📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

HRsource تعلن عن وظيفة أخصائي امتثال أمن المعلومات (غير تقني) في الرياض

Information Security Compliance Specialist - Non-Technical
🕒 نُشرت: (منذ 9 أيام) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة HRsource عن توفر وظيفة مستشار الامتثال لأمن المعلومات (دور غير تقني) في الرياض، السعودية. يركّز الدور على الامتثال والتوثيق والحوكمة والتنسيق التنظيمي ودعم التدقيق.

المهام والمسؤوليات

  • التنسيق مع الجهات التنظيمية السعودية (NCA و SDAIA) كممثل محلي للتواصل الرسمي والمتابعة.
  • رصد وتفسير الإشعارات والمتطلبات التنظيمية وإبلاغ الأطراف الداخلية المعنية.
  • تنسيق المراسلات التنظيمية والإيداعات والردود عبر القنوات الرسمية.
  • دعم الإخطارات المتعلقة بحوادث الأمن السيبراني أو البيانات الشخصية وفقاً للمتطلبات والإجراءات.
  • دعم الامتثال لقانون حماية البيانات الشخصية السعودي (PDPL) من خلال توثيق أنشطة المعالجة وإعداد الإيداعات والإقرارات.
  • إدارة وتحديث وثائق الامتثال المحلية وأدلة التدقيق.
  • توطين السياسات والأطر العالمية للأمن السيبراني بما يتوافق مع متطلبات السعودية (ECC و CCC لهيئة NCA).
  • التنسيق مع الفرق الفنية لجمع أدلة الامتثال والحفاظ على مستودع منظم للأدلة.
  • إعداد وصيانة سجلات التدقيق مثل الموافقات على السياسات ومحاضر الاجتماعات وسجلات التدريب.
  • تتبع متطلبات الامتثال المعلقة وضمان المتابعة والإغلاق في الوقت المناسب.
  • تنسيق تدريبات التوعية بأمن المعلومات وحماية البيانات للموظفين ودعم تمارين محاكاة التصيد.
  • إجراء فحوصات الامتثال الأساسية للموردين والأطراف الثالثة ومراجعة المستندات الداعمة (NDA، شروط الأمن).

الشروط والمتطلبات

  • خبرة لا تقل عن سنة واحدة في مجالات الامتثال أو حوكمة تقنية المعلومات أو الشؤون التنظيمية أو دعم التدقيق أو أدوار متعلقة بأمن المعلومات.
  • فهم قوي لمفاهيم أمن المعلومات وحماية البيانات والامتثال التنظيمي.
  • يفضّل خبرة سابقة في العمل مع الجهات الحكومية أو الهيئات التنظيمية السعودية.
  • القدرة على إعداد مراسلات مهنية وواضحة مع الجهات الحكومية والتنظيمية.
  • إجادة اللغة الإنجليزية بمستوى مهني مع القدرة على فهم المعايير الأمنية وإعداد تقارير مكتوبة.
  • انتباه عالٍ للتفاصيل وانضباط في التوثيق.
  • القدرة على إدارة متطلبات الامتثال والأدلة والسجلات وأنشطة المتابعة بفعالية.
  • القدرة على العمل مع الأطراف العليا والمدققين والمنظمين وفرق تقنية المعلومات والإدارات الأخرى.

المهارات المطلوبة

  • مهارات تواصل وتنسيق ممتازة مع الجهات الداخلية والخارجية.
  • تنظيم وثائقي متقن مع القدرة على الحفاظ على مستودع أدلة تدقيق منظم.
  • القدرة على ترجمة المتطلبات التنظيمية إلى إجراءات عملية والتنسيق مع الفرق المعنية.
  • مهارات تحليلية لمتابعة متطلبات الامتثال وضمان إغلاقها.
عرض النص الأصلي للإعلان

Information Security Compliance Consultant


Important: This Is Not a Technical Cybersecurity Role

This position is focused on compliance, documentation, governance, regulatory coordination, and audit support.


📍 Location: Riyadh, Saudi Arabia


About the Role

We are seeking an Information Security Compliance Consultant to support information security and data protection compliance activities in Saudi Arabia.


The role will serve as a key local representative for information security and personal data protection compliance, working closely with Saudi regulatory authorities, senior leadership, IT and security teams, auditors, and internal stakeholders.


