / CHFI / GIAC / CCIE or equivalent qualifications or equivalent qualifications Product Qualifications: Microsoft, Cisco, Unix/Linux, Storage and IT Security products (Firewall, Switches, IDS / IPS, GRC Software, SIEM / Log Management, Identity Access Controls Software, or other products). Preference will be given to those candidates who have IT security product certifications. Preference will be given to those candidates who have qualifications and experience in SCADA, Process Control Networks, Cyber Security Management, ISMS, Forensic Investigations, PCI DSS and PA DSS domains. Hands-on experience in conducting VAPT assignments, ISO 27001 engagements, Implementation of remedial control in Microsoft and Cisco environment<br>Job Location- Egypt
<p><strong>JOB PURPOSE</strong> To deploy, operate and maintain the appropriate data security solutions and tools and implement necessary controls to protect the bank's information systems against internal and external threats in alignment with the bank's approved security architecture framework.</p><p>1.Monitor, implement and operate appropriate levels of Data security controls and systems according to enterprise Data security solutions on day-to-day basis, in order to keep business secured proactively against identified threats.</p><p>2.Provide first-level support for all managed systems and platforms including: Content Filtering, Sandboxing and others, in order to maintain business operations according to approved service level agreement.</p><p>3.Secure the access to corporate data and crown-jewels information through the operations of Data Loss Prevention (DLP), Secure Domain Name Services (DNS), Data Base (DB) Security, Internet based traffic content filtering, at all levels of the data security architecture in order to safeguard and limit access to key information system assets at all layers.</p><p>4.Implement, Operate, and Maintain Date Security, Protection and Classification program technologies, in order to provide the required levels of assurance that CIB information Security Data security policies applied and enforced.</p><p>5.Provide data security technical expertise for Project Management in order to enable bank's Business Strategic Projects through maintaining a secure Software Development Life Cycle (SDLC) in the organization that complies with Business Strategic objectives, policies, procedures, rules and regulations.</p><p>6.Perform analysis of data security needs and contribute to design, integration, and installation of hardware and software, to ensure effective security architecture and controls over enterprise applications.</p><p>7.Ensure that data security current and new tools and technologies are deployed in line with architectural requirements, and the organization's data loss prevention strategy and policies, in order to ensure effective controls according to business/compliance/regulation requirements.</p><p>8.Employ data confidentiality, integrity and availability controls in order to mitigate the risk of disclosure or alteration of sensitive information.</p><p>9.Provide technical expertise and guide the administration of data security tools that control and monitor information security, in order to keep business up and running seamless.</p><p>10.Develop and maintain monthly Key Performance Indicators (KPIs), security reports and dashboards across various data security solutions, in order to provide business with the required visibility.</p><p>11.Work with information systems owners and administrators to understand their data security needs and assist with implementing practices and procedures in alignment with CIB security policies.</p><p>12.Support Security Operations Centre and Information Security in Identifying, developing, and implementing mechanisms to detect/prevent data security incidents/gaps in order to enhance compliance with and support of security standards and procedures in place.</p><p>13.Respond to discovered security incidents by informing appropriate custodians, determining root cause, and identifying and executing remedial actions (if necessary) required to re-establish respective information system security.</p><p>14.Define and enhance, appropriate levels of Data security controls and systems according to data security solutions on regular basis, in order to keep business secured proactively against known threats.</p><p>15.Act as the technical lead in the development of responses to Request for Information (RFIs) and Request for Proposals (RFPs).</p><p><strong>Policies, Processes and Procedures</strong></p><p>16.Follow all relevant department policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent manner.</p><p><strong>Day-to-day Operations</strong></p><p>17.Follow the day-to-day operations related to own jobs in the IT Security, Control & Quality Assurance department to ensure continuity of work.</p><p><strong>Compliance</strong></p><p>18.Comply with all relevant CBE regulations, banking laws, AML regulations and internal CIB policies and code of conduct in order to maintain CIB's sound legal position and mitigate any potential risks.</p><p><strong>Desired Candidate Profile</strong></p><b>Qualifications & Experience</b><br>Bachelor's degree of Engineering, Computer Science or equivalent is must.<br>Engineer: Minimum of 3 5 years of experience in IT Security and related disciplines.<br>Should have an understanding of TCP/IP protocols, networking and firewall concepts.<br>Enterprise data security architecture and software are required.<br>Understanding of IT operations: help desk, end-point management and server management<br>Experience in configuring and implementing technical security solutions<br>Capability to effectively prioritize and execute tasks under pressure and time constrains.<br><b>Recommended Certifications</b><br>Microsoft Certified Systems Administrator: Security<br>GIAC Information Security Fundamentals & CCNP Security<br><b>Skills</b><br>Good command of English and Arabic languages<br>Good Communication, Negotiation and Time Management skills<br>Good Analytical and Problem-solving skills
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>Description</span><br><span></span><p>JOB PURPOSE<br> To deploy, operate and maintain the appropriate data security solutions and tools and implement necessary controls to protect the bank’s information systems against internal and external threats in alignment with the bank’s approved security architecture framework.</p><br><p>Description<br> 1.Monitor, implement and operate appropriate levels of Data security controls and systems according to enterprise Data security solutions on day-to-day basis, in order to keep business secured proactively against identified threats.<br> 2.Provide first-level support for all managed systems and platforms including: Content Filtering, Sandboxing and others, in order to maintain business operations according to approved service level agreement. <br> 3.Secure the access to corporate data and crown-jewels information through the operations of Data Loss Prevention (DLP), Secure Domain Name Services (DNS), Data Base (DB) Security, Internet based traffic content filtering, at all levels of the data security architecture in order to safeguard and limit access to key information system assets at all layers.<br> 4.Implement, Operate, and Maintain Date Security, Protection and Classification program technologies, in order to provide the required levels of assurance that CIB information Security Data security policies applied and enforced. <br> 5.Provide data security technical expertise for Project Management in order to enable bank’s Business Strategic Projects through maintaining a secure Software Development Life Cycle (SDLC) in the organization that complies with Business Strategic objectives, policies, procedures, rules and regulations.