وظائف مفتش أمن في السعودية
٦٥٨١ وظائف شاغرة
Job Description:<br>Network Security & Perimeter Infrastructure• Administer, configure, and manage Cisco Firepower Firewalls and Cisco FMC for centralized policy management.• Support and maintain Palo Alto firewalls including policy tuning, NAT, and traffic inspection.• Manage Web Proxy (Broadcom Bluecoat) for secure internet access and URL filtering.• Administer DDoS protection solutions (Arbor, Akamai) to ensure network resilience and availability.• Configure and support F5 platforms including:APM (VPN Remote Access) ASM (Web Application Firewall) GTM (DNS / Traffic Management)• Ensure proper network segmentation, firewall rule optimization, and secure connectivity across environments.<br>Network Access Control & Identity Infrastructure• Administer Cisco ISE (AAA Server) for authentication, authorization, and accounting.• Manage Fore Scout NAC for device visibility and network admission control.• Support One Identity (IAM & MFA) and Microsoft Azure MFA for secure authentication mechanisms.• Administer Privileged Access Management (Delinea) to secure privileged accounts.• Manage Microsoft Certificate Authority (CA) for certificate issuance, renewal, and lifecycle management.<br>Endpoint, Server & Core Security Systems• Administer Endpoint Protection platforms (Symantec Endpoint Protection, Microsoft Defender).• Manage File Integrity Monitoring (Change Tracker) for critical systems.• Support secure configuration and hardening of servers, endpoints, and network devices.• Administer Email Security Gateway (Symantec Messaging Gateway).<br>Vulnerability & Infrastructure Security Management• Administer vulnerability management tools including Qualys and Tenable Nessus.• Perform regular vulnerability scans across network, systems, and applications.• Coordinate patching and remediation with infrastructure and application teams.• Maintain baseline security configurations and ensure compliance with hardening standards.<br>Data & Application Security (Infrastructure Perspective)• Support implementation of Microsoft DLP and Microsoft Purview (Data Classification) from an infrastructure integration standpoint.• Administer Web Application Firewall (F5 ASM) and support application security tools (Checkmarx, Secure Eyes) in coordination with development teams.• Manage Database security controls (Imperva) to protect critical data assets<br>Required Skills & Experience5+ years of experience in network security, cybersecurity operations, or security administration roles. Hands-on experience administering multiple security tools, including:Firewalls: Cisco Firepower, Palo Alto WAF/VPN/DNS: F5 (ASM, APM, GTM) DDoS Protection: Arbor, Akamai IAM/PAM: One Identity, Delinea, Azure MFAVulnerability Management: Qualys, Nessus Endpoint & Email Security: Symantec, Microsoft Defender Strong understanding of networking concepts (TCP/IP, DNS, VPN, routing, switching). Experience with security integrations across SIEM, SOAR, IAM, and endpoint tools. Familiarity with threat intelligence platforms and incident response processes. Ability to manage complex multi-vendor environments and troubleshoot integrations. Experience with scripting/automation (Power Shell, Python) is a plus. Excellent analytical, problem-solving, and communication skills. Perform end-to-end administration, configuration tuning, patching, and upgrades of security platforms.<br>Also, You can forward your CV through below link for more upcoming Job vacancies:https://cv-fnrco.com
Own the day-to-day security operations of business applications across Qiddiya's asset environments by managing application security controls, vulnerability remediation, secure configurations, access management, and patching. Act as the primary liaison with the Cybersecurity Team to coordinate penetration testing and code scanning activities, drive timely remediation of identified vulnerabilities, and ensure applications remain secure, compliant, and operational throughout their lifecycle<br><br>Key Responsibilities<br><br> Manage WAF/API security policies, rule tuning, and virtual patching (Cloudflare). Track and drive remediation of application vulnerabilities identified through penetration testing and SAST/DAST, ensuring SLA compliance via Service Now. Coordinate application and service account access provisioning through Beyond Trust PAM. Manage application patching, secure configurations, and dependency updates. Maintain application security baselines, including WAF, access controls, secrets, and certificates for new application go-lives. Manage application secrets and certificate lifecycle. Coordinate with the Cybersecurity Team on penetration testing, code scanning, and remediation activities. Monitor application security compliance and produce regular security reports<br><br>Requirements<br><br> 2+ years of experience in cybersecurity, preferably in application or web security. Experience with WAF platforms, ITSM tools, and vulnerability remediation processes. Understanding of secure SDLC principles and the interpretation of penetration testing and SAST/DAST findings. Familiarity with application patching, access management, and security configuration best practices
A security guard is required to work in a reputable commercial establishment on a full-time basis. Job responsibilities include monitoring the entrances and exits of the building, recording visitor data, and ensuring the implementation of safety and security procedures. The job requires discipline in working hours, the ability to handle emergency situations, and maintaining the security and safety of the establishment and its employees.
