Security inspector Jobs in Saudi
9001 Jobs Found
Lead the day-to-day delivery of IT, network/infrastructure, OT, and application security operations across all ASO-managed platforms. Oversee Managed Service Partner (L1/L2) service delivery, ensuring effective platform governance, SLA compliance, operational efficiency, and continuous improvement.<br><br>Key Responsibilities<br><br> Lead and manage the ASO team, including Senior Lead, Senior Specialist, and Security Specialist. Oversee Managed Service Partner L1/L2 service delivery and SLA performance. Govern platform administration and security tool configuration changes. Oversee the Application Security program, including WAF governance, application vulnerability remediation, and coordination with the Cybersecurity Team. Lead vulnerability management activities, including prioritization, tracking, and reporting. Manage change management for all ASO-owned security platforms. Oversee operational handover of new security tools and ensure service continuity. Coordinate with the Security Lead on security incidents, escalations, and change approvals. Prepare and present monthly operational and performance reports for leadership<br><br>Requirements<br><br>7+ years of cybersecurity experience, including 3+ years in a leadership role. Experience managing enterprise security operations and security platforms. Hands-on experience with security technologies such as firewalls, EDR, PAM, vulnerability management, and WAF. Experience managing Managed Security Service Providers (MSSPs) and SLA performance. Strong stakeholder management and operational governance skills. Professional certification such as CISSP or CISM preferred
Key Responsibilities• Execute daily cybersecurity operational tasks, maintaining adherence to established security policies and operational risk management frameworks.• Perform routine maintenance and support for Public Key Infrastructure (PKI) components and systems.• Verify that technical implementations and proposed service changes comply with existing security policies and regulatory standards.• Identify and report potential cyber risks to senior team members during implementation and daily operations.• Maintain and perform routine configuration and patching of various security tools and solutions (e.g., vulnerability scanners, endpoint protection, SIEM).• Monitor the health, performance, and log data generated by security controls.• Monitor security consoles and alerts, assessing, and escalating potential security risks and threats to the appropriate team lead.• Assist in the initial containment and triage of security incidents following established incident response procedures.• Conduct scheduled vulnerability assessments using established tools and document findings for review and remediation planning.• Support security testing activities (e.g., penetration tests) and apply practical security best practice guidance during system configuration.• Work with internal and external auditors by providing necessary documentation and data to ensure compliance with regulatory and industry requirements.• Assist in addressing identified audit gaps and implementing corrective actions.• Produce clear, concise technical reports detailing monitoring activity, security tool status, and incident support efforts.• Maintains current knowledge of security threats, attack vectors, and evolving security technologies.• Performs other related operational security duties as assigned.<br>Requirements2-5 years’ experience in IT Security field in the payments or banking sector or any related areas.• A bachelor’s or master’s degree and Science in Information Security, Computer Degree Science, Engineering, or any related field.<br>Essential skills Promote and increase security awareness. Self-motivated must have initiative and ability to work with a team. Strong technical documentation skills Certification in a specific security framework Strong knowledge in Security systems. Outstanding technical research and problem-solving skills Strong communication skills that frequently work with other employees to identify risks and prevent future incidents Excellent organizational and time management skills.<br>Desired skills:Ability to communicate technical information to nontechnical personnel. Excellent in project management skills including ability to organize time and work on multiple tasks and follow-up An analytical mind and a keen eye for detail and desire to probe further into data.
Adree is seeking a Security Engineer, Specialist to support our product development and engineering initiatives by leveraging deep application security and analytical expertise to articulate the value of secure, compliant digital solutions. In this role, you will work closely with stakeholders to understand technical requirements and business goals, and clearly demonstrate how enforceable security gates and robust vulnerability lifecycle management can address their needs.<br><br>You will be responsible for bridging the gap between security compliance and rapid delivery execution, collaborating across teams to operationalize automated security controls throughout the SDLC. By blending secrets management, automated scanning pipelines, and artifact trust mechanisms, you will ensure our digital products are highly secure, resilient, and fully audit-ready.<br><br>Key Responsibilities:<br><br>Engage with clients and stakeholders to gather security requirements and understand their digital transformation and compliance goals Deliver impactful presentations, security dashboards, and reporting frameworks showcasing vulnerability triage, remediation tracking, and pipeline safety metrics Support the engineering and Dev Ops teams in configuring and tuning Fortify SAST/DAST, establishing clear thresholds, and governing exception workflows Provide technical insights and application security expertise throughout the product lifecycle to automate SSL/TLS certificate renewals using Hashi Corp Vault and Cert-Manager in Kubernetes Collaborate with cross-functional teams (including Dev Ops and QA) to build secure pipelines, manage test environment controls, and enforce software supply chain visibility via SBOM integration Stay current with industry trends, OWASP frameworks, container security concepts, and threat modeling to position solution security effectively Conduct workshops and technical triage sessions internally and with clients to define Quality Gates, vulnerability SLAs, and secure secrets management patterns with Secur Envoy MFAParticipate in Agile development processes and release alignments, producing required compliance evidence, scan outputs, approvals, and comprehensive release evidence packs<br><br>Requirements<br><br>Education<br><br>Bachelor's degree in Computer Science, Cyber Security, Software Engineering, or a related technical field<br><br>Experience<br><br>4+ years of professional experience in Application Security (App Sec), Dev Sec Ops, or Security Engineering Proven experience operationalizing enforceable security gates within CI/CD pipelines, preferably using Azure Dev Ops Server Demonstrated experience with threat modeling, vulnerability management, and operating within government or highly regulated enterprise sectors is a strong plus<br><br>Skills & Competencies (Technical & Analytical + Soft)<br><br>Deep proficiency in Secure SDLC principles, OWASP Top 10, container security concepts, and Kubernetes/Open Shift security basics Strong hands-on experience implementing image signing/verification (Sigstore/Cosign) and artifacts lifecycle security via JFrog Artifactory Analytical skills to correlate security logs and monitoring alerts with enterprise platforms like App Dynamics, BMC, or Azure Monitoring Excellent soft skills with an ability to influence without authority, deliver pragmatic risk-based guidance, and handle security escalations calmly Strong collaboration, structured reporting, and cross-functional engineering alignment<br><br>Experience (summary)<br><br>Operationalization of automated Dev Sec Ops security gates across CI/CD pipelines Vulnerability lifecycle management including triage, SLA tracking, and remediation Automated software supply chain security (SBOM generation & container image signing) Secrets management integration and automated infrastructure certificate management Application security scanning optimization across SAST and DAST frameworks Regulatory compliance evidence gathering and release package auditing<br><br>Skills & Competencies (summary)<br><br>Azure Dev Ops Server & JFrog Artifactory secure workflow management Fortify SAST/DAST tuning & exception workflow design Hashi Corp Vault secrets management & Cert-Manager infrastructure Container & cluster security principles (Kubernetes / Red Hat Open Shift) Multi-factor authentication access patterns (Secur Envoy MFA) Stakeholder relationship management & security governance Prioritization, risk-based communication, and teamwork Travel for client-facing activities<br><br>Job location: Client Site
