Main Purpose:
The Information Security Senior Specialist is responsible for protecting the organization’s information assets by implementing, monitoring, and continuously improving cybersecurity controls. The role ensures effective risk management, incident response, security governance, and collaboration with IT teams to maintain a secure and resilient technology environment.
Area of Responsibility:
Information Security Governance
- Develop, review, and implement information security controls, policies, procedures, and standards to ensure strong and consistent security practices across the organization.
- Participate in internal and external audits by preparing documentation, evidence, and follow up actions.
- Ensure alignment of security practices with global cybersecurity standards and organizational IT frameworks.
Security Operations & Incident Response
- Monitor security alerts, logs, and events using security monitoring tools (e.g., MS Defender, SIEM, endpoint protection, network security tools).
- Investigate security incidents, coordinate containment and recovery actions, and conduct post incident analysis.
- Identify system and application vulnerabilities and ensure timely remediation in collaboration with infrastructure and application teams.
Security Tools Administration
- Design, implement, and maintain security solutions including firewalls, IAM, PAM, encryption, network/cloud security, endpoint protection, identity and access management tools, email security gateways, and data protection solutions.
- Ensure systems are properly configured, updated, and aligned with security best practices.
- Secure cloud workloads in Microsoft, Google, AWS, and hybrid environments in line with best practice and NCA cloud guidelines.
Risk Assessment & Compliance
- Conduct regular risk assessments, identify gaps, and recommend appropriate mitigation strategies.
- Review systems, solutions, and third party services to ensure secure design and configuration.
- Maintain documentation of risks, controls, and mitigation actions.
Security Awareness & Training
- Support the delivery of security awareness campaigns and targeted training sessions for employees.
- Provide guidance on secure behavior, emerging threats, and preventive practices.
Collaboration & Support
- Act as the point of contact for all security related matters within IT projects and initiatives.
- Collaborate with internal teams and external vendors to ensure cohesive and secure project execution.
- Provide advisory support to maintain secure configurations and protect sensitive information.
Educational Qualification:
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, or an equivalent field.
- Preferred certifications: CISSP,CCSP, CISM, ISO/IEC 27001 Lead Implementer, CRISC, NCA ECC, PDPL, CEH, Security+, or equivalent industry recognized credentials.
Work Experience:
- Minimum 5-6 years of experience in information security, cybersecurity operations, risk management, or related fields.
- Hands on experience with incident response, vulnerability management, end point security, and security monitoring tools.
- Experience supporting the “Security Specialist” function within an IT organization as referenced in internal IT strategy documentation.
- Experience in SOC, MDR incident response, cloud security, vulnerability management, and security engineering.
Required Skills:
- Strong knowledge of cybersecurity frameworks, global best practices, and risk management methodologies.
- Skilled in security monitoring, threat analysis, endpoint protection, network security, and identity management.
- Ability to analyze vulnerabilities, assess risks, and recommend practical remediation actions.
- Strong communication and documentation skills with the ability to collaborate across IT teams.
- Ability to work independently, manage multiple priorities, and maintain high attention to detail.
- Strong knowledge of NCA ECC, SAMA CSF, PDPL, and ISO/IEC 27001.