Cyber Security Engineer Jobs - Jeddah Saudi
5501 Jobs Found
Job Summary We are seeking an experienced Vulnerability Assessment & Penetration Testing (VAPT) Specialist to assess the security posture of the organization’s systems, networks, web applications, and physical infrastructure. The role is responsible for identifying and validating vulnerabilities, conducting authorized penetration testing, evaluating the effectiveness of layered security controls, and providing actionable recommendations to mitigate identified risks. Key Responsibilities Conduct Vulnerability Assessment and Penetration Testing (VAPT) across systems, networks, applications, web applications, and infrastructure. Perform vulnerability scanning across technology assets and identify deviations from approved security configurations, policies, standards, and baselines. Conduct authorized penetration tests using realistic attack techniques and scenarios to identify exploitable vulnerabilities and assess the organization’s security posture. Perform security testing of systems, networks, web applications, and physical facilities in accordance with approved testing procedures and scope. Assess the effectiveness of defense-in-depth and layered security controls against known vulnerabilities and realistic attack scenarios. Conduct web application security testing using appropriate penetration testing methodologies and tools. Perform source code reviews and security testing using static and dynamic application security testing tools where applicable. Identify, validate, and prioritize vulnerabilities based on their technical severity, exploitability, and potential business impact. Prepare comprehensive VAPT and vulnerability assessment reports, including risk ratings, technical findings, remediation recommendations, evidence, and sufficient technical details to reproduce the findings. Discuss and present VAPT findings with management, cybersecurity teams, IT teams, application owners, and other relevant stakeholders. Provide practical remediation recommendations and support technical teams in validating vulnerability remediation. Design, develop, and continuously improve VAPT processes, methodologies, procedures, and testing scenarios. Required Qualifications Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field. Minimum of 4–6 years of experience in Vulnerability Assessment, Penetration Testing, VAPT, or a related cybersecurity discipline. Strong hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT). Experience conducting penetration testing across network, infrastructure, system, and web application environments.
Key Responsibilities Provides advice on analyzing and assessing risks to the Information Technology environment. Recommends activities related to continuous security assessments of the organization's systems and services in alignment with the Technology Risk Management Framework. Recommends activities related to analyzing and assessing risks to the Information Technology environment. Provides advice on participating in cybersecurity incident response. Recommends actions related to monitoring emerging security threats and monitoring the implementation of necessary measures to mitigate risks, in coordination and alignment with Operational Risk Management, as applicable. Reviews the disaster response and business continuity plan, in coordination and alignment with Operational Risk Management, as applicable. Recommends actions to ensure the availability of cybersecurity resilience requirements in the Business Continuity Plan. Identifies tasks related to the ability of information security controls to mitigate risks and provides recommendations in this regard. Recommends actions to ensure the protection of information and technology assets from cyber risks related to external parties. Reviews the processes for assessing the security awareness of system users. Proposes activities for developing plans and implementation programs to enhance security awareness, in coordination with various concerned organizational units (such as: the General Department of Human Resources and the Corporate Communications Department). Proposes activities for implementing security awareness programs and working to develop them. Recommends actions to ensure that security awareness programs comply with all relevant regulations, standards, and requirements of the relevant legislative authorities. Complies with the organization's policies and work behaviors and the procedures of the organizational unit. Performs any other tasks assigned by direct supervisors.<br>Required Experience Minimum of 6 years of experience in a relevant field.<br>Education Bachelor’s degree in Cybersecurity or any related field.
Key Responsibilities Contributes to analyzing and assessing risks to the Information Technology environment. Develops continuous security assessment processes for the organization's systems and services in alignment with the Technology Risk Management Framework. Contributes to activities related to analyzing and assessing risks to the Information Technology environment. Contributes to tasks related to participating in cybersecurity incident response. Establishes activities for monitoring emerging security threats and monitoring the implementation of necessary measures to mitigate risks, in coordination and alignment with Operational Risk Management, as applicable. Develops processes for reviewing the disaster response and business continuity plan, in coordination and alignment with Operational Risk Management, as applicable. Develops activities to ensure the availability of cybersecurity resilience requirements in the Business Continuity Plan. Contributes to processes for reviewing the ability of information security controls to mitigate risks and providing recommendations in this regard. Develops activities to ensure the protection of information and technology assets from cyber risks related to external parties. Develops processes for assessing the security awareness of system users. Contributes to activities related to developing plans and implementation programs to enhance security awareness, in coordination with various concerned organizational units (such as: the General Department of Human Resources and the Corporate Communications Department). Develops processes for implementing security awareness programs and working to develop them. Contributes to ensuring that security awareness programs comply with all relevant regulations, standards, and requirements of the relevant legislative authorities. Complies with the organization's policies and work behaviors and the procedures of the organizational unit. Performs any other tasks assigned by direct supervisors.<br><br>Required Experience Minimum of 4 years of experience in a relevant field.<br>Education Bachelor’s degree in Cybersecurity or any related field.