Key Responsibilities• Execute daily cybersecurity operational tasks, maintaining adherence to established security policies and operational risk management frameworks.• Perform routine maintenance and support for Public Key Infrastructure (PKI) components and systems.• Verify that technical implementations and proposed service changes comply with existing security policies and regulatory standards.• Identify and report potential cyber risks to senior team members during implementation and daily operations.• Maintain and perform routine configuration and patching of various security tools and solutions (e.g., vulnerability scanners, endpoint protection, SIEM).• Monitor the health, performance, and log data generated by security controls.• Monitor security consoles and alerts, assessing, and escalating potential security risks and threats to the appropriate team lead.• Assist in the initial containment and triage of security incidents following established incident response procedures.• Conduct scheduled vulnerability assessments using established tools and document findings for review and remediation planning.• Support security testing activities (e.g., penetration tests) and apply practical security best practice guidance during system configuration.• Work with internal and external auditors by providing necessary documentation and data to ensure compliance with regulatory and industry requirements.• Assist in addressing identified audit gaps and implementing corrective actions.• Produce clear, concise technical reports detailing monitoring activity, security tool status, and incident support efforts.• Maintains current knowledge of security threats, attack vectors, and evolving security technologies.• Performs other related operational security duties as assigned.<br>Requirements2-5 years’ experience in IT Security field in the payments or banking sector or any related areas.• A bachelor’s or master’s degree and Science in Information Security, Computer Degree Science, Engineering, or any related field.<br>Essential skills Promote and increase security awareness. Self-motivated must have initiative and ability to work with a team. Strong technical documentation skills Certification in a specific security framework Strong knowledge in Security systems. Outstanding technical research and problem-solving skills Strong communication skills that frequently work with other employees to identify risks and prevent future incidents Excellent organizational and time management skills.<br>Desired skills:Ability to communicate technical information to nontechnical personnel. Excellent in project management skills including ability to organize time and work on multiple tasks and follow-up An analytical mind and a keen eye for detail and desire to probe further into data.
The Senior Manager - Security Planning is responsible for managing and overseeing security strategies and programs across the Master Developer portfolio as they relate to City Security Planning and the Place Planning and Design team.<br><br>The successful candidate will work in close coordination across the District Master Developer and Place, Planning & Design team to deliver the Qiddiya City Security strategy of an open but secure city that is a global benchmark for safety and security in the 21st Century.<br><br>Security Master Planning <br><br>Representing the Security Planning function, supporting the master developer and specialist consultants working through the planning, design and development process. This will include:<br><br> Security master-planning across Districts and overall City masterplan coordination Balancing adjacencies of uses and security requirements and Place outcomes Review of Place characters at security moment/elements in the masterplan Custodianship of CPTED principles through evolution of the masterplan Encourage innovative approaches to security measures that incorporate technology with strategically placed landscape and hardscape components such as but not limited furniture, art, earth mounding, water, etc. whilst meeting the City's operational objectives<br><br>Development SME Oversight <br><br>Supporting the Security Planning team's general advisory and oversight of security outputs and activities being delivered by development consultants and associated experts, including but not limited to; built environment security consulting, security master planning, security risk assessments, security policy and planning, benchmarking and maturity assessments, security risk workshops; and applying relevant built environment risk management knowledge, tools, standards, and processes.<br><br>Reporting & Strategic Support <br><br> Enhance and maintain dashboards, trackers, and performance frameworks for executive reporting Provide presentation support for key briefing materials and stakeholder packs (e.g. Project Control Groups and other internal governance committees) Assist in shaping policies, standards, and risk frameworks through research and structured documentation<br><br>Strategic Contributions <br><br> Streamlined planning workflows across multidisciplinary teams, enhancing efficiency and aligning project delivery with Qiddiya's strategic objectives Maintain and enhance key organizational tools and processes, such as task trackers, dashboards, and performance frameworks, driving accountability and improving resource allocation Lead initiatives to expand the team's advisory capabilities, positioning Qiddiya's security planning function as a regional benchmark<br><br>Requirements<br><br> Minimum 5 years of relevant experience in built-environment security, relevant infrastructure delivery sectors, government, and high-profile development projects in KSA Proficiency in Aconex, BIM360, Share Point, and reporting/dashboarding tools Demonstrated ability to perform within multidisciplinary teams and track large-scale project dependencies Experienced in advising diverse government and multinational stakeholders Strong written and verbal communication Bachelor's degree preferred
We are seeking a Physical Security Engineer with 2–5 yearsof experience in physical security systems implementation, configuration, andsupport. The candidate will be responsible for designing, installing,integrating, testing, and maintaining security systems including CCTV, accesscontrol, and other physical security solutions.<br>Responsibilities<br>Design, configure, and support CCTV, access control, and physical security systems. Perform installation, testing, commissioning, and troubleshooting activities. Conduct site surveys and prepare technical documentation and reports. Support system integration activities and ensure compliance with project requirements and security standards. Coordinate with clients, vendors, and project teams for successful project execution. Perform security assessments and recommend improvements when required. <br>Qualifications Bachelor’s degree in engineering or related technical field.<br>2–5 years of experience in CCTV, access control, and physical security systems. Strong understanding of physical security technologies and system architecture. Mandatory certification or training certificate in the<br>following: CPP, APP, PSP, and Security Risk Assessment Methodology – API 780<br>Standard. Good communication and problem-solving skills.
