←  Back to all vacancies

Senior Manager - Third Party Security

Qiddiya Investment Company

Engineering & Construction

πŸ“ Saudi Arabia
πŸ’Ό Full-time
πŸ•’ Posted 5 days ago

Job description

Role Overview

Senior Manager - Third Party Security at Qiddiya Investment Company. This role leads Qiddiya's Third-Party Security Risk Management program to ensure vendors, partners, consultants, and service providers comply with cybersecurity requirements and do not introduce unacceptable risks to Qiddiya's information assets, systems, and operations.

Role Purpose

Establish security assessment frameworks, oversee vendor security reviews, and drive remediation of identified risks. This aligns with industry practices for cybersecurity risk management and third-party oversight.

Key Responsibilities

Framework & Governance

  • Develop and maintain the Third-Party Security Risk Management (TPSRM) framework.
  • Define vendor security controls aligned with NCA ECC, ISO 27001, NIST, and Qiddiya cybersecurity standards.
  • Establish vendor risk classification and assessment methodologies.

Risk Assessment & Due Diligence

  • Conduct cybersecurity due diligence and risk assessments for vendors and suppliers.
  • Review security requirements during procurement, RFP, and contract stages.
  • Assess cloud providers, SaaS platforms, managed service providers, and strategic partners.
  • Lead periodic reassessments of critical vendors.

Remediation & Monitoring

  • Monitor remediation plans and track closure of identified security gaps.
  • Manage external security audits, questionnaires, and assurance activities.

Stakeholder Management & Reporting

  • Collaborate with Procurement, Legal, Compliance, Enterprise Risk, and Technology teams.
  • Report third-party cyber risks, trends, and KPIs to senior management.

Team Leadership

  • Lead and develop the Third-Party Security team.

Qualifications & Experience

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, or related field.
  • 8–12 years of cybersecurity experience.
  • Minimum 4 years in Third-Party Security, Vendor Risk Management, Cybersecurity Risk Management, or GRC.
  • Experience within large enterprises, giga projects, banking, telecom, government, or critical infrastructure environments.
  • Experience managing teams and stakeholder engagement at senior levels.

People looking at this role also searched

Report this job

⚑ Quick Apply

Create your account and upload your CV to apply for β€” takes less than a minute.

✨ Get a free AI ATS Score Report for your CV the moment you sign up.