Kaspersky has been protecting individuals and corporate clients all over the world from cyber threats for 27 years. We have 400 million unique users, 270 000 corporate clients, 517 products, 1100 technological patents and 34 offices around the world.<br>Today our team has more than 5 500 top level experts, all of them regular people with their own talents and hobbies. Together we protect the world from cyber threats. <br>Join us to become part of an exceptional team, while remaining yourself and using your skills to keep us growing and evolving.<br>We are now searching for a Key Account Manager. This key role carries the responsibility for developing, overseeing and executing our enterprise sales. And this is an absolutely key role in developing and maintaining our long-term business relationships with our customers.<br><br>Main Responsibilities:<br>Achieve quarterly and annual set targets from the Enterprise on territory from NAL (Named Accounts List);Establish and maintain executive level relationships to create a qualified pipeline and drive revenue;Develop contacts with customers into leads and work through the entire sales cycle;Articulate the value of our product/service to a higher level within the customer organization;Identify, develop and articulate a compelling value proposition to prospective customers in the large enterprise segment;Position Kaspersky specialized services like cyber security training, threat intelligence services, Anti APT etc. to large enterprises;Supply proposals and product information to prospects;Funnel reporting and updates using Salesforce;Work in close connection with Partner Account managers to ensure deal closure and full sales cycle support by the appropriate reseller or system integrator;Independently drive the entire sales cycle for customer acquisition;Stay updated with the competitive landscape and the latest trends in the security market;Work as a trusted consultant for enterprise clients, to get Kaspersky products & services empaneled as their preferred choice;Lead the process of timely response to RFP’s, along with partners & colleagues;Present the Kaspersky Portfolio of product & services at field events such as conferences, seminars, etc;Convey customer requirements to Product Management teams on a regular basis;Co-ordinate with the Global Enterprise Sales Team.<br>Key Requirements:<br>Bachelor Degree in Marketing, Management, Business Administration or equivalent;5+ years direct account management in IT Sales in handling large accounts;Strong, documented track record of achievement against quota;Should have past history of presentations to large corporates;Current contacts / relationships at CxO level in large accounts;10+ years’ experience in IT, 5+ years In Cybersecurity is an advantage;Fluent English.<br>The hiring process for this position looks as follows:<br>1) Resume review (1–3 business days)2) Introductory call with Recruiter (30 min)3) Interview with Hiring Manager (60 min)4) Final interview (optional)5) Offer & reference check
Role Summary The Cloud Compute SME Lead is responsible for managing Level 2 support operations across multi-data center infrastructure. This role ensures stability, performance, and continuity of core IT services by leading incident resolution, ensuring service fulfillment, provisioning, and supporting infrastructure projects. The manager drives operational excellence across operating systems, database, storage, virtualization, networking, and backup domains, and security operations. The role also acts as a technical advisor for hybrid cloud strategy, providing SME support for migrating on-premises workloads to public cloud platforms such as Google Cloud Platform (GCP) and Microsoft Azure, as well as containerized/hybrid environments built on Red Hat Open Shift.<br>Key Responsibilities Lead the team that maintains and operates infrastructure components across multiple data centers. Ensure incident and problem management, delivering timely resolution and root cause analysis. Ensure service fulfillment and provisioning for infrastructure resources (Operating systems, database, storage, backup, virtualization, network, security). Support and review infrastructure projects to guarantee operational readiness and compliance. Provide SME guidance and support for cloud migration initiatives, including workload assessment, migration planning, and hybrid integration across Microsoft Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI), and Red Hat Open Shift. Lead the team that maintain and optimize infrastructure components: Operating Systems: Windows, Linux, AIXDatabase: Oracle, MSSQLStorage: SAN/NAS, enterprise backup solutions Virtualization: VMware, Hyperconverged Infrastructure Networking: LAN/WAN, firewalls, load balancers Security: Basic hardening and compliance with organizational standards Cloud & Hybrid Platforms: Microsoft Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI), Red Hat Open Shift Ensure adherence to SLAs and operational KPIs. Drive automation and standardization of operational tasks using tools like Ansible and scripting. Support disaster recovery planning and execution for infrastructure layers. Provide leadership in team development, training, and performance management.<br>Required Skills Strong leadership skills and technical expertise in enterprise infrastructure operations. Hands-on experience with one or more of the fields in: OS platforms (Windows Server, Linux, AIX), storage systems, database, virtualization, Open Shift, and networking. Working knowledge of public cloud platforms (Google Cloud Platform, Microsoft Azure, Oracle Cloud Infrastructure) and container/hybrid cloud platforms (Red Hat Open Shift), with the ability to support migration of on-premises workloads to the cloud. Familiarity with backup technologies and basic security practices. Familiarity in monitoring and automation tools. Excellent problem-solving, leadership, and communication skills.<br>Qualifications and Certifications Bachelor’s degree in computer engineering, Information Systems, or related field.10+ years of IT infrastructure experience, with at least 3+ years in a managerial role. Preferred Certifications: VMware VCP-DCV Microsoft Certified: Windows Server Administration Red Hat Certified Engineer (RHCE) ITIL v4 Foundation Networking/Security certifications (CCNP, CISSP) Oracle Certified Professional (OCP) Microsoft Certified: SQL Server Database Administration Red Hat Open Shift Administrator Certification Microsoft Certified: Azure Administrator Associate / Azure Solutions Architect Expert Google Cloud Professional Cloud Architect Oracle Cloud Infrastructure (OCI) Architect Associate
