Security inspector Jobs in Saudi
9061 Jobs Found
We are seeking experienced SIEM Security Operations Engineers to support enterprise cybersecurity monitoring, threat detection, incident analysis, and vulnerability management initiatives within a highly secure cloud environment.<br>The successful candidates will play a key role in deploying and operating the organization's Security Information and Event Management (SIEM) platform, integrating security products, monitoring security events, investigating alerts, and coordinating vulnerability remediation activities across cloud services and enterprise infrastructure.<br>This role is ideal for cybersecurity professionals with hands-on experience in SIEM operations, Security Operations Center (SOC) environments, log analysis, security monitoring, and vulnerability management who are passionate about strengthening enterprise cyber resilience. You will work closely with cybersecurity engineers, cloud teams, product development teams, and regulatory stakeholders to enhance security monitoring capabilities, improve threat detection, and ensure timely response to security incidents.<br>Key Responsibilities Assist in the deployment, configuration, and ongoing operation of the enterprise SIEM platform. Integrate security logs from enterprise security solutions including WAF, HIDS, DDoS protection systems, cloud platforms, and other security technologies. Configure and optimize SIEM correlation rules, alert logic, dashboards, and detection use cases. Monitor security events, investigate alerts, and perform initial triage of potential security incidents. Analyze logs to identify suspicious activities, indicators of compromise (IOCs), and emerging security threats. Escalate validated security incidents to the appropriate cybersecurity or engineering teams for remediation. Manage and track security vulnerability tickets for cloud services and enterprise platforms. Validate reported vulnerabilities, coordinate remediation with engineering teams, and perform post-remediation verification. Assist in improving detection capabilities by tuning alert rules and reducing false positives. Support security compliance initiatives and maintain operational documentation. Conduct technical demonstrations and explain cybersecurity solutions during regulatory reviews, audits, or customer engagements. Collaborate with cloud, infrastructure, application, and security teams to continuously improve enterprise security posture. Stay up to date with emerging cyber threats, attack techniques, and security best practices.<br>Required Qualifications Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Security, or a related field. Minimum 2 years of professional experience in SIEM Security Operations, SOC Operations, Cybersecurity Monitoring, or Information Security. Saudi National. Hands-on experience operating SIEM platforms in enterprise environments. Experience with security log collection, correlation, analysis, and alert investigation. Good understanding of cybersecurity threats, attack techniques, indicators of compromise (IOCs), and security monitoring. Experience in vulnerability management and remediation workflows. Familiarity with enterprise security technologies such as:Web Application Firewall (WAF) Host Intrusion Detection Systems (HIDS) DDoS Protection Cloud Security Platforms Strong analytical and troubleshooting skills. Good written and verbal communication skills in English.<br>Preferred Qualifications Experience working within a Security Operations Center (SOC). Knowledge of cloud security concepts and cloud-native security services. Understanding of AI Security or Cloud Security technologies. Knowledge of Saudi Arabia cybersecurity regulations and compliance frameworks (e.g., NCA ECC, SAMA Cybersecurity Framework, PDPL). Experience presenting technical security concepts to auditors, regulators, or customers. Participation or recognition in cybersecurity competitions (e.g., CTFs, hacking competitions). Relevant cybersecurity certifications such as:Comp TIA Security+Comp TIA CySA+GIAC Certifications CEHSplunk Core Certified User/Power User Microsoft SC-200Google Professional Cloud Security Engineer (advantage) ISC2 CC or CISSP (advantage)
???? We’re Hiring | Cybersecurity & Infrastructure Security Specialist<br>Company: [Masharah Company]<br>We are looking for an experienced Cybersecurity & Infrastructure Security Specialist to take ownership of the company’s cybersecurity requirements, security architecture, risk management, and overall security posture.<br>This role will serve as the company’s technical security authority and primary security representative when dealing with external cybersecurity, infrastructure, network, and technology service providers.<br>The successful candidate will be responsible for identifying security risks and gaps, defining the required security controls, evaluating and selecting appropriate solutions, leading technical discussions with service providers, overseeing implementation, and validating that the delivered environment meets the company’s security requirements.<br>???? Key Responsibilities<br>* Own and continuously assess the company’s overall cybersecurity and infrastructure security posture.* Conduct security assessments and identify security gaps, risks, vulnerabilities, and areas requiring improvement.* Define cybersecurity requirements, security controls, and technical security standards.* Develop and review security architecture covering: * Network Security * Firewalls / NGFW * Network Segmentation * DMZ / WAF * VPN / ZTNA * Servers & Virtualization * Identity & Access Management * EDR/XDR * SIEM / SOC * Backup & Disaster Recovery * Application & Data Security* Develop cybersecurity and infrastructure security requirements for external service providers.* Identify, evaluate, and recommend appropriate cybersecurity technologies and solutions.* Lead technical meetings and discussions with cybersecurity, network, infrastructure, and other service providers.* Challenge and evaluate vendors’ proposed architectures, technologies, configurations, and security recommendations.* Review security architecture, HLDs, LLDs, technical proposals, BoQs, and implementation plans.* Oversee security implementation and ensure agreed security requirements and controls are correctly implemented.* Validate and test security controls before accepting implemented solutions.* Establish and oversee vulnerability management and remediation processes.* Coordinate penetration testing and security assessments and ensure findings are properly remediated.* Define and oversee security monitoring, logging, SIEM/SOC, EDR/XDR, and alerting requirements.* Establish incident response, containment, recovery, and security incident-handling requirements.* Define and review IAM, MFA, RBAC, PAM, privileged access, and network access-control requirements.* Ensure appropriate security hardening and secure configuration of infrastructure and security systems.* Review Git Hub, CI/CD, Dev Sec Ops, and application security practices where applicable.* Review backup, disaster recovery, business continuity, RTO/RPO, and ransomware-resilience requirements.