<br> 6.Perform analysis of data security needs and contribute to design, integration, and installation of hardware and software, to ensure effective security architecture and controls over enterprise applications. <br> 7.Ensure that data security current and new tools and technologies are deployed in line with architectural requirements, and the organization’s data loss prevention strategy and policies, in order to ensure effective controls according to business/compliance/regulation requirements.<br> 8.Employ data confidentiality, integrity and availability controls in order to mitigate the risk of disclosure or alteration of sensitive information.<br> 9.Provide technical expertise and guide the administration of data security tools that control and monitor information security, in order to keep business up and running seamless.<br> 10.Develop and maintain monthly Key Performance Indicators (KPIs), security reports and dashboards across various data security solutions, in order to provide business with the required visibility.<br> 11.Work with information systems owners and administrators to understand their data security needs and assist with implementing practices and procedures in alignment with CIB security policies.<br> 12.Support Security Operations Centre and Information Security in Identifying, developing, and implementing mechanisms to detect/prevent data security incidents/gaps in order to enhance compliance with and support of security standards and procedures in place.<br> 13.Respond to discovered security incidents by informing appropriate custodians, determining root cause, and identifying and executing remedial actions (if necessary) required to re-establish respective information system security.<br> 14.Define and enhance, appropriate levels of Data security controls and systems according to data security solutions on regular basis, in order to keep business secured proactively against known threats.<br> 15.Act as the technical lead in the development of responses to Request for Information (RFIs) and Request for Proposals (RFPs).<br> Policies, Processes and Procedures<br> 16.Follow all relevant department policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent manner.<br> Day-to-day Operations<br> 17.Follow the day-to-day operations related to own jobs in the IT Security, Control & Quality Assurance department to ensure continuity of work.<br> Compliance<br> 18.Comply with all relevant CBE regulations, banking laws, AML regulations and internal CIB policies and code of conduct in order to maintain CIB’s sound legal position and mitigate any potential risks.</p><br><br> <br> <span>Qualifications</span><br><span></span><p>Qualifications & Experience<br> Bachelor’s degree of Engineering, Computer Science or equivalent is must. <br> Engineer: Minimum of 3 – 5 years of experience in IT Security and related disciplines.<br> Should have an understanding of TCP/IP protocols, networking and firewall concepts. <br> Enterprise data security architecture and software are required.<br> Understanding of IT operations: help desk, end-point management and server management<br> Experience in configuring and implementing technical security solutions<br> Capability to effectively prioritize and execute tasks under pressure and time constrains. <br> Recommended Certifications<br> Microsoft Certified Systems Administrator: Security <br> GIAC Information Security Fundamentals & CCNP Security<br> Skills<br> Good command of English and Arabic languages<br> Good Communication, Negotiation and Time Management skills <br> Good Analytical and Problem-solving skills<br></p><br><br> </div>
<p>Execute operational implementation of strategic planning as directed by the Regional Security Director (MENA). Physically located in AOR ( Area of responsibility), the role would serve as a Business Unit asset in responding to all emerging security risks and incidents throughout the area of responsibility (Role will be responsible for theprotection of our people and Assets in AOR ( Area of responsibility)</p><p>The principal accountability of the Area Security Manager is driving the implementation and execution of security, crisis management, business continuity management strategies, plans and protocols, and best practices across the AOR ( Area of responsibility) businesses. The highlights of these accountabilities include,but are not limited to:</p><ul><li>In line with the broader security strategy and objectives, implement a security Plan to identify, assess, and mitigate risks to PepsiCo s associates, facilities, proprietary information, and brand/reputation.</li><li>Oversee and facilitate the ongoing strengthening of a sustainable, AOR ( Area of responsibility) Crisis Management and Business Continuity Planning and capability in the Area of Responsibility.</li><li>Through training and audit validate that the AOR ( Area of responsibility) Crisis Management and Business Continuity plans are current and functional.</li><li>Revise and maintain all security main domains (Physical Technical Procedural Investigational Executive Protection) within AOR ( Area of responsibility) .</li><li>Maintain strong working relationships with locations leads, and provide consultation to them.</li><li>Ensure that our engagement with other functions is an added value.</li><li>Excellent organizational skills to be able to prioritize responsibilities meet deadlines and work in a multi-task environment.</li><li>Plan and oversee periodic security self-assessments and bi-annual security risk assessments for premises in the area of responsibility in order to identify critical vulnerabilities and assist in closing these risks through cost effective, bestpractice security enhancements.</li><li>Maintain contacts with security partners at foreign embassies, other multi-national companies, government security agencies, and professional security organizations to benchmark and promote security best practices.</li><li>In close consultation with the Security Director (MENA), analyze security risks inherent in undertaking new business ventures and offer expertise-based risk mitigation measures.</li><li>Within AOR ( Area of responsibility) , develop and maintain working relationships with national and local security, emergency response, law enforcement, and regulatory authorities as well as with security managers of other large multinational companies.</li><li>Ensure compliance with PepsiCo AMESA Security Risk Management System and supporting standards and procedures.</li><li>Develop and deliver quarterly security awareness and training programs.</li><li>Advise and assist before, during, and after security incidents, including on-the-spot risk assessments and security advice to business travelers.</li><li>Implement a consultation plan to strengthen relationships with external 3rd parties.</li><li>Conduct and coordinate investigations to include counterfeit, extortion, contamination of our products, loss reduction, kidnapping, robberies, Speak Up, fraud, corruption, and security threats against the AOR interests and associates.</li><li>During strike operations or labor disputes provide training to security guards and employees in strike protocols.</li><li>Oversee security guard companies to leverage economies of scale and lower costs.</li><li>Implement and manage an effective KPI management system in accordance with Regional Security, and evaluate the service provided by the 3P Security providers on a monthly basis.</li></ul><p>Ensure the continued professional development of the AOR ( Area of responsibility) security team, including the identification of suitable individuals in longer-term succession planning</p><p><strong>Desired Candidate Profile</strong></p><p>A minimum of 10 years of working experience in law enforcement or military mid-management; 3 years ofcorporate security experience in the private sector (preferably industrial sectors) with accountabilities and keymeasures listed above Comprehensive substantive knowledge of best security practices, principles, and objectives Advanced, proven experience in security management Bachelor s degree (minimum) A working proficiency in written and spoken English. Ability to work among a team of peers. Ability to travel in the country and handle multiple locations. Ability to work in a challenging environment and to be connected 24/7. Excellent organizational skills to be able to prioritize responsibilities meet deadlines and work in a multi-task environment Ability to work on any other Task or Duties that could be assigned or delegated.</p>