ESPRIMO Srl, società di consulenza informatica che opera dal 2002 su tutto il territorio nazionale ed internazionale, a supporto delle imprese, si colloca nel settore dell’Information Technology proponendosi come obiettivo quello di fornire una vasta gamma di prodotti, servizi e soluzioni nelle aree più strategiche per l’impresa, come: Infrastrutture IT, Content Management, ERP, Business Intelligence, CRM, Web Applications, è alla ricerca di:<br>Senior Enterprise Architect (Technology, Data & Infrastructure) <br>Per un'importante iniziativa strategica legata a EXPO 2030, siamo alla ricerca di professionisti senior di Enterprise Architecture che contribuiranno alla definizione della futura architettura digitale e tecnologica dell'organizzazione.<br>Cerchiamo esperti con una solida esperienza in uno o più dei seguenti ambiti:Technology Architecture Data & Integration Architecture Security & Infrastructure Architecture<br>Principali responsabilitàDefinire la Target Enterprise Architecture e le roadmap evolutive. Disegnare modelli architetturali, standard tecnologici e framework di governance. Garantire interoperabilità, scalabilità, sicurezza e resilienza dell'ecosistema digitale. Supportare l'adozione di tecnologie innovative quali Artificial Intelligence, Advanced Analytics, Intelligent Command Centers, Smart Operations e IoT. Collaborare con stakeholder business e technology per assicurare l'allineamento tra obiettivi strategici e architettura target. Definire architetture di riferimento, linee guida e principi per l'evoluzione delle piattaforme enterprise.<br>Esperienza richiesta Cerchiamo professionisti con comprovata esperienza in almeno uno dei seguenti domini:<br>Technology Architecture Enterprise Architecture Technology Strategy & Roadmap Digital Transformation Enterprise Platforms Integration Frameworks<br>Data & Integration Architecture Enterprise Data Models Data Governance Data Platforms & Analytics Integration Architecture API Management e Data Exchange<br>Security & Infrastructure Architecture Cloud Architecture Infrastructure Strategy Network Architecture Cyber Security Business Continuity e Resilience<br>Requisiti preferenziali Esperienza in programmi di trasformazione complessi o su larga scala. Background in Smart Cities, Mega Events, Public Sector o grandi ecosistemi digitali. Conoscenza delle architetture basate su AI, IoT e Smart Operations. Eccellenti capacità di stakeholder management e comunicazione executive.<br>Sede operativa: Ibrido con disponibilità per trasferta di 3/6 mesi in Arabia Saudita Retribuzione indicativa: P. IVA € 350-450/gg (spese trasferta a parte) Si richiede ottima conoscenza della lingua inglese<br>Si offre un inserimento in un contesto stimolante e innovativo, con grandi prospettive di crescita professionale e una retribuzione commisurata all'esperienza. Si richiede l’invio di Curricula rispondenti al profilo della posizione aperta, verranno presi in considerazione solo quelli effettivamente in possesso dei requisiti sopraindicati. La ricerca è rivolta ad entrambi i sessi (L.903/77). Inviare dettagliato curriculum vitae, con l’autorizzazione al trattamento dei dati personali secondo la Legge 196/2003.
About the Role<br>The Research User Computing Linux Specialist designs, operates, and continuously improves KAUST's Linux-based research end-user computing platforms, including Ubuntu and Rocky Linux endpoints, physical scientific workstations, and virtual scientific workstation services. This role enables secure, reliable, and high-performance access to scientific desktop environments for faculty, researchers, and students.<br>Responsibilities<br>Administer, maintain, and improve Ubuntu and Rocky Linux end-user platforms to provide stable and secure scientific workstation services for KAUST's research and academic communities. Develop, standardize, and maintain Linux workstation builds and images for physical and virtual scientific desktops, ensuring consistency, reliability, and readiness for research use. Manage and support remote scientific workstation platforms, including NICE DCV and Kasm Workspaces, to enable secure, high-performance access to research desktop environments. Automate provisioning, configuration, patching, monitoring, and compliance activities using scripting, configuration management, Infrastructure as Code, and Git Ops-aligned practices. Troubleshoot and resolve complex Linux endpoint, workstation, remote desktop, GPU, driver, performance, identity, storage, and network-related issues, escalating where deeper platform or infrastructure support is required. Integrate Linux desktops and workstations with enterprise IAM, storage, network, monitoring, security, and endpoint management services to support compliant and reliable operations. Partner with faculty, researchers, students, research labs, HPC, storage, security, and advanced computing teams to understand scientific workflows and translate requirements into sustainable workstation solutions. Support installation, validation, and maintenance of scientific and research software on Linux workstation environments, considering compatibility, performance, reproducibility, and user needs. Implement and maintain security and compliance controls for Linux workstation environments, including patching, hardening, audit logging, endpoint security, and alignment with KAUST policies and relevant frameworks. Develop and maintain operational documentation, runbooks, user guidance, dashboards, and service metrics to improve supportability, transparency, and continuous improvement. Evaluate new Linux desktops, remote access, virtualization, automation, and scientific workstation technologies, and provide recommendations to improve service quality and platform capability. Perform other applicable tasks and duties assigned within the realm of the employee's knowledge, skills, and abilities in the field of the position.<br>Qualifications<br>Essential: Bachelor’s degree in computer science, Information Technology, Computer Engineering, Engineering, or a related field. Preferred: Relevant Linux certification such as Red Hat Certified Engineer, Linux Foundation Certified Engineer, LPIC, or equivalent. Certification or formal training in configuration management, automation, security, IT service management, NICE DCV, Kasm Workspaces, or related platforms is desirable. Security, cloud, networking, or endpoint management certifications such as Security+, CISSP, CCNA, ITIL, or equivalent are desirable.<br>Required Skills<br>Strong Linux administration and troubleshooting skills across endpoint, workstation, and scientific desktop environments. Strong automation mindset, with the ability to reduce manual work through scripting, configuration management, Infrastructure as Code, and repeatable operational processes. Good understanding of research and scientific computing needs, including GPU-enabled workstations, specialized software, reproducibility, performance, and secure remote access. Ability to diagnose issues across operating systems, drivers, remote desktop platforms, identity, storage, network, security controls, and user-side configurations. Customer-centric approach, with the ability to work directly with faculty, researchers, students, and technical teams, communicate clearly, and set realistic expectations. Strong documentation and continuous improvement mindset, with the ability to create runbooks, standards, support materials, and operational metrics. Good collaboration skills, with the ability to work effectively with platform, network, security, IAM, storage, HPC, vendor, and research support teams. Awareness of security, compliance, auditability, and operational risk in enterprise and research computing environments. Ability to prioritize work in a deadline-driven research and teaching environment while maintaining service reliability and user trust. Willingness to learn and evaluate new Linux, remote workstation, automation, and scientific computing technologies.<br>Preferred Skills<br>Hands-on experience with remote scientific workstation platforms such as NICE DCV, Kasm Workspaces, or similar technologies. Experience with GPU-enabled Linux workstations, NVIDIA/CUDA environments, scientific software stacks, or specialized research desktop environments. Exposure to security and compliance baselines such as NIST 800-171, NIST 800-53, CIS Benchmarks, ISO standards, or institutional security requirements. Experience working directly with faculty, researchers, students, labs, vendors, and cross-functional IT teams to gather requirements and deliver sustainable technical solutions.