* Assess data protection, data residency, and cross-border data-transfer considerations.* Identify applicable Saudi cybersecurity and data protection requirements and support compliance efforts.* Maintain cybersecurity policies, standards, risk registers, security architecture, and technical documentation.* Provide management with regular updates on security risks, gaps, priorities, and remediation progress.* Act as the primary technical security representative between the company and external service providers.<br>???? Requirements<br>* 3–5+ years of professional experience in Cybersecurity, Infrastructure Security, Network Security, Security Engineering, or a closely related field.* Strong practical understanding of cybersecurity principles and security architecture.* Demonstrated experience conducting security assessments and identifying security gaps and risks.* Strong knowledge of network security, including: * Firewalls / NGFW * IPS/IDS * Network segmentation * VLANs * DMZ * VPN / ZTNA * Secure remote access* Good understanding of server, virtualization, endpoint, and infrastructure security.* Knowledge of IAM, MFA, RBAC, PAM, and privileged-access management.* Experience or strong understanding of EDR/XDR, SIEM, SOC, security monitoring, and centralized logging.* Understanding of WAF and web/application security.* Knowledge of vulnerability management and penetration-testing processes.* Understanding of backup, disaster recovery, business continuity, RTO/RPO, and ransomware resilience.* Familiarity with Git Hub, CI/CD, Dev Sec Ops, and application security is a strong advantage.* Ability to review, evaluate, and challenge technical architectures, security designs, configurations, and vendor proposals.* Strong experience communicating with technical stakeholders, vendors, and service providers.* Strong analytical and problem-solving skills.* Ability to work independently and take ownership of cybersecurity requirements and decisions.* Strong written and verbal communication skills in English.* Arabic communication skills are a plus.<br>???? Preferred Certifications<br>The following certifications are considered a strong advantage:<br>* CISSP / CISM* Security+* CCNA / CCNP* Palo Alto Networks certifications* Fortinet certifications* ISO 27001-related certifications* Other relevant cybersecurity or infrastructure security certifications<br>???? What We’re Looking For<br>We are looking for someone who can own cybersecurity from the company’s side, rather than simply coordinate between vendors.<br>The ideal candidate should be capable of:<br>Identify → Assess → Design → Recommend → Lead → Implement → Validate → Improve<br>You should be comfortable moving between management-level discussions and detailed technical discussions with cybersecurity and infrastructure engineers.<br>You will be expected to independently assess proposed solutions, identify security gaps, challenge vendors when necessary, and ensure that the company’s security requirements are properly addressed.<br>???? Position Details<br>Location: Jeddah, Saudi Arabia Work Model: Hybrid : (Remote/attendance) based on work needs.(Expected) Onsite Attendance: Typically once/twice per week in Jeddah, with additional attendance when required for important meetings, vendor discussions, implementation activities, assessments, audits, or other business needs. Employment Type: Full-Time<br>???? To Apply: Please send your CV,To [office@masharah.com]<br>Please share this opportunity with anyone who may be a suitable candidate.
Key Responsibilities:✅ Monitor security alerts and manage Security Information and Event Management (SIEM) tools✅ Perform vulnerability assessments and coordinate remediation activities✅ Manage firewalls, endpoint protection, antivirus, and intrusion detection systems✅ Conduct regular security audits and risk assessments across the IT landscape✅ Investigate and respond to security incidents and security breaches✅ Support SAP security roles, authorizations, and compliance controls✅ Implement and enforce security policies, standards, and best practices✅ Coordinate security patching and system upgrades with vendors and internal teams✅ Conduct cybersecurity awareness training and phishing simulation exercises✅ Maintain security documentation, audit records, and incident reports<br><br><br>Qualifications:✔ Bachelor's degree in Cyber Security, Information Technology, Computer Science, or a related field✔ 3+ years of experience in cybersecurity, security operations, or a similar role✔ Hands-on experience with SIEM solutions, vulnerability management, and incident response✔ Strong knowledge of network security, firewalls, IDS/IPS, endpoint security, and threat detection✔ Familiarity with cybersecurity frameworks and compliance standards✔ Experience with SAP security administration is an advantage✔ Security certifications such as Security+, CEH, CISSP, CISM, or equivalent are preferred
<p > </p>
<table class="MsoNormalTable" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr >
<td colspan="6" valign="top">
<p ><strong><span >Job Description </span></strong></p>
</td>
</tr>
<tr >
<td colspan="6" valign="top">
<p ><strong><span >OVERVIEW</span></strong></p>
</td>
</tr>
<tr >
<td valign="top">
<p ><strong><span >Job Title</span></strong></p>
</td>
<td valign="top">
<p ><span >Consultant</span></p>
</td>
<td valign="top">
<p ><strong><span >Job Code</span></strong></p>
</td>
<td valign="top">
<p ><span >680865</span></p>
</td>
<td valign="top">
<p ><strong><span >Grade</span></strong></p>
</td>
<td valign="top">
<p ><span >I3</span></p>
</td>
</tr>
<tr >
<td valign="top">
<p ><strong><span >Group</span></strong></p>
</td>
<td valign="top">
<p ><em><span dir="RTL" >-</span></em></p>
</td>
<td valign="top">
<p ><strong><span >Division</span></strong></p>
</td>
<td colspan="3" valign="top">
<p ><span >Legal, Risk & Governance</span></p>
</td>
</tr>
<tr >
<td valign="top">
<p ><strong><span >Department</span></strong></p>
</td>
<td valign="top">
<p ><span >Cybersecurity</span></p>
</td>
<td valign="top">
<p ><strong><span >Unit</span></strong></p>
</td>
<td colspan="3" valign="top">
<p ><span >Application Security</span></p>
</td>
</tr>
</tbody>
</table>
<p ><span > </span></p>
<table class="MsoNormalTable" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top">
<p ><strong><span >ROLE PURPOSE</span></strong></p>
<p ><em><span >The aim is to state the overall significance of the job from the organization’s perspective.</span></em></p>
</td>
</tr>
<tr >
<td valign="top">
<p ><span >The role exists to perform application security assessments and support the integration of security throughout the software development lifecycle by identifying application vulnerabilities, conducting code and design reviews, assessing APIs and integrations, and providing security guidance to development teams to strengthen the security of Elm's applications and digital solutions.</span></p>
</td>
</tr>
</tbody>
</table>
<p > </p>
<table class="MsoNormalTable" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr >
<td colspan="2" valign="top">
<p ><strong><span >KEY ACCOUNTABILITIES & ACTIVITIES</span></strong></p>
<p ><em><span >This section describes <u>the principal outputs</u> required from the job.</span></em></p>