We are seeking a Physical Security Engineer with 2–5 yearsof experience in physical security systems implementation, configuration, andsupport. The candidate will be responsible for designing, installing,integrating, testing, and maintaining security systems including CCTV, accesscontrol, and other physical security solutions.<br>Responsibilities<br>Design, configure, and support CCTV, access control, and physical security systems. Perform installation, testing, commissioning, and troubleshooting activities. Conduct site surveys and prepare technical documentation and reports. Support system integration activities and ensure compliance with project requirements and security standards. Coordinate with clients, vendors, and project teams for successful project execution. Perform security assessments and recommend improvements when required. <br>Qualifications Bachelor’s degree in engineering or related technical field.<br>2–5 years of experience in CCTV, access control, and physical security systems. Strong understanding of physical security technologies and system architecture. Mandatory certification or training certificate in the<br>following: CPP, APP, PSP, and Security Risk Assessment Methodology – API 780<br>Standard. Good communication and problem-solving skills.
About Masdr Masdr provides integrated digital data and business solutions to public and private sector organizations, enabling operational efficiency, enhanced customer experience, data-driven decision-making, and compliance with regulatory and cybersecurity requirements through advanced digital technologies and enterprise platforms.<br>Job Purpose Lead and directly execute the administration, operation, and continuous improvement of enterprise systems, identity platforms, digital workplace technologies, endpoint governance, and messaging security. The role is responsible for ensuring secure, reliable, and scalable operations while acting as the hands-on technical owner during the initial phase, establishing operational standards, technical foundations, and service maturity as the organization grows.<br>Generic Accountabilities:<br>Leadership & Technical Direction Provide hands-on technical leadership for the Cybersecurity Operations function. Plan, prioritize, and oversee cybersecurity operational activities. Mentor team members and promote technical excellence and knowledge sharing. Operational Excellence Establish and continuously improve cybersecurity operational processes, standards, procedures, and documentation. Ensure the effective and reliable delivery of cybersecurity services. Stakeholder & Vendor Management Collaborate with internal stakeholders to implement and maintain cybersecurity capabilities. Provide technical oversight of external vendors, managed security service providers (MSSPs), and implementation partners. Audit & Compliance Support Support audits by providing technical evidence and coordinating the remediation of technical findings. Maintain documentation supporting compliance with applicable security and regulatory requirements. Performance & Continuous Improvement Monitor operational performance, report key cybersecurity metrics, and drive continuous improvement initiatives.<br>Job-Specific Accountabilities:<br>Security Operations Lead and actively participate in daily cybersecurity operations. Develop and maintain operational procedures, playbooks, and response workflows. SIEM & Security Monitoring Design, implement, administer, and maintain the enterprise SIEM platform. Develop detection rules, dashboards, alerts, and monitoring use cases. Monitor, investigate, and respond to security events. EDR / XDRDeploy, configure, administer, and maintain enterprise EDR/XDR solutions. Investigate endpoint threats and coordinate containment and recovery. Incident Response Lead technical investigation and response to cybersecurity incidents. Perform root cause analysis and coordinate containment, eradication, recovery, and remediation. Maintain and test incident response plans and procedures. Threat Monitoring & Threat Hunting Perform proactive threat monitoring and threat hunting activities. Analyze threat intelligence and identify indicators of compromise (IOCs) and emerging threats. Security Operations Center (SOC) Coordinate internal or outsourced SOC operations. Review escalated incidents and ensure compliance with operational service levels. Identity & Privileged Access Management (IAM/PAM) Design, implement, administer, and maintain Identity and Access Management (IAM) and Privileged Access Management (PAM) solutions. Manage privileged accounts, authentication, authorization, credential protection, and privileged session monitoring. Ensure compliance with identity and privileged access policies. Vulnerability Management Implement, administer, and maintain enterprise vulnerability management solutions. Perform vulnerability scanning, assessments, risk prioritization, and remediation validation. Security Hardening Implement and maintain security baselines across enterprise infrastructure, operating systems, databases, virtualization platforms, cloud platforms, and network devices. Validate compliance with approved hardening standards and security baselines. Technical Security Controls Design, implement, administer, and maintain enterprise technical security controls, including MFA, endpoint protection, encryption, secure remote access, certificate management, logging, monitoring, network security, and application security controls. Ensure security technologies are securely configured and maintained. Security Assessments Perform technical security assessments, configuration reviews, and security validation activities. Support penetration testing and coordinate remediation of identified security findings. Assess new technologies and solutions to ensure security requirements are incorporated before deployment. Operational Readiness & Reporting Maintain cybersecurity operational documentation, runbooks, technical procedures, and recovery plans. Support disaster recovery exercises, technical audits, and compliance assessments. Produce operational reports, dashboards, KPIs, and security metrics.<br>Job Requirements:<br>Minimum Qualification Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field. Professional cybersecurity certifications (e.g., CISSP, Security+, CySA+, GCIH, or equivalent).<br>Experience Minimum 5–6 years of progressive experience in Cybersecurity Operations, Information Security, or Security Engineering. Minimum 3 years of hands-on experience implementing and administering enterprise security technologies, including SIEM, EDR/XDR, IAM/PAM, Vulnerability Management, and Security Monitoring. Experience leading cybersecurity operations, incident response, and security engineering initiatives. Experience working in enterprise or cloud environments and coordinating with internal teams, vendors, and managed security service providers (MSSPs).<br><br><br>Let's Shape the Future Together!