Cipher | سايڤر is a cybersecurity solutions provider based in Riyadh, Saudi Arabia. The company's goal is to simplify the perception of complexity surrounding cybersecurity problems and solutions. Cipher's team of Saudi professionals and experts work tirelessly to develop, customize, and manage digital services and cybersecurity solutions to ensure their peace of mind. Our goal is to provide peace of mind to our clients by making digital security simple and efficient.<br>Key Responsibilities:<br>• Define scope and objectives of penetration tests with clients across systems, applications, and environments.• Perform manual penetration testing on web, mobile, APIs, cloud, and enterprise infrastructure.• Conduct advanced assessments including source code reviews, business logic testing, and red team simulations.• Simulate real-world attacks to evaluate detection and response capabilities.• Identify vulnerabilities, misconfigurations, and security gaps (onsite & remote).• Deliver clear, actionable technical reports with risk and business impact analysis.• Present findings to both technical teams and executive stakeholders.• Provide strategic recommendations to enhance security posture and reduce attack surface.• Stay up to date with emerging threats and frameworks (OWASP, MITRE ATT&CK).<br>Requirements:<br>• Minimum 2+ years of hands-on experience** in penetration testing and cybersecurity.• Bachelor’s degree in computer science, Cybersecurity, IT, or related field.• Certifications such as **OSCP, e WPTX, CRTP** (or equivalent) are highly preferred.• Strong experience across web, mobile, cloud, and infrastructure security testing.• Solid skills in manual vulnerability discovery, code review, and adversary simulation.• Proficiency in scripting (Python, Power Shell, Bash).• Strong analytical, problem-solving, and communication skills.• Ability to translate technical findings into business risks and recommendations.
IBM Resiliency Orchestration L3 Engineer Primary Roles and Responsibilities (R&R) Design & Implementation of Recovery Workflows:Developing and maintaining automated failover and failback processes using over 450 pre-packaged patterns for enterprise applications. Configuring Cyber Incident Recovery (CIR) features, such as immutable WORM storage and air-gapped mechanisms, to protect against malware and ransomware. Advanced Troubleshooting & L3 Support:Serving as the final point of escalation for complex issues within the IBM Resiliency Orchestration software suite. Performing root-cause analysis (RCA) on replication failures or deviations from Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). Automation & Scripting:Developing custom scripts (e.g., Python, Bash, or Ansible) to automate repetitive IT operations and reduce "operational toil". Integrating IBM Resiliency Orchestration with other enterprise security platforms like QRadar SOAR or SIEM , SPLUNK for proactive threat response. Readiness Validation & Compliance:Executing automated, non-disruptive DR drills and "dry runs" to detect environment changes that might cause recovery failures. Generating real-time compliance and audit reports via the centralized dashboard to ensure regulatory requirements are met. Strategic Advisory:Collaborating with SRE and Dev Ops teams to align IBM Concert or RO tools with the organization's broader resilience strategy. Advising on hybrid multicloud infrastructure risks and proactively mitigating potential outage points.<br>Core Technical Requirements<br>Expertise in IBM Infrastructure and hybrid cloud platforms. Proficiency in scripting (Python, Ansible, Terraform) and network protocols. Deep understanding of Copy Data Management and immutable storage technologies.
