About the Role
T2 is seeking a Cybersecurity Governance & Performance Specialist to join its team in Riyadh, Saudi Arabia. This full-time role is central to executing T2's cybersecurity governance operating rhythm, focusing on ensuring leadership visibility over control health, SLA adherence, and strategic security initiatives. The position is suitable for candidates with 0-1 years of experience.
Role Overview
The Cybersecurity Governance & Performance Specialist will be responsible for consolidating key performance and risk indicator data, maintaining cyber roadmap trackers, governing remediation evidence, and supporting critical reporting for audits and committees. This role ensures strategic security initiatives are tracked and communicated effectively across the organization.
Performance Monitoring and Reporting
- Collect and validate cyber performance inputs across SOC, Vulnerability Management, IAM, DevSecOps, and Data Security domains.
- Consolidate key metrics such as MTTD, MTTR, vulnerability aging, and phishing failure rates, translating technical data into clear narratives for leadership.
- Support maturity assessments across SOC, Application Security, IAM, Data Security, cloud, and AI security, updating dashboards and executive scorecards.
- Maintain governance repositories and enhance efficiency through automated feeds, Power BI dashboards, and milestone alerts.
Strategic Initiative and Audit Governance
- Maintain the master tracker for strategic initiatives, including SIEM, SOAR, zero trust, IAM maturity, DLP, PDPL uplift, and DSPM.
- Track milestones, owners, dependencies, and budget checkpoints for strategic initiatives, escalating aging or blocked items as necessary.
- Manage governance trackers for internal and ISO audits, NCA observations, PDPL gaps, and penetration test actions.
- Ensure all audit findings have a designated owner, due date, clear closure criteria, and evidence references.
- Prepare comprehensive packs for CSO reviews, risk councils, audit committees, and board cyber updates, capturing decisions, risk acceptances, escalations, and action items.
Qualifications and Experience
- 0-1 years of experience in cybersecurity governance, performance management, or a related field.
- Demonstrated ability to consolidate data, track initiatives, and support reporting functions.
- Strong organizational skills with attention to detail in managing trackers and evidence.
Work Environment
This is a full-time position based in Riyadh, Saudi Arabia, within a dynamic cybersecurity team at T2.
Application Process
Candidates interested in this role are encouraged to apply.
حول الدور
تسعى T2 إلى توظيف مختص حوكمة وأداء الأمن السيبراني للانضمام إلى فريقها في الرياض، المملكة العربية السعودية. هذا الدور بدوام كامل هو محور تنفيذ روتين حوكمة الأمن السيبراني في T2، مع التركيز على ضمان رؤية القيادة لحالة الضوابط، والالتزام بمستويات الخدمة، والمبادرات الأمنية الاستراتيجية. هذا المنصب مناسب للمرشحين الذين لديهم من 0 إلى 1 سنة خبرة.
نظرة عامة على الدور
سيكون مختص حوكمة وأداء الأمن السيبراني مسؤولاً عن دمج بيانات الأداء والمؤشرات الرئيسية للمخاطر، والحفاظ على متتبعات خارطة طريق الأمن السيبراني، وحوكمة الأدلة التصحيحية، ودعم التقارير الحيوية للحوكمت والتقارير. هذا الدور يضمن تتبع مبادرات الأمن الاستراتيجي والتواصل الفعال لها عبر المؤسسة.
المراقبة الأداء والتقارير
- جمع والتحقق من مدخلات الأداء السيبراني عبر مجالات SOC، إدارة الثغرات، IAM، DevSecOps، وأمن البيانات.
- دمج Metrics رئيسية مثل MTTD وMTTR وشيخوخة الثغرات، وتحويل البيانات التقنية إلى سرد واضح للقيادة.
- دعم تقييمات النضج عبر SOC، أمان التطبيقات، IAM، أمان البيانات، السحابة، وأمان الذكاء الاصطناعي، وتحديث لوحات القياس التنفيذية.
- الحفاظ على مستودعات الحوكمة وتحسين الكفاءة من خلال التدفقات الآلية، ولوحات Power BI، وتنبيهات المعالم.
المبادرات الاستراتيجية وحوكمة التدقيق
- الحفاظ على المتبقي الأساسي للمبادرات الاستراتيجية، بما في ذلك SIEM، SOAR، الثقة الصفرية، نضج IAM، DLP، ترقية PDPL، وDSPM.
- تتبع المعالم، المالكين، الاعتماديات، ونقاط ميزانية المبادرات الاستراتيجية، مع تصعيد العناصر المتأخرة أو المعطلة عند اللزوم.
- إدارة متتبعات الحوكمة لتدقيق داخلي وISO، وملاحظات NCA، وفجوات PDPL، وإجراءات اختبار الاختراق.
- التأكد من وجود مالك محدد لأي نتائج تدقيق، وتاريخ استحقاق، ومعايير إغلاق واضحة، ومرجع الأدلة.
- إعداد حزم شاملة لمراجعات CSO، ولجان المخاطر، ولجان التدقيق، وتحديثات مجلس الأمن السيبراني، مع توثيق القرارات، وقبول المخاطر، والتصعيد، وبنود العمل.
المؤهلات والخبرة
- من 0 إلى 1 سنة من الخبرة في حوكمة الأمن السيبراني، إدارة الأداء، أو مجال ذو صلة.
- إظهار قدرة على دمج البيانات وتتبع المبادرات ودعم وظائف التقارير.
- مهارات تنظيمية قوية مع اهتمام بالتفاصيل في إدارة المتتبعات والأدلة.
بيئة العمل
هذا منصب بدوام كامل مقره في الرياض، المملكة العربية السعودية، ضمن فريق أمن سيبراني ديناميكي في T2.
عملية التقديم
يُشجّع المرشحون المهتمون بهذا الدور على التقدم بطلب.