Cybersecurity Risk Specialist
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Job Overview
The Cybersecurity Risk Specialist is tasked with identifying, evaluating, managing, tracking, and reporting cybersecurity risks that span the company’s technological landscape including systems, projects, third-party relationships, and business operations. The role ensures comprehensive documentation of cybersecurity risks and collaborates with risk and control stakeholders to manage treatment actions, continuously oversee residual and accepted risks, and facilitate strategic decisions guided by the National Cybersecurity Authority (NCA) standards, internal policies, and industry-recognized risk management frameworks.
Key Duties
- Conduct thorough identification, assessment, analysis, and monitoring of cybersecurity risks related to organizational infrastructure, applications, projects, partners, and processes.
- Offer expert cybersecurity risk consultancy to internal teams and guide risk-informed decision-making for technology deployments and third-party engagements.
- Track the organization’s cybersecurity risk posture and emerging threats, ensuring prompt escalation and reporting to pertinent management and governance bodies.
- Ensure cybersecurity risk management practices align with NCA mandates, enterprise risk management systems, and standard cybersecurity frameworks.
Operational Responsibilities
- Determine cyber threats, vulnerabilities, affected resources, control measures, and potential business impacts during risk evaluations.
- Examine evidence supporting completed risk treatments and re-evaluate residual risks where necessary.
- Manage and update the cybersecurity risk register, including ratings, ownership, mitigation plans, timelines, and status updates.
- Assist in assessing risks related to third parties such as vendors, cloud services, and other external entities.
- Contribute to risk assessments throughout project phases including initiation, design, procurement, deployment, and major technology transitions to preemptively address risks.
- Collaborate with teams handling vulnerability management, threat intelligence, incident response, and compliance to integrate relevant insights into risk evaluations.
- Support continuous enhancement of risk methodologies, criteria, templates, taxonomies, and related processes within cybersecurity risk management.
- Create and oversee Key Risk Indicators (KRIs) to detect trends signaling shifts in cybersecurity risk exposure.
Safety & Security
- Report any safety hazards or issues encountered immediately by submitting a safety report.
- Adhere strictly to safety protocols outlined in manuals and safety documents.
- Promptly inform supervisors of all safety incidents, accidents, injuries, or damages.