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>OBJECTIVE & OUTLINE ACCOUNTABILITIES: To build, implement, and maintain secure computer systems and networks, protecting an organization's digital assets from cyber threats, focusing on proactive defence, strengthening security infrastructure, identifying vulnerabilities, and implementing measures to prevent cyberattacks.</p><p>Responsibilities:</p><ul><li>Planning, implementing, monitoring, and upgrading security measures for the protection of the organization's data, systems, and networks</li><li>Troubleshooting security and network problems</li><li>Responding to all system and/or network security breaches</li><li>Ensuring that the organization's data and infrastructure are protected by enabling the appropriate security controls</li><li>Participating in the change management process</li><li>Testing and identifying network and system vulnerabilities</li><li>Daily administrative tasks, reporting, and communication with the relevant departments in the organization.</li></ul></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><p>Job Requirements:</p><ul><li>Education: University degree in Computer Science, Data Science or equivalent. CompTIA qualifications or equivalent proven industry entry training.</li><li>Experience: 2+ years on IT security, Network Security fields</li><li>Problem solving and Analytical thinking.</li></ul><p>SAUDI NATIONAL EMPLOYEE BENEFITS</p><p>In return for the required high levels of commitment and hard work you will receive a competitive salary and benefits package, including a generous leave and leave allowance, a full health care scheme and access to discounted gym membership.</p><p></p></section>
<h2 class="h5">وصف الوظيفة</h2>
<div class="t-break" data-jb-field="description">
<p><span>تقوم شركة أكسنتشر بتعيين <b>أخصائي هندسة أمان الشبكات</b> شغوف وماهر للانضمام إلى فريقنا. في هذا الدور، ستكون مسؤولاً عن تشغيل ودعم خدمات أمان الشبكات يومياً، بما يضمن الوظائف الآمنة والموثوقة للبنية التحتية للشبكة وحلول إدارة التهديدات.</span></p><br><br><br><p><span><b>المسؤوليات الأساسية:</b></span></p><br><br><ul><li><span>تشغيل ورصد ودعم <b>أدوات أمان الشبكات (مثل: جدران الحماية، WAF، أمان API، DDoS، IPS، بوابة البريد، الوكيل، حلول NAC).</b></span></li><li><span><b>إنشاء سياسات الجدار الناري وإدارة التغيير</b>: الاستفادة من <b>AlgoSec</b> لمراجعات السياسات والجوانب التحقق من الجدار الناري.</span></li><li><span><b>عمليات جدار حماية التطبيقات والـ API</b>: إدارة <b>F5 WAF وأمان الـ API</b> لحماية تطبيقات الويب.</span></li><li><span>إدارة و<b>تشخيص</b> <b>أجهزة أمان الشبكات</b> والمنصات، مع ضمان أن تكون <b>الإعدادات آمنة، والتوفر، والأداء</b> محققاً عبر كل من بيئات <b>الموقع والجهات السحابية</b>.</span></li><li><span>تنفيذ وإدارة <b>التحديثات، والترقيات، وتحديثات التوقيعات</b> لحلول أمان الشبكات، وفقاً لعمليات مؤسسية معتمدة.</span></li><li><span>تقييم مستمر لـ<b>الفعالية التشغيلية</b>، وتحديد الثغرات ودفع مبادرات التحسين لتعزيز وضع أمان الشبكة.</span></li><li><span>دعم تشخيص مشاكل الشبكة والأمان، بما في ذلك <b>تحليل حركة المرور وتقاطعات الحزم</b>، لضمان حلول سريعة وفعالة.</span></li><li><span>الحفاظ على وتحديث وثائق تشغيلية شاملة لضمان ممارسات أمان الشبكة متسقة وفعالة.</span></li><li><span>دعم <b>أنشطة التدقيق والتقارير</b> لتوفير الشفافية في عمليات أمان الشبكة.</span></li><li><span>تصعيد المسائل المعقدة أو التهديدات المحتملة حسب الضرورة، مع ضمان معالجتها بكفاءة وفعالية.</span></li></ul><br> </div><h2 data-automation-id="subHeaderPreferredCandidate" class="h5">مرشح وظيفي مفضل</h2>
<div class="row is-m v-align-top t-small bg-mute">
<div class="col is-3 p5" data-automation-id="label_Years_of_experience">
<b>سنوات الخبرة</b>
</div>
<div class="col is-9 p5" data-automation-id="data_Years_of_experience">
لا يوجد خبرة مطلوبة
</div>
</div>
<div class="row is-m v-align-top t-small ">
<div class="col is-3 p5" data-automation-id="label_Degree">
<b>المؤهل</b>
</div>
<div class="col is-9 p5" data-automation-id="data_Degree">
درجة البكالوريوس / دبلوم عالي
</div>
</div>
About SiFi:<br> <br> SiFi is a corporate expense management platform designed to empower /accounting teams with seamless control over corporate spending. Our platform allows companies to issue cards with specific spending restrictions, ensuring that funds are used efficiently and only for approved expenses.<br>Announcement number: 24782099<br><br>Tamheer Program Requirements:<br> Saudi nationals<br> Bachelor’s degree or higher in a relevant field (Cybersecruity or similar is highly preferred)<br> Age between 22 and 30 years<br> Not currently employed<br> Not registered in GOSI for the past 6 months<br> Eligible for and registered in the Tamheer Program through Hadaf<br> Skills:<br> Strong understanding of cybersecurity principles, frameworks, and best practices<br> Analytical thinking with strong problem-solving and incident investigation skills<br> Hands-on experience with security tools (SIEM, EDR, firewalls, IDS/IPS)<br> Knowledge of network security, system vulnerabilities, and threat detection<br> Ability to respond to security incidents and perform root cause analysis<br> Strong communication skills to collaborate with technical and non-technical teams<br> Good documentation, organizational, and time management skills<br> Ability to work under pressure and handle security incidents effectively<br> Preferred (Plus for SiFi Environment)<br> Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or related fields<br> Certifications such as CISSP, CEH, or Comp TIA Security+<br> Familiarity with compliance standards (ISO 27001, NCA ECC, PCI DSS)<br> Understanding of cloud security (AWS, Azure) and secure architecture<br> Knowledge of vulnerability management and penetration testing concepts<br> High attention to detail with a proactive security mindset
JOB PURPOSE:To manage information security and networking functions, ensuring confidentiality, integrity, and availability of systems.<br>KEY ACCOUNTABILITIESDevelop and enforce network and security policies. Monitor firewalls, IDS/IPS, and SIEM systems. Ensure compliance with ISO 27001, NCA, and DP World policies. Coordinate security incident response. Manage vendor contracts and SLAs.<br>QUALIFICATIONS, EXPERIENCE AND SKILLSBachelor’s in IT/Cybersecurity.8+ years in information security and networking. Certifications: CISSP, CCNP, CEH, ISO 27001 LA.
