📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

The Lending Hub SA تعلن عن وظيفة أخصائي أمن سيبراني في الرياض

Cybersecurity Specialist/ Senior Specialist
🏢 The Lending Hub SA
🕒 نُشرت: (اليوم) 📍 الرياض وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

شركة The Lending Hub SA تبحث عن أخصائي أو أخصائي أول في الأمن السيبراني (Cybersecurity Specialist/Senior Specialist) للعمل في الرياض، لقيادة وظيفة الأمن السيبراني وضمان حماية أصول المعلومات والبنية التحتية السحابية والخدمات الرقمية.

نبذة عن الوظيفة

نسعى إلى تعيين أخصائي أمن سيبراني استباقي وذو خبرة لقيادة وظيفة الأمن السيبراني في الشركة وضمان حماية أصول المعلومات والبنية التحتية السحابية والخدمات الرقمية. يتولى المسؤول تنفيذ وصيانة برنامج أمن سيبراني قوي يتماشى مع إطار الأمن السيبراني للبنك المركزي السعودي (SAMA CSF) ومتطلبات الهيئة الوطنية للأمن السيبراني (NCA) وأفضل الممارسات. سيشرف على حوكمة الأمن السيبراني وإدارة المخاطر والامتثال والمراقبة والاستجابة للحوادث ومبادرات التوعية، مع العمل الوثيق مع الإدارة العليا لتعزيز الوضع الأمني.

المهام والمسؤوليات

  • تطوير وتنفيذ وصيانة سياسات ومعايير وإجراءات الأمن السيبراني للشركة.
  • ضمان توافق حوكمة الأمن السيبراني مع إطار SAMA CSF ولوائح NCA وأفضل الممارسات.
  • وضع مبادئ معمارية للأمن السيبراني وضمان دمج متطلبات الأمان في الحلول التقنية.
  • مراقبة مؤشرات الأداء الرئيسية (KPIs) ومؤشرات المخاطر الرئيسية (KRIs) للأمن السيبراني وتقديم تقارير دورية للإدارة العليا.
  • دعم التحسين المستمر لبرنامج الأمن السيبراني للشركة.
  • إجراء تقييمات مخاطر الأمن السيبراني والإشراف على تنفيذ خطط التخفيف.
  • صيانة إطار إدارة مخاطر الأمن السيبراني وسجل المخاطر.
  • تصنيف المعلومات والأنظمة لضمان الحماية المناسبة للأصول الحيوية.
  • دعم المراجعات الأمنية للأنظمة والتطبيقات والمشاريع الجديدة.
  • الإشراف على إدارة الثغرات والمراقبة الأمنية وأنشطة الاستجابة للحوادث.
  • تنسيق تحقيقات حوادث الأمن السيبراني وضمان الإبلاغ والمعالجة في الوقت المناسب.
  • مراقبة التهديدات السيبرانية الناشئة والتوصية بالضوابط الأمنية المناسبة.
  • العمل عن كثب مع فرق تقنية المعلومات والأعمال لتعزيز الوضع الأمني للمنظمة.
  • ضمان الامتثال لإطار SAMA CSF وضوابط NCA ECC وسياسات الأمن السيبراني الداخلية.
  • دعم عمليات تدقيق الأمن السيبراني والتقييمات التنظيمية ومراجعات الامتثال.
  • تنسيق أنشطة المعالجة لنتائج التدقيق والملاحظات التنظيمية.
  • العمل كجهة اتصال رئيسية للأمن السيبراني لدى المدققين والتقييمات التنظيمية.
  • دعم حوكمة أمن السحابة وتقييمات مخاطر الأمن السيبراني للطرف الثالث.
  • مراجعة مزودي التقنية وترتيبات الاستعانة بمصادر خارجية لضمان الالتزام بالمتطلبات الأمنية.
  • مراقبة مخاطر الأمن السيبراني للطرف الثالث والتوصية بإجراءات التخفيف.
  • قيادة مبادرات التوعية والتدريب في الأمن السيبراني عبر المؤسسة.
  • تعزيز ثقافة أمن سيبراني قوية وتقديم إرشادات أمنية لفرق الأعمال.
  • التعاون مع أصحاب المصلحة الداخليين لضمان دمج الأمن السيبراني في العمليات التجارية.

الشروط والمتطلبات

  • درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو تقنية المعلومات أو مجال ذي صلة.
  • خبرة من 3 إلى 5 سنوات في الأمن السيبراني أو أمن المعلومات مع خلفية في الحوكمة أو المخاطر أو الامتثال، ويفضل في قطاع التكنولوجيا المالية أو البنوك أو أي قطاع خاضع للتنظيم.
  • معرفة عملية بإطار الأمن السيبراني للبنك المركزي السعودي (SAMA CSF) وضوابط الأمن السيبراني الأساسية للهيئة الوطنية للأمن السيبراني (NCA ECC).
  • خبرة في تقييمات مخاطر الأمن السيبراني والاستجابة للحوادث وإدارة الثغرات والتوعية وأنشطة الامتثال.
  • ملم بمفاهيم أمن السحابة وإدارة مخاطر الطرف الثالث.
  • الشهادات المهنية مثل Security+ أو ISO 27001 Lead Implementer/Auditor أو CEH أو CISM أو CISSP تعتبر ميزة إضافية.
  • مهارات تواصل ممتازة باللغتين العربية والإنجليزية (كتابة وتحدث).

المهارات المطلوبة

  • فهم قوي لحوكمة الأمن السيبراني وإدارة المخاطر والامتثال.
  • معرفة بإطار SAMA CSF وضوابط NCA ECC وأفضل ممارسات الأمن السيبراني.
  • مهارات تحليلية قوية وحل المشكلات.
  • قدرات ممتازة في التواصل وإدارة أصحاب المصلحة.
  • القدرة على إدارة أولويات متعددة في بيئة سريعة الخطى ومنظمة.
  • خبرة في تنسيق حوادث الأمن السيبراني والأنشطة التنظيمية.
عرض النص الأصلي للإعلان

About the Role

We are seeking a proactive and experienced Cybersecurity Specialist to lead the company's cybersecurity function and ensure the protection of its information assets, cloud infrastructure, and digital services. The role is responsible for implementing and maintaining a robust cybersecurity program aligned with the Saudi Central Bank (SAMA) Cyber Security Framework (CSF), National Cybersecurity Authority (NCA) requirements, and industry best practices.

The Specialist will oversee cybersecurity governance, risk management, compliance, threat monitoring, incident response, and security awareness initiatives while working closely with senior management to strengthen the organization's cybersecurity posture.

Key Responsibilities

Cybersecurity Strategy & Governance

  • Develop, implement, and maintain the company's cybersecurity policies, standards, and procedures.
  • Ensure cybersecurity governance aligns with SAMA CSF, NCA regulations, and industry best practices.
  • Establish cybersecurity architecture principles and ensure security requirements are integrated into technology solutions.
  • Monitor cybersecurity KPIs and KRIs and provide regular reports to senior management.
  • Support the continuous improvement of the company's cybersecurity program.

Cybersecurity Risk Management

  • Conduct cybersecurity risk assessments and oversee the implementation of mitigation plans.
  • Maintain the cybersecurity risk management framework and risk register.
  • Perform information and system classification to ensure appropriate protection of critical assets.
  • Support security reviews for new systems, applications, and projects.

Security Operations & Incident Management

  • Oversee vulnerability management, security monitoring, and incident response activities.
  • Coordinate cybersecurity incident investigations and ensure timely reporting and remediation.
  • Monitor emerging cyber threats and recommend appropriate security controls.
  • Work closely with IT and business teams to strengthen the organization's security posture.

Regulatory Compliance & Assurance

  • Ensure compliance with SAMA CSF, NCA ECC, and internal cybersecurity policies.
  • Support cybersecurity audits, regulatory assessments, and compliance reviews.
  • Coordinate remediation activities for audit findings and regulatory observations.
  • Act as the primary cybersecurity contact for auditors and regulatory assessments.

Cloud & Third-Party Security

  • Support cloud security governance and third-party cybersecurity risk assessments.
  • Review technology vendors and outsourcing arrangements to ensure compliance with security requirements.
  • Monitor third-party security risks and recommend mitigation measures.

Security Awareness & Leadership

  • Lead cybersecurity awareness and training initiatives across the organization.
  • Promote a strong cybersecurity culture and provide security guidance to business teams.
  • Collaborate with internal stakeholders to ensure cybersecurity is embedded across business operations.

Key Competencies

  • Strong understanding of cybersecurity governance, risk management, and compliance.
  • Knowledge of SAMA CSF, NCA ECC, and cybersecurity best practices.
  • Strong analytical and problem-solving skills.
  • Excellent communication and stakeholder management abilities.
  • Ability to manage multiple priorities in a fast-paced, regulated environment.
  • Experience coordinating cybersecurity incidents and regulatory activities.

Qualifications & Experience

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • 3-5 years of experience in cybersecurity, information security with background in governance, risk, or compliance, preferably within fintech, banking, or another regulated industry.
  • Working knowledge ofSAMA Cyber Security Framework (CSF) andNCA Essential Cybersecurity Controls (ECC).
  • Experience in cybersecurity risk assessments, incident response, vulnerability management, security awareness, and compliance activities.
  • Familiarity with cloud security concepts and third-party risk management.
  • Professional certifications such asSecurity+,ISO 27001 Lead Implementer/Auditor,CEH,CISM, orCISSPare considered an advantage.
  • Excellent communication skills in Arabic and English (written and verbal).

  • المصدر: LinkedIn - أُضيفت للموقع في 18 أغسطس 2026