Cybersecurity Manager Location: Saudi Arabia-Jededah Experience: 5–12 Years Industry: Cybersecurity / Information Security About the Role We are seeking a highly skilled and experienced Cybersecurity Manager to join our team. The ideal candidate will have a strong blend of technical expertise, hands-on operational experience, and leadership capabilities, with a proven track record in designing, implementing, and managing cybersecurity programs across complex environments. This role requires a strategic thinker who can also operate at a deep technical level, lead security teams, and work closely with executive leadership, clients, and stakeholders to ensure robust cybersecurity posture and compliance with local and international standards. Key Responsibilities Lead and manage end-to-end cybersecurity operations, including SOC, incident response, threat intelligence, and vulnerability management. Design, implement, and continuously improve information security frameworks, policies, and procedures. Oversee risk assessments, penetration testing, and security assessments, ensuring timely remediation. Manage and respond to cyber incidents, leading investigations, root cause analysis, and post-incident reporting. Ensure compliance with regulatory and industry standards (e.g., NCA, ISO 27001, NIST, SAMA, PCI-DSS). Collaborate with internal teams and clients to align cybersecurity strategies with business objectives. Lead, mentor, and develop cybersecurity engineers and analysts. Evaluate, implement, and manage security tools and technologies (SIEM, SOAR, EDR, DLP, IAM, etc.). Prepare executive-level security reports, dashboards, and risk summaries. Stay up to date with emerging threats, vulnerabilities, and cybersecurity trends. Required Experience & Skills5–12 years of experience in cybersecurity or information security roles. Strong hands-on technical background in:Security Operations (SOC) Incident Response & Digital Forensics Network & Cloud Security Vulnerability Management & Penetration Testing Proven experience in security architecture and security controls design. Solid understanding of GRC (Governance, Risk, and Compliance). Experience working with enterprise and government environments is a strong plus. Ability to communicate complex technical concepts to non-technical stakeholders. Strong leadership, decision-making, and problem-solving skills. Certifications (Required / Preferred) CISSP (Required or Strongly Preferred) CISM or CISACEH / OSCP / GPENISO 27001 Lead Implementer or Lead Auditor Cloud Security certifications (AWS, Azure, or GCP Security) are a plus Any NCA-related or local regulatory certifications are a plus Education Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field Master’s degree is a plus Why Join UsWork with a leading cybersecurity organization in the region Engage in high-impact, national-level and enterprise cybersecurity projects Continuous learning, certification support, and career growth Collaborative, innovative, and professional work environment
مدير الأمن السيبراني الموقع: المملكة العربية السعودية - جدة الخبرة: 5-12 سنة القطاع: الأمن السيبراني / أمن المعلومات نبذة عن الدور: نحن نبحث عن مدير أمن سيبراني ذو خبرة ومهارات عالية للانضمام إلى فريقنا. المرشح المثالي هو من يمتلك مزيجاً قوياً من الخبرة التقنية، والخبرة التشغيلية الميدانية، والقدرات القيادية، مع سجل حافل في تصميم وتنفيذ وإدارة برامج الأمن السيبراني عبر بيئات معقدة. يتطلب هذا الدور مفكراً استراتيجياً قادراً على العمل على مستوى تقني عميق، وقيادة فرق الأمن، والعمل عن كثب مع الإدارة التنفيذية والعملاء وأصحاب المصلحة لضمان وضع أمني سيبراني قوي والامتثال للمعايير المحلية والدولية. المسؤوليات الرئيسية: قيادة وإدارة عمليات الأمن السيبراني الشاملة، بما في ذلك مركز العمليات الأمنية (SOC)، والاستجابة للحوادث، واستخبارات التهديدات، وإدارة الثغرات الأمنية. تصميم وتنفيذ وتحسين أطر وسياسات وإجراءات أمن المعلومات بشكل مستمر. الإشراف على تقييمات المخاطر، واختبارات الاختراق، والتقييمات الأمنية، وضمان المعالجة في الوقت المناسب. إدارة الحوادث السيبرانية والاستجابة لها، وقيادة التحقيقات، وتحليل الأسباب الجذرية، وإعداد تقارير ما بعد الحوادث. ضمان الامتثال للمعايير التنظيمية والصناعية (مثل NCA، ISO 27001، NIST، SAMA، PCI-DSS). التعاون مع الفرق الداخلية والعملاء لمواءمة استراتيجيات الأمن السيبراني مع أهداف العمل. قيادة وتوجيه وتطوير مهندسي ومحللي الأمن السيبراني. تقييم وتنفيذ وإدارة الأدوات والتقنيات الأمنية (SIEM، SOAR، EDR، DLP، IAM، إلخ). إعداد تقارير أمنية على مستوى الإدارة التنفيذية، ولوحات المعلومات، وملخصات المخاطر. البقاء على اطلاع دائم بالتهديدات الناشئة والثغرات واتجاهات الأمن السيبراني. الخبرات والمهارات المطلوبة: خبرة من 5 إلى 12 سنة في أدوار الأمن السيبراني أو أمن المعلومات. خلفية تقنية عملية قوية في: عمليات الأمن (SOC)، الاستجابة للحوادث والتحقيقات الجنائية الرقمية، أمن الشبكات والسحابة، إدارة الثغرات واختبار الاختراق. خبرة مثبتة في هندسة الأمن وتصميم الضوابط الأمنية. فهم قوي للحوكمة والمخاطر والامتثال (GRC). تعتبر الخبرة في العمل مع بيئات المؤسسات والقطاع الحكومي ميزة إضافية كبيرة. القدرة على شرح المفاهيم التقنية المعقدة لأصحاب المصلحة غير التقنيين. مهارات قيادية قوية، وقدرة على اتخاذ القرار وحل المشكلات. الشهادات (مطلوبة / مفضلة): CISSP (مطلوبة أو مفضلة بشدة)، CISM أو CISA، CEH / OSCP / GPEN، ISO 27001 Lead Implementer أو Lead Auditor، شهادات أمن السحابة (AWS، Azure، أو GCP Security) تعد ميزة إضافية، وأي شهادات متعلقة بـ NCA أو اللوائح المحلية تعد ميزة إضافية. التعليم: درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو تقنية المعلومات أو مجال ذي صلة. درجة الماجستير تعتبر ميزة إضافية. لماذا تنضم إلينا: العمل مع مؤسسة أمن سيبراني رائدة في المنطقة، المشاركة في مشاريع أمن سيبراني ذات تأثير عالٍ على المستوى الوطني والمؤسسي، التعلم المستمر ودعم الشهادات والتطور الوظيفي، بيئة عمل تعاونية ومبتكرة واحترافية.