<p> </p> Job Description <p>Managed.sa is seeking a motivated <strong>GRC Specialist</strong> to support a cybersecurity project based in Jeddah.</p> <p>The ideal candidate will have practical experience in Governance, Risk, and Compliance, with a strong interest in cybersecurity risk management. This role requires working closely with business and technical stakeholders to assess risks, maintain compliance documentation, and support the implementation of cybersecurity controls.</p> Key Responsibilities <ul> <li> Conduct cybersecurity risk assessments and document identified risks. </li> <li> Maintain risk registers, treatment plans, and follow-up actions. </li> <li> Support the development and review of cybersecurity policies, procedures, and standards. </li> <li> Assess compliance with applicable cybersecurity frameworks and regulatory requirements. </li> <li> Identify control gaps and recommend appropriate remediation actions. </li> <li> Collect, organize, and review compliance evidence. </li> <li> Prepare risk and compliance reports for management and project stakeholders. </li> <li> Monitor remediation activities and follow up with relevant teams. </li> <li> Support internal and external cybersecurity audits and assessments. </li> <li> Coordinate with business, IT, cybersecurity, and project stakeholders. </li> </ul><p><strong>Desired Candidate Profile</strong></p><ul> <li> Bachelor s degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related field. </li> <li> Approximately <strong>1.5 3 years of relevant experience</strong> in cybersecurity GRC. </li> <li> Practical experience in cybersecurity risk assessment and risk management. </li> <li> Familiarity with cybersecurity frameworks and standards such as: </li> <ul> <li> NCA ECC </li> <li> ISO 27001 </li> <li> ISO 31000 </li> <li> NIST Cybersecurity Framework </li> </ul> <li> </li> <li> Strong documentation, reporting, and stakeholder communication skills. </li> <li> Ability to work independently and follow up on multiple risk and compliance activities. </li> <li> Professional certifications in GRC, cybersecurity, or risk management are preferred. </li> <li> Availability to work <strong>full-time on-site in Jeddah</strong>. </li> <li> Candidates who can join within a short timeframe will be prioritized. </li> </ul>
Key Responsibilities Contributes to conducting audits and monitoring compliance with cybersecurity-related controls and works to raise awareness of the importance of cybersecurity among all employees of the organization. Contributes to activities for monitoring the implementation of controls and recommendations issued by the National Cybersecurity Authority. Develops processes for preparing, compiling, and sharing periodic reports with the National Cybersecurity Authority. Contributes to conducting periodic audits of cybersecurity procedures within the organization. Develops processes for establishing a framework for compliance management and managing the policy related to exceptions. Develops a mechanism for implementing the compliance review plan for information security controls and ensuring that any identified gaps, if any, are addressed. Contributes to activities aimed at ensuring compliance with relevant national and international laws and regulations related to information security. Develops processes for conducting and evaluating Compromised assessment and disaster response simulations. Contributes to the tasks of supervising and scheduling penetration tests, such as Red Team penetration attempt testing and email phishing simulations, in coordination with the relevant Information Technology department. Contributes to the tasks of supervising the preparation and implementation of cybersecurity incident preparedness exercises (Table Top / Exercise Drill for Cybersecurity incidents), in coordination with the relevant departments within the organization. Develops processes for assessing security awareness among users of the organization's systems. Contributes to developing plans and executive programs to raise security awareness, in coordination with various relevant organizational units within the organization. Develops processes for preparing information security awareness and educational programs and delivering them to the organization's beneficiaries. Contributes to activities for implementing security awareness programs and works on developing them. Develops processes for evaluating technical projects to ensure their compliance with published standards. Adheres to the organization's policies, work behaviors, and procedures specific to the organizational unit. Performs any other tasks assigned by direct supervisors.<br>Required Experience Minimum of 4 years of experience in a relevant field.<br>Education Bachelor’s degree in cybersecurity or any related field.
About the Role<br>The Research User Computing Platforms Lead provides hands-on technical leadership for KAUST’s Linux scientific workstation platform, with responsibility for its architecture, provisioning, configuration, automation, security, and lifecycle management. The role ensures that high-performance Linux workstations and remote workstation services effectively support faculty, researchers, and students across research and teaching activities. While the primary focus is Linux, the role also supervises and provides technical direction to Windows and mac OS engineers supporting the wider end-user computing fleet, ensuring alignment, consistency, and reliable service delivery across platforms.<br>Responsibilities<br>Set the architecture and technical direction for KAUST’s Linux scientific workstation fleet, including configuration management, provisioning, inventory, patching, access control, security, and lifecycle management. Establish infrastructure-as-code, Git Ops, automation, and engineering standards for the Linux platform team, and provide technical direction for the Windows and mac OS endpoint platforms supported by the team. Lead and document build-vs-buy and tooling decisions for provisioning, configuration management, secrets management, observability, and fleet operations, including rationale, risks, and tradeoffs. Own the design and continuous improvement of physical and remote scientific workstation platforms, ensuring secure, high-performance access for faculty, researchers, students, and teaching users. Oversee platform operations, including bare-metal and virtual provisioning, patch orchestration, inventory, drift detection, observability, reliability, and service continuity for active research users. Own the security and compliance posture of the workstation fleet, including host hardening, secrets management, audit logging, compliance baselines, and alignment with frameworks such as NIST 800-171 and CIS Benchmarks. Define hardware standards, refresh cycles, model validation, driver compatibility, firmware and BIOS automation, and lifecycle plans while balancing research priorities, budget constraints, and user disruption. Lead, mentor, supervise, and develop the Linux workstation platform team, including Windows and mac OS engineers, ensuring clear roles, objectives, performance expectations, and shared engineering practices. Serve as the senior technical escalation point for complex platform, provisioning, access-control, hardware, and cross-platform endpoint issues. Work directly with faculty, researchers, students, vendors, and internal IT teams to understand requirements, manage expectations, and translate research and teaching needs into sustainable platform capabilities. Partner with network, security, IAM, storage, and advanced computing teams to deliver integrated, secure, and compliant platform services. Provide regular updates and recommendations to senior IT leadership on platform direction, risks, lifecycle planning, investment needs, and service improvements. Perform other applicable tasks and duties assigned within the realm of the employee’s knowledge, skills, and abilities in the field of the position.<br>Qualifications<br>Essential: Bachelor’s degree in computer science, Information Technology, Engineering, or a related field. Preferred: Master’s degree in a relevant technical or management discipline. Preferred certifications: Red Hat Certified Engineer (RHCE), Linux Professional Institute Certification (LPIC), Puppet Certified Professional or equivalent configuration-management certification. Preferred certifications: Networking or security certification relevant to NAC/802.1X, such as CCNA or Aruba certification; ITIL Foundation or higher; security certifications such as CISSP, CISM, or Comp TIA Security+.<br>Required Skills<br>Extensive experience in Linux systems, infrastructure, endpoint engineering, or platform engineering, with a strong record of owning systems at scale. Hands-on production experience with declarative configuration management, preferably Puppet or Ansible, and a demonstrated infrastructure-as-code and Git Ops mindset using Git workflows, code review, and CI/CD for infrastructure. Experience managing large Linux endpoints or workstation fleets, ideally 500+ endpoints, including Ubuntu and Rocky Linux in enterprise, research, academic, or scientific computing environments. Experience with network-based provisioning, patch management, endpoint security, observability, hardware lifecycle management, firmware/BIOS automation, and security/compliance baselines. Working knowledge of network access control, including 802.1X, RADIUS, certificate-based authentication, endpoint supplicant configuration, and provisioning or break-glass scenarios. Evidence of technical leadership, including setting architecture, making consequential tradeoffs, mentoring engineers, improving engineering practices, and supporting hiring or team development. Experience working directly with faculty, researchers, students, technical teams, vendors, and leadership to gather requirements, manage expectations, and balance competing priorities. Experience supporting high-performance or GPU-enabled scientific computing environments, including NVIDIA/CUDA, performance tuning, and workload-specific desktop requirements.
