Associate Director - Cybersecurity Risk and Compliance

Qiddiya

Riyadh

On-site

SAR 300,000 - 550,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Qiddiya in Riyadh, Saudi Arabia, seeks an experienced cybersecurity risk leader to conduct and oversee IT and OT risk assessments, validate controls, and drive regulatory compliance across the organization.

You will coordinate external audits, map controls to standards such as IEC 62443, manage remediation plans, and provide guidance to business teams while tracking KRIs and risk posture. A Bachelor's degree is required; a Master’s degree is preferred and 10–12+ years of experience is expected.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
  • Master's degree preferred.
  • 10-12+ years of cybersecurity experience.
  • Strong experience in risk management, compliance, assessments, and assurance.

Responsibilities

  • Conduct periodic and ad hoc cybersecurity risk assessments across IT and OT environments.
  • Perform OT-specific risk assessments on assets such as PLCs, HMIs, RTUs, and engineering systems.
  • Coordinate risk reviews as part of major IT/OT changes, such as system upgrades or new deployments.
  • Reassess risk posture following major changes, incidents, or regulatory updates.
  • Review and validate existing controls to calculate residual risk and prioritize treatment actions.
  • Provide standardized tools and guidance to support self‑assessments by IT, OT, and business teams.
  • Support integration of assessment outcomes into control design, zoning, segmentation, and system deployment.
  • Track risk treatment progress and elevate overdue or high‑priority items as needed.
  • Coordinate with performance management to define and monitor KRIs to proactively track changes in cybersecurity risk exposure.
  • Maintain the cybersecurity risk register, including OT‑specific entries, capturing identified risks, likelihood and impact ratings, treatment plans, ownership, and status.
  • Coordinate and execute internal cybersecurity compliance assessments across all relevant domains and functions.
  • Serve as the lead interface for external audits and regulatory inspections, including preparation, execution, and response.
  • Conduct periodic compliance assessments of OT environments, including SCADA, DCS, PLCs, and associated network infrastructure.
  • Maintain an inventory of compliance‑relevant OT assets and map them to applicable control requirements and standards.
  • Monitor adherence to cybersecurity policies, escalate non‑compliance, and coordinate corrective actions with relevant teams.
  • Track and manage remediation plans for compliance gaps, non‑conformities, and audit findings through closure.
  • Validate the effectiveness of implemented controls or mitigation plans before closing compliance gaps.
  • Review and validate configuration baselines for OT systems (e.g., firewall rules, firmware versions) to ensure alignment with compliance standards.
  • Coordinate evidence collection, documentation, and remediation planning for compliance‑related findings.
  • Report OT and IT cybersecurity compliance status and risks to leadership and cybersecurity governance.
  • Support compliance awareness and training for teams with control responsibilities in both IT and OT.
  • Maintain a centralized compliance register, covering both IT and OT, that maps regulatory requirements to policies, controls, responsible teams, and evidence sources.
  • Govern third‑party cybersecurity risk by maintaining standardized assessment processes, due diligence criteria, and remediation tracking.
  • Coordinate and conduct third‑party cybersecurity assessments across IT and OT suppliers to ensure alignment with internal policies and regulatory requirements.
  • Review vendor‑supplied OT systems and supporting documentation to ensure inclusion of security controls and compliance with applicable standards (e.g., NCA OTCC, IEC 62443).
  • Ensure third‑party risk findings are documented, risk‑rated, and tracked through resolution, including acceptance or application of compensating controls.
  • Maintain a register of assessed vendors, associated risks, control gaps, and remediation status for ongoing oversight and reporting.
  • Collaborate with procurement, legal, and compliance to embed cybersecurity requirements into third‑party agreements, including OT‑specific clauses where applicable.
  • Contribute to the development and review of third‑party security policy and minimum control requirements for use in procurement and onboarding.
  • Support internal and external audit requests related to third‑party cybersecurity risk management

Skills

Cybersecurity risk management
Regulatory compliance
IT/OT risk assessments
Audits
Vendor risk management
Key risk indicators (KRIs)

Education

Bachelor's degree in Cybersecurity/Information Security/related field
Master's degree preferred