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p>Key Responsibilities</p><p>1. Fortinet Mail Gateway</p><ul><li>Monitor <b>service health, mail flow, system performance, and availability</b> of the Fortinet Mail Gateway environment.</li><li>Configure and maintain email security policies, including <b>anti-spam, anti-malware, anti-phishing, and email filtering</b>.</li><li>Investigate and resolve <b>mail delivery issues, false positives/negatives, mail queue problems, and connectivity issues</b>.</li><li>Monitor email security events and troubleshoot email-related security incidents.</li><li>Plan and execute <b>software upgrades, firmware updates, and hotfix installations</b>.</li><li>Ensure email security configurations comply with organizational security policies and applicable regulatory requirements.</li></ul><p>2. FortiSandbox</p><ul><li>Configure and maintain <b>FortiSandbox security policies, malware analysis profiles, IOC generation, quarantine actions, and notification settings</b>.</li><li>Configure file submission policies and supported file types for malware analysis.</li><li>Deploy, configure, and maintain integrations between <b>FortiSandbox and Fortinet Mail Gateway</b>.</li><li>Monitor malware analysis activities and investigate suspicious or malicious files.</li><li>Plan and execute <b>firmware upgrades, hotfix installations, and signature updates</b>.</li><li>Ensure FortiSandbox configurations comply with organizational security policies and regulatory requirements.</li></ul><p>3. Fortinet WAF</p><ul><li>Configure and maintain <b>Fortinet WAF policies, virtual servers, protected applications, and security profiles</b>.</li><li>Configure and manage <b>SSL/TLS inspection and certificate management</b>.</li><li>Perform onboarding of new <b>web applications and APIs</b> into the Fortinet WAF platform.</li><li>Validate application functionality following WAF policy implementation and changes.</li><li>Monitor WAF logs, alerts, and security events to identify <b>malicious activities, vulnerabilities, and web-based attacks</b>.</li><li>Investigate and troubleshoot WAF-related incidents and policy issues.</li><li>Optimize WAF policies to maintain an appropriate balance between security and application availability.</li></ul><p>4. Firewall Policy Review – FireMon</p><ul><li>Perform periodic <b>firewall policy reviews</b> across multi-vendor firewall environments using <b>FireMon</b>.</li><li>Identify and assess security risks, including:</li><li>Overly permissive rules</li><li>Any-to-Any access</li><li>Shadowed rules</li><li>Duplicate rules</li><li>Redundant objects</li><li>Unused or obsolete firewall rules</li><li>Configure <b>FireMon policy analysis, compliance policies, risk scoring, rule recertification, and reporting</b>.</li><li>Configure and maintain integrations between <b>FireMon and supported firewall vendors</b>.</li><li>Analyze firewall policy posture and recommend <b>rule optimization and risk remediation</b>.</li><li>Generate and analyze <b>operational, compliance, and executive-level reports</b> covering policy violations, rule optimization, security risks, and overall firewall risk exposure.</li></ul><p>Required Technical Skills</p><ul><li>Strong hands-on experience with <b>Fortinet security solutions</b>.</li><li>Experience with <b>Fortinet Mail Gateway / FortiMail</b>.</li><li>Experience with <b>FortiSandbox</b> and malware analysis.</li><li>Experience with <b>Fortinet WAF / FortiWeb</b>.</li><li>Strong understanding of <b>firewall policies, rule bases, network security, and access controls</b>.</li><li>Hands-on experience with <b>FireMon</b> for firewall policy analysis and review.</li><li>Knowledge of <b>SSL/TLS inspection and certificate management</b>.</li><li>Experience with security monitoring, log analysis, incident investigation, and troubleshooting.</li><li>Experience working with <b>multi-vendor firewall environments</b>.</li><li>Understanding of email security, web application security, malware detection, and threat protection.</li></ul><p>Preferred Skills</p><ul><li>Experience integrating <b>FortiMail with FortiSandbox</b>.</li><li>Experience onboarding and securing web applications/APIs through FortiWeb.</li><li>Experience with <b>Fortinet Firewall, FortiManager, and FortiAnalyzer</b>.</li><li>Knowledge of security compliance frameworks and organizational security policies.</li><li>Relevant Fortinet or network security certifications such as <b>FCF, FCA, FCP, or equivalent</b> would be an advantage.</li></ul><p><br></p> </div><h2 class="h5">Skills</h2>
<div data-jb-field="skills"><p>"WAF", "Mail GW", "Sandbox", "Firewall"</p></div>
Since 2004, 2P has been a leader in Saudi Arabia’s ICT landscape, delivering integrated technology solutions that help organizations accelerate digital transformation and improve operational efficiency. With a strong foundation in innovation and service excellence, 2P continues to provide end-to-end solutions through its specialized business units and trusted market expertise. We are always looking to connect with talented professionals who are passionate about making an impact and growing within a dynamic, forward-looking environment.<br>We are seeking a highly experienced Information Security Engineer L3 with 7+ years of experience in cybersecurity to join our Cybersecurity team. The ideal candidate will play a key role in protecting the organization's infrastructure, systems, applications, and data by conducting advanced security assessments, implementing enterprise security controls, and ensuring compliance with the Saudi National Cybersecurity Authority (NCA) regulations.