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p>A leading company in the field of men's accessories, headquartered in Buraidah, is seeking experienced warehouse security personnel. The ideal candidates will have between 3 to 5 years of experience in the field, ensuring the safety and security of valuable assets.</p> </div><h2 class="h5">Skills</h2>
<div data-jb-field="skills"><p>Ability to lead a team, work under pressure, and take on responsibilities.</p><p> </p></div>
Company Description Majestic International Company, part of Majestic International Group, is built on core principles of discipline, excellence, adaptability, and strong team motivation to serve clients and customers. Since 1986, the group has operated globally, initially in defense, and has since diversified into strategic business sectors that support national development and growth. The company focuses on superior technical capabilities, specialized skillsets, and intelligent technology to deliver premium, efficient services across all divisions and territories. Team members join a performance-driven environment that values high standards, innovation, and long-term partnerships.<br>We are looking for an experienced and proactive Security & Safety Supervisor to join our team in Riyadh. Requirements:· Diploma or Bachelor’s degree in Security, Safety, Occupational Health & Safety, or a related field.· Minimum 5 years of relevant experience in security and safety supervision.· Strong knowledge of security procedures, safety requirements, emergency response, and risk assessment.· Experience in supervising security and safety teams and monitoring site compliance.· Strong communication, leadership, and problem-solving skills.· Good command of English is preferred.· Candidates currently residing in Riyadh are preferred.<br>Key Responsibilities:· Supervise and monitor security and safety operations.· Ensure compliance with company policies and applicable safety regulations.· Conduct regular safety and security inspections and risk assessments.· Monitor emergency preparedness, fire safety, and incident response procedures.· Investigate incidents and prepare required reports.· Supervise security and safety personnel and ensure proper performance.· Coordinate with management, clients, contractors, and relevant authorities when required.
At Capgemini Engineering, the world leader in engineering services, we bring together a global team of engineers, scientists, and architects to help the world’s most innovative companies unleash their potential. From autonomous cars to life‑saving robots, our digital and software technology experts think outside the box as they provide unique R&D and engineering services across all industries. Join us for a career full of opportunities. Where you can make a difference. Where no two days are the same.<br>Your Role<br>As a Cyber Security Architect, you will contribute to complex, large-scale telecom transformation programs focused on designing and securing next-generation telecom infrastructures and networks. You will play a key role in enabling critical use cases such as Mission Critical Communications (post-TETRA), Public Safety Networks, Non-Terrestrial Networks (NTN), and Industrial IoT.<br>Design end-to-end security architectures for telecom and cloud environments, covering domains including SIM/e SIM, Devices, RAN, Transport (MPLS/IP), EPC/5G Core, IMS, MCx, OSS, and BSSDevelop and implement security frameworks aligned with standards such as 3GPP, GSMA, ETSI, NIST, ISO 27001, and industry best practices (Zero Trust, Defense-in-Depth, Adaptive Security) Conduct threat modeling, risk assessments, and vulnerability analysis for telecom networks Provide expert recommendations to mitigate cybersecurity risks, vulnerabilities, and incidents across telecom ecosystems Evaluate and recommend security technologies (Firewalls, IDS/IPS, PKI, HSM, PAM, EDR, SIEM, SOAR, etc.) and validate vendor solutions Produce and maintain high-quality architecture artifacts including HLDs, LLDs, guidelines, and security procedures Collaborate with solution architects, engineering, and integration teams to ensure secure design and deployment Lead customer workshops and present security strategies to technical and executive stakeholders<br>Your Profile<br>Experience & Qualifications Master’s degree in Computer Science, Cybersecurity, or Telecommunications10+ years of experience in cybersecurity, including at least 5 years in telecom environments Relevant certifications preferred: TOGAF, CISSP, ISSAP, CCSP or equivalent<br>Technical Expertise4G/5G security standards and compliance (3GPP TS33.x, TS33501, GSMA, ETSI, NIST, ENISA) Security