Location: On-site – Riyadh, Saudi Arabia
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 8+ years
Role Purpose
Govern and improve the security posture of cloud environments and encryption controls, ensuring secure storage, processing, transmission, and monitoring of entity data.
Key Responsibilities
- Monitor cloud environments for compliance with approved security policies, standards, and architecture requirements.
- Review the security posture of compute, storage, database, platform, and supporting cloud services.
- Monitor cloud-security tools and dashboards, investigate suspicious activity, and coordinate response with cybersecurity teams.
- Review CSPM findings, misconfigurations, exposed services, policy violations, and unauthorized deployments or Shadow IT.
- Assess third-party cloud services and integrations and track remediation of cloud-security findings through closure.
- Define and review encryption requirements for sensitive data at rest, in transit, and during processing.
- Support governance of cryptographic controls, keys, certificates, and secure integrations in line with Ministry requirements.
- Maintain cloud asset visibility, operational reports, risk status, and remediation accountability.
Technical and Professional Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- At least 8 years of relevant cloud security, security architecture, or encryption experience, as specified in the workforce table.
- Strong cloud-security knowledge across compute, storage, databases, platform services, IAM, logging, monitoring, network controls, and third-party integrations.
- Hands-on experience with CSPM and cloud-native security monitoring tools.
- Strong knowledge of data encryption at rest and in transit, cryptographic controls, key and certificate management, and secure cloud architecture.
- Knowledge of NCA requirements, Zero Trust, least privilege, and cloud risk-management practices.
Personal Requirements
- Strong risk judgment and ownership of remediation follow-through.
- Excellent analytical, troubleshooting, and cross-functional coordination skills.
- Clear technical documentation and stakeholder communication.
- Proactive, detail-oriented, and comfortable working across cloud, infrastructure, SOC, IAM, and architecture teams.
Professional Certifications
Preferred: CCSP, CISSP, SABSA, TOGAF, GIAC GCSA, or equivalent. A major cloud-platform security certification is also highly relevant.