←  العودة إلى كل الوظائف

Associate Director - Cybersecurity Risk and Compliance

Qiddiya Investment Company

قطاع: Engineering & Construction

📍 السعودية
💼 دوام كامل
🕒 نُشرت قبل 5 أسابيع

وصف الوظيفة

Role Overview

Associate Director - Cybersecurity Risk and Compliance at Qiddiya Investment Company. This role oversees cybersecurity risk and compliance strategy, governance, and execution across IT and OT environments.

Role Purpose

To establish, maintain, and continuously improve cybersecurity risk management and compliance frameworks across all organizational IT and OT systems, ensuring alignment with regulatory requirements and internal governance standards while managing third-party cybersecurity risk.

Key Responsibilities

Risk Assessment & Management

  • Conduct periodic and ad hoc cybersecurity risk assessments across IT and OT environments
  • Perform OT-specific risk assessments on assets such as PLCs, HMIs, RTUs, and engineering systems
  • Identify and document OT-relevant risk scenarios including control system disruption, unauthorized access, and safety manipulation
  • Coordinate risk reviews as part of major IT/OT changes, such as system upgrades or new deployments
  • Reassess risk posture following major changes, incidents, or regulatory updates
  • Review and validate existing controls to calculate residual risk and prioritize treatment actions
  • Track risk treatment progress and escalate overdue or high-priority items as needed
  • Maintain the cybersecurity risk register, including OT-specific entries, capturing identified risks, likelihood and impact ratings, treatment plans, ownership, and status

Governance & Monitoring

  • Coordinate with performance management to define and monitor key risk indicators (KRIs) to proactively track changes in cybersecurity risk exposure
  • Monitor adherence to cybersecurity policies, escalate non-compliance, and coordinate corrective actions with relevant teams
  • Report OT and IT cybersecurity compliance status and risks to leadership and cybersecurity governance
  • Maintain a centralized compliance register covering both IT and OT, mapping regulatory requirements to policies, controls, responsible teams, and evidence sources

Compliance & Assurance

  • Coordinate and execute internal cybersecurity compliance assessments across all relevant domains and functions
  • Serve as the lead interface for external audits and regulatory inspections, including preparation, execution, and response
  • Conduct periodic compliance assessments of OT environments, including SCADA, DCS, PLCs, and associated network infrastructure
  • Maintain an inventory of compliance-relevant OT assets and map them to applicable control requirements and standards
  • Track and manage remediation plans for compliance gaps, non-conformities, and audit findings through closure
  • Validate the effectiveness of implemented controls or mitigation plans before closing compliance gaps
  • Review and validate configuration baselines for OT systems, such as firewall rules and firmware versions, to ensure alignment with compliance standards
  • Coordinate evidence collection, documentation, and remediation planning for compliance-related findings

Assessment Support & Self-Service

  • Provide standardized tools and guidance to support self-assessments by IT, OT, and business teams
  • Support integration of assessment outcomes into control design, zoning, segmentation, and system deployment
  • Support compliance awareness and training for teams with control responsibilities in both IT and OT

Third-Party Risk Management

  • Govern third-party cybersecurity risk by maintaining standardized assessment processes, due diligence criteria, and remediation tracking
  • Coordinate and conduct third-party cybersecurity assessments across IT and OT suppliers to ensure alignment with internal policies and regulatory requirements
  • Review vendor-supplied OT systems and supporting documentation to ensure inclusion of security controls and compliance with applicable standards such as NCA OTCC and IEC 62443
  • Ensure third-party risk findings are documented, risk-rated, and tracked through resolution, including acceptance or application of compensating controls
  • Maintain a register of assessed vendors, associated risks, control gaps, and remediation status for ongoing oversight and reporting
  • Collaborate with procurement, legal, and compliance to embed cybersecurity requirements into third-party agreements, including OT-specific clauses where applicable
  • Contribute to the development and review of third-party security policy and minimum control requirements for use in procurement and onboarding
  • Support internal and external audit requests related to third-party cybersecurity risk management

Qualifications & Experience

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field
  • Master's degree preferred
  • 10–12+ years of cybersecurity experience
  • Strong experience in cybersecurity risk management, compliance, assessments, and assurance

الباحثون عن هذه الوظيفة بحثوا أيضاً عن

الإبلاغ عن هذه الوظيفة

⚡ تقدّم سريع

أنشئ حسابك وارفع سيرتك الذاتية للتقدّم إلى — يستغرق أقل من دقيقة.

✨ احصل على تقرير تقييم مجاني بالذكاء الاصطناعي لسيرتك الذاتية فور التسجيل.