<p>Administrate and fine tune System Security Platforms (MSG, HSM, Secure file transfer, MFA, IAM, XDR, EPP, PAM, etc.). Implement Security baseline for System Security assets. Develop and enforce security policies, procedures, and best practices to secure Systems Prepare and Execute System Security runbook in coordination with service continuity team. Prepare technical reports to show progress System Security activities to the IT System Security Manager. Regularly Remediate the System Security Solutions after vulnerability assessments, IT Security specialist & advisor. Assessment and penetration testing. Prepare reports and documentation regarding security incidents, risk assessments, and compliance audits.</p><p><strong>Desired Candidate Profile</strong></p><p>Bacheloru2019s degree in computer science, Information Technology, Cyber Security, Engineering, or equivalent industry experience. 3-5 experience in System Security Area. Basic Knowledge of Security standards such as ISO 27K, NIST , CIS benchmarks , PCIDSS.</p>
<p>Are you a visionary leader with an unparalleled understanding of security strategy and operations? Do you possess a profound background in militarization, ready to apply your expertise to safeguard critical assets and personnel? We are seeking an exceptional <strong>Director of Security</strong> to lead our security initiatives in <strong>Minya, Egypt</strong>, operating on-site to ensure robust protection and strategic oversight.</p><p><strong>Overview:</strong> This pivotal role demands a seasoned professional capable of establishing and maintaining a world-class security framework. Leveraging your background in the militarization of a retired army brigade, you will be instrumental in developing and implementing comprehensive security strategies that protect our interests, assets, and people. This is an extraordinary opportunity to shape the security landscape within a dynamic and critical environment.</p><p><strong>Responsibilities:</strong></p><ul><li><strong>Develop and implement</strong> cutting-edge security policies and procedures tailored to the unique operational context in Minya.</li><li><strong>Lead and mentor</strong> a dedicated security team, fostering a culture of vigilance, excellence, and continuous improvement.</li><li><strong>Conduct thorough risk assessments</strong> and develop proactive mitigation strategies to address potential threats.</li><li><strong>Oversee security operations</strong>, including physical security, access control, surveillance, and emergency response planning.</li><li><strong>Collaborate effectively</strong> with internal and external stakeholders, including legal and local authorities, to ensure compliance and seamless security integration.</li><li><strong>Manage security budgets</strong> and resource allocation efficiently to maximize protection and operational effectiveness.</li><li><strong>Provide expert guidance</strong> on all security-related matters, ensuring strategic alignment with organizational objectives.</li></ul><p><strong>Skills & Technologies:</strong> Success in this role hinges on your mastery of <strong>Security Management</strong>, advanced <strong>Risk Assessment</strong> techniques, and <strong>Crisis Management</strong> protocols. You will be adept in <strong>Strategic Planning</strong>, <strong>Team Leadership</strong>, and <strong>Security Operations</strong>, with a strong emphasis on <strong>Physical Security</strong>. Experience with <strong>Intelligence Analysis</strong>, <strong>Legal Compliance</strong>, and <strong>Emergency Response</strong> is crucial.</p><p><strong>Growth Opportunities:</strong> This position offers unparalleled opportunities for professional development and strategic impact. You will be at the forefront of shaping security paradigms, with pathways to influence broader organizational safety and risk management strategies. Your contributions will be highly valued, leading to significant career advancement within a challenging yet rewarding environment.</p><p><strong>Team & Culture:</strong> Join a dedicated and professional team committed to excellence and unwavering vigilance. Our culture promotes collaboration, empowerment, and continuous learning, where your expertise will be respected and your insights will drive critical decisions. We value resilience, integrity, and a proactive approach to security challenges.</p><p><strong>Impact:</strong> As the Director of Security, your impact will be profound. You will directly contribute to the safety and operational continuity of our organization, safeguarding our most valuable assets and ensuring peace of mind for our personnel. Your leadership will establish a benchmark for security excellence in the region.</p><p><strong>Requirements</strong></p><ul><li><strong>Exceptional Leadership:</strong> A minimum of <strong>5-10 years of progressive experience</strong> in security management, with a proven track record of leading and developing high-performing security teams.</li><li><strong>Strategic Security Expertise:</strong> Demonstrated mastery of <strong>Security Management</strong>, <strong>Risk Assessment</strong>, <strong>Crisis Management</strong>, and <strong>Strategic Planning</strong>.</li><li><strong>Operational Excellence:</strong> Proficient in <strong>Security Operations</strong>, <strong>Physical Security</strong>, and <strong>Emergency Response</strong>, with a strong understanding of implementation in complex environments.</li><li><strong>Analytical Acumen:</strong> Strong capabilities in <strong>Intelligence Analysis</strong> and <strong>Decision-making</strong> under pressure.</li><li><strong>Legal & Compliance:</strong> Solid understanding of <strong>Legal Compliance</strong> and regulatory frameworks pertaining to security.</li><li><strong>Communication & Collaboration:</strong> Excellent <strong>Communication</strong>, <strong>Cross-functional Collaboration</strong>, and <strong>Conflict Resolution</strong> skills.</li><li><strong>Military Background:</strong> A strong background in the militarization of a retired army brigade, bringing invaluable experience in <strong>Military Protocol</strong> and high-stakes security environments.</li><li><strong>Career Level:</strong> This is a <strong>Manager-level</strong> position, requiring a strategic mindset and the ability to drive significant initiatives.</li></ul>
