M

Information Security Manager (KSA National)

Maximus KSA | ماكسيموس السعودية

Riyadh, Riyadh Province, Saudi Arabia · Full Time

Be the first to apply

Experience
7–10 yrs
Salary
Openings
1
Posted
1 week ago
Work mode
In office
Education
Bachelor's degree
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Job Overview

We seek an experienced Information Security Manager to join our team based in Riyadh, Saudi Arabia. This pivotal governance position is responsible for independent oversight, risk management, and assurance related to our cybersecurity and information security framework. You will collaborate closely with senior leadership, IT, Internal Audit, Legal, and external regulatory bodies to maintain a secure, compliant environment aligned with Saudi Arabian regulations.

Key Responsibilities

  • Craft and update the organisation's cybersecurity strategy and roadmap.
  • Lead the Information Security Management Framework in accordance with ISO 27001, NCA ECC, and relevant Saudi regulatory standards.
  • Manage cybersecurity governance, policies, standards, and maintain the Cybersecurity Risk Register.
  • Conduct cybersecurity risk assessments involving technology projects, cloud environments, new systems, and third-party partnerships.
  • Supervise security compliance, control reviews, and independent cybersecurity audits.
  • Monitor audit findings and remediation efforts, reporting critical risks to senior management.
  • Oversee cybersecurity incident governance and response operations.
  • Manage risks associated with third-party security and vendors.
  • Serve as a primary contact for regulators, auditors, and external security assessors.
  • Collaborate with Legal and other departments to ensure compliance with Saudi PDPL and data protection legislation.

Required Qualifications and Skills

  • 7 to 10 years of experience in information security, cybersecurity governance, or IT governance, including at least 3 years in managerial or governance roles.
  • Strong familiarity with NCA ECC and Saudi cybersecurity regulatory frameworks.
  • Knowledge of Saudi PDPL and SDAIA compliance requirements.
  • Extensive experience with ISO/IEC 27001 standards, including leading audits.
  • Proven expertise in cybersecurity governance, risk management, compliance, and assurance.
  • Exceptional skills in policy development, reporting, and managing senior stakeholders.
  • Bachelor's degree in a relevant field.
  • Professional certifications such as CISM, CISA, ISO 27001 Lead Implementer/Auditor, or COBIT 2019.
  • Fluency in English and Arabic is mandatory.

Additional Information

This role requires a strong command of the Saudi cybersecurity regulatory landscape along with experience in governance. Fluency in Arabic is essential, highlighting the importance of local knowledge and communication abilities.

Minimum education

Bachelor's Degree

How they work

Communication Attention to Detail Strategic Thinking Relationship Building

Languages

Apple Servicenow
🤖
Online · instant AI help
Broxer