Director of Cybersecurity (CISO-Level Role)
Saudi Nationals Only
Cybersecurity - Reporting to the Vice President / Executive Leadership
A leading university in Riyadh is seeking a Director of Cybersecurity to lead and govern the institution's cybersecurity strategy, risk posture, and digital trust ecosystem at a strategic (CISO-level) level.
Key Responsibilities
- Develop and execute a comprehensive cybersecurity strategy aligned with the university vision, regulatory frameworks (NCA ECC, CSCC), and international frameworks (ISO 27001, NIST, COBIT)
- Establish and oversee cybersecurity governance frameworks, policies, standards, and compliance programs across the institution
- Lead enterprise cyber risk management - risk identification, assessment, mitigation, and executive reporting
- Direct incident response (IR), crisis management, and business continuity (BCP/DR) at an institutional level
- Oversee Security Operations (SOC), threat intelligence, vulnerability management, and protection of critical infrastructure and data assets
- Ensure full compliance with regulatory cybersecurity requirements and audit requirements (internal and external)
- Lead secure digital transformation initiatives, including cloud security, identity and access management (IAM), and zero-trust architecture
- Build and lead high-performing cybersecurity teams, while managing vendors, contracts, and programs
- Coordinate with internal and external stakeholders and foster a culture of cybersecurity awareness across academic and administrative units
Requirements
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, IT, or related field from a globally recognized institution (QS or Times-ranked preferred); Master's strongly preferred
- 10+ years of experience in cybersecurity or information security, with 5+ years in a senior leadership role (CISO, Head of Cybersecurity, or Director of Information Security)
- Proven experience in regulated environments (government, higher education, or large-scale enterprise organizations)
- Strong skills in cybersecurity governance, enterprise risk management, incident response leadership, and compliance
- Hands-on understanding of SIEM, SOC operations, IDS/IPS, EDR, and cloud security solutions
- Professional proficiency in English and Arabic
- Demonstrated impact in risk reduction, compliance improvement, or cybersecurity maturity advancement
Preferred:
- Industry certifications such as CISSP, CISM, CISA, CRISC, or equivalent
- Experience in higher education, research institutions, or government digital transformation programs
- Knowledge of emerging threats, threat intelligence, and APT landscapes
- Experience with Zero Trust Architecture, Identity Governance, and cloud security frameworks