Job Purpose:<br>The Kafka Streaming Platform Administrator is responsible for administering, securing, monitoring, and optimizing Apache Kafka environments to ensure the availability, scalability, performance, and resilience of enterprise event-streaming platforms. The role supports real-time data integration and streaming workloads by managing Kafka infrastructure, disaster recovery capabilities, capacity planning, platform security, and operational excellence in highly available and regulated environments.<br>Key Accountabilities:<br>Administer, configure, monitor, and maintain Apache Kafka clusters across production and non-production environments. Manage Kafka brokers, topics, partitions, replication factors, retention policies, and cluster performance settings. Implement and maintain platform security controls including TLS encryption, SASL authentication, ACLs, and Kerberos integration. Monitor platform health and availability using observability and monitoring solutions and proactively resolve performance bottlenecks. Configure and maintain monitoring, alerting, logging, and operational dashboards for real-time visibility into platform performance. Plan and execute disaster recovery strategies, backup procedures, multi-cluster replication, and failover testing activities. Perform cluster capacity planning, scaling, performance tuning, upgrades, patching, and maintenance activities. Develop and maintain operational procedures, runbooks, troubleshooting guides, and recovery documentation. Support incident management, root cause analysis (RCA), problem management, and service improvement initiatives. Collaborate with application teams, data engineers, architects, and infrastructure teams to onboard new workloads and optimize cluster utilization. Ensure compliance with security, governance, audit, and operational standards. Support automation initiatives to improve platform deployment, monitoring, and operational efficiency. Contribute to continuous improvement initiatives to enhance platform stability, scalability, and reliability.<br>Minimum Qualifications:<br>Bachelor's Degree in Computer Science, Information Technology, Computer Engineering, or a related field. Confluent Certified Administrator for Apache Kafka or equivalent certification. Additional certifications in Cloud, Linux Administration, Kubernetes, or Data Platforms.<br>Minimum Experience:<br>+4 years of experience administering and supporting Apache Kafka production environments. Proven experience managing Kafka clusters in high-availability and mission-critical environments. Experience in security hardening, monitoring, performance tuning, disaster recovery, and operational support. Experience within banking, financial services, fintech, telecommunications, or other regulated industries. Hands-on experience with enterprise-scale event streaming and real-time data integration platforms.<br>Job-Specific Skills:<br>Apache Kafka Administration and Operations. Kafka Cluster Provisioning, Configuration, and Scaling. Topic, Partition, Replication, and Retention Management. Kafka Security (TLS, SASL, ACLs, Kerberos). Kafka Performance Tuning and Capacity Planning. Disaster Recovery and Multi-Cluster Replication. Mirror Maker and Cluster Linking. Monitoring and Observability Tools (Prometheus, Grafana, Confluent Control Center). Linux Server Administration. Shell Scripting and Automation. Networking Fundamentals (TCP/IP, DNS, Load Balancing, Network Security). Docker and Kubernetes Administration. Cloud Platforms (AWS, GCP, Azure). Incident Management and Root Cause Analysis (RCA). Backup, Recovery, and Business Continuity Planning. IT Operations and Platform Support. Strong troubleshooting and analytical skills. Documentation, reporting, and operational governance.
