📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

وظيفة أخصائي الامتثال للأمن السيبراني شاغرة لدى طيران ناس في الرياض

Cybersecurity Compliance Specialist
🏢 طيران ناس (flynas)
🕒 نُشرت: (منذ 11 يوماً) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

طيران ناس تعلن عن وظيفة 'أخصائي الامتثال السيبراني' (Cybersecurity Compliance Specialist) في الرياض.

نبذة عن الوظيفة

المسؤولية عن دعم وتنفيذ أنشطة الامتثال السيبراني لضمان التزام المنظمة بقوانين ولوائح وسياسات ومعايير ومتطلبات داخلية سارية. يشمل الدور دعم تقييمات الامتثال، وجمع الأدلة والتحقق منها، وتحديد وتتبع فجوات الامتثال والإجراءات التصحيحية، وإعداد التقارير التنظيمية، والحفاظ على جاهزية المنظمة لعمليات التدقيق السيبراني والتقييمات التنظيمية.

المهام والمسؤوليات

  • مراقبة وتقييم امتثال المنظمة لقوانين ولوائح وأطر الامتثال السيبراني سارية، بما في ذلك متطلبات الهيئة الوطنية للأمن السيبراني (NCA) مثل الضوابط الأساسية للأمن السيبراني (ECC)، وضوابط الأمن السيبراني للأنظمة الحرجة (CSCC)، وضوابط الأمن السيبراني للسحابة (CCC)، وضوابط أمن البيانات السيبرانية (DCC)، وغيرها من متطلبات NCA سارية.
  • تحديد فجوات الامتثال السيبراني وتنسيق تتبع وإغلاق النتائج والإجراءات التصحيحية مع مالكي الضوابط المعنيين.
  • مراقبة وصيانة التزامات ومتطلبات الامتثال السيبراني سارية، بما في ذلك التغييرات في المتطلبات التنظيمية والتنظيمية للمنظمة.
  • الحفاظ على سجلات دقيقة وكاملة وقابلة للتتبع لتقييمات الامتثال السيبراني والنتائج والإجراءات التصحيحية والأدلة الداعمة.
  • دعم التقييمات التنظيمية السيبرانية والتدقيقات الداخلية والخارجية ومراجعات الامتثال الأخرى من خلال تنسيق المعلومات والأدلة والاستجابات والإجراءات المتابعة المطلوبة.
  • تقديم الإرشادات والدعم في الامتثال السيبراني لأصحاب المصلحة الداخليين المعنيين بشأن المتطلبات والضوابط والسياسات والمعايير سارية.
  • تنسيق إعداد وجمع الأدلة والوثائق المطلوبة للتقييمات التنظيمية والتدقيقات الداخلية والخارجية.
  • تتبع النتائج المتعلقة بالتدقيق السيبراني والتنظيمي والتقييمية من خلال المعالجة والإغلاق.
  • دعم مراجعة وتحديث سياسات ومعايير وإجراءات ومتطلبات الضوابط السيبرانية للحفاظ على التوافق مع المتطلبات التنظيمية سارية.
  • دعم تقييمات الامتثال السيبراني للموردين والأطراف الثالثة، بما في ذلك إعداد ومراجعة استبيانات الامتثال والأدلة الداعمة.
  • الحفاظ على وتتبع الاستثناءات والإعفاءات السيبرانية المعتمدة، بما في ذلك الشروط والضوابط التعويضية والمالكين والموافقات وتواريخ الانتهاء.
  • إعداد تقارير دورية للامتثال السيبراني وتقديم مدخلات للوحات المعلومات والتقارير الإدارية.
  • التنسيق مع تقنية المعلومات ووحدات الأعمال ومالكي الضوابط وأصحاب المصلحة الآخرين للحصول على المعلومات والأدلة المطلوبة لتقييمات الامتثال السيبراني.
  • المشاركة في أنشطة التوعية والتواصل بالامتثال السيبراني لتعزيز فهم المتطلبات والمسؤوليات سارية.
  • تتبع الإجراءات التصحيحية مع مالكي الضوابط والعمليات المسؤولين، ومراقبة التواريخ المستهدفة المتفق عليها، ورفع الإجراءات المتأخرة أو غير المحلولة حسب الاقتضاء.
  • إجراء تقييمات وفحوص امتثال دورية مقابل اللوائح والأطر والسياسات والمعايير والإجراءات ومتطلبات الضوابط السيبرانية سارية.
  • جمع ومراجعة والتحقق من وصيانة الأدلة الداعمة لتقييم تنفيذ وفعالية الضوابط السيبرانية سارية.
عرض النص الأصلي للإعلان

Job Purpose

Responsible for supporting and conducting cybersecurity compliance activities to ensure the organization’s adherence to applicable cybersecurity laws, regulations, policies, standards, and internal requirements. The role supports compliance assessments, evidence collection and validation, identification and tracking of compliance gaps and corrective actions, regulatory reporting, and maintaining organizational readiness for cybersecurity audits and regulatory assessments.

Key Accountabilities

• Monitor and assess the organization’s compliance with applicable cybersecurity laws, regulations, and regulatory frameworks, including National Cybersecurity Authority (NCA) requirements such as and not limited to the Essential Cybersecurity Controls (ECC), Critical Systems Cybersecurity Controls (CSCC), Cloud Cybersecurity Controls (CCC), Data Cybersecurity Controls (DCC), and other applicable NCA requirements.

• Identify cybersecurity compliance gaps and coordinate the tracking and timely remediation of identified findings and corrective actions with relevant control owners.

• Monitor and maintain applicable cybersecurity compliance obligations and requirements, including changes to relevant regulatory and organizational requirements.

• Maintain accurate, complete, and traceable records of cybersecurity compliance assessments, findings, corrective actions, and supporting evidence.

• Support cybersecurity regulatory assessments, internal and external audits, and other compliance reviews by coordinating required information, evidence, responses, and follow-up actions.

• Provide cybersecurity compliance guidance and support to relevant internal stakeholders regarding applicable requirements, controls, policies, and standards.

Operational Responsibilities

• Coordinate the preparation and collection of evidence and documentation required for regulatory assessments and internal and external audits.

• Track cybersecurity-related audit, regulatory, and assessment findings through remediation and closure.

• Support the review and update of cybersecurity policies, standards, procedures, and control requirements to maintain alignment with applicable regulatory requirements.

• Support cybersecurity compliance assessments of vendors and third parties, including preparation and review of compliance questionnaires and supporting evidence.

• Maintain and track approved cybersecurity exceptions and waivers, including conditions, compensating controls, owners, approvals, and expiry dates.

• Prepare periodic cybersecurity compliance reports and provide inputs to dashboards and management reporting.

• Coordinate with IT, business units, control owners, and other relevant stakeholders to obtain information and evidence required for cybersecurity compliance assessments.

• Participate in cybersecurity compliance awareness and communication activities to promote understanding of applicable requirements and responsibilities.

• Track remediation actions with responsible control and process owners, monitor agreed target dates, and escalate overdue or unresolved actions as appropriate.

• Conduct periodic compliance assessments and checks against applicable cybersecurity regulations, frameworks, policies, standards, procedures, and control requirements.

• Collect, review, validate, and maintain supporting evidence to assess the implementation and effectiveness of applicable cybersecurity controls.

المصدر: LinkedIn - أُضيفت للموقع في 28 سبتمبر 2026
رقم الإعلان لدى المصدر: 4470827891