S

Information Security Risk Assessment Manager

SAB

Riyadh, Riyadh Province, Saudi Arabia · Full Time

Be the first to apply

Experience
3+ yrs
Salary
Openings
1
Posted
2 weeks ago
Work mode
In office
Education
Bachelor’s or Master’s in Cybersecurity or related field
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

This position is dedicated to leading the enterprise-wide cybersecurity risk management program, charged with identifying, evaluating, and mitigating cybersecurity risks to safeguard organizational information assets. The role involves performing thorough threat modeling and maintaining risk assessment methodologies within the risk management team in the Cybersecurity division located in Riyadh, working Sunday to Thursday from 8:00 AM to 5:00 PM.

Key Responsibilities

  • Conduct comprehensive, risk-based cybersecurity risk assessments adhering to defined SLAs during IT and cybersecurity engagements.
  • Stay informed about industry best practices and standards in Information Security, evaluating policy shortcomings and risks affecting SAB's IT infrastructure, and recommending policy enhancements accordingly.
  • Collaborate closely with end-users, educating them about cybersecurity risks and promoting risk prevention initiatives.
  • Advise IT and business units on optimal strategies for managing identified cybersecurity risks and mitigation tactics.
  • Execute final cybersecurity risk assessments prior to system or project go-live to ensure readiness.
  • Perform detailed threat modeling and cybersecurity risk assessments during early project phases, introduction of new technologies, or periodic reviews of existing assets; documenting threats, vulnerabilities, and controls in a centralized risk register.
  • Analyze and validate risk assessment outcomes to align with cybersecurity concerns identified by other teams.
  • Identify and report application security defects.
  • Enhance cybersecurity patterns during scheduled or ad-hoc assessments by highlighting emerging risks to domain owners.
  • Ensure all engagements conform to the Cybersecurity Risk Management Methodology, risk patterns, and Change Review processes within agreed SLAs.
  • Customize and optimize the cybersecurity risk assessment platform for better accuracy and compatibility.
  • Improve the maturity of cybersecurity risk management by refining processes and documentation.
  • Review and update Cybersecurity Risk Management documentation, including methodologies, FIM sections, standards, and guidelines aligning with group policies and regulatory frameworks such as NCA and SAMA CSF.
  • Maintain risk management design documents ensuring alignment with internal policies and regulatory requirements.
  • Develop and maintain unified cybersecurity risk management methodologies and procedures consistent with enterprise risk management and regulatory demands, ensuring risk treatment plans are tracked and completed.
  • Perform scheduled cybersecurity risk assessments including evaluation of crown jewels and IT services according to the annual plan.
  • Manage periodic cybersecurity assessment plans ensuring regular security reviews of critical systems with documented findings and risk recommendations.
  • Coordinate with independent cybersecurity teams as necessary.
  • Compile quarterly reports highlighting priority cybersecurity risks and present them to IT and Cybersecurity management.
  • Calculate and monitor KPIs and KRIs related to cybersecurity risks.
  • Establish and enforce an escalation matrix for unresolved cybersecurity risks.

Qualifications and Experience

  • Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Information Security, or equivalent discipline.
  • At least 3 years of professional experience in cybersecurity risk management, governance, IT audit, or related roles, preferably within the financial or banking industry.
  • Practical knowledge and experience ensuring compliance with frameworks such as SAMA CSF and NCA ECC.

Minimum education

Master's Degree

How they work

Communication Teamwork & Collaboration Problem Solving Attention to Detail Time Management
🤖
Online · instant AI help
Broxer