HRsource تعلن عن وظيفة مستشار الامتثال لأمن المعلومات (غير تقني) في الرياض
تفاصيل الوظيفة
تقدم شركة HRsource فرصة عمل بمسمى مستشار الامتثال لأمن المعلومات (غير تقني) في الرياض، المملكة العربية السعودية. هذا الدور يركز على الامتثال والحوكمة والتوثيق والتنسيق التنظيمي ودعم التدقيق، وليس على الجوانب التقنية للأمن السيبراني.
نبذة عن الوظيفة
نبحث عن مستشار امتثال لأمن المعلومات لدعم أنشطة الامتثال لأمن المعلومات وحماية البيانات الشخصية في المملكة. سيكون المرشح الممثل المحلي الرئيسي للامتثال، ويعمل بشكل وثيق مع الهيئات التنظيمية السعودية، والإدارة العليا، وفرق تقنية المعلومات والأمن، والمدققين، وأصحاب المصلحة الداخليين. تشمل المسؤوليات تنسيق المتطلبات التنظيمية، ودعم الامتثال لقانون حماية البيانات الشخصية (PDPL)، وتوطين السياسات والإجراءات، وصيانة وثائق الامتثال، وضمان جاهزية المنظمة للمراجعات والتدقيقات التنظيمية.
المهام والمسؤوليات
- التواصل الحكومي والامتثال التنظيمي: العمل كنقطة اتصال محلية مع الهيئات التنظيمية السعودية (NCA وSDAIA). مراقبة وتفسير وإبلاغ الإشعارات والمتطلبات والتعاميم التنظيمية لأصحاب المصلحة الداخليين. تنسيق المراسلات التنظيمية والتقديمات والردود والوثائق عبر القنوات والبوابات الرسمية. دعم الإخطارات التنظيمية المتعلقة بحوادث الأمن السيبراني أو البيانات الشخصية وفقاً للمتطلبات والإجراءات الداخلية. الحفاظ على تواصل فعال مع الجهات الحكومية والتنظيمية.
- الامتثال لحماية البيانات الشخصية وقانون PDPL: دعم الامتثال لقانون حماية البيانات الشخصية السعودي (PDPL). تنسيق تحديد وتوثيق أنشطة معالجة البيانات الشخصية مع فرق تقنية المعلومات والأعمال. دعم إعداد وصيانة الملفات والإعلانات والسياسات والإجراءات والاتصالات المتعلقة بـ PDPL. امتلاك وصيانة وثائق الامتثال المحلية لـ PDPL وأدلة التدقيق الداعمة. ضمان دقة وتحديث وتنظيم وثائق الامتثال وجاهزيتها للمراجعات والتدقيقات التنظيمية.
- حوكمة أمن المعلومات وتوطين السياسات: دعم توطين سياسات الأمن السيبراني العالمية إلى سياسات وإجراءات تشغيلية قياسية متوافقة مع المتطلبات السعودية (NCA ECC وCCC). التنسيق مع الفرق التقنية لجمع وتنظيم أدلة الامتثال. الحفاظ على التحكم في الإصدارات ومعايير التوثيق عبر السياسات والإجراءات وسجلات الامتثال.
- الجاهزية للتدقيق وأدلة الامتثال: تطوير وصيانة مستودع منظم لأدلة الامتثال لضمان إمكانية التتبع والجاهزية للتدقيق. جمع وتنظيم وصيانة أدلة الامتثال مثل موافقات السياسات، محاضر اجتماعات اللجان، سجلات الموافقات على الوصول، سجلات التدريب، لقطات الشاشة، والوثائق الداعمة الأخرى. التنسيق مع أصحاب المصلحة والمدققين لضمان اكتمال الأدلة ودقتها وتوفرها عند الحاجة. تتبع متطلبات الامتثال المعلقة وضمان المتابعة والإغلاق في الوقت المناسب.
- التدريب والامتثال للأطراف الثالثة: تنسيق التدريب التوعوي لأمن المعلومات وPDPL للموظفين المحليين. دعم تمارين محاكاة التصيد والحفاظ على سجلات التدريب. المساعدة في فحوصات الامتثال الأساسية لأمن المعلومات للموردين والأطراف الثالثة. مراجعة الوثائق الداعمة بما في ذلك اتفاقيات عدم الإفصاح وبنود أمن المعلومات عند الحاجة.
الشروط والمتطلبات
- خبرة لا تقل عن سنتين في مجالات الامتثال أو حوكمة تقنية المعلومات أو الشؤون التنظيمية أو دعم التدقيق أو أدوار متعلقة بأمن المعلومات.
- فهم قوي لمفاهيم أمن المعلومات، حماية البيانات، والامتثال التنظيمي.
- يفضل بشدة خبرة سابقة في العمل مع الجهات الحكومية السعودية أو الهيئات التنظيمية.
- القدرة على إعداد مراسلات حكومية وتنظيمية واضحة ومهنية.
- إتقان اللغة الإنجليزية بشكل احترافي مع القدرة على فهم المعايير الأمنية وإعداد تقارير مكتوبة واضحة.
- اهتمام كبير بالتفاصيل وانضباط عالٍ في التوثيق.
- القدرة على إدارة متطلبات الامتثال والأدلة والسجلات وأنشطة المتابعة بفعالية.