of RAN infrastructures (DNS, DHCP, IPAM, AAA, DIAMETER, RIC security) Telecom protocols security (LTE/5G, GSM/2G/3G, GTP, SCTP) Transport network security (MPLS, IP, BGP) Cloud and virtualization security (Open Stack, Kubernetes, Docker, Open Shift, VMware) EPC / 5G Core security (AMF, SMF, UDM, NRF, AUSF, NEF, etc.) Security of IMS and MCx services OSS/BSS and network management systems security Security architecture models: Zero Trust, Layered Security, Defense-in-Depth, Adaptive Security Implementation of baseline security standards (MBSS) for telecom environments Security solutions integration across ecosystems: PKI, CLM, HSM, IdM, PAM, EDR, SIEM, SOAR<br>Professional Skills Strong analytical and structured problem-solving approach Ability to manage multiple priorities in complex environments Excellent communication and stakeholder management skills Strong presentation skills for both technical and executive audiences Flexibility to work across cultures and travel internationally<br>What you’ll love about working here<br> Digital campuses and academy – Our engineering academy offers more than 60,000 hours of training, as also our digital campus on Gen AI, data or sustainability, support digital learning in the flow of work from awareness to expert certifications. Dedicated innovation labs – We help the world's largest innovators engineer the products and services of tomorrow by leveraging our experts and labs, dedicated to topics as 5G, 6G, AI, Autonomous Vehicles and Quantum. Worldwide Leader of Engineering Services – Capgemini Engineering combines its broad industry knowledge and cutting-edge technologies in digital and software to support the convergence of the physical and digital worlds. We help our clients unleashing their R&D potential to develop smart products and services of tomorrow. Communities – Our Framework drives career development and elevates Capgemini's capabilities across various domains. Roles like architects, software engineers, these communities form the pillars of our Engineering Career Framework, outlining the foundational elements and anticipated growth. Tech for Societal Solutions – We're committed to addressing emerging crises, be it humanitarian, health, or biodiversity, to the best of our abilities. Collaborating with ITER project to build a safer, large-scale source of energy. Our global scientists and experts work to prove that the goal of clean, unlimited #Fusion Energy is possible.<br>About Capgemini<br>Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55‑year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end‑to‑end services and solutions leveraging strengths from strategy and design to engineering, all fuelled by its market‑leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem.
The SAP Platform Operation & Security Lead (BASIS / GRC) is responsible for managing end-to-end SAP platform operations, system stability, and security governance across the SAP landscape. The role oversees SAP BASIS operations, user access governance, SAP GRC Access Control, and audit compliance support to ensure secure, compliant, and highly available SAP systems while coordinating with HEC, functional teams, and business stakeholders.<br>Job Competencies• Strong ability to manage and operate SAP platforms.• Strong knowledge of SAP BASIS operations.• Ability to manage system stability, performance monitoring, and incident resolution.• Strong knowledge of SAP security and access management.• Ability to design and manage SAP roles and authorizations.• Knowledge of SAP GRC Access Control and access risk management.• Ability to support audit and compliance requirements.• Ability to manage system patching, transports, refreshes, and upgrades.• Ability to coordinate with HEC and manage SLA requirements.• Knowledge of security and integration for related systems such as Success Factors, CPI, BTP, and Fiori.<br>Job Specifications• 7 to 9 years of experience in SAP BASIS and SAP Security.• Experience managing SAP S/4HANA Private Cloud hosted on HEC or similar cloud platforms.• Hands-on experience with SAP GRC Access Control.• Experience in audit compliance support.• Strong knowledge of SAP BASIS administration, transport management, and system monitoring.• Strong knowledge of SAP security, role design, SoD concepts, and access governance.• SAP BASIS, SAP Security, or SAP GRC certification is preferred.• Pharmaceutical or manufacturing industry experience is preferred only, not mandatory.• Experience with Success Factors, SAP CPI, SAP BTP, and SAP Fiori security and integrations.• Saudi nationality is preferred.• Strong English communication skills are required.
