Cybersecurity Specialist — Alkhorayef Group | Riyadh, Saudi Arabia
Alkhorayef Group is looking for a Cybersecurity Specialist to join our Cybersecurity function, protecting the Group's information assets and technology infrastructure across all our entities and sustaining compliance with NCA regulations.
About the role
You will operate the Group's security tooling day to day, support the vulnerability management lifecycle, contribute to incident response, and help maintain the evidence base behind our regulatory compliance — working across multiple operating companies in a genuinely varied environment. This is a strong second role for someone who has spent their first year or two in a SOC, a GRC team, or a vulnerability management function and wants broader exposure.
Key responsibilities
- Operate the Group security tooling — SIEM, EDR, firewall, web filtering and email security consoles
- Review and triage security alerts daily, escalated confirmed threats, and track open alerts through to closure
- Work with IT Operations on detection tuning, log source coverage and false-positive reduction
- Run scheduled vulnerability scans across servers, endpoints, network devices and cloud workloads
- Rank findings by exploitability and business impact, follow up remediation with system owners, and verify fixes by rescanning
- Support control self-assessments against the NCA Essential Cybersecurity Controls, CSCC where applicable, and ISO 27001, and help keep the cyber risk register current
- Assist with compliance reporting against the NCA control set and with regulatory, internal and external audits
- Perform first-line analysis of suspected incidents, contain them within approved playbooks, preserve evidence, and document the incident timeline
- Contribute to post-incident reports covering root cause, impact and lessons identified
- Process access requests to critical systems, administer MFA and privileged access management tooling, and support periodic user access reviews
- Reconcile joiner, mover and leaver activity with HR and IT records in line with NCA control 1-9-5
- Deliver the Group security awareness programme, run phishing simulation campaigns, and report completion metrics
- Support vendor and cloud service provider security assessments against the Group's cybersecurity requirements
What we're looking for
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, or a related field
- 1–2 years of cybersecurity experience in security operations, vulnerability management, GRC, or incident handling — internships, co-op and Tamheer programmes count
- Working knowledge of the NCA Essential Cybersecurity Controls (ECC) and familiarity with ISO 27001 or the NIST Cybersecurity Framework
- Hands-on exposure to SIEM, EDR and vulnerability scanning tools
- A professional certification such as CompTIA Security+, ISC2 CC, or equivalent is an advantage
- Strong written English and Arabic — you will produce reports read by both technical teams and management