- الراحة في التعامل مع كبار أصحاب المصلحة والمدققين والمنظمين وفرق تقنية المعلومات والوظائف التجارية.
المهارات المطلوبة
- الإلمام بمعايير ISO/IEC 27001 (يفضل خبرة في التدقيق أو التنفيذ).
- الإلمام بمعايير ISO 22301 أو SOC 2.
- الإلمام بالضوابط الأساسية للأمن السيبراني لهيئة الاتصالات وتقنية المعلومات (NCA ECC).
- الإلمام بالضوابط السحابية للأمن السيبراني لهيئة الاتصالات وتقنية المعلومات (NCA CCC).
- معرفة بمتطلبات قانون حماية البيانات الشخصية السعودي (PDPL).
- الشهادات مثل CompTIA Security+ أو مدقق داخلي ISO أو ما يعادلها (ميزة إضافية).
عرض النص الأصلي للإعلان
Information Security Compliance Consultant
Important: This Is Not a Technical Cybersecurity Role
This position is focused on compliance, documentation, governance, regulatory coordination, and audit support.
📍 Location: Riyadh, Saudi Arabia
About the Role
We are seeking an Information Security Compliance Consultant to support information security and data protection compliance activities in Saudi Arabia.
The role will serve as a key local representative for information security and personal data protection compliance, working closely with Saudi regulatory authorities, senior leadership, IT and security teams, auditors, and internal stakeholders.
The successful candidate will be responsible for coordinating regulatory requirements, supporting PDPL compliance, localizing policies and procedures, maintaining compliance documentation, and ensuring the organization remains prepared for regulatory reviews and audits.
Key Responsibilities
Government Liaison & Regulatory Compliance
- Serve as the local point of contact with relevant Saudi regulatory authorities, including NCA and SDAIA.
- Monitor, interpret, and communicate regulatory notices, requirements, circulars, and updates to relevant internal stakeholders.
- Coordinate regulatory communications, submissions, responses, and required documentation through official channels and portals.
- Support regulatory notifications related to cybersecurity or personal data incidents in line with applicable requirements and internal procedures.
- Maintain professional and effective communication with government and regulatory stakeholders.
Personal Data Protection & PDPL Compliance
- Support compliance with the Saudi Personal Data Protection Law (PDPL).
- Coordinate the identification and documentation of personal data processing activities with IT and business teams.
- Support the preparation and maintenance of PDPL-related filings, declarations, policies, procedures, and employee communications.
- Own and maintain local PDPL compliance documentation and supporting audit evidence.
- Ensure compliance documentation remains accurate, current, organized, and readily available for regulatory reviews and audits.
Information Security Governance & Policy Localization
- Support the localization of global cybersecurity policies and frameworks into Saudi-compliant policies, SOPs, and procedures.
- Ensure relevant documentation is aligned with applicable Saudi requirements, including NCA Essential Cybersecurity Controls (ECC) and Cloud Cybersecurity Controls (CCC) where applicable.
- Coordinate with technical teams to collect and organize evidence required to demonstrate compliance.
- Maintain appropriate version control and documentation standards across policies, procedures, and compliance records.
Audit Readiness & Compliance Evidence
- Develop and maintain a structured Compliance Evidence Repository to ensure audit traceability and readiness.
- Collect, organize, and maintain compliance evidence, including:
- Policy approvals and acknowledgements
- Security committee and management meeting minutes
- Access approval records
- Security and awareness training records
- System screenshots and extracts provided by technical teams
- Other supporting documentation required for compliance
- Coordinate with internal stakeholders and auditors to ensure evidence is complete, accurate, and available when required.
- Track outstanding compliance requirements and ensure timely follow-up and closure.
Training & Third-Party Compliance
- Coordinate information security and PDPL awareness training for local employees.
- Support phishing simulation exercises and maintain appropriate training and awareness records.
- Assist with basic information security compliance checks for local vendors and third parties.
- Review supporting documentation, including NDAs and information security clauses, where required.
What We're Looking For
- Minimum 2 years of experience in compliance, IT governance, regulatory affairs, audit support, or information security-related roles.
- Strong understanding of information security, data protection, and regulatory compliance concepts.
- Previous experience working with Saudi government entities or regulatory bodies is strongly preferred.
- Ability to prepare clear and professional government and regulatory correspondence.
- Professional English proficiency, with the ability to understand security standards and prepare clear written reports.
- Strong attention to detail and a high level of documentation discipline.
- Ability to manage compliance requirements, evidence, records, and follow-up activities effectively.
- Comfortable working with senior stakeholders, auditors, regulators, IT teams, and business functions.
Preferred Qualifications
The following would be advantageous:
- Exposure to ISO/IEC 27001 audits or implementation.
- Exposure to ISO 22301 or SOC 2 audits.
- Familiarity with NCA Essential Cybersecurity Controls (ECC).
- Familiarity with NCA Cloud Cybersecurity Controls (CCC).
- Knowledge of Saudi PDPL requirements.
- Certifications such as CompTIA Security+, ISO Internal Auditor, or equivalent.
What Success Looks Like
The successful candidate will be someone who can take regulatory requirements, understand their implications for the organization, coordinate effectively with the relevant internal teams, and ensure that required documentation and evidence are complete, accurate, traceable, and readily available.
Strong performance in this role will be demonstrated through regulatory alignment, audit readiness, documentation quality, and effective coordination across stakeholders.