Qiddiya | القدية

Senior Manager - Third Party Security

Qiddiya | القدية

Riyadh, Riyadh Province, Saudi Arabia · Full Time

Be the first to apply

Experience
8–12 yrs
Salary
—
Openings
1
Posted
4 days ago
Work mode
In office
Education
Bachelor's degree
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Position Overview

Join Qiddiya as a Senior Manager overseeing the Third-Party Security Risk Management program. This role is vital to safeguarding Qiddiya's information assets by ensuring that vendors, partners, consultants, and service providers adhere strictly to cybersecurity standards, thus preventing any unacceptable risks.

Key Responsibilities

  • Design, implement, and upkeep the Third-Party Security Risk Management (TPSRM) framework.
  • Carry out comprehensive cybersecurity due diligence and risk evaluations of vendors and suppliers.
  • Evaluate security prerequisites through procurement, RFP, and contract phases.
  • Assess cloud service providers, SaaS solutions, managed service vendors, and strategic partners for compliance and risk.
  • Define and standardize vendor security controls aligned with frameworks such as NCA ECC, ISO 27001, NIST, alongside specific Qiddiya cybersecurity protocols.
  • Create methodologies for vendor risk classification and assessment.
  • Oversee remediation initiatives, ensuring identified vulnerabilities are resolved appropriately.
  • Work collaboratively with Procurement, Legal, Compliance, Enterprise Risk, and Technology departments.
  • Lead routine reassessments for critical vendors to maintain compliance and security posture.
  • Provide senior leadership with detailed reporting on third-party cyber risks, emerging trends, and key performance indicators.
  • Manage external security audits, questionnaires, and assurance engagements efficiently.
  • Guide and develop the Third-Party Security team to meet organizational goals.

Candidate Requirements

  • A bachelor's degree in Cybersecurity, Information Security, Computer Science, or a closely related discipline.
  • A solid experience background in cybersecurity ranging from eight to twelve years.
  • At least four years specializing in Third-Party Security, Vendor Risk Management, Cybersecurity Risk Management, or Governance, Risk, and Compliance (GRC).
  • Proven track record working in large-scale enterprises, giga projects, banking, telecommunications, government sectors, or critical infrastructure settings.
  • Experience leading teams and engaging with senior-level stakeholders effectively.

Additional Information

Employment type is full-time and requires onsite presence in Riyadh, Saudi Arabia.

Minimum education

Bachelor's Degree

How they work

Leadership Relationship Building

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer