Search by job, company or skills

Cybersecurity Specialist / Expert

  • Posted 9 hours ago
  • Be among the first 10 applicants

Job Description

Cybersecurity Specialist / Expert

Job Description

About the Role

We are looking for a seasoned Cybersecurity Specialist to lead the protection of our systems, data, and infrastructure, and to drive our compliance with the cybersecurity regulations of the Kingdom of Saudi Arabia. In this hands-on expert role you will own the full cybersecurity lifecycle — implementing and testing the National Cybersecurity Authority (NCA) controls across the organization, uncovering and closing security vulnerabilities before they can be exploited, conducting security testing of critical systems, and operating the cybersecurity platforms that defend our environment around the clock. You will be the organization's reference point for cybersecurity: advising leadership on risk, guiding IT and application teams on secure design and remediation, representing the organization before regulators and auditors, and building a security-first culture across the business.

Key Responsibilities

•     Lead the implementation of the NCA regulatory frameworks — the Essential Cybersecurity Controls (ECC) and related control sets (CSCC for critical systems, CCC for cloud, DCC for data, TCC for telework, OTCC for operational technology) — across all organizational domains.

•     Assess compliance with NCA controls: perform gap analyses, define remediation roadmaps, implement corrective actions, and test/validate control effectiveness on an ongoing basis.

•     Prepare and maintain the evidence required for NCA self-assessments, regulator reporting, and internal and external cybersecurity audits, and act as the technical counterpart during those engagements.

•     Run the vulnerability management program end to end: scheduled scanning, risk-based prioritization, coordinating and verifying remediation with system owners, and closing findings within defined SLAs.

•     Conduct security testing of systems and applications — penetration tests, configuration reviews, and secure-baseline (hardening) assessments — before go-live and periodically in production.

•     Operate and tune cybersecurity systems and platforms: SIEM, EDR/XDR, next-generation firewalls, IPS/IDS, WAF, email and web security, NAC, and data loss prevention.

•     Monitor, detect, and respond to cybersecurity incidents: triage alerts, contain and eradicate threats, perform root-cause analysis and forensics, and produce post-incident reports with lessons learned.

•     Define and maintain cybersecurity policies, standards, and procedures aligned with NCA requirements and international best practices (ISO/IEC 27001, NIST CSF, CIS).

•     Perform cybersecurity risk assessments for projects, systems, and third parties, and embed security requirements into procurement, development, and change management.

•     Review and govern identity and access management: privileged access (PAM), MFA enforcement, periodic access recertification, and least-privilege design.

•     Deliver cybersecurity awareness activities and phishing simulations, and raise the security maturity of technical teams through guidance and training.

•     Track the threat landscape (threat intelligence, CVE advisories, NCA alerts) and proactively drive protective measures before threats materialize.

Required Qualifications

•     7+ years of hands-on cybersecurity experience, including a senior/expert role in an enterprise or government environment.

•     Deep, demonstrable knowledge of the Saudi National Cybersecurity Authority (NCA) frameworks — ECC as a minimum, with CSCC/CCC/DCC exposure — including a proven track record of materially contributing to their implementation and testing in a real organization.

•     Strong practical expertise in identifying, analyzing, and closing security vulnerabilities across operating systems, networks, databases, and applications.

•     Proven experience conducting security testing of systems: penetration testing, vulnerability assessment, and secure configuration review.

•     Strong hands-on experience operating cybersecurity systems: SIEM, EDR/XDR, firewalls, IPS/IDS, WAF, email security, and vulnerability management platforms.

•     Solid incident response capability: detection, containment, eradication, recovery, and reporting.

•     Working knowledge of ISO/IEC 27001 and international standards (NIST, CIS) and how they map to NCA controls.

•     Ability to produce high-quality technical reports and compliance documentation in Arabic and English.

•     Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent proven experience).

Preferred / Nice-to-Have Qualifications

•     Professional certifications: CISSP, CISM, CEH, OSCP, GIAC (GSEC/GPEN/GCIH), CompTIA Security+, or SABSA; ISO/IEC 27001 Lead Implementer/Auditor is a strong plus.

•     Direct experience preparing organizations for NCA compliance reviews or working with sector regulators (e.g., SAMA CSF, CST) in the Kingdom.

•     Experience securing cloud environments (Azure, AWS, OCI) and hybrid architectures, including cloud-native security services.

•     Scripting and automation for security tasks (PowerShell, Python, Bash) and familiarity with security orchestration (SOAR).

•     Knowledge of secure software development practices (DevSecOps, OWASP SAMM) and application security testing tools (SAST/DAST).

•     Experience with data protection technologies: encryption, PKI/certificate management, and database security.

•     Exposure to operational technology (OT/ICS) security and to business continuity / disaster recovery planning.

Technical Skills Summary

Area

Skill

Expected Level

Regulatory Compliance

NCA Essential Cybersecurity Controls (ECC) implementation

Expert

Regulatory Compliance

NCA CSCC / CCC / DCC / TCC / OTCC control frameworks

Expert

Regulatory Compliance

Compliance assessment, gap analysis, and audit support

Expert

Vulnerability Management

Vulnerability scanning, prioritization, and remediation

Expert

Vulnerability Management

Hardening and secure configuration baselines (CIS)

Advanced

Security Testing

Penetration testing and security assessment of systems

Expert

Security Testing

Web/application security testing (OWASP)

Advanced

Security Operations

SIEM operation and use-case tuning (Splunk / QRadar / Sentinel)

Advanced

Security Operations

EDR / XDR platforms and endpoint protection

Expert

Security Operations

Incident response, digital forensics, and threat hunting

Advanced

Network Security

NGFW, IPS/IDS, WAF, NAC, email and web security gateways

Expert

Identity & Access

IAM / PAM, MFA, and least-privilege access governance

Advanced

Governance & Risk

Cybersecurity policies, risk assessment, and awareness

Advanced

Governance & Risk

ISO/IEC 27001 and international best practices

Advanced

Soft Skills

•     Strong analytical and investigative mindset, with the discipline to trace an alert or a finding to its root cause.

•     Clear written and verbal communication in Arabic and English; able to brief executives, regulators, and auditors as confidently as technical teams.

•     High integrity, confidentiality, and sound judgment when handling sensitive information and incidents.

•     Ownership mindset — drives findings from discovery through verified closure, and works to prevent recurrence.

•     Calm and structured under pressure, especially during live security incidents.

•     Collaborative influence: builds security into projects by working with, not against, IT and business teams.

•     Continuous learner who keeps pace with the evolving threat landscape and regulatory requirements.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 151784159

Beware of Scammers

We don’t charge money for job offers