</td>
</tr>
<tr >
<td >
<p ><strong><span >Key Accountabilities</span></strong></p>
</td>
<td >
<p ><strong><span >Key Activities</span></strong></p>
</td>
</tr>
<tr >
<td >
<ol >
<li ><span >Application Security Assessment</span></li>
</ol>
</td>
<td >
<ul >
<li ><span >Perform security assessments for applications and digital solutions.</span></li>
<li ><span >Evaluate applications against approved security requirements and standards.</span></li>
<li ><span >Document identified vulnerabilities, risks, and recommended remediation actions.</span></li>
</ul>
</td>
</tr>
<tr >
<td >
<ol start="2">
<li ><span >Secure Code Review</span></li>
</ol>
</td>
<td >
<ul >
<li ><span >Conduct security-focused source code reviews to identify vulnerabilities and insecure coding practices.</span></li>
<li ><span >Assess code against secure coding standards and common application security risks.</span></li>
<li ><span >Provide remediation guidance to development teams.</span></li>
</ul>
</td>
</tr>
<tr >
<td >
<ol start="3">
<li ><span >Threat Modeling</span></li>
</ol>
</td>
<td >
<ul >
<li ><span >Conduct threat modeling for new and existing applications and services.</span></li>
<li ><span >Identify potential attack scenarios, threats, and security control gaps.</span></li>
<li ><span >Recommend security controls based on identified risks.</span></li>
</ul>
</td>
</tr>
<tr >
<td >
<ol start="4">
<li ><span >Application Vulnerability Management</span></li>
</ol>
</td>
<td >
<ul >
<li ><span >Identify, analyze, and assess application-layer vulnerabilities.</span></li>
<li ><span >Coordinate with development teams on vulnerability remediation activities.</span></li>
<li ><span >Validate remediation and monitor outstanding application security findings.</span></li>
</ul>
</td>
</tr>
<tr >
<td >
<ol start="5">
<li ><span >API & Integration Security</span></li>
</ol>
</td>
<td >
<ul >
<li ><span >Assess APIs, microservices, and third-party integrations for cybersecurity risks.</span></li>
<li ><span >Evaluate authentication, authorization, data protection, and integration controls.</span></li>
<li ><span >Recommend appropriate security improvements.</span></li>
</ul>
</td>
</tr>
<tr >
<td >
<ol start="6">
<li ><span >Secure Design & Development Advisory</span></li>
</ol>
</td>
<td >
<ul >
<li ><span >Provide security guidance to development and engineering teams throughout the development lifecycle.</span></li>
<li ><span >Support the application of secure design and development practices.</span></li>
<li ><span >Recommend security controls appropriate to solution risks and requirements.</span></li>
</ul>
</td>
</tr>
<tr >
<td >
<ol start="7">
<li ><span >Application Security Standards & Frameworks</span></li>
</ol>
</td>
<td >
<ul >
<li ><span >Develop and maintain application security standards, guidelines, and technical requirements.</span></li>
<li ><span >Support alignment with secure software development practices and applicable cybersecurity standards.</span></li>
<li ><span >Evaluate emerging application security practices and recommend enhancements.</span></li>
</ul>
</td>
</tr>
<tr >
<td >
<ol start="8">
<li ><span >Developer Security Awareness</span></li>
</ol>
</td>
<td >
<ul >
<li ><span >Support secure coding awareness and technical security training for developers.</span></li>
<li ><span >Develop security guidance and knowledge materials addressing common application vulnerabilities.</span></li>
<li ><span >Promote secure development practices across engineering teams.</span></li>
</ul>
</td>
</tr>
<tr >
<td >
<ol start="9">
<li ><span >Policies, Processes & Procedures</span></li>
</ol>
</td>
<td >
<ul >
<li ><span >Follow all relevant departmental policies, processes, standard operating procedures, and instructions so that work is carried out in a controlled and consistent manner.</span></li>
<li ><span >Comply with all relevant safety, quality, and environmental management policies, procedures, and controls to ensure a healthy and safe work environment.</span></li>
</ul>
</td>
</tr>
<tr >
<td >
<ol start="10">
<li ><span >Information Security</span></li>
</ol>
</td>
<td >
<ul >
<li ><span >Comply with all relevant information security practices and standards to ensure data integrity and confidentiality.</span></li>
</ul>
</td>
</tr>
</tbody>
</table>
<p > </p>
<p > </p>
<table class="MsoNormalTable" border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" valign="top">
<p ><strong><span >JOB SPECIFICATIONS</span></strong></p>
</td>
</tr>
<tr>
<td valign="top">
<p ><strong><span >Academic and professional qualifications</span></strong></p>
</td>
<td >
<ul >
<li ><span >Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Computer Engineering, or a related field.</span></li>
<li ><span >Professional certifications in Application Security, Secure Software Development, or related cybersecurity disciplines are considered an advantage.</span></li>
</ul>
</td>
</tr>
<tr>
<td valign="top">
<p ><strong><span >Years and Nature of Experience</span></strong></p>
</td>
<td >
<ul >
<li ><span >4–6 years of experience in application security, secure software development, security assessments, vulnerability management, or related cybersecurity domains.</span></li>
</ul>
</td>
</tr>
</tbody>
</table>
<p > </p>
<p > </p>
</span>
Position: Security Supervisor Contract Duration: September 2026 – February 2027Location: Jeddah, Saudi Arabia<br>We are hiring a Security Supervisor to support security operations for a high-profile international sporting event in Saudi Arabia. This is a site-based operational role responsible for coordinating day-to-day security activities and supporting the delivery of a safe and secure environment for athletes, officials, staff, spectators, and other event stakeholders.<br>???? Key Responsibilities Coordinate day-to-day security operations across event venues and operational areas Liaise with security personnel, contractors, event teams, venue management, and relevant authorities Support the implementation of security plans, procedures, and access control measures Coordinate security staffing, deployment, briefings, and daily operational requirements Monitor access control points, restricted areas, screening operations, and security checkpoints Support crowd management, incident response, and emergency procedures Assist with security risk assessments and identify potential operational risks Maintain accurate security logs, incident reports, daily activity reports, and documentation Escalate security incidents and operational concerns to the Security Manager and relevant stakeholders Ensure security procedures are implemented in line with event protocols, local regulations, and international standards Attend operational meetings and security briefings as required Support pre-event preparations, venue readiness checks, rehearsals, and event-time operations Assist with post-event reporting, debriefs, and recommendations for improvement???? Requirements Bachelor’s degree or relevant qualification in Security Management, Law Enforcement, Risk Management, or a related field Proven experience in a security coordination or operational security role, preferably within large-scale events, sports, venues, or public environments Experience working in high-profile or international sporting events is highly desirable Strong coordination, communication, and organizational skills Ability to work effectively with security teams, contractors, government authorities, and event stakeholders Understanding of access control, crowd management, incident reporting, and emergency procedures Good knowledge of security operations and event security protocols Ability to remain calm and effective in a fast-paced, high-pressure environment Strong attention to detail and ability to manage multiple operational requirements Fluent in Arabic and English Previous experience working with police, military, government authorities, or major event security operations is an advantage
