Information Security and Risk Manager
Indexed description
- Job Details
Department: Technology Services / IT
Reports To: Information Security / CTO
Employment Type: Permanent
Location: Maadi, Degla - On-site
Grade: As per organizational structure
Direct Reports: As per approved organizational structure
- Job Purpose
The role provides strategic and operational leadership across Information Security Governance, Risk & Compliance (GRC), Security Operations, Incident Response, Data Protection, and Security Awareness.
- Key Accountabilities & Deliverables
- Information Security Strategy and Cybersecurity Roadmap
- Information Security policies, standards, procedures, and guidelines
- Information Security Management System (ISMS)
- Enterprise IT and Cybersecurity Risk Register
- Information Security Risk Assessment Reports
- Risk Treatment and Remediation Plans
- Security Compliance Reports, including ISO 27001 and applicable regulatory requirements
- Cybersecurity Control Framework and Control Effectiveness Reports
- Vulnerability Assessment and Penetration Testing (VAPT) Reports
- Cybersecurity Incident Reports and Root Cause Analysis (RCA)
- Security Monitoring and Threat Dashboards
- Cybersecurity KPI and KRI Dashboards
- Identity and Access Management (IAM) Policies, Models, and Access Matrices
- Data Classification and Data Protection Framework
- Internal and External Audit Reports and Evidence Repository
- Audit Findings and Remediation Tracking
- Business Continuity and Disaster Recovery (BCP/DR) Security Alignment
- Security Awareness and Training Programs and Reports
- Regulatory Assessments, submissions, and compliance evidence
- Key Responsibilities
- Information Security Strategy & Governance
- Define, develop, and execute the organization's Information Security Strategy and cybersecurity roadmap
- Own and continuously improve the Information Security Management System (ISMS)
- Develop and maintain information security policies, standards, procedures, and guidelines
- Establish effective cybersecurity governance frameworks aligned with business objectives
- Provide regular reporting on cybersecurity posture, risk exposure, compliance, and security program performance to the CTO and executive leadership
- Establish and monitor security KPIs, KRIs, and performance metrics
- Ensure information security requirements are incorporated into technology initiatives, projects, and business processes
- Lead regular information security and cybersecurity risk assessments across the organization
- Own and maintain the enterprise IT and cybersecurity risk register
- Identify, assess, prioritize, and communicate information security risks
- Develop and manage risk treatment plans and ensure remediation activities are tracked through to closure
- Work closely with business units, IT, and other stakeholders to establish appropriate risk mitigation strategies
- Translate technical cybersecurity risks into business impact and communicate them effectively to senior management
- Monitor the organization's overall cyber risk profile and provide recommendations for risk reduction
- Oversee Security Operations Centre (SOC) activities, including SOC Analysts and Security Engineers
- Ensure effective security monitoring, threat detection, investigation, and response capabilities
- Oversee SIEM operations and security monitoring platforms such as Microsoft Sentinel, Splunk, or equivalent technologies
- Establish and monitor security incident management processes
- Review security alerts, incidents, trends, and threat intelligence
- Ensure appropriate escalation and response mechanisms are in place for critical security events
- Monitor and improve the effectiveness of security controls and operational processes
- Lead the organization's cybersecurity incident response capability
- Ensure effective detection, containment, eradication, recovery, and post-incident activities
- Develop, maintain, and continuously improve the Cybersecurity Incident Response Plan (CIRP)
- Conduct regular incident response exercises and simulations
- Lead investigations into significant security incidents and ensure Root Cause Analysis (RCA) is completed
- Track corrective and preventive actions resulting from security incidents
- Ensure lessons learned are incorporated into security controls and processes
- Lead Information Security Governance, Risk, and Compliance (GRC) activities
- Ensure compliance with applicable regulatory and industry requirements, including:
- National Cybersecurity Authority (NCA) requirements
- Saudi Personal Data Protection Law (PDPL)
- National Data Management Office (NDMO) requirements, where applicable
- ISO/IEC 27001
- Other applicable cybersecurity and data protection regulations
- Coordinate internal and external security audits and assessments
- Manage audit evidence collection and maintain an organized security evidence repository