The SAP Platform Operation & Security Lead (BASIS / GRC) is responsible for managing end-to-end SAP platform operations, system stability, and security governance across the SAP landscape. The role oversees SAP BASIS operations, user access governance, SAP GRC Access Control, and audit compliance support to ensure secure, compliant, and highly available SAP systems while coordinating with HEC, functional teams, and business stakeholders.<br>Job Competencies• Strong ability to manage and operate SAP platforms.• Strong knowledge of SAP BASIS operations.• Ability to manage system stability, performance monitoring, and incident resolution.• Strong knowledge of SAP security and access management.• Ability to design and manage SAP roles and authorizations.• Knowledge of SAP GRC Access Control and access risk management.• Ability to support audit and compliance requirements.• Ability to manage system patching, transports, refreshes, and upgrades.• Ability to coordinate with HEC and manage SLA requirements.• Knowledge of security and integration for related systems such as Success Factors, CPI, BTP, and Fiori.<br>Job Specifications• 7 to 9 years of experience in SAP BASIS and SAP Security.• Experience managing SAP S/4HANA Private Cloud hosted on HEC or similar cloud platforms.• Hands-on experience with SAP GRC Access Control.• Experience in audit compliance support.• Strong knowledge of SAP BASIS administration, transport management, and system monitoring.• Strong knowledge of SAP security, role design, SoD concepts, and access governance.• SAP BASIS, SAP Security, or SAP GRC certification is preferred.• Pharmaceutical or manufacturing industry experience is preferred only, not mandatory.• Experience with Success Factors, SAP CPI, SAP BTP, and SAP Fiori security and integrations.• Saudi nationality is preferred.• Strong English communication skills are required.
Role Description This is a full-time, on-site Cyber Security Manager role based in Riyadh for a Saudi National. The Cyber Security Manager will oversee the planning, implementation, and monitoring of the organization’s cybersecurity program, ensuring the protection of networks, systems, and data. <br>Education:Cybersecurity or Information Security.<br>Experience Minimum 2-4 years in a cybersecurity, information security and management role.<br>Professional Certifications or equivalent o ISO 27001 Lead Implementer.o ISO 27001 Lead Auditor.<br>Technical Certificates:Any NGFW certificate such as Forti Gate, Cisco ASA, Palo Alto. Manage Engine products such as SIEM, PAM, Active Directory.. Technical Knowledge Requirements• SOC Operations• SIEM Monitoring and Log Management• Threat Intelligence• Security Incident Management and Response• Digital Forensics Concepts• Vulnerability Assessments• Cloud Security Controls<br>Language Requirements • Fluent Arabic (Reading, Writing, and Speaking).• Fluent English (Reading, Writing, and Speaking).<br>Personal Competencies Strong leadership and people management skills. Excellent verbal and written communication skills. Ability to confidently engage with: NCA auditors, CST auditors, ISO auditors, Customer and third-party security auditors Strong stakeholder management and negotiation skills.<br>Nationality Requirement (Mandatory)• Saudi National
Position Summary Experienced SAP Security & GRC professional with over 15+ years of expertise in SAP Security, Role Design, Governance Risk & Compliance (GRC), and enterprise access control. Proven track record in leading end-to-end SAP implementations, global security transformations, and S/4HANA security design across complex landscapes. Key Responsibilities SAP Security & Role Management Lead design and implementation of SAP Security architecture across ECC, S/4HANA, BW/4HANA, Ariba, IBP, Success Factors, and BTP environments Design and maintain enterprise role matrix aligned with business processes and regulatory requirements Develop single, composite, and derived roles using PFCG and authorization concepts Design authorization concept for S/4HANA systems including Fiori tile-based access Prepare Fiori security design, catalog mapping, and role assignment strategy Support S/4HANA implementation security strategy<br>SAP GRC AC, IAG and Cloud Security Implementation & Governance Implement SAP GRC Access Control modules including ARA, ARM, BRM, EAM, and UARDesign and configure SOD rule sets and risk mitigation controls Build risk and control matrices aligned with SOX and internal audit requirements Implement emergency access management (Firefighter IDs) and monitor logs Implement IAG for Ariba, IBP, Success Factors, and BTP cloud applications Implement SAP Identity Access Governance (IAG) services including Access Request, Access Analysis, Access Certification Configure custom rule sets for cloud applications Enable hybrid access governance between on-prem and cloud SAP systems Support privileged access management<br>GRC Process Control, Audit & Risk Management Risk Framework Development: Establish risk catalogs, assess risk likelihood and financial impact, and define risk mitigation strategies within the SAP platform. Control Design & Automation: Map business processes, design internal controls (SOX, Segregation of Duties), and configure Automated Continuous Control Monitoring (CCM). Testing & Remediation: Manage control self-assessments, evaluate control effectiveness, track testing evidence, and address identified deficiencies. Audit & Reporting: Generate compliance dashboards, maintain control documentation, and assist internal/external auditors with compliance reviews. Workflow Configuration: Set up roles, notifications, and approval workflows for surveys, testing, and issue resolution.<br>Key Skills SAP Security (ECC, S/4HANA, BW/4HANA, Fiori, BTP, ARIBA, IBP), SAP GRC (AC, PC, RM), SAP IAG, Success Factors RBP, CUA, SOX Compliance, IT Audit, SOD Management.
