وظيفة نائب مدير مخاطر الأمن السيبراني والامتثال لدى القدية في الرياض
Associate Director - Cybersecurity Risk and Compliance
🏢 القدية (Qiddiya | القدية)
تفاصيل الوظيفة
القدية تعلن عن وظيفة Associate Director - Cybersecurity Risk and Compliance في الرياض، السعودية.
المهام والمسؤوليات
- إجراء تقييمات دورية ومخصصة لمخاطر الأمن السيبراني عبر بيئات تكنولوجيا المعلومات (IT) وتكنولوجيا التشغيل (OT).
- إجراء تقييمات مخاطر خاصة بـ OT على الأصول مثل PLCs و HMIs و RTUs والأنظمة الهندسية.
- تحديد وتوثيق سيناريوهات المخاطر ذات الصلة بـ OT (مثل تعطل نظام التحكم، الوصول غير المصرح به، التلاعب بالسلامة).
- تنسيق مراجعات المخاطر كجزء من التغييرات الرئيسية في IT/OT، مثل ترقيات الأنظمة أو النشر الجديد.
- إعادة تقييم وضع المخاطر بعد التغييرات الكبيرة أو الحوادث أو التحديثات التنظيمية.
- مراجعة والتحقق من صحة الضوابط الحالية لحساب المخاطر المتبقية وتحديد أولويات إجراءات المعالجة.
- توفير أدوات وإرشادات موحدة لدعم التقييمات الذاتية من قبل فرق IT و OT والأعمال.
- دعم دمج نتائج التقييم في تصميم الضوابط، والتقسيم (zoning)، والتجزئة (segmentation)، ونشر الأنظمة.
- تتبع تقدم معالجة المخاطر ورفع العناصر المتأخرة أو ذات الأولوية العالية حسب الحاجة.
- التنسيق مع إدارة الأداء لتحديد ومراقبة مؤشرات المخاطر الرئيسية (KRIs) لتتبع التغيرات في التعرض لمخاطر الأمن السيبراني بشكل استباقي.
- الحفاظ على سجل المخاطر السيبرانية، بما في ذلك الإدخالات الخاصة بـ OT، مع تسجيل المخاطر المحددة وتصنيفات الاحتمالية والتأثير وخطط المعالجة والملكية والحالة.
- تنسيق وتنفيذ تقييمات الامتثال الداخلي للأمن السيبراني عبر جميع المجالات والوظائف ذات الصلة.
- العمل كواجهة رئيسية لعمليات التدقيق الخارجية والتفتيش التنظيمي، بما في ذلك التحضير والتنفيذ والرد.
- إجراء تقييمات امتثال دورية لبيئات OT، بما في ذلك SCADA و DCS و PLCs والبنية التحتية للشبكات المرتبطة بها.
- الحفاظ على جرد لأصول OT ذات الصلة بالامتثال وربطها بمتطلبات ومعايير التحكم المطبقة.
- مراقبة الالتزام بسياسات الأمن السيبراني، ورفع حالات عدم الامتثال، وتنسيق الإجراءات التصحيحية مع الفرق المعنية.
- تتبع وإدارة خطط المعالجة لثغرات الامتثال وعدم المطابقة ونتائج التدقيق حتى الإغلاق.
- التحقق من فعالية الضوابط المنفذة أو خطط التخفيف قبل إغلاق ثغرات الامتثال.
- مراجعة والتحقق من خطوط الأساس للتكوين لأنظمة OT (مثل قواعد جدار الحماية، إصدارات البرامج الثابتة) لضمان التوافق مع معايير الامتثال.
- تنسيق جمع الأدلة والتوثيق وتخطيط المعالجة للنتائج المتعلقة بالامتثال.
- الإبلاغ عن حالة الامتثال والمخاطر الخاصة بـ IT و OT للقيادة وحوكمة الأمن السيبراني.
- دعم الوعي والتدريب على الامتثال للفرق ذات مسؤوليات التحكم في كل من IT و OT.
- الحفاظ على سجل مركزي للامتثال يغطي كلاً من IT و OT، ويربط المتطلبات التنظيمية بالسياسات والضوابط والفرق المسؤولة ومصادر الأدلة.
- إدارة مخاطر الأمن السيبراني للأطراف الثالثة من خلال الحفاظ على عمليات تقييم موحدة ومعايير العناية الواجبة وتتبع المعالجة.
- تنسيق وإجراء تقييمات الأمن السيبراني للأطراف الثالثة عبر موردي IT و OT لضمان التوافق مع السياسات الداخلية والمتطلبات التنظيمية.
- مراجعة أنظمة OT المقدمة من البائع والوثائق الداعمة لضمان تضمين ضوابط الأمان والامتثال للمعايير المطبقة (مثل NCA OTCC، IEC 62443).