Security Architecture Analyst(Secure‑by‑Design • Cloud Security • Enterprise Architecture)<br>we are seeking an experienced Security Architecture Analyst to join their cybersecurity and enterprise architecture function in Riyadh. This is a fully on‑site role supporting secure‑by‑design governance across cloud and on‑prem environments.<br>Role Summary The Security Architecture Analyst will ensure that all technology projects and platforms follow approved security architecture standards, secure‑by‑design principles, and regulatory requirements. The role requires deep expertise in cloud security patterns, secure design reviews, and enterprise‑grade architecture governance.<br>Key Responsibilities Security Architecture Reviews - Conduct security architecture assessments for new projects, major changes, and cloud deployments (OCI, microservices, APIs, data platforms). Secure Design Patterns - Develop and maintain enterprise security design patterns and reference architectures covering network segmentation, IAM, encryption, API security, and data protection. Cloud Security Architecture - Define secure configurations for OCI services, including identity models, network security groups, encryption, and key management. Dev Sec Ops Integration - Embed security controls into CI/CD pipelines (SAST, dependency scanning, container security, IaC validation). Technology Evaluation - Support evaluation and selection of security technologies and ensure architectural alignment. Cross‑Functional Collaboration - Work with SOC, GRC, and Enterprise Architecture teams to ensure monitoring and governance requirements are built into solution designs. Architecture Governance - Participate in architecture review boards and document decisions, risks, and required design adjustments. Documentation & Reporting - Produce high‑quality architecture review reports, diagrams, and design rationales.<br>Minimum Experience & Qualifications7+ years of experience in security architecture, secure‑by‑design reviews, and enterprise security frameworks. Strong expertise in cloud security (preferably OCI), microservices, API security, and data protection. Deep knowledge of network segmentation, IAM, encryption, and secure third‑party integration. Experience integrating security into Dev Ops/CI‑CD pipelines. Strong documentation and architectural governance discipline. Preferred Certifications Cloud security certifications (OCI, AWS, Azure) SABSA, TOGAF, CCSK, CCSP, or equivalent architecture/security certifications<br>Work Model???? On‑site in Riyadh Due to the sensitivity of architecture governance and secure‑by‑design processes, this role requires full on‑site presence
Security Architecture Analyst(Secure‑by‑Design • Cloud Security • Enterprise Architecture)<br>we are seeking an experienced Security Architecture Analyst to join their cybersecurity and enterprise architecture function in Riyadh. This is a fully on‑site role supporting secure‑by‑design governance across cloud and on‑prem environments.<br>Role Summary The Security Architecture Analyst will ensure that all technology projects and platforms follow approved security architecture standards, secure‑by‑design principles, and regulatory requirements. The role requires deep expertise in cloud security patterns, secure design reviews, and enterprise‑grade architecture governance.<br>Key Responsibilities Security Architecture Reviews - Conduct security architecture assessments for new projects, major changes, and cloud deployments (OCI, microservices, APIs, data platforms). Secure Design Patterns - Develop and maintain enterprise security design patterns and reference architectures covering network segmentation, IAM, encryption, API security, and data protection. Cloud Security Architecture - Define secure configurations for OCI services, including identity models, network security groups, encryption, and key management. Dev Sec Ops Integration - Embed security controls into CI/CD pipelines (SAST, dependency scanning, container security, IaC validation). Technology Evaluation - Support evaluation and selection of security technologies and ensure architectural alignment. Cross‑Functional Collaboration - Work with SOC, GRC, and Enterprise Architecture teams to ensure monitoring and governance requirements are built into solution designs. Architecture Governance - Participate in architecture review boards and document decisions, risks, and required design adjustments. Documentation & Reporting - Produce high‑quality architecture review reports, diagrams, and design rationales.<br>Minimum Experience & Qualifications7+ years of experience in security architecture, secure‑by‑design reviews, and enterprise security frameworks. Strong expertise in cloud security (preferably OCI), microservices, API security, and data protection. Deep knowledge of network segmentation, IAM, encryption, and secure third‑party integration. Experience integrating security into Dev Ops/CI‑CD pipelines. Strong documentation and architectural governance discipline. Preferred Certifications Cloud security certifications (OCI, AWS, Azure) SABSA, TOGAF, CCSK, CCSP, or equivalent architecture/security certifications<br>Work Model???? On‑site in Riyadh Due to the sensitivity of architecture governance and secure‑by‑design processes, this role requires full on‑site presence
Security Expert <br>Experience: 10 Years Location: Saudi Arabia ( On-Site )<br>Job Description<br>We are looking for an experienced Security Expert with strong expertise in security requirement assessment, Role-Based Access Control (RBAC), authorization design, and access governance.<br>Key Responsibilities<br>Assess security requirements across all in-scope work packages. Design and implement RBAC, roles, and authorization structures. Define secure access models aligned with business and enterprise security standards. Support access provisioning, security testing, compliance, and audit requirements. Identify security risks and recommend appropriate controls. Collaborate with business, functional, and technical teams on security design and implementation.<br>Mandatory Skills<br>Strong hands-on experience in Security Architecture / Security Design. Strong expertise in RBAC, Role Design, Authorization, and Access Control. Experience in IAM, Access Governance, and security requirement assessment. Good understanding of SoD, security compliance, and risk management. Excellent communication and stakeholder management skills.