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>• Deep technical experience on F5 advanced WAF • Identify and clean up unused or orphaned IP addresses on F5 BIG-IP load balancers to improve performance, efficiency, and manageability.<br> • Review, validate, and remove unused, duplicate, or obsolete firewall policies across HQ and DR data centers while maintaining security posture and compliance.<br> • Ensure firewall and load balancer changes are aligned with high availability (HA) and disaster recovery (DR) requirements.<br> Network & Security Assessment • Perform a comprehensive assessment of all devices, applications, databases, and network components using public IP addresses.<br> • Analyze application, service, and security dependencies to determine the potential impact of IP, firewall, and load balancer changes.<br> • Classify firewall rules and DNS-related entries based on criticality, usage, activity level, and business relevance.<br> IP Addressing & DNS Governance • Develop detailed cleanup and migration plans including sequencing, timelines, backups, and rollback procedures.<br> • Design and allocate private IP address ranges, ensuring compatibility with existing network and security architecture.<br> • Assess and analyze DNS records to identify unused, outdated, or invalid entries related to applications and security controls.<br> • Remove or update invalid, obsolete, or unnecessary DNS records while ensuring no impact on applications or end users.<br> Secure Execution & Validation • Execute cleanup and migration activities in a secure, controlled, and auditable manner, ensuring uninterrupted service continuity.<br> • Coordinate with application, systems, SOC, and operations teams to align firewall rules, NAT, routing, DNS, and access controls.<br> • Perform post-change testing and validation to confirm service availability, security enforcement, and performance stability.<br> Governance, Review & Documentation • Establish periodic review procedures for firewall rules, F5 configurations, IP addressing, and DNS records to ensure ongoing accuracy and security.<br> • Ensure cleanup activities do not negatively impact applications, services, or end users.<br> • Maintain comprehensive documentation for all activities, including changes implemented, issues encountered, root cause analysis, and approved remediation actions.<br> • Support audit, compliance, and regulatory requirements through proper documentation and change tracking.<br> • Strong hands-on experience with firewalls (NGFW), security policies, NAT, and access control management.<br> • Proven expertise in F5 BIG-IP (LTM), including VIPs, Self IPs, SNATs, and HA configurations.<br> • Solid understanding of enterprise IP addressing, DNS, routing, and network security architecture.<br> • Experience operating in HQ / DR, high-availability, and mission-critical environments.<br> • Strong knowledge of change management, rollback planning, and risk mitigation.<br> Education & Certifications (Preferred) • Bachelor’s degree in Computer Science, Information Technology, or related field • Certifications such as CCNP Security, F5-CA/CTS, NSE, or equivalent are high</span> </div><h2 data-automation-id="subHeaderPreferredCandidate" class="h5">
Preferred candidate </h2>
<div class="row is-m v-align-top t-small bg-mute">
<div class="col is-3 p5" data-automation-id="label_Years_of_experience">
<b>Years of experience</b>
</div>
<div class="col is-9 p5" data-automation-id="data_Years_of_experience">
No experience required </div>
</div>
<div class="row is-m v-align-top t-small ">
<div class="col is-3 p5" data-automation-id="label_Degree">
<b>Degree</b>
</div>
<div class="col is-9 p5" data-automation-id="data_Degree">
Bachelor's degree / higher diploma </div>
</div>
Since 2004, 2P has been a leader in Saudi Arabia’s ICT landscape, delivering integrated technology solutions that help organizations accelerate digital transformation and improve operational efficiency. With a strong foundation in innovation and service excellence, 2P continues to provide end-to-end solutions through its specialized business units and trusted market expertise. We are always looking to connect with talented professionals who are passionate about making an impact and growing within a dynamic, forward-looking environment.>>><br>We are seeking a senior Information Security Engineer (L3) with 7+ years of cybersecurity experience. The ideal candidate will be responsible for securing enterprise environments, conducting advanced security assessments, and ensuring compliance with cybersecurity standards and regulations.<br>Key Responsibilities Conduct penetration testing and advanced security assessments. Ensure compliance with cybersecurity regulations such as NCA. Protect systems, applications, and data from cyber threats. Ensure confidentiality, integrity, and availability (CIA) of organizational data. Secure web applications and infrastructure against vulnerabilities. Monitor and respond to security incidents and risks. Collaborate with teams to improve overall security posture.<br>Qualifications & Requirements Bachelor’s degree in computer science or related field. Minimum 7+ years of experience in cybersecurity.e JPT and CCNA certifications are required. Experience in penetration testing and security assessments. Strong knowledge of cybersecurity frameworks, risk management, and compliance. Industry certifications such as CISSP, CISA, or CEH are preferred.<br>Key Skills Penetration Testing Cybersecurity Compliance (NCA) Risk Management Threat Analysis & Incident Response Security Architecture
<b>Join Our Team as a Security Supervisor at Accor!</b><br><br>At Novotel Madinah, part of the global Accor family, we are seeking a dedicated and professional <i>Security Supervisor</i> to ensure the safety and security of our esteemed guests and staff. You will play a crucial role in maintaining the high standards of hospitality that Accor is known for.<br><br><b>About Novotel Madinah:</b><br>Located in the heart of the holy city of Madinah, just 120 meters from Al-Masjid an-Nabawi, our hotel offers modern comfort and strategic facilities ideal for both pilgrims and leisure travelers.<br><br><b>Key Responsibilities:</b><br>- Oversee the security operations within the hotel.<br>- Ensure the safety of guests and staff through effective surveillance and security measures.<br>- Collaborate with local authorities as needed.<br>- Conduct regular safety audits and risk assessments.<br><br><b>Qualifications:</b><br>- Minimum of 2 years of experience in international hotels.<br>- Good knowledge of Microsoft Office applications (Excel and Word).<br>- Proficient in English communication.<br>- Strong interpersonal and communication skills.<br>- Physically fit and well-groomed.<br>- Ability to adapt to shift schedules and work under pressure.<br><br><b>Mandatory Requirements:</b><br>- A valid Police Clearance Certificate (No Criminal Record).<br>- Security and safety certifications from recognized institutions.<br><br><b>What We Offer:</b><br>- Career growth and development opportunities.<br>- Global opportunities within the Accor network.<br>- Competitive benefits and a culture of recognition.<br>- A commitment to work-life balance.<br><br><b>Our Culture:</b><br>At Accor, our Heartist spirit drives us to deliver exceptional experiences and showcase diversity and teamwork. Join us in crafting unique hospitality experiences that leave a lasting impact.