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>About The Role This Senior Security Engineer role is a highly collaborative position designed for a security professional who can seamlessly bridge the gap between offensive exploitation and defensive engineering. Instead of sitting in a silo, you will be deeply embedded within the product, engineering, and infrastructure teams to champion security architecture from the ground up.</p><p>What You'll Do Work closely with the product and engineering teams to review new features and suggest new features that improve security. Drive S-SDLC in our cycles and review security acceptance criteria and threat modeling. Guide and train the team to cover security checks and security best practices. Perform pre-deployment and post-deployment security penetration tests. Plan and execute regular web, mobile, and cloud security assessments and pen tests. Work closely with the Infrastructure teams to identify security issues through red teaming activities. Define, implement, and monitor infrastructure security measures. Contribute to the security roadmap & backlog. Assess security tools and integrate tools as needed. Incident Response & Research. Follow new security news, trends, tools, and incidents and drive needed changes. Support in managing our Bug-bounty program and security channels. Conduct vulnerability research against company assets. Work on understanding and improving our security logging and monitoring solutions. Coordinate company-wide response to security incidents till remediation. Vulnerability management for production/staging environments. Actively mentor members of the security team.</p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><ul><li>Bachelor's degree in Computer Science, Software Engineering, or a related field (or equivalent work experience).</li><li>Minimum 5 years of experience performing application and/or infrastructure penetration testing experience above and beyond running automated tools.</li><li>Highly experienced in performing security code reviews; Python experience is a plus.</li><li>Solid understanding of cloud platforms (AWS, Azure, or GCP) and containerization technologies (Docker, Kubernetes), serverless / lambda as a plus.</li><li>Solid understanding of software development principles, software testing methodologies, and version control systems (e.g., Git).</li><li>Hands-on experience implementing security policies in various environments (servers, storage, networks, security, virtualization, systems monitoring, and management).</li><li>Strong communication skills and the ability to effectively articulate technical concepts to technical and non-technical stakeholders.</li><li>Solid understanding of networks and network security (experience in Fortinet is a plus).</li><li>Hands-on experience in managing SIEM solutions.</li><li>Knowledge in EDR, IDS, CSPM, CWPP.</li></ul><p></p></section>
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><b>JOB PURPOSE</b><p>Ensure the confidentiality, integrity, and availability of an organization's information systems and data and effective implementation of security measures within development processes through integrating security into the operational and development processes to support the organization in streamlining and enhancing the development processes In addition, work closely with cross-functional teams to integrate security practices into their workflows and ensure that security is considered throughout the software development lifecycle, collaborate with stakeholders, manage security initiatives, and provide guidance on secure coding practices. responsible for identifying and mitigating security risks, conducting security assessments, and ensuring compliance with relevant regulations and standards to help improve software reliability, security, and quality. </p>
<p><br></p><p>4. KEY ACCOUNTABILITIES </p>
<p>Description </p>
<p>1. Collaborate with cross-functional teams to integrate security practices into development processes and create seamless flow of work. </p>
<p>2. Provide guidance and support on secure coding practices, secure design principles, and security risk mitigation. </p>
<p>3. Develop and maintain security documentation and guidelines for Continuous Integration / Continuous Development CI/CD pipeline tools and processes. Additionally, Design and implement secure (CI/CD) pipelines for building, testing and deploying software, incorporating security testing tools such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST) and Software Composition Analysis (SCA) </p>
<p>4. Evaluate and recommend the implementation of security tools and technologies to enhance the security posture of the organization within the CI/CD pipeline. </p>
<p>5. Responsible for the security of the software development process, including automating scans, code verification, and developing security protocol to protect sensitive data and ensure proper prevention against cyber threats. </p>
<p>6. Review and enhance containers security measures within the bank IT environment (e.g. Kubernetes, OpenShift, etc) </p>
<p>7. Collaborate with both development and operations teams to create a seamless flow of work and maintain an agile workflow. </p>
<p>8. Ensure continuous integration and delivery (CI/CD) processes are followed, promoting the speedy release of high-quality software </p>
<p>9. Support the implementation of the key strategic business initiatives and projects through following the secure software development life cycle including specifying the confidentiality, integrity, and availability requirements, addressing security requirements throughout the development of new systems and performing proper risk assessment prior to releasing new systems to production. </p>
<p>10. Review new technologies and changes to existing technologies for in house developed applications to ensure proper information security requirements/controls and compliance with relevant security policies and compliance mandates. </p>
<p>11. Conduct the annual review and update of the area s processes, procedures and recommend updates to relevant policies with the adherence to the developed SLAs. </p>
<p>Policies, Processes and Procedures </p>
<p>12. Participate, develop and recommend improvements to policies, processes and procedures and manage their implementation to ensure all relevant procedural / legislative requirements are fulfilled. </p>
<p>Day-to-day management </p>
<p>13. Follow the day-to-day operations related to own jobs in the Information Security Management department to ensure continuity of work. </p>
<p>Compliance </p>
<p>14.<span> Ensure compliance with relevant laws, regulations, and industry standards (e.g., CBE, PCI-DSS, ISO 27001).<br> <br> </span> </p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"><b>QUALIFICATIONS, EXPERIENCE, & SKILLS</b></p><p>Qualifications & Experience </p> <p> Bachelor's degree in Computer Science, Information Security, or a related field. A master's degree is preferred. </p> <p> 3-6 years of proven experience in a similar security-focused role. (5-8 years for Sr. analyst) </p> <p> Proven experience as a DevSecOps Engineer or similar role, with strong background in software development lifecycle and security </p> <p> Strong knowledge of secure coding practices, secure design principles, and common security vulnerabilities. </p> <p> Familiarity with agile development methodologies and experience integrating security into agile processes. </p> <p> Knowledge of industry regulations and standards such as ISO 27001, NIST, OWASP, etc. </p> <p> Abroad understanding of security practices such as penetration testing, threat modelling, vulnerability management and static & dynamic application security testing </p> <p> Experience with CI/CD tools such as Gitlab CI/CD, version control systems, code repositories, etc. </p> <p> Experience with containerization and orchestration tools (e.g. Docker, Kubernetes, Helm, ArgoCD) </p> <p> Knowledge of scripting languages (e.g. Bash, Python, Go) </p> <p> Experience conducting security assessments, vulnerability testing, and risk assessments. </p> <p> Familiarity with security tools and technologies such as vulnerability scanners, code analysis tools, etc. </p> <p>Recommended Certification: </p> <p> CISSP </p> <p> CISM </p> <p> CSSLP </p> <p> GIAC Cloud Security Automation (GCSA) </p> <p> Certified DevSecOps Engineer (CDSOE) </p> <p> Certified DevSecOps Professional (CDP) </p> <p> DevSecOps Engineering (DSOE) </p> <p> Certified Ethical Hacker (CEH) </p> <p> Offensive Security Defense Analyst (OSDA) </p> <p>Skills </p> <p> Excellent communication and collaboration skills </p> <p> Strong problem-solving and analytical skills </p> <p> Proficient verbal and written English </p> <p> Ability to manage and prioritize tasks </p> <p> Knowledge of top-level cybersecurity subjects and issues </p> <p> Ability to research threats and draw up logical conclusions through well-thought-out, unbiased processes </p> <p> Ability to troubleshoot and solve problems </p> <p> Ability to learn new technologies quickly </p> <p> Ability to bring together data from diverse sources and articulate it into simple and concise information<br> <br> </p><p></p></section>