<br>Key Responsibilities Conduct penetration testing prior to the implementation of production change requests. Perform regular and on-demand security scanning, vulnerability assessments, and security reviews across enterprise systems. Support the implementation of and ensure compliance with the National Cybersecurity Authority (NCA) cybersecurity regulations and standards. Protect the organization's infrastructure, applications, and technical configurations from cyber threats and vulnerabilities. Ensure the confidentiality, integrity, and availability (CIA) of the organization's data and information assets. Secure external web applications against cyber threats and application-layer vulnerabilities. Manage and support enterprise security technologies including:Identity & Access Management (IAM) Privileged Access Management (PAM) Mail Security Antivirus & Endpoint Protection Advanced Threat Protection (ATP) SSL / VPNNetwork Access Control (NAC) Web Application Firewall (WAF) Investigate security vulnerabilities, recommend remediation actions, and collaborate with technical teams to strengthen the organization's security posture. Prepare technical security reports, risk assessments, and security recommendations.<br>Qualifications & Requirements Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field. Minimum 7 years of experience in Cybersecurity or Information Security. Saudi Nationality is mandatory.e JPT certification is required. CCNA certification is required. Hands-on experience with enterprise security technologies including IAM, PAM, Mail Security, Antivirus, Advanced Threat Protection (ATP), SSL, VPN, NAC, and WAF. Strong experience conducting penetration testing, vulnerability assessments, and security scanning. Strong analytical, troubleshooting, and problem-solving skills. Excellent communication and interpersonal skills. Ability to work independently and collaboratively within cross-functional teams.<br>Preferred Certifications The following certifications are considered an advantage:CISSPCISACEH<br>Key Skills Penetration Testing Vulnerability Assessment Security Scanning Cybersecurity Compliance (NCA) Identity & Access Management (IAM) Privileged Access Management (PAM) Enterprise Security Technologies Risk Management Threat Analysis & Incident Response Security Architecture Web Application Security Data Protection & Information Security
<h3><strong>About the Role</strong></h3><p>stc is seeking a <strong>Security Operations Expert</strong> to execute and support cybersecurity operations across Specialized’s networks, systems, applications, and Mission-Critical environments. This full-time role focuses on ensuring effective threat detection, incident response, vulnerability management, and risk mitigation. The expert will perform security monitoring and assessments, maintain security controls, analyze cybersecurity incidents and threats, and coordinate remediation activities to strengthen Specialized’s security posture, all in accordance with established business policies and procedures.</p><h3><strong>Key Responsibilities</strong></h3><ul><li>Monitor Specialized’s networks, applications, systems, and integration points with Mission-Critical clients to identify, assess, and respond to cybersecurity threats and vulnerabilities.</li><li>Implement and maintain security controls across network assets, systems, and security platforms, aligning with cybersecurity frameworks, regulatory requirements, and approved security standards.</li><li>Execute SOC operational activities, including threat detection, incident triage, response coordination, and resolution, in accordance with defined service levels and operational procedures.</li><li>Analyze cybersecurity incidents, attack patterns, and threat trends to identify root causes and recommend appropriate corrective and preventive actions.</li><li>Conduct security assessments, vulnerability assessments, and penetration testing across Mission-Critical networks, systems, devices, and applications, and support remediation activities.</li><li>Coordinate vulnerability management activities, including patch deployment, system hardening, and security configuration reviews, to address identified security exposures.</li><li>Maintain cybersecurity documentation, evidence, and operational records in coordination with Strategy & Governance and relevant stakeholders to support audits, compliance, and regulatory requirements.</li><li>Apply threat intelligence, emerging threat indicators, and security advisories to strengthen security monitoring and protection capabilities.</li><li>Monitor cybersecurity performance metrics and incident trends, identifying improvement opportunities to enhance SOC and security operations effectiveness.</li><li>Support the enhancement of cybersecurity procedures, security controls, and incident response practices based on operational findings and evolving threats.</li><li>Prepare cybersecurity incident updates, operational reports, and security insights for relevant stakeholders and management.</li></ul><h3><strong>Experience Required</strong></h3><p>Candidates should possess <strong>6 to 10 years of experience</strong> in a relevant field.</p><h3><strong>Work Type</strong></h3><p>This is a <strong>full-time</strong> position.</p>
<h3><strong>About the Role</strong></h3><p>stc is seeking a <strong>Security Operations Expert</strong> to execute and support cybersecurity operations across Specialized’s networks, systems, applications, and Mission-Critical environments. This full-time role focuses on ensuring effective threat detection, incident response, vulnerability management, and risk mitigation. The expert will perform security monitoring and assessments, maintain security controls, analyze cybersecurity incidents and threats, and coordinate remediation activities to strengthen Specialized’s security posture in accordance with stipulated business policies and procedures.</p><h3><strong>Key Responsibilities</strong></h3><ul><li>Monitor Specialized’s networks, applications, systems, and integration points with Mission-Critical clients to identify, assess, and respond to cybersecurity threats and vulnerabilities.</li><li>Implement and maintain security controls across network assets, systems, and security platforms in alignment with cybersecurity frameworks, regulatory requirements, and approved security standards.