Cyber Security Specialist

Masharah Advisory

Jeddah

Hybrid

SAR 335,000 - 603,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Masharah Company in Jeddah, Saudi Arabia, seeks an experienced Cybersecurity & Infrastructure Security Specialist to own the company’s cybersecurity requirements, security architecture, risk management, and overall security posture.

The role serves as the technical security authority and main security representative when dealing with external providers. You will identify risks, define controls, lead discussions, and validate delivered security outcomes.

Qualifications

  • 3–5+ years of professional experience in Cybersecurity, Infrastructure Security, Network Security, Security Engineering, or related field.
  • Strong understanding of cybersecurity principles and security architecture.
  • Experience conducting security assessments and identifying gaps and risks.
  • Knowledge of network security technologies: Firewalls/NGFW, IPS/IDS, network segmentation, VLANs, DMZ, VPN/ZTNA, secure remote access.
  • Understanding of server, virtualization, endpoint, and infrastructure security.
  • Knowledge of IAM, MFA, RBAC, PAM, and privileged access management.
  • Experience with EDR/XDR, SIEM/SOC, security monitoring and centralized logging.
  • Understanding of WAF and web/application security.
  • Knowledge of vulnerability management and penetration testing.
  • Understanding of backup, disaster recovery, business continuity, RTO/RPO, and ransomware resilience.
  • Familiarity with GitHub, CI/CD, DevSecOps, and application security is a strong advantage.
  • Ability to review, evaluate and challenge security architectures, vendor proposals.
  • Strong communication with technical stakeholders, vendors, and service providers.
  • Strong analytical and problem-solving skills.
  • Ability to work independently and own cybersecurity requirements.
  • English communication skills; Arabic a plus.

Responsibilities

  • Own and continuously assess the company’s overall cybersecurity and infrastructure security posture.
  • Conduct security assessments and identify security gaps, risks, vulnerabilities, and areas requiring improvement.
  • Define cybersecurity requirements, security controls, and technical security standards.
  • Develop and review security architecture covering: Network Security, Firewalls / NGFW, Network Segmentation, DMZ / WAF, VPN / ZTNA, Servers & Virtualization, Identity & Access Management, EDR/XDR, SIEM / SOC, Backup & Disaster Recovery, Application & Data Security.
  • Develop cybersecurity and infrastructure security requirements for external service providers.
  • Identify, evaluate, and recommend appropriate cybersecurity technologies and solutions.
  • Lead technical meetings and discussions with cybersecurity, network, infrastructure, and other service providers.
  • Challenge and evaluate vendors’ proposed architectures, technologies, configurations, and security recommendations.
  • Review security architecture, HLDs, LLDs, technical proposals, BoQs, and implementation plans.
  • Oversee security implementation and ensure agreed security requirements and controls are correctly implemented.
  • Validate and test security controls before accepting implemented solutions.
  • Establish and oversee vulnerability management and remediation processes.
  • Coordinate penetration testing and security assessments and ensure findings are properly remediated.
  • Define and oversee security monitoring, logging, SIEM/SOC, EDR/XDR, and alerting requirements.
  • Establish incident response, containment, recovery, and security incident-handling requirements.
  • Define and review IAM, MFA, RBAC, PAM, privileged access, and network access-control requirements.
  • Ensure appropriate security hardening and secure configuration of infrastructure and security systems.
  • Review GitHub, CI/CD, DevSecOps, and application security practices where applicable.
  • Review backup, disaster recovery, business continuity, RTO/RPO, and ransomware-resilience requirements.
  • Assess data protection, data residency, and cross-border data-transfer considerations.
  • Identify applicable Saudi cybersecurity and data protection requirements and support compliance efforts.
  • Maintain cybersecurity policies, standards, risk registers, security architecture, and technical documentation.
  • Provide management with regular updates on security risks, gaps, priorities, and remediation progress.
  • Act as the primary technical security representative between the company and external service providers.

Skills

Cybersecurity
Security architecture
Security assessments
Network security
IAM / MFA / RBAC
EDR/XDR / SIEM / SOC
Vulnerability management
Penetration testing
Disaster recovery
English fluency
Arabic skills

Job description

We’re Hiring | Cybersecurity & Infrastructure Security Specialist

Company: [Masharah Company]

We are looking for an experienced Cybersecurity & Infrastructure Security Specialist to take ownership of the company’s cybersecurity requirements, security architecture, risk management, and overall security posture.

This role will serve as the company’s technical security authority and primary security representative when dealing with external cybersecurity, infrastructure, network, and technology service providers.

The successful candidate will be responsible for identifying security risks and gaps, defining the required security controls, evaluating and selecting appropriate solutions, leading technical discussions with service providers, overseeing implementation, and validating that the delivered environment meets the company’s security requirements.