<br> <p> </p> 2. Job Purpose <p>The Information Security & Risk Manager is responsible for leading the organization s Information Security and Cyber Risk function. The role will design, implement, and maintain the cybersecurity program, manage enterprise information security risks, ensure compliance with applicable Saudi regulatory and industry requirements, and promote a strong security-aware culture across the organization.</p> <p>The role provides strategic and operational leadership across <strong>Information Security Governance, Risk & Compliance (GRC), Security Operations, Incident Response, Data Protection, and Security Awareness</strong>.</p> <p> </p> 3. Key Accountabilities & Deliverables <p>The role will be accountable for the development, implementation, and continuous improvement of:</p> <ul> <li>Information Security Strategy and Cybersecurity Roadmap</li> <li>Information Security policies, standards, procedures, and guidelines</li> <li>Information Security Management System (ISMS)</li> <li>Enterprise IT and Cybersecurity Risk Register</li> <li>Information Security Risk Assessment Reports</li> <li>Risk Treatment and Remediation Plans</li> <li>Security Compliance Reports, including ISO 27001 and applicable regulatory requirements</li> <li>Cybersecurity Control Framework and Control Effectiveness Reports</li> <li>Vulnerability Assessment and Penetration Testing (VAPT) Reports</li> <li>Cybersecurity Incident Reports and Root Cause Analysis (RCA)</li> <li>Security Monitoring and Threat Dashboards</li> <li>Cybersecurity KPI and KRI Dashboards</li> <li>Identity and Access Management (IAM) Policies, Models, and Access Matrices</li> <li>Data Classification and Data Protection Framework</li> <li>Internal and External Audit Reports and Evidence Repository</li> <li>Audit Findings and Remediation Tracking</li> <li>Business Continuity and Disaster Recovery (BCP/DR) Security Alignment</li> <li>Security Awareness and Training Programs and Reports</li> <li>Regulatory Assessments, submissions, and compliance evidence</li> </ul> <p> </p> 4. Key Responsibilities A. Information Security Strategy & Governance <ul> <li>Define, develop, and execute the organization s Information Security Strategy and cybersecurity roadmap.</li> <li>Own and continuously improve the Information Security Management System (ISMS).</li> <li>Develop and maintain information security policies, standards, procedures, and guidelines.</li> <li>Establish effective cybersecurity governance frameworks aligned with business objectives.</li> <li>Provide regular reporting on cybersecurity posture, risk exposure, compliance, and security program performance to the CTO and executive leadership.</li> <li>Establish and monitor security KPIs, KRIs, and performance metrics.</li> <li>Ensure information security requirements are incorporated into technology initiatives, projects, and business processes.</li> </ul><br><ul> <li>Support testing and continuous improvement of security-related recovery procedures.</li> </ul> <p> </p> 5. Qualifications & Experience Minimum Qualifications <ul> <li>Bachelor s degree in <strong>Information Technology, Computer Science, Cybersecurity, Information Security</strong>, or a related discipline.</li> <li> <strong>CISSP or CISM certification Mandatory.</strong> </li> <li>ISO/IEC 27001 Lead Implementer or Lead Auditor certification preferred.</li> <li>NCA-related cybersecurity accreditation or certification is preferred.</li> </ul> Minimum Experience <ul> <li> <strong>8 10 years of professional experience in Information Security / Cybersecurity.</strong> </li> <li>At least <strong>3 years of experience in a cybersecurity or information security management/leadership role.</strong> </li> <li>Proven experience managing enterprise cybersecurity programs and security teams.</li> <li>Proven experience in GRC, risk management, security operations, and incident response.</li> <li>Proven experience working with regulatory compliance, audits, and cybersecurity frameworks.</li> </ul> <p> </p> 6. Technical & Professional Skills <p>The successful candidate should demonstrate:</p> <ul> <li>Strong knowledge of cybersecurity frameworks, standards, and best practices.</li> <li>Deep understanding of <strong>NCA, PDPL, NDMO, ISO 27001</strong>, and applicable data protection requirements.</li> <li>Strong expertise in Governance, Risk, and Compliance (GRC).</li> <li>Experience with SOC operations and SIEM platforms such as <strong>Microsoft Sentinel, Splunk</strong>, or equivalent.</li> <li>Strong understanding of vulnerability management and penetration testing.</li> <li>Strong knowledge of Incident Response and Cybersecurity Incident Response Plans (CIRP).</li> <li>Strong understanding of IAM and access governance.</li> <li>Knowledge of data protection, data classification, and data governance.</li> <li>Strong understanding of secure architecture and security controls.</li> <li>Ability to develop and monitor cybersecurity KPIs and KRIs.</li> <li>Strong audit and regulatory assessment experience.</li> <li>Ability to assess and communicate cybersecurity risks in terms of business impact.</li> <li>Strong strategic thinking and high-level decision-making capability.</li> <li>Excellent leadership and people-management skills.</li> <li>Ability to manage cross-functional teams and stakeholders under pressure.</li> <li>Strong communication, presentation, and reporting skills.</li> <li> <strong>Bilingual proficiency in Arabic and English.</strong> </li> </ul> <p> </p> 7. Leadership Competencies <ul> <li>Strategic Thinking</li> <li>Cybersecurity Leadership</li> <li>Risk-Based Decision Making</li> <li>Stakeholder Management</li> <li>Executive Communication</li> <li>Team Leadership & Development</li> <li>Problem Solving</li> <li>Crisis and Incident Management</li> <li>Governance & Accountability</li> <li>Continuous Improvement</li> <li>Business Acumen</li> <li>Change Management</li> </ul> <p> </p> <p> </p> Special Requirements <ul> <li>Ability to work effectively in a fast-paced and dynamic environment.</li> <li>Ability to manage cybersecurity incidents and critical security situations.</li> <li>Willingness to participate in security incident response and escalation activities when required.</li> <li>Strong confidentiality and professional integrity.</li> <li>Ability to work collaboratively with executive leadership, IT, business functions, auditors, and regulatory stakeholders.</li> </ul><p><strong>Desired Candidate Profile</strong></p><p> </p> <p> </p> <p> </p>
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><br><p>1. Ensure proper security controls are enforced across the different systems based on the identified systems criticality. </p>
<p>2. Review and recommend updates to the bank s IT & Cyber security policy, relevant processes, procedures and guidelines. </p>
<p>3. Participate in the security gap and threat assessments post globally/locally identified security incidents/threats and ensure the effective implementation of action plans with the relevant stakeholders. </p>
<p>4. Support the implementation of the key strategic business initiatives and projects through following the secure software acquisition life cycle including specifying the confidentiality, integrity, and availability requirements, addressing security requirements throughout the acquisition of new systems and performing proper risk assessment prior to releasing new systems to production. </p>
<p>5. Review new technologies and changes to existing technologies for vendor acquired solutions to ensure proper information security requirements/controls and compliance with relevant security policies and compliance mandates. </p>
<p>6. Validate the security requirements to ensure the proper management of test data on development and test environments according to the set test data management strategy and in alignment with the developed security policies. </p>
