Cybersecurity Architect – Security Governance, Cloud & GRC | Riyadh, Saudi Arabia

VaporVM Ltd.

Saudi Arabia

On-site

SAR 94,000 - 156,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

VaporVM Ltd. in Riyadh, Saudi Arabia, is seeking a seasoned Cybersecurity Architect to lead security strategy and governance on-site.

The role targets professionals with 8–12 years of experience across GRC, risk management, threat monitoring, incident response, and cloud security. You will work with ISO 27001:2022, SAMA-CSF, NCA, PDPL, CST CRF compliance, oversee penetration testing, vulnerability management, SIEM, and secure vendor risk assessments while enabling secure cloud, application, API

Qualifications

  • 8–12 years of professional cybersecurity experience.
  • Current residence in Saudi Arabia.
  • Availability as an immediate joiner.
  • Strong knowledge of ISO 27001:2022, SAMA-CSF, NCA, PDPL, CST CRF.
  • Strong experience in Security Governance, GRC, and Risk Management.
  • Experience with penetration testing and vulnerability management.
  • Knowledge of SIEM, threat monitoring, and incident response.
  • Experience with cloud, application, API, and IoT security.
  • Strong understanding of OWASP Top 10, PTES, and MITRE ATT&CK.
  • Experience in vendor security and third-party risk assessments.
  • Strong analytical, communication, stakeholder-management, and problem-solving skills.

Responsibilities

  • Develop and support cybersecurity architecture and security strategies.
  • Apply relevant cybersecurity frameworks, standards, and regulatory requirements.
  • Support compliance with ISO 27001:2022, SAMA-CSF, NCA, PDPL, and CST CRF requirements.
  • Manage and support security governance, GRC, and enterprise risk-management activities.
  • Assess security risks and recommend appropriate mitigation strategies.
  • Support penetration testing and vulnerability management programs.
  • Monitor security threats and support SIEM and incident-response activities.
  • Apply security controls across cloud, applications, APIs, and IoT environments.
  • Assess security risks throughout the technology and application lifecycle.
  • Apply security testing and assessment methodologies aligned with OWASP Top 10, PTES, and MITRE ATT&CK.
  • Conduct or support vendor security assessments and third-party risk reviews.
  • Collaborate with technology, infrastructure, application, compliance, and business stakeholders.
  • Support continuous improvement of cybersecurity controls, policies, and architecture.

Skills

Security Governance
GRC
Risk Management
Penetration Testing
Vulnerability Management
SIEM
Threat Monitoring
Incident Response
Cloud Security
Application Security
API Security
IoT Security

Tools

OWASP Top 10
PTES
MITRE ATT&CK
ISO 27001:2022

Job description

Location

Riyadh, Saudi Arabia — On-site


Job Category


  • Information Technology (IT) & Software

  • Security & Defence

  • Legal & Compliance

  • Banking & Insurance

  • Telecommunications


Job Overview

VaporVM is seeking an experienced Cybersecurity Architect to join its team in Riyadh, Saudi Arabia. This on-site opportunity is suitable for cybersecurity professionals with 8–12 years of experience and strong expertise across security architecture, governance, risk and compliance, vulnerability management, threat monitoring, incident response, and cloud security.


The role requires comprehensive knowledge of cybersecurity frameworks and Saudi regulatory requirements, including ISO 27001:2022, SAMA-CSF, NCA, PDPL, and CST CRF. The successful candidate will work across security governance, penetration testing, vulnerability management, SIEM, cloud, application, API, and IoT security, as well as vendor and third-party risk assessments.


This position offers opportunities for career growth and professional development within cybersecurity architecture, GRC, security engineering, cloud security, and regulatory compliance. Relevant certifications and specialized cybersecurity training can further strengthen long-term career progression.


Key Responsibilities


  • Develop and support cybersecurity architecture and security strategies.

  • Apply relevant cybersecurity frameworks, standards, and regulatory requirements.

  • Support compliance with ISO 27001:2022, SAMA-CSF, NCA, PDPL, and CST CRF requirements.

  • Manage and support security governance, GRC, and enterprise risk-management activities.

  • Assess security risks and recommend appropriate mitigation strategies.

  • Support penetration testing and vulnerability management programs.

  • Monitor security threats and support SIEM and incident-response activities.