<h3 >About ******* and the Role</h3>
<p >******* is seeking a <strong >GRC Specialist</strong> to join their team for a cybersecurity project based in Jeddah, Makkah. This is a full-time, on-site position where the specialist will contribute to strengthening the organization's cybersecurity posture.</p> <h3 >Role Overview</h3>
<p >The GRC Specialist will support the cybersecurity project by applying practical experience in Governance, Risk, and Compliance, with a focus on cybersecurity risk management. The role involves close collaboration with business and technical stakeholders to conduct risk assessments, maintain compliance documentation, and facilitate the implementation of cybersecurity controls.</p> <h3 >Key Responsibilities</h3>
<ul >
<li >Conduct cybersecurity risk assessments and document identified risks.</li>
<li >Maintain risk registers, treatment plans, and follow-up actions.</li>
<li >Support the development and review of cybersecurity policies, procedures, and standards.</li>
<li >Assess compliance with applicable cybersecurity frameworks and regulatory requirements.</li>
<li >Identify control gaps and recommend appropriate remediation actions.</li>
<li >Collect, organize, and review compliance evidence.</li>
<li >Prepare risk and compliance reports for management and project stakeholders.</li>
<li >Monitor remediation activities and follow up with relevant teams.</li>
<li >Support internal and external cybersecurity audits and assessments.</li>
<li >Coordinate with business, IT, cybersecurity, and project stakeholders.</li>
</ul> <h3 >Required Qualifications and Experience</h3>
<ul >
<li >Bachelor's degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related field.</li>
<li >Approximately <strong >** years</strong> of relevant experience in cybersecurity GRC.</li>
<li >Practical experience in cybersecurity risk assessment and risk management.</li>
</ul> <h3 >Essential Skills and Attributes</h3>
<ul >
<li >Familiarity with cybersecurity frameworks and standards.</li>
<li >Strong documentation, reporting, and stakeholder communication skills.</li>
<li >Ability to work independently and manage multiple risk and compliance activities.</li>
<li >Professional certifications in GRC, cybersecurity, or risk management are preferred.</li>
</ul> <h3 >Work Environment and Availability</h3>
<p >This role requires full-time, on-site work in Jeddah. Candidates who are available to join within a short timeframe will be given priority.</p>
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>As a Data Protection & Privacy Specialist, you will support the organization's data privacy and protection initiatives by assisting in compliance activities, privacy risk assessments, Data Protection Impact Assessments (DPIAs), policy development, and awareness programs. You will collaborate with internal stakeholders to ensure personal data is processed securely and in accordance with applicable regulations. Key Responsibilities Support compliance with applicable data protection and privacy regulations, including the Saudi Personal Data Protection Law (PDPL) and NCA Data Cybersecurity Controls (DCC). Assist in identifying and assessing privacy risks associated with business processes and data processing activities. Support the development, review, and maintenance of privacy policies, procedures, and standards. Contribute to the implementation and continuous improvement of the organization's Data Protection & Privacy Program. Assist in investigating privacy incidents and documenting findings and corrective actions. Support the execution of Data Protection Impact Assessments (DPIAs). Participate in privacy awareness campaigns and employee training programs. Coordinate with business units, Legal, IT, and external stakeholders to support compliance initiatives. Assist in data classification and governance activities. Monitor changes in privacy regulations and recommend improvements where appropriate. Prepare reports and documentation related to privacy compliance and governance activities.</p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><p>Bachelor's degree in Cybersecurity, Information Security, Computer Engineering, Systems Engineering, Telecommunications Engineering, Information Technology, or a related field. Minimum one year of experience in Cybersecurity, Data Protection, Privacy Compliance, Information Security, or completion of a Tamheer program in Data Protection & Privacy. Understanding of Saudi Personal Data Protection Law (PDPL). Familiarity with NCA Data Cybersecurity Controls (DCC). Knowledge of privacy principles, data classification, and information governance. Understanding of Data Protection Impact Assessments (DPIAs) is preferred. Professional certifications in cybersecurity or data privacy (e.g., CDPSE, CIPM, CIPT, CIPP/E, ISO 27701, Security+) are an advantage. What We're Looking For Strong analytical and critical thinking skills. Excellent attention to detail. Effective communication and stakeholder engagement. Strong organizational and documentation skills. Ability to work collaboratively across departments. Passion for privacy, compliance, and continuous learning.</p><p></p></section>
Saudi Infra Operations Manager | Riyadh, Saudi Arabia Lead and manage 24x7 operations for Webex infrastructure across Saudi Arabia, ensuring high availability, resilience, and operational excellence for data centre environments. Key Responsibilities Lead and develop the Saudi Operations team, ensuring effective monitoring, incident response, on-call support, and operational readiness. Own availability, reliability, and performance of regional network, data centre, and AWS cloud infrastructure. Drive incident management, root cause analysis, problem resolution, and service restoration activities. Ensure safe execution of infrastructure, network, and cloud changes with proper risk assessment and rollback planning. Partner with global engineering, SRE, security, facilities, vendors, and service owners to improve operational resilience.<br>Required Skills & Experience7+ years of experience in infrastructure, network, cloud, data centre, or SRE operations.2+ years leading technical teams in a 24x7 production environment. Strong expertise in networking (BGP, DNS, routing, switching, firewalls, WAN). Experience with AWS cloud services, monitoring, incident management, and operational reporting. Preferred Experience with Webex, collaboration, or real-time communication platforms. Kubernetes, automation, Infrastructure as Code (IaC), and SRE practices. AWS, Cisco, ITIL, or related certifications. Location: Saudi Arabia (Riyadh/Jeddah) Work Environment: Fast-paced operational leadership role supporting critical customer-facing infrastructure.