Duties and Responsibilities: <br>Develop, review, and maintain cybersecurity policies, standards, and procedures in alignment with NCA ECC and IA CSF. Conduct cybersecurity compliance assessments and gap analyses, and track remediation actions to closure. Perform cybersecurity risk assessments and maintain the cybersecurity risk register. Establish and monitor cybersecurity KPIs and KRIs, and report on compliance and risk posture. Support the implementation and continuous improvement of cybersecurity governance practices and frameworks. Coordinate and support internal and external cybersecurity audits and regulatory inspections. Oversee third-party cybersecurity risk assessments and ensure compliance with security requirements. Review and validate security configurations and ensure proper implementation of security controls across systems and applications. Support vulnerability management activities and remediation tracking. Coordinate and review penetration testing and security assessment results. Ensure proper documentation, evidence management, and audit readiness always. Collaborate with IT and business units to embed cybersecurity controls into projects and operations. Support cybersecurity awareness and training initiatives across the organization. Stay updated on emerging threats, regulatory changes, and industry best practices to continuously enhance the cybersecurity posture.<br>Developing new defensive systems and protocols: Design and enhance cybersecurity controls and defensive mechanisms in alignment with NCA ECC and SAMA CSF. Develop and update security standards, baselines, and hardening guidelines for systems, applications, and cloud environments. Evaluate and recommend new security technologies and solutions to strengthen the organization’s security posture. Support the implementation of secure architecture principles across IT and business systems. Develop and improve processes for vulnerability management, patching, and configuration management. Define and enhance identity and access management controls, including least privilege and segregation of duties. Establish and refine data protection controls, including encryption and data classification standards. Continuously assess control effectiveness and recommend improvements based on risk assessments and audit findings. Align new security protocols with regulatory requirements and industry best practices. Collaborate with IT teams to ensure secure deployment of new systems and technologies.<br>Education:Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field. Relevant professional certifications such as CISSP, CYSA+, CGRC, or ISO 27001 Lead Implementer/Auditor are highly desirable.<br>Experience:Minimum 4 years of related work experience, various domains, systems, network, incident response tools, and packet analysis knowledge is needed. Experience in designing large scale security operation tools and processes.<br>Personal Attributes / Skills:Outstanding computer and Cybersecurity skills related to IT security. Excellent analytical and problem-solving skills.
Antal is partnering with a leading multinational railway engineering and consulting organization that is seeking an experienced Cyber Security Specialist to support a major metro/rail project in Saudi Arabia. This role focuses on cybersecurity governance for critical rail systems, ensuring design compliance, cyber risk management, system integration security, and operational readiness across a complex multi-system environment.<br>Job Title: Cyber Security Specialist Location: Riyadh, KSAPay : OPEN<br>This is not a typical role; it is a key position on a major metro project where you will take ownership of cybersecurity across rail and metro systems, driving risk assessments, secure system integration, testing & commissioning security validation, and ensuring full operational resilience and protection within a highly complex rail infrastructure environment.<br>For Saudi Arabia, we are looking for a passionate Cyber Security Specialist (m/f/d). Your responsibilities:Review and assess cybersecurity designs, technical submittals, and architecture proposals to ensure compliance with project cybersecurity requirements (ISO/IEC 27002, IEC 62443, KSA NCA) Conduct cyber risk assessments covering attacks, threats, vulnerabilities, and potential impacts across all metro digital systems Develop, review, and validate cybersecurity frameworks including the Methodological Framework, Initial Risk Analysis, and Security Policy as required by the Employer Ensure network, data, and communication systems are protected against unauthorized access, eavesdropping, spoofing, malware, hacking, and Denial-of-Service attacks Support the design and implementation of access control mechanisms (authentication, authorization, cryptographic key validation) in accordance with IEEE 802.1X and other relevant standards Coordinate cybersecurity requirements and audits with PMCM teams, D&B Contractor, system integrators, and other stakeholders to ensure system-wide protection and compliance Review and approve cybersecurity elements for network security plans, operational guidelines, and system-level protections ensuring end-to-end integrity and confidentiality Prepare documentation, reports, and recommendations related to cybersecurity compliance, non-conformities, audits, and risk mitigation actions for Employer review<br>Your profile :Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Systems Engineering, or a related discipline, with 15+ years of relevant professional experience Proven experience in cybersecurity for metro, rail, critical infrastructure, or large-scale industrial systems, including threat mitigation, cyber risk assessment, and security architecture design Strong understanding of international cybersecurity frameworks, especially ISO/IEC 27002, IEC 62443, and KSA NCA national cybersecurity requirements Demonstrated ability to analyze, review, and validate cybersecurity documentation, risk studies, network security plans, and system and subsystem security controls Experience implementing access control systems, data protection measures, encryption, authentication, and intrusion detection/prevention mechanisms Strong analytical and problem-solving skills for identifying vulnerabilities, evaluating cyber threats, and recommending effective mitigation measures Excellent coordination and communication skills, enabling collaboration with design teams, contractors, system integrators, and Employer representatives across a multi-contract environment High level of professional integrity, attention to detail, and adaptability to manage cybersecurity challenges in a complex, fast-moving mega-project
