Cybersecurity Specialist
Yanbu Aramco Sinopec Refining Company (YASREF) Ltd.
Yanbu, Al Madinah Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 15+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Education
- Bachelor's Degree in Computer Science, IT, Computer Engineering or equivalent
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Job Overview
The role involves developing, communicating, and managing a comprehensive information and cybersecurity governance framework. The specialist will be responsible for defending digital assets including computers, servers, mobile devices, networks, and data against cyber threats and breaches. This position requires establishing and ensuring adherence to frameworks and processes that meet internal and external compliance mandates for YASREF.
Key Duties and Responsibilities
- Create and update policies and procedures for the Information Security Division to comply with standards and regulations.
- Apply Risk Assessment aligned with ISO 31000 and corporate Enterprise Risk Management standards.
- Carry out regular internal technical and process risk assessments as part of self-assessments.
- Assess and monitor the effectiveness of implemented IT and OT controls, addressing identified risks and gaps continuously to prevent incidents and manage crisis recovery efficiently.
- Advise and recommend technical controls to mitigate, detect, and respond to security incidents.
- Schedule and conduct internal security audits, random audits at vendor locations; maintain audit documentation and ensure resolution of findings across frameworks such as Internal Controls, ERM, ISO 27001, ISA 99/IEC 62443, and corporate governance.
- Align IT and OT controls with standards like NIST CSF, 800-82, 800-53, and other regulatory bodies including SAMA, NCA, HCIS, as well as best practices like ISO 27001 and SANS Top 20 Critical Controls.
- Develop and manage data classification and privacy frameworks, supporting departments in classifying data and applying appropriate technical safeguards to protect sensitive information.
- Form a unified IT and OT governance body and advisory board to oversee integrated security approaches through IT/OT convergence.
- Maintain continuous improvements of IT Governance functions.
- Review and analyze processes relating to information security, access control, change management, HR security, incident management, asset management, operational and communication security, system development and maintenance, physical security, IT continuity, and compliance.
- Conduct regular information security awareness training and phishing simulation campaigns to evaluate and raise cybersecurity awareness among staff.
- Design diverse training initiatives using multiple channels including email campaigns, online modules, classroom sessions, and digital awareness materials.
- Plan and document disaster recovery resources and priorities, evaluate business disruption risks, and develop mitigation strategies aligned with business continuity goals.
- Develop OT and IT continuity requirements with clearly defined Key Risk Areas and Key Performance Indicators for monitoring and improvement.
- Provide technical support for Industrial Control Systems, Electrical Automation, cybersecurity systems, networking, and operations.
- Engage in cybersecurity research and stay updated with emerging threats; participate actively in the cybersecurity educational community.
- Perform additional tasks as assigned by supervisors.
Education and Certification
- Degree in Computer Science, Information Technology, Computer Engineering, or a related field.
- Relevant professional certification in cybersecurity is mandatory.
Experience Requirements
Applicants should bring at least 15 years of relevant professional experience in cybersecurity roles.
Minimum education
Bachelor's Degree