<p>7. Develop and maintain threat modelling strategy and procedures for the purpose of optimizing the infrastructure and network security through identifying clear objectives and developing countermeasures to prevent or mitigate the impacts of cybersecurity attacks/threats on the environment. </p>
<p>8. Provide updates on the different Security KRIs, RAIs and RCSA and develop an action plan to mitigate those risks to be reported to the Security & Technology Risk Management Team for tracking. </p>
<p>9. Conduct the different security assessments for vendors and third Parties providing critical services and engagements that involve access to or sharing of CIB s information, as per the respective policies and guidelines. </p>
<p>10. Responsible for initial security risk assessment for any identified security risks across the organization and liaise with the security & technology risk management for final risk rating and reporting. </p>
<p>11. Conduct the annual review and update of the area s processes, procedures and recommend updates to relevant policies with the adherence to the developed SLAs. </p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph">*</p><p>Qualifications & Experience </p>
<p> Bachelor s degree of Engineering, Computer Science, Information Security or equivalent. </p>
<p> 3-5 (5-8 for the senior) years of work experience in Information Security, IT Security Analysis or Risk Analysis </p>
<p> Excellent Knowledge of ISO 27001, PCI standards, NIST frameworks, OWASP and SWIFT CSP </p>
<p> Excellent knowledge about ISMS implementation </p>
<p> Risk Management & Security Risk assessments. </p>
<p> Must have technical background in areas like software development, security architecture, security platforms and IT tools/platforms commonly used in a modern software architecture, administration and management along with risk background </p>
<p> </p>
<p>Recommended Certifications: </p>
<p>o ISO 27001:2013 Implementer/Lead Implementer </p>
<p>o CISSP </p>
<p>o CRISC </p>
<p>o CISM </p>
<p>o GIAC Certifications </p>
<p>o CEH </p>
<p>o Security+ </p>
<p>Skills </p>
<p> Time Management Skills, Analytical skills, and Strong presentation skills </p>
<p> Teamwork Spirit </p>
<p> Strong Communication skills </p><p></p></section>
<p> <u>Objective: (summary about the position)</u> </p> <p> </p> <p>Seeking a highly experienced <strong>Security Lead Engineer</strong> to lead the design, implementation, and continuous improvement of cybersecurity measures across our hybrid environment. This role requires overseeing infrastructure, application, and cloud security; managing threat detection and response systems; guiding the security posture of internally developed software; and ensuring regulatory compliance through GRC frameworks. The ideal candidate brings technical depth, leadership capabilities, and a proactive mindset to protect our digital assets and business operations.</p> <p> </p> <p> <u>Responsibilities: </u> </p> <p> </p> <p> <strong>1. Security Architecture & Strategy</strong> </p> <ul> <li>Design, integrate, and maintain end-to-end security architecture for on-premises and cloud environments.</li> <li>Ensure secure network topology including segmentation, access control, and VPN tunnels.</li> <li>Lead development and enforcement of security policies, procedures, and best practices.</li> <li>Work closely with developers and IT architects to embed security into application and infrastructure design.</li> </ul> <p> <strong>2. SOC, SIEM, and Threat Management</strong> </p> <ul> <li>Oversee the operation and tuning of <strong>Security Operations Center (SOC)</strong> including <strong>SIEM</strong> platforms.</li> <li>Manage endpoint protection through <strong>EDR and threat-hunting solutions</strong>.</li> <li>Manage and enhance email security systems to protect against phishing, malware, and spam, ensuring compliance with organizational security policies.</li> <li>Lead incident response efforts and develop threat prevention strategies.</li> </ul> <p> <strong>3. Application and Cloud Security</strong> </p> <ul> <li>Supervise vulnerability scanning and penetration testing for internally developed applications.</li> <li>Lead <strong>WAF</strong> deployment and optimization to protect business-critical web applications.</li> <li>Implement security best practices and policy enforcement across multi-cloud environments</li> </ul> <p> </p> <p> <strong>4. Governance, Risk & Compliance (GRC)</strong> </p> <ul> <li>Drive cybersecurity-related compliance programs (e.g., <strong>SOC 2 Type 2</strong>, ISO 27001).</li> <li>Lead cross-functional GRC initiatives and support internal/external audits.</li> <li>Manage security risk assessments and recommend mitigation strategies.</li> </ul> <p> <strong>5. Documentation & Collaboration</strong> </p> <ul> <li>Maintain detailed documentation for security controls, policies, systems, and incidents.</li> <li>Plan and conduct quarterly security awareness sessions to educate staff on emerging cyber threats, security best practices, and the organization's security policies.</li> <li>Work collaboratively with software engineers, network teams, DevOps, and business units.</li> </ul><p><strong>Desired Candidate Profile</strong></p><p> <u>Min requirements: </u> </p> <p>1. Education: Bachelor s degree in engineering, Computer Science, Information Security or a related field.</p> <p> </p> <p>2. Experience:</p> <p> 7 years in cybersecurity and information security roles.</p> <p> 5+ years of hands-on experience in security architecture and threat management.</p> <p> </p> <p>3. Qualifications necessary for the vacancy.</p> <p> Proven expertise in:</p> <p>o Security architecture for hybrid cloud/on-prem setups.</p> <p>o Firewalls, WAF, EDR, SIEM, UTM, IPS, Proxy, and DDoS mitigation.</p> <p>o Network security protocols, subnetting, VPNs, and access control models.</p> <p> </p> <p>4. Set of skills necessary for the vacancy.</p> <p> Problem-Solving and Analytical Skills:</p> <p>o Ability to diagnose and resolve complex technical issues efficiently.</p> <p>o Skilled in designing and implementing scalable and secure IT solutions.</p> <p> Organizational Skills:</p> <p>o Strong ability to manage multiple projects and prioritize tasks effectively.</p> <p>o Commitment to meeting deadlines and maintaining high-quality standards.</p> <p> Communication and Teamwork:</p> <p>o Excellent written and verbal communication skills.</p> <p>o Ability to collaborate effectively with team members and stakeholders.</p> <p> </p> <p>5. Certifications (Desirable):</p> <p> CISSP, CISM, CEH, OSCP, CCSP</p> <p> Cloud security certifications (e.g., AWS Security Specialty, Microsoft SC-100/SC-200)</p> <p> IT governance certifications (e.g., ISO 27001 LA, CISA)</p>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>Objective: (summary about the position) Seeking a highly experienced Security Lead Engineer to lead the design, implementation, and continuous improvement of cybersecurity measures across our hybrid environment.<br> This role requires overseeing infrastructure, application, and cloud security; managing threat detection and response systems; guiding the security posture of internally developed software; and ensuring regulatory compliance through GRC frameworks.<br> The ideal candidate brings technical depth, leadership capabilities, and a proactive mindset to protect our digital assets and business operations.<br> Responsibilities: 1.<br> Security Architecture & Strategy Design, integrate, and maintain end-to-end security architecture for on-premises and cloud environments.<br> Ensure secure network topology including segmentation, access control, and VPN tunnels.<br> Lead development and enforcement of security policies, procedures, and best practices.<br> Work closely with developers and IT architects to embed security into application and infrastructure design.<br> 2. SOC, SIEM, and Threat Management Oversee the operation and tuning of Security Operations Center (SOC) including SIEM platforms.