أخصائي مخاطر الأمن السيبراني
تفاصيل الوظيفة
Job Purpose
Responsible for conducting and supporting the identification, assessment, analysis, treatment, monitoring, and reporting of cybersecurity risks across the organization’s technology environment, systems, projects, third parties, and business operations. The role maintains cybersecurity risk records, coordinates risk treatment activities with relevant risk and control owners, monitors residual and accepted risks, and supports informed risk-based decision making in alignment with applicable National Cybersecurity Authority (NCA) requirements, organizational policies, and recognized cybersecurity risk management frameworks.
Key Accountabilities
• Identify, assess, analyze, evaluate, and monitor cybersecurity risks across the organization’s systems, applications, infrastructure, projects, third parties, and business processes.
• Provide cybersecurity risk guidance to internal stakeholders and support risk based decision-making for systems, projects, technology changes, and third party engagements.
• Monitor the cybersecurity risk profile and emerging risk exposure and support timely escalation and reporting of significant cybersecurity risks to relevant management and governance forums.
• Support alignment of cybersecurity risk management activities with applicable National Cybersecurity Authority (NCA) requirements, organizational Enterprise Risk Management (ERM) processes, and recognized cybersecurity risk management frameworks.
Operational Responsibilities
• Identify relevant cyber threats, vulnerabilities, potential threat scenarios, affected assets, existing controls, and potential business impacts as part of cybersecurity risk assessments.
• Review supporting evidence submitted for completed risk treatment activities and reassess residual risk where applicable.
• Maintain the cybersecurity risk register, including risk ratings, ownership, treatment decisions, action plans, target dates, review dates, and current status.
• Support cybersecurity third-party risk assessments and evaluate cybersecurity risks associated with vendors, service providers, cloud providers, and other external parties.
• Support cybersecurity risk assessments during project initiation, solution design, procurement, implementation, and significant technology changes to identify risks before production deployment.
• Coordinate with vulnerability management, threat intelligence, incident management, compliance, and other cybersecurity functions to incorporate relevant findings and threat information into cybersecurity risk assessments.
• Support the development and continuous improvement of the cybersecurity risk management methodology, risk criteria, assessment templates, risk taxonomy, and supporting processes.
• Develop and maintain cybersecurity Key Risk Indicators (KRIs) and monitor trends that may indicate changes in the organization’s cybersecurity risk exposure.
Safety & Security
• Responsible to submit a safety report if exposed to any safety hazard or issue.
• Understanding and complying with safety precautions contained in this manual and/or safety publications.
• Immediately reporting to the concerned supervisor all safety hazards, accidents/incidents, injuries and damage.
هذا الإعلان منشور على تنقيب السعودية ويُعرض هنا مع الإشارة إلى المصدر. لا نتقاضى أي رسوم من الباحثين عن عمل. إذا كان الإعلان مسيئًا أو احتياليًا، أبلغنا.