Cyber Security Specialist
Jeddah, Makkah Province, Saudi Arabia (Hybrid) · Full Time
Be the first to apply
- Experience
- 3–5 yrs
- Salary
- —
- Openings
- 1
- Posted
- 20 hours ago
- Work mode
- Hybrid
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Join Masharah Advisory as a Cybersecurity & Infrastructure Security Specialist based in Jeddah, Saudi Arabia. This role demands leadership in owning and enhancing the company’s cybersecurity and infrastructure security posture. You will be the central technical security authority and liaison between the organization and external cybersecurity, infrastructure, network, and technology providers.
Key Responsibilities
- Maintain continual evaluation and ownership of the organization's cybersecurity and infrastructure security landscape.
- Perform comprehensive security assessments to detect vulnerabilities, risks, and improvement areas.
- Define cybersecurity requirements, controls, and technical standards encompassing network security, firewalls, segmentation, VPN/ZTNA, identity & access management, endpoint detection and response, SIEM, backup, disaster recovery, application, and data security.
- Develop security requirements for third-party service providers.
- Evaluate, recommend, and lead the adoption of appropriate security technologies and solutions.
- Lead technical dialogues and scrutinize vendor architectures, configurations, and proposals, ensuring implementation adheres to security obligations.
- Oversee the implementation and validation of all security controls and solutions.
- Manage vulnerability and remediation workflows, coordinate penetration tests, and ensure all issues are resolved effectively.
- Establish security monitoring protocols, including logging, alerting, SIEM/SOC, and EDR/XDR settings.
- Implement incident response plans and manage containment, recovery, and handling of security incidents.
- Define and supervise roles and controls related to IAM, MFA, RBAC, PAM, privileged access, and network access control.
- Ensure the hardening and secure configuration of systems and infrastructure.
- Review DevSecOps practices, including GitHub, CI/CD, and application security measures.
- Assess and maintain backup, disaster recovery, business continuity, RTO/RPO, and ransomware preparedness.
- Support compliance by identifying and implementing Saudi-specific cybersecurity and data protection requirements.
- Maintain relevant cybersecurity documentation such as policies, standards, risk registers, and architecture diagrams.
- Provide management reports detailing security risks, gaps, remediation status, and priorities.
- Serve as the key company representative in cybersecurity matters with external service parties.
Candidate Profile
- Minimum of 3 to 5 years of relevant professional experience in cybersecurity, infrastructure security, network security, or security engineering.
- Demonstrated expertise in conducting security assessments and identifying risks or gaps.
- Strong knowledge in network security technologies and protocols including firewalls, NGFW, IPS/IDS, VLANs, VPN/ ZTNA, DMZ, and secure remote access.
- Sound understanding of server, virtualization, endpoint security, and identity management protocols like IAM, MFA, RBAC, PAM.
- Familiarity with security monitoring tools such as EDR/XDR, SIEM, SOC, and centralized logging.
- Experience with web application security concepts including WAFs and penetration testing methodologies.
- Good grasp of backup, disaster recovery, business continuity, and ransomware resilience strategies.
- Preferred knowledge of GitHub, CI/CD pipelines, DevSecOps, and application security best practices.
- Strong capabilities in reviewing and critiquing technical architectures, security designs, vendor proposals, and implementation plans.
- Excellent communication skills in English, Arabic proficiency is a plus.
- Ability to work autonomously, lead complex security initiatives, and engage effectively with technical and management stakeholders.
Preferred Certifications
- CISSP or CISM
- Security+
- CCNA or CCNP
- Palo Alto Networks or Fortinet Certifications
- ISO 27001-related certifications
- Other relevant cybersecurity or infrastructure security certifications
Work Environment and Conditions
The role is based in Jeddah with a hybrid work model, combining remote work and onsite attendance approximately once or twice per week, plus additional visits as needed for meetings, vendor engagements, implementations, audits, or assessments. The employment type is full-time.
Industry
Cybersecurity