</li><li>Execute SOC operational activities, including threat detection, incident triage, response coordination, and resolution in accordance with defined service levels and operational procedures.</li><li>Analyze cybersecurity incidents, attack patterns, and threat trends to identify root causes and recommend appropriate corrective and preventive actions.</li><li>Conduct security assessments, vulnerability assessments, and penetration testing across Mission-Critical networks, systems, devices, and applications, and support remediation activities.</li><li>Coordinate vulnerability management activities, including patch deployment, system hardening, and security configuration reviews to address identified security exposures.</li><li>Maintain cybersecurity documentation, evidence, and operational records in coordination with Strategy & Governance and relevant stakeholders to support audits, compliance, and regulatory requirements.</li><li>Apply threat intelligence, emerging threat indicators, and security advisories to strengthen security monitoring and protection capabilities.</li><li>Monitor cybersecurity performance metrics and incident trends, identifying improvement opportunities to enhance SOC and security operations effectiveness.</li><li>Support the enhancement of cybersecurity procedures, security controls, and incident response practices based on operational findings and evolving threats.</li><li>Prepare cybersecurity incident updates, operational reports, and security insights for relevant stakeholders and management.</li></ul><h3><strong>Experience Required</strong></h3><ul><li>Candidates should possess 6-10 years of relevant experience in cybersecurity operations.</li></ul>
Job Title: Information Security Governance and Awareness Manager Division: Cybersecurity Location: Riyadh Working Hours: 8:00 AM to 5:00 PM (Sunday to Thursday)<br><br>Core responsibilities: Ensures compliance with SAMA Cyber Security Framework, NCA frameworks, and other applicable regulatory requirements. Responsible for procedures and controls to assure compliance with applicable regulatory requirements and internal security controls/standards. Establish and oversee formal risk analysis and self-assessments program for applicable regulatory requirements/frameworks and internal security controls/standards. Manage reporting to various Risk Committees in the bank. Liaise with multiple relevant functions to remediate new and outstanding compliance issues related to applicable regulatory requirements/frameworks and internal security controls/standards. Track and report on issues related to applicable requirements/frameworks/internal security controls and standards. Develop and report key indicators in line with regulatory requirements/frameworks implementations/internal security controls and standards. Oversight and track the risks/issues remediation efforts. Manage and implement the security awareness program to improve the security culture/knowledge among end users of the ever-evolving cyber security threats. Manage the information security strategy execution with respective stakeholders. Manage and maintain the information security policy with the respective stakeholders and ensure the alignment with regulatory requirements, international standard, and best practices. Manage the submission to the different risk governance committees including Cyber Security Committee<br>.<br>What We’re Looking For Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related fieldgood understanding of cybersecurity concepts - including network, endpoint, and application security Awareness of cybersecurity risk management principles and security control frameworks Familiarity with SAMA and NCA regulatory requirements is an advantage Strong research, analytical, and documentation skills Excellent written and verbal communication in Arabic and English - ability to present findings clearly and concisely Eagerness to learn, high attention to detail, and a risk-based mindset For years of experience: Around 4 years of experience with preferred 3 years in a relevant rol<br>e.
Role purpose:The IT Security Analyst plays a critical role in safeguarding an organization’s IT systems, networks, and data from cyber threats. This role involves implementing security measures, monitoring vulnerabilities, and responding to incidents to ensure the organization’s digital assets are protected.<br>Key responsibilities:Deploy, configure, and manage security tools such as firewalls, antivirus software, and intrusion detection systems (IDS/IPS). Implement security protocols and policies to protect data and systems. Monitor networks and systems for potential security breaches or anomalies. Utilize SIEM tools to analyze logs and alerts, investigating suspicious activities. Act as the first responder for cybersecurity incidents, including detection, containment, and eradication. Conduct post-incident reviews to identify root causes and implement preventive measures. Perform vulnerability assessments and penetration testing to identify security gaps. Work with IT teams to prioritize and remediate vulnerabilities. Ensure the organization complies with relevant security standards and regulations (e.g., GDPR, PCI-DSS, ISO 27001). Maintain detailed documentation of security policies, incidents, and procedures. Conduct regular training sessions to educate employees about cybersecurity best practices. Promote awareness of phishing, social engineering, and secure data handling. Collaborate with IT teams to design and implement secure infrastructure solutions. Liaise with external vendors and auditors to assess and improve security measures.<br>Qualifications:Bachelor’s degree in computer science, Cybersecurity, Information Technology, or a related field.2 – 4 years in IT security or a related role. Professional certificate in Comp TIA Security+, Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP) or Certified Cybersecurity (CC) and GIAC Security Essentials (GSEC).