Key Responsibilities
  • Own and continuously assess the company’s overall cybersecurity and infrastructure security posture.
  • Conduct security assessments and identify security gaps, risks, vulnerabilities, and areas requiring improvement.
  • Define cybersecurity requirements, security controls, and technical security standards.
  • Develop and review security architecture covering:
    • Network Security
    • Firewalls / NGFW
    • Network Segmentation
    • DMZ / WAF
    • VPN / ZTNA
    • Servers & Virtualization
    • Identity & Access Management
    • EDR/XDR
    • SIEM / SOC
    • Backup & Disaster Recovery
    • Application & Data Security
  • Develop cybersecurity and infrastructure security requirements for external service providers.
  • Identify, evaluate, and recommend appropriate cybersecurity technologies and solutions.
  • Lead technical meetings and discussions with cybersecurity, network, infrastructure, and other service providers.
  • Challenge and evaluate vendors’ proposed architectures, technologies, configurations, and security recommendations.
  • Review security architecture, HLDs, LLDs, technical proposals, BoQs, and implementation plans.
  • Oversee security implementation and ensure agreed security requirements and controls are correctly implemented.
  • Validate and test security controls before accepting implemented solutions.
  • Establish and oversee vulnerability management and remediation processes.
  • Coordinate penetration testing and security assessments and ensure findings are properly remediated.
  • Define and oversee security monitoring, logging, SIEM/SOC, EDR/XDR, and alerting requirements.
  • Establish incident response, containment, recovery, and security incident-handling requirements.
  • Define and review IAM, MFA, RBAC, PAM, privileged access, and network access-control requirements.
  • Ensure appropriate security hardening and secure configuration of infrastructure and security systems.
  • Review GitHub, CI/CD, DevSecOps, and application security practices where applicable.
  • Review backup, disaster recovery, business continuity, RTO/RPO, and ransomware-resilience requirements.
  • Assess data protection, data residency, and cross-border data-transfer considerations.
  • Identify applicable Saudi cybersecurity and data protection requirements and support compliance efforts.
  • Maintain cybersecurity policies, standards, risk registers, security architecture, and technical documentation.
  • Provide management with regular updates on security risks, gaps, priorities, and remediation progress.
  • Act as the primary technical security representative between the company and external service providers.
Requirements
  • 3–5+ years of professional experience in Cybersecurity, Infrastructure Security, Network Security, Security Engineering, or a closely related field.
  • Strong practical understanding of cybersecurity principles and security architecture.
  • Demonstrated experience conducting security assessments and identifying security gaps and risks.
  • Strong knowledge of network security, including:
    • Firewalls / NGFW
    • IPS/IDS
    • Network segmentation
    • VLANs
    • DMZ
    • VPN / ZTNA
    • Secure remote access
  • Good understanding of server, virtualization, endpoint, and infrastructure security.
  • Knowledge of IAM, MFA, RBAC, PAM, and privileged-access management.
  • Experience or strong understanding of EDR/XDR, SIEM, SOC, security monitoring, and centralized logging.
  • Understanding of WAF and web/application security.
  • Knowledge of vulnerability management and penetration-testing processes.
  • Understanding of backup, disaster recovery, business continuity, RTO/RPO, and ransomware resilience.
  • Familiarity with GitHub, CI/CD, DevSecOps, and application security is a strong advantage.
  • Ability to review, evaluate, and challenge technical architectures, security designs, configurations, and vendor proposals.
  • Strong experience communicating with technical stakeholders, vendors, and service providers.
  • Strong analytical and problem-solving skills.
  • Ability to work independently and take ownership of cybersecurity requirements and decisions.
  • Strong written and verbal communication skills in English.
  • Arabic communication skills are a plus.
Preferred Certifications

The following certifications are considered a strong advantage:

  • CISSP / CISM
  • Security+
  • CCNA / CCNP
  • Palo Alto Networks certifications
  • Fortinet certifications
  • ISO 27001-related certifications
  • Other relevant cybersecurity or infrastructure security certifications
What We’re Looking For

We are looking for someone who can own cybersecurity from the company’s side, rather than simply coordinate between vendors.

The ideal candidate should be capable of:

Identify → Assess → Design → Recommend → Lead → Implement → Validate → Improve

You should be comfortable moving between management-level discussions and detailed technical discussions with cybersecurity and infrastructure engineers.

You will be expected to independently assess proposed solutions, identify security gaps, challenge vendors when necessary, and ensure that the company’s security requirements are properly addressed.

Position Details

Location: Jeddah, Saudi Arabia

Work Model: Hybrid : (Remote/attendance) based on work needs.

(Expected) Onsite Attendance: Typically once/twice per week in Jeddah, with additional attendance when required for important meetings, vendor discussions, implementation activities, assessments, audits, or other business needs.

Employment Type: Full-Time

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity & Infrastructure Security Lead — Hybrid
Cybersecurity & Infrastructure Security Lead — Hybrid

Masharah Advisory • Jeddah

Hybrid
SAR 335,000 - 603,000
Cybersecurity Engineer (Saudi National)
Cybersecurity Engineer (Saudi National)

Astek Middle East • Riyadh

On-site
SAR <240,000
Cybersecurity Specialist Senior - Metro
Cybersecurity Specialist Senior - Metro

Egis • Riyadh

On-site
SAR 300,000 - 540,000
Information Security Engineer
Information Security Engineer

KK People • Riyadh

On-site
Competitive remuneration and benefits package
Access to cutting-edge security technologies
Senior Cyber Security Specialist
Senior Cyber Security Specialist

Join Solutions • Dammam

On-site
Cybersecurity Engineer
Cybersecurity Engineer

PrimeGate Company • Saudi Arabia

On-site
SAR 120,000 - 180,000
Network Security Senior Manager
Network Security Senior Manager

Cyberani by aramco digital • Riyadh

On-site
SAR 350,000 - 520,000
Network & Security Expert
Network & Security Expert

CNTXT • Riyadh

On-site
SAR 360,000 - 600,000
Security Solutions Engineer
Security Solutions Engineer

SamaWave Solutions • Jeddah

On-site
SAR 100,000 - 130,000
Cyber Incident Responder
Cyber Incident Responder

Join Solutions • Jeddah

On-site
SAR 180,000 - 300,000