- ضمان توثيق نتائج مخاطر الطرف الثالث وتصنيفها من حيث المخاطر وتتبعها حتى الحل، بما في ذلك القبول أو تطبيق الضوابط التعويضية.
- الحفاظ على سجل للموردين الذين تم تقييمهم والمخاطر المرتبطة وفجوات التحكم وحالة المعالجة للإشراف المستمر وإعداد التقارير.
- التعاون مع المشتريات والشؤون القانونية والامتثال لتضمين متطلبات الأمن السيبراني في اتفاقيات الطرف الثالث، بما في ذلك البنود الخاصة بـ OT عند الاقتضاء.
- المساهمة في تطوير ومراجعة سياسة أمان الطرف الثالث ومتطلبات التحكم الدنيا لاستخدامها في المشتريات والتعاقد.
- دعم طلبات التدقيق الداخلي والخارجي المتعلقة بإدارة مخاطر الأمن السيبراني للطرف الثالث.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو علوم الحاسب أو تكنولوجيا المعلومات أو مجال ذي صلة.
- يفضل درجة الماجستير.
- خبرة لا تقل عن 10-12 سنة في مجال الأمن السيبراني.
- خبرة قوية في إدارة مخاطر الأمن السيبراني والامتثال والتقييمات والضمان.
عرض النص الأصلي للإعلان
- Roles and Responsibilities:
- Conduct periodic and ad hoc cybersecurity risk assessments across IT and OT environments
- Perform OT-specific risk assessments on assets such as PLCs, HMIs, RTUs, and engineering systems
- Identify and document OT-relevant risk scenarios (e.g., control system disruption, unauthorized access, safety manipulation)
- Coordinate risk reviews as part of major IT/OT changes, such as system upgrades or new deployments
- Reassess risk posture following major changes, incidents, or regulatory updates
- Review and validate existing controls to calculate residual risk and prioritize treatment actions
- Provide standardized tools and guidance to support self-assessments by IT, OT, and business teams
- Support integration of assessment outcomes into control design, zoning, segmentation, and system deployment
- Track risk treatment progress and escalate overdue or high-priority items as needed
- Coordinate with performance management to define and monitor key risk indicators (KRIs) to proactively track changes in cybersecurity risk exposure
- Maintain the cybersecurity risk register, including OT-specific entries, capturing identified risks, likelihood and impact ratings, treatment plans, ownership, and status
- Coordinate and execute internal cybersecurity compliance assessments across all relevant domains and functions
- Serve as the lead interface for external audits and regulatory inspections, including preparation, execution, and response
- Conduct periodic compliance assessments of OT environments, including SCADA, DCS, PLCs, and associated network infrastructure
- Maintain an inventory of compliance-relevant OT assets and map them to applicable control requirements and standards
- Monitor adherence to cybersecurity policies, escalate non-compliance, and coordinate corrective actions with relevant teams
- Track and manage remediation plans for compliance gaps, non-conformities, and audit findings through closure
- Validate the effectiveness of implemented controls or mitigation plans before closing compliance gaps
- Review and validate configuration baselines for OT systems (e.g., firewall rules, firmware versions) to ensure alignment with compliance standards
- Coordinate evidence collection, documentation, and remediation planning for compliance-related findings
- Report OT and IT cybersecurity compliance status and risks to leadership and cybersecurity governance
- Support compliance awareness and training for teams with control responsibilities in both IT and OT
- Maintain a centralized compliance register, covering both IT and OT, that maps regulatory requirements to policies, controls, responsible teams, and evidence sources
- Govern third-party cybersecurity risk by maintaining standardized assessment processes, due diligence criteria, and remediation tracking
- Coordinate and conduct third-party cybersecurity assessments across IT and OT suppliers to ensure alignment with internal policies and regulatory requirements
- Review vendor-supplied OT systems and supporting documentation to ensure inclusion of security controls and compliance with applicable standards (e.g., NCA OTCC, IEC 62443)
- Ensure third-party risk findings are documented, risk-rated, and tracked through resolution, including acceptance or application of compensating controls
- Maintain a register of assessed vendors, associated risks, control gaps, and remediation status for ongoing oversight and reporting
- Collaborate with procurement, legal, and compliance to embed cybersecurity requirements into third-party agreements, including OT-specific clauses where applicable
- Contribute to the development and review of third-party security policy and minimum control requirements for use in procurement and onboarding
- Support internal and external audit requests related to third-party cybersecurity risk management
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
- Master's degree is preferred.
- 10-12+ years of cybersecurity experience
- Strong experience in cybersecurity risk management, compliance, assessments, and assurance
المصدر: LinkedIn - أُضيفت للموقع في 18 أغسطس 2026
وظائف أخرى لدى القدية