Job Purpose:Support secure facilities and operations by designing, configuring, and maintaining security systems to ensure reliable monitoring, controlled access, and effective response to security events across operational environments.<br>Key Responsibilities:Support configuration and maintenance of security systems across facilities e.g., access control, attendance system, screening, and monitoring platforms Monitor systems performance, alarms, and events to identify issues and support timely response Support integration of security systems with network and monitoring platforms to ensure system interoperability Conduct preventive maintenance and system health checks to ensure operational readiness Analyze security system logs and trends to identify anomalies and improvement opportunities Support upgrades, capacity checks, and retention policy implementation for security systems Coordinate vendor activities and field support for installations, maintenance, and issue resolution Maintain adherence to NCA regulations, cybersecurity requirements, and approved security system standards, configurations, and documentation practices<br>Job Requirements:Bachelor’s degree in Engineering, Electronics, Information Technology, or a related discipline This role typically requires a minimum of 1 year of experience in security systems engineering or electronic security roles Demonstrated experience working with CCTV, access control, and security monitoring systems Good understanding of system integration, networking concepts, and security infrastructure Strong troubleshooting, analytical, and documentation skills
Location: Saudi Arabia Contract: 6-12 Months Industry: Banking / Financial Services<br>Overview We are supporting a large banking client in Saudi Arabia who is seeking an experienced Application Security Assurance Lead to establish, mature, and optimize their Application Security (App Sec) governance and assurance capability.<br>This is not a hands-on penetration testing or offensive security role. The client has already invested in security tooling and established offensive security capabilities, including SAST and DAST. The focus of this position is to provide independent oversight, assurance, governance, and process optimization to ensure application security controls are operating effectively and consistently across the organization.<br>The successful candidate will assess the current App Sec landscape, identify gaps, formalize processes, and drive best-practice adoption across engineering and technology teams.<br>Key Responsibilities Lead Application Security governance and assurance activities across the organization. Review existing App Sec processes, controls, and operating models to identify gaps and improvement opportunities. Conduct gap assessments, maturity reviews, and control effectiveness assessments. Ensure security activities are being performed consistently and aligned to industry best practices. Partner with engineering, development, Dev Ops, architecture, and security teams to streamline security processes and improve operational effectiveness. Develop and implement App Sec governance frameworks, policies, standards, and procedures. Establish clear controls, ownership models, and assurance mechanisms across the software development lifecycle. Review and optimize existing SAST, DAST, and application security processes to ensure there are no control gaps. Provide independent assurance over the effectiveness of application security controls and activities. Drive consistency and standardization of secure development practices across technology teams. Facilitate stakeholder workshops and gather requirements to define and document target-state processes. Produce governance documentation, reporting, and recommendations for senior technology and security stakeholders. Act as a trusted advisor to technology and security leadership on App Sec governance and assurance matters.<br>Required Experience10+ years of experience within Cyber Security, Application Security, Technology Risk, or Security Governance. Strong experience in Application Security governance, assurance, or secure software development oversight. Experience performing:App Sec maturity assessments Control reviews Security assurance activities Risk and gap assessments Process optimization initiatives Strong understanding of:Secure SDLCSASTDASTDev Sec Ops Secure development practices Application Security frameworks and standards Experience creating and implementing:Governance frameworks Policies Standards Procedures Control libraries Previous experience within banking or highly regulated financial services environments is highly desirable.<br>Preferred Profile Strong communicator capable of engaging both technical and non-technical stakeholders. Comfortable facilitating workshops and challenging existing processes constructively. Able to operate at a strategic and advisory level rather than purely technical delivery. Ideally, we want UK or EU candidates. Strong document creation and process design capability. Experience influencing engineering and development teams without direct authority. Able to assess current-state environments and build practical, scalable governance models.
Penta Consulting is a leading technology services partner delivering professional and managed solutions across EMEA.<br>We're seeking an OT Security Operations Engineer to support one of our key enterprise clients. This role is ideal for someone with strong OT security monitoring experience, hands-on expertise with Nozomi Networks, and a passion for protecting critical industrial environments.<br>Key Responsibilities:OT Security Operations Provide onsite OT Security Operations support as a Resident Engineer Support day-to-day security monitoring, log source analysis, and troubleshooting Monitor Nozomi dashboards and SIEM alerts, validating system status and coordinating remediation activities Conduct OT traffic analysis to identify new devices, communication anomalies, and potential security threats Advise on improvements to OT monitoring capabilities, network segmentation, and security coverage Produce regular security, threat, vulnerability, and performance reports<br>Key Requirements:Experience in OT Security Operations within industrial or critical infrastructure environments Hands-on experience with Nozomi Networks and SIEM platforms Strong understanding of OT protocols, network monitoring, and threat detection Knowledge of OT security governance, compliance, and vulnerability management Excellent analytical, problem-solving, and stakeholder management skills<br>Mandatory Certification:Nozomi Networks Certified Engineer (NNCE)<br>If you're passionate about OT cybersecurity and delivering critical security services that enhance operational resilience, apply now.