Role Purpose:The IT Security Lead is responsible for implementing and managing ASD’s enterprise information security programme to protect its systems, data, and digital assets from cyber threats and ensure regulatory compliance. The role establishes and matures the organization's security posture through policy, technology, and awareness — with a specific focus on securing the SAP S/4HANA programme environment, Microsoft platforms, cloud infrastructure, and operational technology. The Security Lead operates within the B-ITSC governance framework and reports on security risk to executive leadership and the board.<br>Key Accountabilities:Own ASD’s information security strategy, policy framework, and security roadmap. Coordinate and maintain information security policies, standards, and procedures. Produce quarterly security risk reports for the IT Operations Manager. Conduct annual information security risk assessments; maintain the enterprise security risk register and treatment plans. Ensure compliance with applicable regulations including PDPL (Saudi Personal Data Protection Law), GDPR, and NCA ECC framework. Collaborate with the Security Operations Centre (SOC) function, monitoring and alerting. Lead incident response activities; own the Incident Response Plan and Playbooks for P1/P2 cyber security events. Manage threat intelligence feeds and vulnerability management programme; prioritize patching based on risk exposure. Conduct regular penetration testing, red team exercises, and security assessments; remediate findings within agreed SLAs. Oversee endpoint detection and response (EDR) using Microsoft Defender for Endpoint across all ASD devices. Manage Business Continuity Planning (BCP) and Disaster Recovery (DR) for cyber event scenarios. Define and govern the SAP S/4HANA security architecture including role-based access control, segregation of duties (SoD), and audit logging. Review SAP security design deliverables produced by the system integrator; validate against ASD’s security standards. Conduct SoD conflict analysis during UAT and prior to go-live; ensure remediation before production cutover. Manage security requirements for all application systems: Sales Buzz, Sales Code, Shelfr, SO99, and third-party Saa S. Collaborate with AFG, ASD’s Identity and Access Management (IAM) programme including Privileged Access Management (PAM) and Zero Trust implementation. Govern user provisioning, de-provisioning, and access certification processes across all systems including SAP and M365. Manage Azure Active Directory / Entra ID security configuration: MFA, Conditional Access, PIM, and identity protection. Define and enforce least-privilege access principles and role segregation policies across IT and business systems. Conduct quarterly access reviews and user entitlement audits; report exceptions to the IT Operations Manager. Deliver the organisation-wide security awareness and training programme; track completion rates and phishing simulation outcomes. Manage third-party and supply chain security risk assessments; include security requirements in vendor contracts. Liaise with Internal Audit on security-related audit findings; develop and track remediation action plans. Prepare for and support external regulatory audits and certifications, including NCA ECC, ISO 27001, and ZATCA security requirements. Produce monthly security metrics dashboards covering threat landscape, vulnerability posture, and compliance status.<br>Qualifications:Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field. CISM (Certified Information Security Manager) — required or CISA — preferred. Microsoft SC-200 (Security Operations Analyst) or SC-300 — advantageous.5–8 years of experience in information security, with at least 3 years in a security leadership role. Proven experience securing SAP environments including role design, SoD analysis, and SAP security audit. Experience with cloud security: Azure Security Center / Defender for Cloud, AWS Guard Duty, or GCP SCC. Knowledge of Saudi Arabia regulatory requirements: PDPL and NCA ECC cybersecurity framework — strongly preferred. Strong incident response and forensic investigation experience; crisis communication skills. GCC or FMCG industry experience is an advantage. Excellent risk communication skills; experience presenting security risk to executive and board audiences.
A leading organization is seeking an experienced Director of Security Technologies to lead the operation, development, and continuous improvement of network and application security technologies. The role will oversee cybersecurity controls, security infrastructure, operational security requests, vulnerability management, threat mitigation, and the performance of the Security Technologies function.<br>Key Responsibilities• Lead the operation and enhancement of network and application security technologies.• Oversee firewall policies, port access requests, device isolation, and website and email security controls.• Ensure security systems, signatures, configurations, and technologies are continuously updated and optimized.• Oversee web application security controls and resolve network and application access issues.• Evaluate, test, approve, and implement new security technologies and cybersecurity controls.• Lead vulnerability management activities and ensure identified security risks are effectively addressed.• Oversee root cause analysis for security incidents and ensure compliance with cybersecurity policies and controls.• Develop security policies, processes, procedures, tools, and operating models.• Establish departmental objectives, performance measures, and key performance indicators.• Manage departmental operations, workforce requirements, annual budget planning, and strategic priorities.• Lead, develop, and evaluate team members through objective setting, performance feedback, and professional development.<br>Qualifications and Experience• Bachelor’s degree in Cybersecurity, Information Technology, Network Engineering, or a related field.• Minimum of 7 years of relevant experience, including leadership or managerial experience.• Strong experience in network security, firewalls, web application security, vulnerability management, and security operations.• Proven ability to lead technical teams and manage complex cybersecurity environments.• Professional certifications such as CISSP, CISM, CEH, CCNP Security, or equivalent are preferred.
Tips: We are seeking a Security Specialist to strengthen our overall cybersecurity posture, safeguard our hybrid/cloud infrastructure, and protect our digital assets. While you will manage general security operations and incident response, a key focus will be administering and optimizing our core Microsoft ecosystem—including Entra ID, Intune, email security, and endpoint protection.<br>Responsibilities[Identity & Access Management: Implement Zero Trust principles, manage identity governance, and enforce access controls (MFA, Conditional Access, RBAC). Endpoint & Device Security: Secure endpoints across platforms using unified management tools (MDM/MAM), deployment baselines, and EDR solutions.<br>Email & Threat Protection: Maintain email security controls, prevent phishing/spoofing threats, and manage core authentication protocols (SPF, DKIM, DMARC).<br>Security Operations & Response: Monitor security alerts, perform threat analysis, respond to incidents, and improve our overall security posture and hardening baselines.<br>Security Awareness & Compliance: Assist in enforcing security policies, vulnerability management, and driving security best practices across the organization.<br><br>Qualifications Identity & Access Management: Implement Zero Trust principles, manage identity governance, and enforce access controls (MFA, Conditional Access, RBAC).<br>Endpoint & Device Security: Secure endpoints across platforms using unified management tools (MDM/MAM), deployment baselines, and EDR solutions.<br>Email & Threat Protection: Maintain email security controls, prevent phishing/spoofing threats, and manage core authentication protocols (SPF, DKIM, DMARC).<br>Security Operations & Response: Monitor security alerts, perform threat analysis, respond to incidents, and improve our overall security posture and hardening baselines.<br>Security Awareness & Compliance: Assist in enforcing security policies, vulnerability management, and driving security best practices across the organization.