SAUDI ONLY<br><br>Job Description: The GRC Consultant supports the delivery of Governance, Risk, and Compliance (GRC) services, assisting senior team members in executing client projects.<br>Responsibilities: · Assist in gathering and analyzing data for GRC assessments.· Support the preparation of assessment reports, governance documentation, and client presentations.· Lead the preparation and execution of external audits for ISO 27001 and SOC 2 (Type 1 & 2) certifications.· Manage compliance with local Saudi regulations, specifically NCA ECC and SAMA cybersecurity frameworks, also perform assessments for different frameworks (e.g., ISO 27001, NDI Controls, NCA-Frameworks- ECC, CSCC, DCC, TCC & OSMACC, and other best practices.· Collaborate with senior consultants on the development and implementation of policies, procedures, frameworks, etc.· Develop and implement policies, procedures, and controls that ensure compliance with laws, regulations, and industry standards.· Participate in client workshops and project meetings.· Liaise with cross-functional teams (GRC, IT, legal, audit, operations) to support secure and compliant business operations.· Assist in the selection and implementation of GRC software solutions to automate processes and improve reporting capabilities.· Stay informed about industry trends, regulatory changes, and emerging risks to provide proactive advice to clients.· Evaluate third-party vendors for compliance with security standards and risk management requirements.· Provide input into enterprise risk management processes from a cybersecurity perspective.· Track and report key GRC metrics and issues to stakeholders and executive leadership.<br>Minimum Requirements: Bachelor's degree in Cybersecurity, Information Technology, or related fields.· Basic understanding of cybersecurity concepts, Internal Audit, Risk management, and compliance standards along with 5-6 years of relevant experience· Certifications such as CISM /CISSP, Comp TIA Security+, ISO 27001 Lead Implementor, SSCP & ITIL or equivalent are a plus.· Experience with GRC platforms & ITSM knowledge is plus<br>Competencies:· Strong analytical and problem-solving skills.· Effective communication skills (verbal and written).· Attention to detail in documentation and reporting.· Team-oriented mindset with a proactive attitude.
Lead the organization's Vulnerability Management program and strategy. Oversee vulnerability scanning, assessment, prioritization, and remediation activities. Monitor remediation progress and enforce agreed SLAs. Coordinate with IT, Cloud, Infrastructure, Application, and Security teams to address vulnerabilities. Manage critical and zero-day vulnerability response activities. Develop KPIs, dashboards, and executive reports on vulnerability risk and remediation status. Support audits, compliance assessments, and cybersecurity governance requirements. Lead and mentor the Vulnerability Management team and manage relevant vendors. <br><br>Requirements<br><br>Bachelor's degree in Cybersecurity, IT, Computer Science, or related field.<br><br>8+ years of cybersecurity experience, including 4+ years in Vulnerability Management or Security Operations.<br><br>Hands-on experience with Tenable, Qualys, Rapid7, Microsoft Defender, or similar tools.<br><br>Strong understanding of vulnerability management, risk management, cloud security, and patch management.<br><br>Preferred certifications: CISSP, CISM, CRISC, or GIAC.
Responsibilities:Manage and execute comprehensive third-party and vendor risk assessments from onboarding through ongoing monitoring. Ensure strict alignment and compliance with the SAMA Outsourcing Framework and other relevant financial regulatory requirements. Conduct detailed cybersecurity due diligence, contract reviews, and compliance monitoring across all vendor risk tiers. Lead remediation tracking for critical vendor findings and continuously improve risk scoring frameworks and methodologies. Prepare, analyze, and present structured vendor risk reports for executive management and regulatory authorities.<br>Qualifications:Experience: 8+ years of dedicated professional experience specializing in third-party risk assessment and management, ideally within a regulated financial institution or regional banking environment. Education: Bachelor’s degree in information systems, Master of Business Administration (MBA), or a closely related field. Certifications: Professional certifications such as ISO 27001 Lead Auditor or CISM (Certified Information Security Manager) are highly preferred. Core Expertise: Deep knowledge of vendor due diligence, SAMA requirements, contract compliance, risk reporting, and mitigation strategies.
For one of our clients, we are looking for a Senior IAM Consultant specializing in Sail Point IIQ to support the design, implementation, and enhancement of enterprise Identity Governance and Access Management solutions.<br>Key Responsibilities and Tasks Design, configure, and support Sail Point Identity IQ and Identity Governance solutions. Implement RBAC models, roles, entitlements, SoD policies, and access certification campaigns. Automate Joiner-Mover-Leaver (JML) lifecycle processes, provisioning, and deprovisioning. Develop and maintain Sail Point IIQ workflows, rules, forms, approval processes, and Bean Shell logic. Onboard and integrate applications using Web Services, JDBC, Delimited File, and other connectors. Configure identity and entitlement aggregation, account correlation, lifecycle events, and provisioning policies. Troubleshoot Sail Point IIQ workflows, integrations, provisioning issues, and aggregation failures. Support IAM audits, compliance requirements, access reviews, and security controls. Collaborate with application owners, business stakeholders, HR, infrastructure, security, and compliance teams. Prepare technical documentation, test cases, deployment plans, and operational procedures. Support production environments and ensure timely resolution of incidents and service requests. Contribute to automation, platform stability, and continuous improvement initiatives. Support File Access Management activities, including file-share onboarding and access visibility, where required.<br>Requirements :Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.5+ years of hands-on experience with Sail Point Sail Point IIQStrong experience in IAM, Identity Governance, access management, and compliance controls. Practical experience with RBAC, SoD, access certifications, and JML lifecycle automation. Hands-on experience developing Sail Point IIQ workflows and rules using Bean Shell and Java. Experience onboarding applications and configuring connectors, including Web Services, JDBC, and Delimited File. Knowledge of identity correlation, account and entitlement aggregation, provisioning, deprovisioning, and reconciliation. Experience troubleshooting Sail Point IIQ issues in enterprise or production environments. Familiarity with SQL, XML, REST/SOAP APIs, Active Directory, LDAP, or similar technologies. Experience working with business and technical stakeholders in a client-facing or consulting environment. Strong analytical, problem-solving, documentation, and communication skills. Sail Point certification, such as Sail Point IIQ Engineer, is an advantage. Experience with File Access Management, Net App, Cyber Ark, Sail Point upgrades, or migrations is an advantage.