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p>Network Security Engineer (CCNP Security) – Cisco & Palo Alto</p><br><p>We are seeking<strong> experienced CCNP Security Resident Engineers</strong> to support a major client in Jeddah. The ideal candidate will have strong hands-on experience with <strong>Cisco Security</strong> technologies and <strong>Palo Alto Firewalls</strong>, providing implementation, administration, troubleshooting, and operational support within an enterprise environment.</p><br>Key Responsibilities<ul><li> Provide onsite resident engineering support for enterprise network security infrastructure. </li><li> Configure, administer, and troubleshoot Cisco security solutions. </li><li> Manage and support Palo Alto Next-Generation Firewalls. </li><li> Monitor security infrastructure performance and ensure high availability. </li><li> Investigate and resolve security incidents and network connectivity issues. </li><li> Implement firewall policies, NAT, VPNs, and security rules. </li><li> Perform software upgrades, patching, and maintenance activities. </li><li> Work closely with customer IT and security teams. </li><li> Produce technical documentation, operational reports, and incident records. </li><li> Participate in change management activities following ITIL processes.</li></ul> </div><h2 data-automation-id="subHeaderPreferredCandidate" class="h5">
Preferred candidate </h2>
<div class="row is-m v-align-top t-small bg-mute">
<div class="col is-3 p5" data-automation-id="label_Years_of_experience">
<b>Years of experience</b>
</div>
<div class="col is-9 p5" data-automation-id="data_Years_of_experience">
No experience required </div>
</div>
<div class="row is-m v-align-top t-small ">
<div class="col is-3 p5" data-automation-id="label_Degree">
<b>Degree</b>
</div>
<div class="col is-9 p5" data-automation-id="data_Degree">
Bachelor's degree / higher diploma </div>
</div>
Qiddiya Investment Company is looking for a highly experienced and innovative Senior Manager - Cybersecurity Security Architecture to join our forward-thinking team. In this pivotal role, you will oversee the development and implementation of a comprehensive cybersecurity architecture framework designed to protect our digital and operational environments. Your strategic leadership will be essential in integrating security into all levels of our organization, ensuring that security measures support our ambitious growth and innovation goals.<br><br>As a senior leader, you will play an instrumental role in shaping the security posture of Qiddiya by designing robust security architectures that align with industry best practices and regulatory standards.<br><br>Responsibilities<br><br>Establish security design principles and standards that guide the implementation of secure systems and applications Conduct thorough assessments of existing security architectures and identify areas for improvement to mitigate risks Collaborate with cross-functional teams, including IT, engineering, and operations, to ensure that security architecture is implemented throughout the SDLC and operational phases Monitor advancements in cybersecurity technologies and integrate relevant solutions to enhance the security architecture Provide mentoring and leadership to team members and promote a culture of security awareness within the organization Develop and deliver presentations on cybersecurity architecture strategies to stakeholders and executive leadership Engage with external partners and vendors to assess potential security solutions and ensure alignment with architecture goals<br><br>Requirements<br><br>Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field; a master's degree is preferred Demonstrated expertise in developing enterprise-level cybersecurity architectures for complex IT environments In-depth knowledge of security frameworks, standards (e.g., NIST, ISO 27001, CIS Controls), and best practices Strong analytical and problem-solving abilities, with a strategic and innovative mindset Relevant certifications such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Architect (CISA) are highly desirable
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>Network Security Engineer (CCNP Security) – Cisco & Palo Alto We are seeking experienced CCNP Security Resident Engineers to support a major client in Jeddah.<br> The ideal candidate will have strong hands-on experience with Cisco Security technologies and Palo Alto Firewalls , providing implementation, administration, troubleshooting, and operational support within an enterprise environment.<br> Key Responsibilities Provide onsite resident engineering support for enterprise network security infrastructure.<br> Configure, administer, and troubleshoot Cisco security solutions.<br> Manage and support Palo Alto Next-Generation Firewalls.<br> Monitor security infrastructure performance and ensure high availability.<br> Investigate and resolve security incidents and network connectivity issues.<br> Implement firewall policies, NAT, VPNs, and security rules.<br> Perform software upgrades, patching, and maintenance activities.<br> Work closely with customer IT and security teams.<br> Produce technical documentation, operational reports, and incident records.<br> Participate in change management activities following ITIL processes.<br> CCNP Security Certification (Preferred/Required).<br> 3+ years of hands-on experience in Network Security.<br> Strong experience with Cisco Security technologies.<br> Hands-on experience with Palo Alto Firewalls.<br> Strong understanding of: Routing & Switching TCP/IP VPN Technologies (IPSec, SSL VPN) NAT Access Control Lists (ACLs) Network Segmentation Experience troubleshooting enterprise network security environments.<br> Excellent communication skills.<br> Ability to join immediately and relocate/work in Jeddah.<br> Preferred Skills Panorama administration.<br> Cisco Firepower Management Center (FMC).<br> Cisco ASA / Firepower.<br> High Availability (HA) configurations.<br> ITIL knowledge.<br></span> </div><h2 data-automation-id="subHeaderPreferredCandidate" class="h5">
Preferred candidate </h2>
<div class="row is-m v-align-top t-small bg-mute">
<div class="col is-3 p5" data-automation-id="label_Years_of_experience">
<b>Years of experience</b>
</div>
<div class="col is-9 p5" data-automation-id="data_Years_of_experience">
No experience required </div>
</div>
<div class="row is-m v-align-top t-small ">
<div class="col is-3 p5" data-automation-id="label_Degree">
<b>Degree</b>
</div>
<div class="col is-9 p5" data-automation-id="data_Degree">
Bachelor's degree / higher diploma </div>
</div>