Job Description<br><br>We are seeking a detail-oriented and analytical Project Security and Access Control Specialist to join our organization in Jeddah, Saudi Arabia. In this role, you will be responsible for designing, implementing, and managing comprehensive security and access control systems for our projects. You will work collaboratively with cross-functional teams to ensure that all security protocols are maintained at the highest standards while supporting project objectives and organizational compliance requirements.<br><br>Conduct thorough security assessments and risk analyses to identify vulnerabilities and recommend mitigation strategies Manage user access provisioning and de-provisioning processes, maintaining accurate documentation and audit trails Monitor and analyze security incidents and access anomalies, responding promptly to potential threats Develop and maintain comprehensive security documentation, including access control policies, procedures, and guidelines Coordinate with IT and project teams to ensure seamless integration of security measures into project workflows Perform regular security audits and compliance reviews to verify adherence to established protocols and regulatory requirements Maintain and troubleshoot access control systems and identity and access management (IAM) platforms Provide security training and guidance to project stakeholders on access control procedures and best practices Track and report on security metrics, access control effectiveness, and compliance status to project leadership Stay current with emerging security threats, technologies, and industry standards relevant to access control<br><br><br>Qualifications<br><br>3+ years of professional experience in security, access control, or IT security roles Preferred Airport exp. Demonstrated expertise in designing and managing access control systems and identity and access management Proficiency with security tools and systems, security monitoring tools Solid understanding of project management principles and ability to coordinate security across project Excellent analytical and problem-solving skills with strong attention to detail Exceptional organizational and documentation skills Strong communication abilities with the capacity to explain complex security concepts to non-technical stakeholders Ability to work independently and collaboratively within a team environment Preferred: Security certifications such as CISSP, Security+, or CCSKPreferred: Experience with incident response and vulnerability assessment Preferred: Familiarity with regional compliance requirements and security standards applicable to Saudi Arabia
<p><strong>Role Purpose</strong></p><p>Coordinate studio security and access operations for the Film Studio asset, ensuring safe, controlled, and production-friendly access for crew, tenants, visitors, contractors, vehicles, and equipment. The role acts as the operational focal point between studio teams, productions, security providers, and internal stakeholders to protect people, assets, confidential productions, and operational continuity.</p><p><strong>Key Responsibilities</strong></p><ul><li>Coordinate access arrangements for productions, tenants, employees, visitors, VIPs, contractors, suppliers, vehicles, and equipment across studio facilities.</li><li>Act as the primary operational interface with SAFE, outsourced security providers, and internal stakeholders on day-to-day security matters.</li><li>Develop, implement, and maintain access control procedures, credentialing requirements, visitor protocols, and restricted-area controls.</li><li>Coordinate production-specific security plans, crew movement, equipment deliveries, parking, loading activities, and operational access requirements.</li><li>Support secure onboarding and offboarding of tenants, productions, contractors, and temporary operational teams.</li><li>Monitor security incidents, access breaches, lost credentials, site risks, and operational disruptions, escalating where required.</li><li>Coordinate emergency response procedures, evacuation support, incident reporting, and security-related corrective actions.</li><li>Maintain access records, visitor logs, incident registers, security reports, and documentation in line with governance requirements.</li><li>Coordinate with Operations, Facilities, HSE, IT, Commercial, and Corporate Enablement teams to resolve security and access dependencies.</li><li>Support physical security readiness for workshops, events, productions, VIP visits, and high-profile activities.</li><li>Ensure security requirements are embedded into operational readiness plans, tenant onboarding plans, and production activation schedules.</li><li>Monitor security provider performance, staffing coverage, response times, and service quality.</li><li>Support implementation of CCTV, access-control systems, badging processes, and physical security procedures in coordination with IT and security providers.</li><li>Identify security risks and recommend improvements to access processes, site circulation, parking, loading, and restricted-zone controls.</li><li>Prepare security updates, access performance reports, incident summaries, and risk escalations for management review.</li></ul><p><strong>KPIs</strong></p><ul><li>Access request processing turnaround time</li><li>Number of access-related incidents or breaches</li><li>Security provider SLA compliance</li><li>Incident reporting and closure timeliness</li><li>Accuracy of access records and visitor logs</li><li>Production and tenant satisfaction with access coordination</li><li>Emergency readiness and drill participation compliance</li></ul><p><strong>Desired Candidate Profile</strong></p><p><strong>Education</strong></p><p>Bachelor s degree or diploma in Security Management, Operations, Business Administration, Criminal Justice, or related field. Security, access control, emergency response, or incident management certification preferred.</p><p><strong>Experience</strong></p><p>4 7 years of experience in security operations, access control, site coordination, protective services, or operational security. Experience managing high-volume visitors, contractors, vehicles, equipment movements, or event-style operations. Experience coordinating outsourced security providers and production-, tenant-, or event-specific access plans preferred.</p><p><strong>Preferred Background</strong></p><p>Film studios, entertainment venues, events, hospitality, mixed-use assets, industrial campuses, or confidential / high-profile operating environments. Exposure to VIP visits, production confidentiality, restricted-area management, and operational security planning preferred.</p><p><strong>Technical & Functional Expectations</strong></p><p>Strong understanding of access control, visitor management, credentialing, and restricted-area protocols. Ability to coordinate people, vehicle, and equipment movements without disrupting production activity. Knowledge of physical security procedures, incident reporting, emergency response, and escalation protocols. Strong coordination and communication capability with security providers, productions, tenants, and internal teams.</p><p><strong>Key Competencies</strong></p><ul><li>Access management</li><li>Security coordination</li><li>Incident management</li><li>Production logistics</li><li>Stakeholder communication</li><li>Risk awareness</li><li>Service provider management</li></ul>
