Information Technology Security Manager

cenomi retail

As Sudiyah

On-site

OMR 18,000 - 30,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Cenomi Retail is seeking an IT Security Manager to lead the organization's security strategy, governance, and incident response. You will oversee third‑party risk management, ensure regulatory compliance, and drive security initiatives across the enterprise.

The role requires deep expertise in cloud security, SIEM/SOAR, and IAM, with leadership responsibilities and a focus on safeguarding data and systems in a retail environment.

Qualifications

  • Bachelor’s degree in information technology, information systems, computer science or related field required.
  • Master’s degree in information technology, information systems, computer science or related field optional.
  • Certifications (CISSP, CISM, CEH, CompTIA Security+) optional.
  • Experience in IT/cyber security within retail is advantageous.

Responsibilities

  • Collaborate to execute and shape the IT Security strategy to protect assets and data.
  • Lead third‑party risk management in line with security standards.
  • Develop and implement the organization's security governance and incident response framework.

Skills

Cloud Security
Microsoft Security Stack
SIEM
SOAR
DLP
Zero Trust
IAM

Education

Bachelor’s degree in information technology
Master’s degree in information technology
CISSP
CISM
CEH
CompTIA Security+

Job description

Founded in 1990 as Fawaz Alhokair Fashion Retail Co., Cenomi Retail has introduced more than 80 international retail and F&B brands to the Kingdom of Saudi Arabia. These include some of the world’s most loved including Zara, Mango, Aldo, Cinnabon, Subway and more. Cenomi Retail operates more than 1,600 stores across 100 shopping centers in 11 countries. We are dedicated to growth and breaking down boundaries to offer a truly unique brand partnership proposition.

Position - IT Security Manager
Reporting To - IT Director
Job Role:

The primary job goal for an IT Security Manager is ensuring the confidentiality, integrity, and availability of the organization's information and systems, leading the organization's IT Security strategy, fostering team growth, managing third-party risks, ensuring regulatory compliance, and continuously monitoring performance for effective safeguarding.

Key Responsibilities:
  • Collaborate in the execution of the organization's IT Security strategy to safeguard critical assets and data.
  • Sets the overarching strategy for third-party risk management and ensures alignment with organizational security standards.
  • Define the organization's physical security strategy, ensuring integration with broader security goals.
  • Direct the strategic vision and ensures alignment of the organization's network security initiatives with overarching IT Security goals.
  • Determine the strategic approach to data protection, ensuring alignment with regulatory requirements.
  • Establishes the IT Security incident management framework and strategy, ensuring organizational preparedness.
  • Consider IT Security requirements in all outsourcing contracts.
  • Evaluate and assess security risks associated with third-party vendors and service providers to protect the organization's data and assets.
  • Sets the direction for Vulnerability Assessment and Penetration Testing(VAPT) initiatives, ensuring thorough coverage and regulatory compliance.
  • Oversee the monitoring and logging of all administrative activities, implement stringent privileged access controls, and periodically conduct comprehensive access reviews to ensure adherence to IT Security protocols.
  • Establish key performance indicators (KPIs) to measure the effectiveness of security initiatives and track progress toward security goals.
  • Develop and deliver security training and awareness programs.
  • Stay abreast of emerging threats and technologies.
  • Provide leadership and guidance to a team of IT Security professionals, fostering their growth and ensuring effective security practices.
Technical Skills (Preferred)
  • Cloud Security: Experience securing cloud environments such as Microsoft Azure, Amazon Web Services (AWS), and Oracle Cloud Infrastructure (OCI).
  • Microsoft Security Stack: Hands-on experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Microsoft Intune, and Microsoft 365 Security solutions.
  • Security Information and Event Management (SIEM): Experience implementing, monitoring, and managing SIEM platforms for threat detection, incident analysis, and security monitoring.
  • Security Orchestration, Automation and Response (SOAR): Experience with security automation, playbook development, and incident response orchestration.
  • Data Loss Prevention (DLP): Knowledge of enterprise DLP technologies and data protection policies to safeguard sensitive information.
  • Zero Trust Security Architecture: Understanding and implementation of Zero Trust principles, including continuous verification, least privilege, and micro-segmentation.
  • Identity & Access Management (IAM): Experience with identity governance, privileged access management (PAM), multi-factor authentication (MFA), single sign-on (SSO), role-based access control (RBAC), and lifecycle management.
Academic Qualifications and Certification:
  • Bachelor’s degree in information technology, information systems, computer science or related field (required)
  • Master’s degree in information technology, information systems, computer science or related field (optional)
  • Certified Information Systems Security Professional (CISSP) (optional)Certified Information Security Manager (CISM) (optional)
  • Certified Ethical Hacker (CEH) (optional)
  • CompTIA Security+ (optional)