  • Apply security controls across cloud, applications, APIs, and IoT environments.

  • Assess security risks throughout the technology and application lifecycle.

  • Apply security testing and assessment methodologies aligned with OWASP Top 10, PTES, and MITRE ATT&CK.

  • Conduct or support vendor security assessments and third-party risk reviews.

  • Collaborate with technology, infrastructure, application, compliance, and business stakeholders.

  • Support continuous improvement of cybersecurity controls, policies, and architecture.


Requirements & Qualifications


  • 8–12 years of professional cybersecurity experience.

  • Current residence in Saudi Arabia is required.

  • Availability as an immediate joiner is required.

  • Strong knowledge of:

    • ISO 27001:2022

    • SAMA Cyber Security Framework (SAMA-CSF)

    • National Cybersecurity Authority (NCA) requirements

    • Personal Data Protection Law (PDPL)

    • CST Cybersecurity Regulatory Framework (CST CRF)



  • Strong experience in Security Governance, GRC, and Risk Management.

  • Experience with penetration testing and vulnerability management.

  • Knowledge of SIEM, threat monitoring, and incident response.

  • Experience with cloud, application, API, and IoT security.

  • Strong understanding of OWASP Top 10, PTES, and MITRE ATT&CK.

  • Experience in vendor security and third-party risk assessments.

  • Strong analytical, communication, stakeholder-management, and problem-solving skills.


Preferred Certifications


  • CISM

  • CISA

  • ISO 27001 Lead Auditor

  • ISO 27001 Lead Implementer

  • CAP or equivalent cybersecurity certification


Salary, Benefits & Career Growth

Salary: Up to SAR 14,000 per month, based on the job posting.


The position provides opportunities for career growth and professional development across cybersecurity architecture, security governance, GRC, regulatory compliance, cloud security, vulnerability management, and threat response. Candidates can further strengthen their professional profile through certifications such as CISM, CISA, ISO 27001 Lead Auditor/Implementer, CAP, and other relevant cybersecurity credentials.


Joining: Immediate joiner required


Location Requirement: Candidates must currently be based in Saudi Arabia.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Architect - GRC, Cloud & IoT (On-Site)
Cybersecurity Architect - GRC, Cloud & IoT (On-Site)

VaporVM Ltd. • Saudi Arabia

On-site
SAR 94,000 - 156,000
Cybersecurity Architecture Specialist – Riyadh, Saudi Arabia
Cybersecurity Architecture Specialist – Riyadh, Saudi Arabia

Cloud Consultancy - CCDS • Saudi Arabia

On-site
SAR 300,000 - 460,000
Cyber Security Engineer – Riyadh, Saudi Arabia
Cyber Security Engineer – Riyadh, Saudi Arabia

SITE سايت • Saudi Arabia

On-site
SAR 180,000 - 240,000
Social allowance
Mobile allowance
Medical insurance for employee, family
Cybersecurity Architecture Specialist
Cybersecurity Architecture Specialist

CCDS • Riyadh

On-site
SAR 250,000 - 420,000
Cybersecurity Architecture Specialist
Cybersecurity Architecture Specialist

cloud consultancy - ccds • Saudi Arabia

On-site
OMR 33,000 - 53,000
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
Cybersecurity Governance, Risk & Compliance (GRC) Specialist

cloud consultancy - ccds • Saudi Arabia

On-site
OMR 29,000 - 48,000
Cybersecurity Intern – Saudi Nationals Only
Cybersecurity Intern – Saudi Nationals Only

Algebrass • Riyadh

On-site
SAR 33,000 - 67,000
Certificate of completion
Mentorship program
Hands-on client exposure
Information Security Manager (KSA National)
Information Security Manager (KSA National)

Maximus KSA | ماكسيموس السعودية • Riyadh

On-site
SAR 320,000 - 460,000
Senior Cybersecurity Engineer | Global Technologies GT – التقنيات العالمية | Riyadh, Saudi Arabia
Senior Cybersecurity Engineer | Global Technologies GT – التقنيات العالمية | Riyadh, Saudi Arabia

Global Technologies GT - التقنيات العالمية • Riyadh

On-site
SAR 200,000 - 360,000
Cyber Security Specialist
Cyber Security Specialist

Sahm Capital • Riyadh

On-site
SAR 180,000 - 240,000