Job Role: Cyber Security Architect / Expert<br><br>Experience: 10+ years<br><br>Location: KSA (Onsite)<br><br>Duration: 1 year<br><br>Technology Stack<br><br>Azure Security Architecture & Engineering: Entra ID, APIM, Azure Policy, Key Vault, Defender for Cloud, Microsoft Sentinel, Microsoft Fabric/Purview, Azure Dev Ops security pipelines, API and microservices security, IoT security, and Gen AI security.<br><br>Security Assessment & Detection: Sentinel/KQL, Burp Suite, Nessus, SAST/DAST/SCA tools, OWASP web, API, and mobile security, and security scripting.<br><br>Job Description<br><br>Define security architecture, controls, identity, access, compliance and risk mitigation requirements. Ensure solution design follows secure-by-design principles across application, data, cloud and integration layers.<br><br>Configure Entra ID, MFA, Conditional Access, RBAC/PIM, Key Vault, WAF, Firewall, private endpoints, Defender and Sentinel. Execute or coordinate SAST, DAST, VA/PT, API and configuration assessments, track remediation and retest fixes.<br><br>Technical Skills Summary<br><br>Security configuration, Dev Sec Ops, vulnerability testing, SIEM/SOAR, evidence collection and operational security.<br><br>Functional Skills Summary<br><br>Security Architecture & Governance:<br><br>Define target architecture, security controls, risk mitigation measures, compliance alignment, access governance, and secure-by-design reviews, ensuring adherence to applicable NCA, PDPL, NDMO, and DGA requirements.<br><br>Platform Engineering & Operations<br><br>Build and operate environments, automate deployments, manage releases, and ensure monitoring, reliability, performance, and operational readiness.<br><br>Skills: soar,security architect,vulnerability,cyber security,architecture,security,siem,operational security,devsecops,security confirguration
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>Role Purpose Coordinate studio security and access operations for the Film Studio asset, ensuring safe, controlled, and production-friendly access for crew, tenants, visitors, contractors, vehicles, and equipment.<br> The role acts as the operational focal point between studio teams, productions, security providers, and internal stakeholders to protect people, assets, confidential productions, and operational continuity.<br> Key Responsibilities Coordinate access arrangements for productions, tenants, employees, visitors, VIPs, contractors, suppliers, vehicles, and equipment across studio facilities.<br> Act as the primary operational interface with SAFE, outsourced security providers, and internal stakeholders on day-to-day security matters.<br> Develop, implement, and maintain access control procedures, credentialing requirements, visitor protocols, and restricted-area controls.<br> Coordinate production-specific security plans, crew movement, equipment deliveries, parking, loading activities, and operational access requirements.<br> Support secure onboarding and offboarding of tenants, productions, contractors, and temporary operational teams.<br> Monitor security incidents, access breaches, lost credentials, site risks, and operational disruptions, escalating where required.<br> Coordinate emergency response procedures, evacuation support, incident reporting, and security-related corrective actions.<br> Maintain access records, visitor logs, incident registers, security reports, and documentation in line with governance requirements.<br> Coordinate with Operations, Facilities, HSE, IT, Commercial, and Corporate Enablement teams to resolve security and access dependencies.<br> Support physical security readiness for workshops, events, productions, VIP visits, and high-profile activities.<br> Ensure security requirements are embedded into operational readiness plans, tenant onboarding plans, and production activation schedules.<br> Monitor security provider performance, staffing coverage, response times, and service quality.<br> Support implementation of CCTV, access-control systems, badging processes, and physical security procedures in coordination with IT and security providers.<br> Identify security risks and recommend improvements to access processes, site circulation, parking, loading, and restricted-zone controls.<br> Prepare security updates, access performance reports, incident summaries, and risk escalations for management review.<br> KPIs Access request processing turnaround time Number of access-related incidents or breaches Security provider SLA compliance Incident reporting and closure timeliness Accuracy of access records and visitor logs Production and tenant satisfaction with access coordination Emergency readiness and drill participation compliance Candidate Profile Education Bachelor’s degree or diploma in Security Management, Operations, Business Administration, Criminal Justice, or related field.<br> Security, access control, emergency response, or incident management certification preferred.<br> Experience 4–7 years of experience in security operations, access control, site coordination, protective services, or operational security.<br> Experience managing high-volume visitors, contractors, vehicles, equipment movements, or event-style operations.<br> Experience coordinating outsourced security providers and production-, tenant-, or event-specific access plans preferred.<br> Preferred Background Film studios, entertainment venues, events, hospitality, mixed-use assets, industrial campuses, or confidential / high-profile operating environments.<br> Exposure to VIP visits, production confidentiality, restricted-area management, and operational security planning preferred.<br> Technical & Functional Expectations Strong understanding of access control, visitor management, credentialing, and restricted-area protocols.<br> Ability to coordinate people, vehicle, and equipment movements without disrupting production activity.<br> Knowledge of physical security procedures, incident reporting, emergency response, and escalation protocols.<br> Strong coordination and communication capability with security providers, productions, tenants, and internal teams.<br> Key Competencies Access management Security coordination Incident management Production logistics Stakeholder communication Risk awareness Service provider management</span> </div><h2 data-automation-id="subHeaderPreferredCandidate" class="h5">
Preferred candidate </h2>
<div class="row is-m v-align-top t-small bg-mute">
<div class="col is-3 p5" data-automation-id="label_Years_of_experience">
<b>Years of experience</b>
</div>
<div class="col is-9 p5" data-automation-id="data_Years_of_experience">
No experience required </div>
</div>
<div class="row is-m v-align-top t-small ">
<div class="col is-3 p5" data-automation-id="label_Degree">
<b>Degree</b>
</div>
<div class="col is-9 p5" data-automation-id="data_Degree">
Bachelor's degree / higher diploma </div>
</div>