<br> Manage endpoint protection through EDR and threat-hunting solutions .<br> Manage and enhance email security systems to protect against phishing, malware, and spam, ensuring compliance with organizational security policies.<br> Lead incident response efforts and develop threat prevention strategies.<br> 3. Application and Cloud Security Supervise vulnerability scanning and penetration testing for internally developed applications.<br> Lead WAF deployment and optimization to protect business-critical web applications.<br> Implement security best practices and policy enforcement across multi-cloud environments 4.<br> Governance, Risk & Compliance (GRC) Drive cybersecurity-related compliance programs (e.<br>g., SOC 2 Type 2 , ISO 27001).<br> Lead cross-functional GRC initiatives and support internal/external audits.<br> Manage security risk assessments and recommend mitigation strategies.<br> 5. Documentation & Collaboration Maintain detailed documentation for security controls, policies, systems, and incidents.<br> Plan and conduct quarterly security awareness sessions to educate staff on emerging cyber threats, security best practices, and the organization's security policies.<br> Work collaboratively with software engineers, network teams, DevOps, and business units.<br> Min requirements: 1.<br> Education: Bachelor’s degree in engineering, Computer Science, Information Security or a related field.<br> 2. Experience: · 7 years in cybersecurity and information security roles.<br> · 5+ years of hands-on experience in security architecture and threat management.<br> 3. Qualifications necessary for the vacancy.<br> · Proven expertise in: o Security architecture for hybrid cloud/on-prem setups.<br> o Firewalls, WAF, EDR, SIEM, UTM, IPS, Proxy, and DDoS mitigation.<br> o Network security protocols, subnetting, VPNs, and access control models.<br> 4. Set of skills necessary for the vacancy.<br> · Problem-Solving and Analytical Skills: o Ability to diagnose and resolve complex technical issues efficiently.<br> o Skilled in designing and implementing scalable and secure IT solutions.<br> · Organizational Skills: o Strong ability to manage multiple projects and prioritize tasks effectively.<br> o Commitment to meeting deadlines and maintaining high-quality standards.<br> · Communication and Teamwork: o Excellent written and verbal communication skills.<br> o Ability to collaborate effectively with team members and stakeholders.<br> 5. Certifications (Desirable): · CISSP, CISM, CEH, OSCP, CCSP · Cloud security certifications (e.<br>g., AWS Security Specialty, Microsoft SC-100/SC-200) · IT governance certifications (e.<br>g., ISO 27001 LA, CISA)</span> </div>
Establish and maintain the organization's Cyber Defense methodology in line with security regulations and requirements. Obtain senior management endorsement for security policies, standards, and procedures by clearly articulating their benefits. Investigate cybersecurity incidents and violations, reporting findings and recommendations to the CISO. Respond rapidly and effectively to cybersecurity incidents in line with incident management processes. Prepare periodic performance reports based on analysis and correlation of security events. Oversee projects and deployments of security tools to ensure an effective security posture. Lead the Security Operations Center (SOC) team, including shift planning and operational tool implementation. Manage the Cyber Defense Centre and its resources to ensure operational effectiveness. Maintain the security of corporate information against all internal and external threats. Provide security input into the organization's strategic planning process and enterprise-level decisions. Implement and maintain the organization's information security program in alignment with business objectives. Raise major cybersecurity incidents directly to the CISO. <br><br>Requirements<br><br>Bachelor's degree in Computer Science, Information Systems, or related field. 12+ years of experience in Cyber Defense. Proven experience managing SOC teams and cyber defense operations. Strong knowledge of incident response, threat detection, and security monitoring. Hands-on expertise with SIEM, endpoint protection, and enterprise security tools. Relevant certifications (CISSP, CISM, CISA, or equivalent) preferred. Strong analytical, leadership, and communication skills.
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p><span style="font-size: 11px;"><b>What you ll do</b></span></p><p>About the Role We are looking for a Cyber Security Assurance Tech Lead to join our team and play a key role in delivering and supporting penetration testing and security assurance activities across Vodafone s digital environment. This role is responsible for performing penetration testing engagements, supporting security assessment activities, conducting vulnerability analysis, and ensuring the security posture of web applications, mobile platforms, networks, and cloud environments. As a Cyber Security Assurance Tech Lead, you will work closely with technical teams, vendors, and business stakeholders to identify, assess, and remediate security vulnerabilities while ensuring compliance with Vodafone s cyber security policies, standards, and best practices.</p><p><b>Who you are</b></p><p>Job Responsibilities : Perform penetration testing activities on web applications, mobile applications, networks, APIs, and cloud environments to identify security vulnerabilities and weaknesses. Support penetration testing activities conducted internally or through third-party vendors, ensuring proper execution and reporting. Conduct vulnerability assessments and security analysis, providing remediation recommendations to improve the overall security posture. Validate secure implementation and acceptance of new technologies, systems, and infrastructure in alignment with Vodafone security policies and standards. Perform regular security assurance activities on existing applications and environments to ensure continuous compliance and protection against emerging threats. Participate in security risk assessments for new projects and initiatives, ensuring security risks are identified and mitigated during early project phases. Collaborate with technical teams and business stakeholders to track and remediate penetration testing findings in a timely manner. Review and validate penetration testing reports, ensuring findings are properly documented with clear remediation guidance. Stay up to date with emerging cyber threats, vulnerabilities, attack techniques, and industry best practices to continuously improve penetration testing and security assurance capabilities.</p><p><b>Not a perfect fit?</b></p><p>Worried that you don t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you re excited about this role but your experience doesn t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.</p><p>What's in it for you</p><p>Core competencies, knowledge, and experience Strong knowledge of security frameworks and methodologies such as MITRE ATT&CK, NIST, OWASP, and CIS Controls. Hands-on understanding of penetration testing methodologies for web, mobile, network, API, and cloud environments. Familiarity with hardening and secure configuration practices for servers, databases, operating systems, and applications. Experience in vulnerability assessment, risk analysis, and providing security recommendations aligned with business requirements. Ability to work collaboratively with cross-functional teams to identify, prioritize, and remediate security vulnerabilities. Strong analytical, troubleshooting, and problem-solving skills with the ability to communicate technical findings to both technical and non-technical stakeholders. Relevant certifications are considered a plus (OSCP, eWPTX, eCPPT, CEH, PNPT, or similar).