- Track audit findings, remediation plans, and closure status
- Prepare management and regulatory compliance reports
- Support regulatory assessments, reviews, and submissions as required
- Establish and maintain data protection and information classification frameworks
- Ensure appropriate security controls are implemented for sensitive and personal data
- Work with relevant stakeholders to support compliance with PDPL and applicable data protection requirements
- Establish appropriate data access, handling, retention, and protection controls
- Support privacy and data protection risk assessments where required
- Oversee vulnerability management activities across IT environments
- Coordinate Vulnerability Assessments and Penetration Testing (VAPT)
- Review vulnerability and penetration testing reports
- Ensure security vulnerabilities are appropriately prioritized based on business risk
- Track remediation activities and validate closure of critical and high-risk vulnerabilities
- Ensure security testing is incorporated into relevant technology projects and systems
- Establish and maintain IAM policies, standards, and access control frameworks
- Ensure appropriate access governance and segregation of duties
- Review privileged access and high-risk accounts
- Support periodic user access reviews and access recertification
- Ensure access controls align with business requirements and security policies
- Develop and implement an organization-wide security awareness program
- Lead cybersecurity awareness campaigns and security training
- Implement phishing simulation and social engineering awareness programs
- Monitor employee security awareness performance and identify improvement areas
- Promote a strong cybersecurity culture across all business functions
- Ensure cybersecurity requirements are incorporated into Business Continuity and Disaster Recovery plans
- Participate in BCP/DR risk assessments and exercises
- Ensure critical systems have appropriate security, recovery, and resilience controls
- Support testing and continuous improvement of security-related recovery procedures
- Qualifications & Experience
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Security, or a related discipline
- CISSP or CISM certification - Mandatory
- ISO/IEC 27001 Lead Implementer or Lead Auditor certification preferred
- NCA-related cybersecurity accreditation or certification is preferred
- 8-10 years of professional experience in Information Security / Cybersecurity
- At least 3 years of experience in a cybersecurity or information security management/leadership role
- Proven experience managing enterprise cybersecurity programs and security teams
- Proven experience in GRC, risk management, security operations, and incident response
- Proven experience working with regulatory compliance, audits, and cybersecurity frameworks
- Technical & Professional Skills
- Strong knowledge of cybersecurity frameworks, standards, and best practices
- Deep understanding of NCA, PDPL, NDMO, ISO 27001, and applicable data protection requirements
- Strong expertise in Governance, Risk, and Compliance (GRC)
- Experience with SOC operations and SIEM platforms such as Microsoft Sentinel, Splunk, or equivalent
- Strong understanding of vulnerability management and penetration testing
- Strong knowledge of Incident Response and Cybersecurity Incident Response Plans (CIRP)
- Strong understanding of IAM and access governance
- Knowledge of data protection, data classification, and data governance
- Strong understanding of secure architecture and security controls
- Ability to develop and monitor cybersecurity KPIs and KRIs
- Strong audit and regulatory assessment experience
- Ability to assess and communicate cybersecurity risks in terms of business impact
- Strong strategic thinking and high-level decision-making capability
- Excellent leadership and people-management skills
- Ability to manage cross-functional teams and stakeholders under pressure
- Strong communication, presentation, and reporting skills
- Bilingual proficiency in Arabic and English
- Leadership Competencies
- Strategic Thinking
- Cybersecurity Leadership
- Risk-Based Decision Making
- Stakeholder Management
- Executive Communication
- Team Leadership & Development
- Problem Solving
- Crisis and Incident Management
- Governance & Accountability
- Continuous Improvement
- Business Acumen
- Change Management
- Ability to work effectively in a fast-paced and dynamic environment
- Ability to manage cybersecurity incidents and critical security situations
- Willingness to participate in security incident response and escalation activities when required
- Strong confidentiality and professional integrity
- Ability to work collaboratively with executive leadership, IT, business functions, auditors, and regulatory stakeholders
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search