The successful candidate will be responsible for coordinating regulatory requirements, supporting PDPL compliance, localizing policies and procedures, maintaining compliance documentation, and ensuring the organization remains prepared for regulatory reviews and audits.


Key Responsibilities

Government Liaison & Regulatory Compliance

  • Serve as the local point of contact with relevant Saudi regulatory authorities, including NCA and SDAIA.
  • Monitor, interpret, and communicate regulatory notices, requirements, circulars, and updates to relevant internal stakeholders.
  • Coordinate regulatory communications, submissions, responses, and required documentation through official channels and portals.
  • Support regulatory notifications related to cybersecurity or personal data incidents in line with applicable requirements and internal procedures.
  • Maintain professional and effective communication with government and regulatory stakeholders.

Personal Data Protection & PDPL Compliance

  • Support compliance with the Saudi Personal Data Protection Law (PDPL).
  • Coordinate the identification and documentation of personal data processing activities with IT and business teams.
  • Support the preparation and maintenance of PDPL-related filings, declarations, policies, procedures, and employee communications.
  • Own and maintain local PDPL compliance documentation and supporting audit evidence.
  • Ensure compliance documentation remains accurate, current, organized, and readily available for regulatory reviews and audits.

Information Security Governance & Policy Localization

  • Support the localization of global cybersecurity policies and frameworks into Saudi-compliant policies, SOPs, and procedures.
  • Ensure relevant documentation is aligned with applicable Saudi requirements, including NCA Essential Cybersecurity Controls (ECC) and Cloud Cybersecurity Controls (CCC) where applicable.
  • Coordinate with technical teams to collect and organize evidence required to demonstrate compliance.
  • Maintain appropriate version control and documentation standards across policies, procedures, and compliance records.

Audit Readiness & Compliance Evidence

  • Develop and maintain a structured Compliance Evidence Repository to ensure audit traceability and readiness.
  • Collect, organize, and maintain compliance evidence, including:
  • Policy approvals and acknowledgements
  • Security committee and management meeting minutes
  • Access approval records
  • Security and awareness training records
  • System screenshots and extracts provided by technical teams
  • Other supporting documentation required for compliance
  • Coordinate with internal stakeholders and auditors to ensure evidence is complete, accurate, and available when required.
  • Track outstanding compliance requirements and ensure timely follow-up and closure.

Training & Third-Party Compliance

  • Coordinate information security and PDPL awareness training for local employees.
  • Support phishing simulation exercises and maintain appropriate training and awareness records.
  • Assist with basic information security compliance checks for local vendors and third parties.
  • Review supporting documentation, including NDAs and information security clauses, where required.


What We're Looking For

  • Minimum 1 year of experience in compliance, IT governance, regulatory affairs, audit support, or information security-related roles.
  • Strong understanding of information security, data protection, and regulatory compliance concepts.
  • Previous experience working with Saudi government entities or regulatory bodies is strongly preferred.
  • Ability to prepare clear and professional government and regulatory correspondence.
  • Professional English proficiency, with the ability to understand security standards and prepare clear written reports.
  • Strong attention to detail and a high level of documentation discipline.
  • Ability to manage compliance requirements, evidence, records, and follow-up activities effectively.
  • Comfortable working with senior stakeholders, auditors, regulators, IT teams, and business functions.


Preferred Qualifications

The following would be advantageous:

  • Exposure to ISO/IEC 27001 audits or implementation.
  • Exposure to ISO 22301 or SOC 2 audits.
  • Familiarity with NCA Essential Cybersecurity Controls (ECC).
  • Familiarity with NCA Cloud Cybersecurity Controls (CCC).
  • Knowledge of Saudi PDPL requirements.
  • Certifications such as CompTIA Security+, ISO Internal Auditor, or equivalent.


What Success Looks Like

The successful candidate will be someone who can take regulatory requirements, understand their implications for the organization, coordinate effectively with the relevant internal teams, and ensure that required documentation and evidence are complete, accurate, traceable, and readily available.


Strong performance in this role will be demonstrated through regulatory alignment, audit readiness, documentation quality, and effective coordination across stakeholders.

المصدر: LinkedIn - أُضيفت للموقع في 1 سبتمبر 2026
رقم الإعلان لدى المصدر: 4459281673