Cybersecurity Risk Specialist
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 5–8 yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Position Overview
The role involves conducting comprehensive cybersecurity risk assessments to identify, analyze, and evaluate cyber threats. The specialist will maintain an updated cybersecurity risk register, monitor exposure to risks and emerging threats, and assess the effectiveness of existing security controls.
Key Responsibilities
- Conduct cybersecurity risk assessments and evaluations.
- Identify, analyze, and assess cyber risks impacting the organization.
- Maintain and keep current the cybersecurity risk register.
- Continuously monitor cyber risk exposure and new threats.
- Evaluate the adequacy of security controls in place.
- Recommend strategies for risk mitigation and treatment.
- Track progress of remediation and corrective measures.
- Perform assessments on third-party cybersecurity risks.
- Contribute to ensuring compliance with relevant cybersecurity regulations and standards.
- Develop detailed cybersecurity risk reports and dashboards for stakeholders.
- Escalate critical risks to management and governance boards.
- Offer advisory services regarding cybersecurity risk to internal stakeholders.
- Encourage awareness of cybersecurity risk throughout the organization.
- Collaborate with IT security, compliance, risk management, and audit teams.
- Support initiatives in cybersecurity governance and risk management.
- Monitor and report on Key Risk Indicators (KRIs).
Technical Expertise Required
- Skilled in cybersecurity risk assessment and analysis processes.
- Strong understanding of information security controls and frameworks.
- Experience in vulnerability assessment, malware analysis, and threat management.
- Knowledgeable in network, cloud, and application security basics.
- Adept at security incident analysis and log review.
- Proficient in third-party risk management practices.
Experience and Certifications
Candidates must have between five to eight years of professional experience in cybersecurity risk. Relevant certifications include CISM, Security+, CySA+, and CEH.