Other IT/Cyber Security-recognized certifications (optional)

Job Specific Skills:
  • Industry Specific: Deep understanding of IT Security regulations, standards, best practices, and trends within the retail industry.
  • Data-Driven: Ability to analyze complex issues, make data-driven decisions for proper tracking and optimizing of IT Security processes.
  • Ethics and Integrity: Ethical and committed to upholding the highest standards in IT Security.
  • Regulatory Expert: Strong understanding of IT Security regulatory requirements and applicable laws and regulations in the Kingdom of Saudi Arabia.
  • Technical Knowledge: Excellent knowledge in IT Security tools, methodologies, and frameworks.
  • Analytical: Strong analytical and problem-solving skills, and the ability to define and track key performance indicators (KPIs) for IT Security efforts.
  • Leadership Skills: Demonstrated leadership abilities in managing and motivating teams focused on IT Security matters.

Communication Skills: Ability to work collaboratively across departments and with external stakeholders.

Required Prior Experience:
  • 7-9 years of relevant experience in IT Security or a related role, with a demonstrated track record of leading successful security initiatives.
  • Proven experience in managing third-party risks and ensuring compliance with industry regulations and standards.
  • Strong background in developing and executing IT Security strategies.
  • Experience in responding to and managing security incidents.
  • Strong understanding of firewalls, VPNs, IDS/IPS, and other network security technologies.
  • Knowledge of secure coding practices, web application security, and vulnerability assessment & Penetration Testing(VAPT).
  • Previous experience in team leadership and people management, with a focus on promoting team growth and ensuring effective security practices.

Track record of successful collaboration with cross-functional teams to integrate security measures effectively.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Specialist
Cyber Security Specialist

Gulfjobfair • As Sudiyah

On-site
OMR 50,000 - 70,000
Cybersecurity Manager
Cybersecurity Manager

Gender • Dhofar

On-site
OMR 90,000 - 120,000
Security & Safety Sr. Manager
Security & Safety Sr. Manager

confidential jobs • As Sudiyah

On-site
OMR 18,000 - 33,000
Cloud Security & Encryption Specialist
Cloud Security & Encryption Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 25,000 - 37,000
Identity & Access Management (IAM/PAM) Specialist
Identity & Access Management (IAM/PAM) Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 18,000 - 29,000
Cyber Defense Specialist - Detection & Monitoring
Cyber Defense Specialist - Detection & Monitoring

cloud consultancy - ccds • As Sudiyah

On-site
OMR 31,000 - 62,000
Channel / Alliances Manager
Channel / Alliances Manager

Cybersecit • As Sudiyah

On-site
OMR 36,000 - 56,000
OQ8 - Expert, Cybersecurity & GRC
OQ8 - Expert, Cybersecurity & GRC

oq8.om • Muscat

On-site
OMR 30,000 - 47,000
Cybersecurity Architect
Cybersecurity Architect

Your ITeams Sp. z o.o. • As Sudiyah

Hybrid
OMR 34,000 - 47,000
Luxmed Gold Extended medical care
Multisport Plus benefit
Outstanding integration trips to Europe
Cybersecurity Architecture Specialist
Cybersecurity Architecture Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 33,000 - 53,000