JD:
- +4 years of experience in GRC rules
- Saudi National.
- Bachelor's degree in computer science, Information systems or any relevant field.
- Strong technical background in IT Security, Information Security and Risk Management
- Security certifications desirable (SANS certifications, ISACA certifications.
CISSP, ISO27001 LI/LA, Security+)
- Good knowledge in cybersecurity field.
- Good technical background.
- Strong writing and verbal communications skills.
Responsibility:
- Extensive hands-on experience on conducting GRC services and perform job duties with highest quality and meetings client's expectation.
- Determine security requirements by evaluating business environment of the client and their network architecture and design.
- Perform hands-on gap assessments and security assessments to identify and track security issues and gaps.
- Strong technical backgrounds and essential knowledge in technical and security controls such as (Firewall, Endpoint security, DLP, APT solutions, Encryption solutions, SIEM).
- Design, build and maintain the security architecture of the client's systems and networks against best practices such as SABSA. Also, improve detection and identification of gaps, risks, threats and audit the network architecture holistically.
- Build Risk Management framework and conduct risk assessment activities on technology, process, and human level.
- Perform compliance and audit activities against local and international standards such as but not limited to (NCA, ISO 27001, NIST, SAMA-CSF).
- Develop Cybersecurity strategies and roadmaps for the clients.
- Develop best practices, standards, and methodologies to assist in the assessment, implementation and execution of Data Governance and Data protection.