Information Security Compliance Consultant<br>Important: This Is Not a Technical Cybersecurity Role This position is focused on compliance, documentation, governance, regulatory coordination, and audit support.<br>???? Location: Riyadh, Saudi Arabia<br>About the Role We are seeking an Information Security Compliance Consultant to support information security and data protection compliance activities in Saudi Arabia.<br>The role will serve as a key local representative for information security and personal data protection compliance, working closely with Saudi regulatory authorities, senior leadership, IT and security teams, auditors, and internal stakeholders.<br>The successful candidate will be responsible for coordinating regulatory requirements, supporting PDPL compliance, localizing policies and procedures, maintaining compliance documentation, and ensuring the organization remains prepared for regulatory reviews and audits.<br>Key Responsibilities Government Liaison & Regulatory Compliance Serve as the local point of contact with relevant Saudi regulatory authorities, including NCA and SDAIA. Monitor, interpret, and communicate regulatory notices, requirements, circulars, and updates to relevant internal stakeholders. Coordinate regulatory communications, submissions, responses, and required documentation through official channels and portals. Support regulatory notifications related to cybersecurity or personal data incidents in line with applicable requirements and internal procedures. Maintain professional and effective communication with government and regulatory stakeholders. Personal Data Protection & PDPL Compliance Support compliance with the Saudi Personal Data Protection Law (PDPL). Coordinate the identification and documentation of personal data processing activities with IT and business teams. Support the preparation and maintenance of PDPL-related filings, declarations, policies, procedures, and employee communications. Own and maintain local PDPL compliance documentation and supporting audit evidence. Ensure compliance documentation remains accurate, current, organized, and readily available for regulatory reviews and audits. Information Security Governance & Policy Localization Support the localization of global cybersecurity policies and frameworks into Saudi-compliant policies, SOPs, and procedures. Ensure relevant documentation is aligned with applicable Saudi requirements, including NCA Essential Cybersecurity Controls (ECC) and Cloud Cybersecurity Controls (CCC) where applicable. Coordinate with technical teams to collect and organize evidence required to demonstrate compliance. Maintain appropriate version control and documentation standards across policies, procedures, and compliance records. Audit Readiness & Compliance Evidence Develop and maintain a structured Compliance Evidence Repository to ensure audit traceability and readiness. Collect, organize, and maintain compliance evidence, including:Policy approvals and acknowledgements Security committee and management meeting minutes Access approval records Security and awareness training records System screenshots and extracts provided by technical teams Other supporting documentation required for compliance Coordinate with internal stakeholders and auditors to ensure evidence is complete, accurate, and available when required. Track outstanding compliance requirements and ensure timely follow-up and closure. Training & Third-Party Compliance Coordinate information security and PDPL awareness training for local employees. Support phishing simulation exercises and maintain appropriate training and awareness records. Assist with basic information security compliance checks for local vendors and third parties. Review supporting documentation, including NDAs and information security clauses, where required.<br>What We're Looking For Minimum 2 years of experience in compliance, IT governance, regulatory affairs, audit support, or information security-related roles. Strong understanding of information security, data protection, and regulatory compliance concepts. Previous experience working with Saudi government entities or regulatory bodies is strongly preferred. Ability to prepare clear and professional government and regulatory correspondence. Professional English proficiency, with the ability to understand security standards and prepare clear written reports. Strong attention to detail and a high level of documentation discipline. Ability to manage compliance requirements, evidence, records, and follow-up activities effectively. Comfortable working with senior stakeholders, auditors, regulators, IT teams, and business functions.<br>Preferred Qualifications The following would be advantageous:Exposure to ISO/IEC 27001 audits or implementation. Exposure to ISO 22301 or SOC 2 audits. Familiarity with NCA Essential Cybersecurity Controls (ECC). Familiarity with NCA Cloud Cybersecurity Controls (CCC). Knowledge of Saudi PDPL requirements. Certifications such as Comp TIA Security+, ISO Internal Auditor, or equivalent.<br>What Success Looks Like The successful candidate will be someone who can take regulatory requirements, understand their implications for the organization, coordinate effectively with the relevant internal teams, and ensure that required documentation and evidence are complete, accurate, traceable, and readily available.<br>Strong performance in this role will be demonstrated through regulatory alignment, audit readiness, documentation quality, and effective coordination across stakeholders.