</p><p>Key activities Follow internal delivery and governance processes to execute cyber security assurance and penetration testing activities in alignment with global and local security policies. Support the delivery of cyber security projects and assessments within agreed timelines and scope. Ensure all security assessment streams are progressing effectively and meeting their defined objectives. Prepare and issue reports and dashboards related to penetration testing and security assurance activities to Cyber Security and Technology Management. Coordinate and maintain effective communication with internal teams and external vendors involved in penetration testing and security assurance activities. Ensure security assessment activities and vendor deliverables are completed on time and according to required quality standards.</p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><ul><li>Strong knowledge of security frameworks and methodologies such as MITRE ATT&CK, NIST, OWASP, and CIS Controls.</li><li>Hands-on understanding of penetration testing methodologies for web, mobile, network, API, and cloud environments.</li><li>Familiarity with hardening and secure configuration practices for servers, databases, operating systems, and applications.</li><li>Experience in vulnerability assessment, risk analysis, and providing security recommendations aligned with business requirements.</li><li>Ability to work collaboratively with cross-functional teams to identify, prioritize, and remediate security vulnerabilities.</li><li>Strong analytical, troubleshooting, and problem-solving skills with the ability to communicate technical findings to both technical and non-technical stakeholders.</li><li>Relevant certifications are considered a plus (OSCP, eWPTX, eCPPT, CEH, PNPT, or similar).</li></ul><p></p></section>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>Valleysoft | Center of Excellence, based in Riyadh, is a premier IT services provider partnering with global technology leaders like SAP to deliver innovative solutions worldwide.<br> We are currently seeking a dedicated SAP Security Specialist (Band 6B) to join our dynamic team.<br> As a SAP Security Specialist, you will be responsible for assisting in implementing and maintaining SAP security frameworks that safeguard our clients' systems and data.<br> You will work closely with senior consultants to ensure proper user access management, role design, and compliance with security policies.<br> Responsibilities Assist in configuring and maintaining SAP security roles and authorizations.<br> Support user administration activities including provisioning and deprovisioning.<br> Help monitor SAP systems for security compliance and support remediation efforts.<br> Collaborate with SAP teams to implement security policies and procedures.<br> Participate in security audits and support documentation efforts.<br> Coordinate with other IT teams to address security incidents and vulnerabilities.<br> Stay updated on SAP security best practices and tools.<br> Private Health Insurance Training & Development Bachelor's degree in Computer Science, Information Technology, or related field.<br> 3-5 years of experience in SAP security or related roles.<br> Knowledge of SAP security concepts including user management, role design, and authorization objects.<br> Familiarity with SAP GRC and other security tools is a plus.<br> Good analytical and problem-solving skills.<br> Strong communication and teamwork abilities.<br> Ability to follow established security protocols and standards.<br> Saudi Arabian nationality is required.<br></span> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>JOB DETAILS: Position Title: Security Engineer Reports to: Information Security and Risk Manager Business Line/ Department: Information Security 3.<br> JOB PURPOSE: The Job Holder is Responsible to.<br> Designs, implements, and maintains cybersecurity controls and technologies across the IT environment, ensuring technical security measures are robust, current, and aligned with NCA and internal security policies.<br> 4. Job Deliverables - Accountability Description Deliverables Security architecture designs & system diagrams (network, IAM, security controls) .<br> Risk assessment & vulnerability reports (risk register, threat analysis).<br> Security monitoring dashboards & SIEM reports (threat detection, events, alerts) .<br> Incident response artifacts (logs, RCA reports, response playbooks).<br> Security configuration & hardening outputs (policies, access controls, system configs) .<br> Compliance & audit documentation (control evidence, regulatory alignment.<br> Description Security Control Implementation • Design and implement cybersecurity controls: firewalls, EDR, DLP, PAM, email security, and WAF.<br> • Harden infrastructure, endpoints, and applications in line with security baselines.<br> • Manage vulnerability scanning and coordinate remediation with IT teams.<br> Identity & Access Management • Administer Identity and Access Management (IAM) controls including Privileged Access Management (PAM).<br> • Manage MFA, Conditional Access, and Zero Trust access policies.<br> • Conduct access reviews and enforce least privilege principles.<br> 6. QUALIFICATIONS, EXPERIENCE : Minimum Qualification Bachelor’s degree in computer science.<br> Certified in CompTIA Security+ / CySA+.<br> Microsoft SC-300 or SC-100.<br> CEH preferred.<br> Minimum Experience Minimum Experience of 4–6 years in cybersecurity engineering or architecture.<br> Other Requirement (Skills Set) Endpoint security: Microsoft Defender, Kaspersky Network security: Fortinet firewalls.<br> Identity: Azure AD, PAM tools (CyberArk/Beyond Trust).<br> Vulnerability management: Qualys, Tenable, or equivalent.<br> NCA ECC and ISO 27001 technical controls.<br></span> </div>
<p>JOB DETAILS:</p><p>Position Title: Security Engineer</p><p>Reports to: Information Security and Risk Manager</p><p>Business Line/ Department: Information Security</p><p>3. JOB PURPOSE:</p><p>The Job Holder is Responsible to. Designs, implements, and maintains cybersecurity controls and technologies across the IT environment, ensuring technical security measures are robust, current, and aligned with NCA and internal security policies.</p><p>4. Job Deliverables - Accountability Description Deliverables</p><ul><li>Security architecture designs & system diagrams (network, IAM, security controls) .</li><li>Risk assessment & vulnerability reports (risk register, threat analysis).</li><li>Security monitoring dashboards & SIEM reports (threat detection, events, alerts) .</li><li>Incident response artifacts (logs, RCA reports, response playbooks).</li><li>Security configuration & hardening outputs (policies, access controls, system configs) .</li><li>Compliance & audit documentation (control evidence, regulatory alignment.</li></ul><p>Description</p><p>Security Control Implementation</p><ul><li>Design and implement cybersecurity controls: firewalls, EDR, DLP, PAM, email security, and WAF.</li><li>Harden infrastructure, endpoints, and applications in line with security baselines.</li><li>Manage vulnerability scanning and coordinate remediation with IT teams.</li></ul><p>Identity & Access Management</p><ul><li>Administer Identity and Access Management (IAM) controls including Privileged Access Management (PAM).</li><li>Manage MFA, Conditional Access, and Zero Trust access policies.</li><li>Conduct access reviews and enforce least privilege principles.</li></ul><p><strong>Desired Candidate Profile</strong></p><p>6. QUALIFICATIONS, EXPERIENCE :</p><p>Minimum Qualification Bachelor s degree in computer science. Certified in CompTIA Security+ / CySA+. Microsoft SC-300 or SC-100. CEH preferred.</p><p>Minimum Experience Minimum Experience of 4 6 years in cybersecurity engineering or architecture.</p><p>Other Requirement (Skills Set)</p><ul><li>Endpoint security: Microsoft Defender, Kaspersky</li><li>Network security: Fortinet firewalls.</li><li>Identity: Azure AD, PAM tools (CyberArk/Beyond Trust).</li><li>Vulnerability management: Qualys, Tenable, or equivalent.</li><li>NCA ECC and ISO 27001 technical controls.</li></ul>