The Cybersecurity Specialist is responsible for designing implementing and operating technical cybersecurity controls across the organization. The role focuses on securing infrastructure reviewing system and cloud architectures managing vulnerabilities and supporting penetration testing activities while ensuring alignment with internal security standards and Saudi cybersecurity requirements
Duties and Responsibilities
Security Engineering and Infrastructure Protection
- Deploy configure and manage cybersecurity tools including DLP EDR firewalls and IAM solutions …etc.
- Support secure configuration of systems servers endpoints and cloud environments
- Monitor security events and support SOC operations for threat detection and response
Architecture Security Review
- Review system applications and cloud architectures from a security perspective
- Identify design weaknesses and recommend security improvements
- Support secure design practices for new systems and integrations
Vulnerability Management and Penetration Testing
- Conduct regular vulnerability assessments across infrastructure and applications
- Track prioritize and support remediation of security vulnerabilities
- Coordinate and support third party penetration testing activities and validate findings
Incident Response and Security Operations
- Support incident detection investigation and response activities
- Assist in maintaining and improving incident response procedures
- Participate in security investigations and root cause analysis
Systems and Security Hardening
- Support system hardening activities across servers endpoints and network devices
- Ensure security baselines and configurations are properly implemented
- Assist in improving overall security posture across IT environments
Education
Bachelor’s degree in Cybersecurity, Information Security, Computer Science or equivalent degree
Qualifications and Experience:
3–6 years of experience in cybersecurity operations, SOC or security engineering roles
- Certifications (Must have):
Security+
- Certified Ethical Hacker (CEH)
- CompTIA CySA+
- OffSec Certified Professional (OSCP)
- Native Arabic fluent in write and speak English (Saudi National)
- Proven experience implementing NCA ECC, CMA Cybersecurity Guidelines, SDAIA PDPL rules, and Tadawul security framework is preferable.
- Knowledge of Brand Protection / Digital Risk Protection (DRP) tools (e.g., BrandShield, PhishLabs, Recorded Future) and domain takedown mechanisms.
- Knowledge of cybersecurity tools (SIEM, EDR, firewalls, IAM …).
- Understanding of vulnerability management, incident response and risk management.
- Basic understanding of email security (DMARC, DKIM, SPF) and phishing defense.
- Strong documentation and coordination skills.
- Ability to manage multiple tasks in a structured environment.
- Team-oriented attitude to help other colleagues and teams with technical problems
- Strong interpersonal communication and relationship-building skills
- Ability to manage time and effectively prioritize numerous projects at one time
- Organized and attentive to detail, flexible with changing priorities and able to communicate in a polite and professional manners