Job description

Roles and Responsibilities
  • Conduct periodic and ad hoc cybersecurity risk assessments across IT and OT environments
  • Perform OT-specific risk assessments on assets such as PLCs, HMIs, RTUs, and engineering systems
  • Identify and document OT-relevant risk scenarios (e.g., control system disruption, unauthorized access, safety manipulation)
  • Coordinate risk reviews as part of major IT/OT changes, such as system upgrades or new deployments
  • Reassess risk posture following major changes, incidents, or regulatory updates
  • Review and validate existing controls to calculate residual risk and prioritize treatment actions
  • Provide standardized tools and guidance to support self‑assessments by IT, OT, and business teams
  • Support integration of assessment outcomes into control design, zoning, segmentation, and system deployment
  • Track risk treatment progress and elevate overdue or high‑priority items as needed
  • Coordinate with performance management to define and monitor key risk indicators (KRIs) to proactively track changes in cybersecurity risk exposure
  • Maintain the cybersecurity risk register, including OT‑specific entries, capturing identified risks, likelihood and impact ratings, treatment plans, ownership, and status
  • Coordinate and execute internal cybersecurity compliance assessments across all relevant domains and functions
  • Serve as the lead interface for external audits and regulatory inspections, including preparation, execution, and response
  • Conduct periodic compliance assessments of OT environments, including SCADA, DCS, PLCs, and associated network infrastructure
  • Maintain an inventory of compliance‑relevant OT assets and map them to applicable control requirements and standards
  • Monitor adherence to cybersecurity policies, escalat non‑compliance, and coordinate corrective actions with relevant teams
  • Track and manage remediation plans for compliance gaps, non‑conformities, and audit findings through closure
  • Validate the effectiveness of implemented controls or mitigation plans before closing compliance gaps
  • Review and validate configuration baselines for OT systems (e.g., firewall rules, firmware versions) to ensure alignment with compliance standards
  • Coordinate evidence collection, documentation, and remediation planning for compliance‑related findings
  • Report OT and IT cybersecurity compliance status and risks to leadership and cybersecurity governance
  • Support compliance awareness and training for teams with control responsibilities in both IT and OT
  • Maintain a centralized compliance register, covering both IT and OT, that maps regulatory requirements to policies, controls, responsible teams, and evidence sources
  • Govern third‑party cybersecurity risk by maintaining standardized assessment processes, due diligence criteria, and remediation tracking
  • Coordinate and conduct third‑party cybersecurity assessments across IT and OT suppliers to ensure alignment with internal policies and regulatory requirements
  • Review vendor‑supplied OT systems and supporting documentation to ensure inclusion of security controls and compliance with applicable standards (e.g., NCA OTCC, IEC 62443)
  • Ensure third‑party risk findings are documented, risk‑rated, and tracked through resolution, including acceptance or application of compensating controls
  • Maintain a register of assessed vendors, associated risks, control gaps, and remediation status for ongoing oversight and reporting
  • Collaborate with procurement, legal, and compliance to embed cybersecurity requirements into third‑party agreements, including OT‑specific clauses where applicable
  • Contribute to the development and review of third‑party security policy and minimum control requirements for use in procurement and onboarding
  • Support internal and external audit requests related to third‑party cybersecurity risk management
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
  • Master's degree is preferred.
  • 10-12+ years of cybersecurity experience.
  • Strong experience in cybersecurity risk management, compliance, assessments, and assurance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate Director - Cybersecurity Risk and Compliance
Associate Director - Cybersecurity Risk and Compliance

Qiddiya | القدية • Riyadh

On-site
SAR 320,000 - 520,000
Cyber Security Architect – OT/ICS
Cyber Security Architect – OT/ICS

FNRCO • Riyadh

On-site
SAR 1,100,000 - 1,900,000
OT/ICS Cybersecurity Engineer
OT/ICS Cybersecurity Engineer

Optimal • Dhahran Compound

On-site
SAR 224,000 - 375,000
Sr Specialist I, OT Security Defense Job
Sr Specialist I, OT Security Defense Job

Tasnee • Saudi Arabia

On-site
SAR 360,000 - 480,000
Cybersecurity Lead Engineer
Cybersecurity Lead Engineer

Schneider Electric • Al Khobar

On-site
SAR 112,000 - 188,000
Cybersecurity Lead Engineer
Cybersecurity Lead Engineer

Schneider Electric • Saudi Arabia

On-site
SAR 300,000 - 400,000
Senior Advanced Cyber Security Architect / Engineer - ICS/OT
Senior Advanced Cyber Security Architect / Engineer - ICS/OT

Virtuthinko W. L • Saudi Arabia

On-site
SAR 320,000 - 520,000
NGHP IT/DT Cybersecurity Engineer
NGHP IT/DT Cybersecurity Engineer

Air Products • Duba

On-site
SAR 90,000 - 130,000
Advanced Cyber Security Architect / Engineer - ICS/OT
Advanced Cyber Security Architect / Engineer - ICS/OT

Virtuthinko W. L • Saudi Arabia

On-site
SAR 300,000 - 450,000
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

Tibah Airports Operation | طيبة لتشغيل المطارات • Medina

On-site
SAR 140,000 - 210,000