Position Summary<br><br>The Manager - Security & Threat leads the governance of security operations and threat management across Qiddiya Workers Villages.<br><br>Key Purpose of the Role<br><br>To prevent, detect, and respond to security threats through disciplined security governance and emergency preparedness.<br><br>Key Responsibilities<br><br> Develop and implement security and threat management frameworks Oversee access control, patrols, and CCTV operations Lead threat assessments and vulnerability analyses Coordinate intelligence and threat alerts with authorities Investigate security incidents and implement corrective actions Ensure compliance with Saudi security regulations Maintain training and licensing compliance<br><br>Key Deliverables And Accountabilities<br><br> Approved security and threat frameworks Threat risk registers and assessments Incident investigation reports Emergency and crisis response plans Security KPI dashboards and reports<br><br>KPIs/ Performance Metrics <br><br> Security incident rate and response time Threat assessment completion rate Access control compliance rate Training and licensing compliance rate Audit non-conformance rate<br><br>Requirements<br><br>Experience Requirements <br><br> Minimum 8 years of experience in security and threat management At least 3 years in a managerial role<br><br>Technical and Professional Competencies <br><br> Security governance and SOP development Threat assessment and vulnerability analysis Access control and surveillance systems Incident investigation and crisis response Contractor performance management<br><br>Behavioral Competencies <br><br> Leadership and accountability Stakeholder engagement and collaboration Decision-making under pressure Integrity and professionalism Continuous improvement mindset<br><br>Authority and Decision- Making limits<br><br> Stop unsafe or non-compliant security practices Escalate credible threats to leadership and authorities Approve corrective security action plans
Role Summary The Cyber Security Specialist will strengthen the organization’s security posture by implementing, monitoring, and enhancing cyber defense mechanisms across critical government systems. The role requires hands‑on expertise in threat detection, incident response, governance frameworks, and secure infrastructure operations. Candidates outside Saudi Arabia are welcome, provided they meet the technical and regulatory requirements of government‑grade security environments. Key Responsibilities1. Security Operations & Monitoring Monitor SIEM, IDS/IPS, endpoint security, and network security tools for real‑time threat detection. Perform log analysis, correlation, and triage of security alerts. Lead containment, eradication, and recovery activities during cyber incidents.2. Incident Response & Forensics Develop and execute incident response playbooks aligned with government standards. Conduct digital forensics investigations, evidence collection, and root‑cause analysis. Prepare incident reports for senior leadership and regulatory bodies.3. Governance, Risk & Compliance (GRC) Ensure compliance with Saudi government frameworks such as NCA ECC, NCA CCC, NCA CSCC, and SAMA CSF (if applicable). Support risk assessments, vulnerability assessments, and security audits. Maintain security documentation, policies, and procedures.4. Infrastructure & Application Security Implement hardening standards for servers, endpoints, cloud environments, and network devices. Conduct secure code reviews and application security assessments. Collaborate with IT teams to ensure secure architecture design.5. Security Tools & Technology Management Manage and optimize tools such as SIEM (Splunk/QRadar/Arc Sight), EDR/XDR, DLP, PAM, WAF, and vulnerability scanners. Evaluate new technologies and recommend enhancements to the security stack.6. Awareness & Training Conduct cybersecurity awareness sessions for employees. Support phishing simulations and behavioral security programs. Required Qualifications Education & Certifications Bachelor’s degree in Cyber Security, Computer Science, Information Technology, or related field. Preferred certifications: CISSP, CISM, CEH, Comp TIA Security+, GIAC (GCIH, GCIA), ISO 27001 LA. Technical Skills Strong knowledge of network security, endpoint protection, and cloud security (Azure/AWS). Experience with SIEM, EDR, DLP, and vulnerability management platforms. Understanding of secure architecture, encryption, IAM, and zero‑trust principles. Familiarity with government cybersecurity frameworks (NCA, SAMA, CITC). Experience4–8 years of hands‑on cybersecurity experience, preferably in government, defense, or critical infrastructure. Proven track record in incident response, SOC operations, or security engineering.
Overview:The Security Specialist is responsible for supporting and maintaining the organization’s IT security operations to ensure the availability, integrity, and protection of systems, networks, and applications. The role focuses on the day-to-day operation and administration of security technologies.<br>Key Responsibilities:Provide advanced operational support for IT security controls and security platforms Support protection and availability of security controls and platforms Resolve security platform related incidents and support problem management Execute approved security related changes Support recovery and restoration of security controls and platforms<br>Talent Profile:Bachelor’s degree in computer science, Information Technology, Network Engineering, or a related field. Minimum 4 years of relevant experience in IT security operations<br>Job Nature:SITE, Project-Based.<br>In addition to the monthly salary, SITE provides you these Benefits:Social allowance. Mobile allowance. Medical Insurance employee, his/her family, and parents.
Position: Senior Network Security Engineer Location: Riyadh, Saudi Arabia Experience: 5-8 Years Notice Period: Immediate to 30 Days Candidates currently residing in Saudi Arabia are preferred<br>Must have Skills:ADC, WAF & GTMFirewalls (Palo Alto preferred) Proxy / Secure Web Gateway Email Gateway IPSNACSandbox F5 Technologies Forcepoint Security Suite<br>Key Responsibilities:<br>Design, implement, and manage network security solutions across enterprise environments. Configure, maintain, and troubleshoot Palo Alto Firewalls and F5 solutions. Manage web security, email security, and DLP solutions using Forcepoint. Monitor, analyze, and respond to security incidents and threats. Perform vulnerability assessments, risk assessments, and security audits. Ensure compliance with security standards, governance frameworks, and best practices. Collaborate with infrastructure and operations teams for secure network architecture. Prepare technical documentation, reports, and security recommendations. Preferred Certifications: CISSP | CISM |PCNSE |CCNP Security
Lead the day-to-day delivery of IT, network/infrastructure, OT, and application security operations across all ASO-managed platforms. Oversee Managed Service Partner (L1/L2) service delivery, ensuring effective platform governance, SLA compliance, operational efficiency, and continuous improvement.<br><br>Key Responsibilities<br><br> Lead and manage the ASO team, including Senior Lead, Senior Specialist, and Security Specialist. Oversee Managed Service Partner L1/L2 service delivery and SLA performance. Govern platform administration and security tool configuration changes. Oversee the Application Security program, including WAF governance, application vulnerability remediation, and coordination with the Cybersecurity Team. Lead vulnerability management activities, including prioritization, tracking, and reporting. Manage change management for all ASO-owned security platforms. Oversee operational handover of new security tools and ensure service continuity. Coordinate with the Security Lead on security incidents, escalations, and change approvals. Prepare and present monthly operational and performance reports for leadership<br><br>Requirements<br><br>7+ years of cybersecurity experience, including 3+ years in a leadership role. Experience managing enterprise security operations and security platforms. Hands-on experience with security technologies such as firewalls, EDR, PAM, vulnerability management, and WAF. Experience managing Managed Security Service Providers (MSSPs) and SLA performance. Strong stakeholder management and operational governance skills. Professional certification such as CISSP or CISM preferred