Enable job alerts via email!

Cybersecurity Compliance Operations Head

aramco digital

Dhahran Compound

On-site

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Cybersecurity Compliance Operations Head to lead security compliance across cloud environments and enterprise applications. This pivotal role focuses on implementing robust security governance, managing risks, and ensuring adherence to critical security standards. The ideal candidate will have extensive experience in cloud security and application security, with a strong background in Secure Software Development Lifecycle (SSDLC) implementation. Join a forward-thinking organization where your expertise will drive significant improvements in security compliance and risk management, making a real impact in a dynamic environment.

Qualifications

  • 10+ years of experience in cloud security and application security.
  • Proven expertise in implementing SSDLC and vulnerability management.

Responsibilities

  • Lead cloud security governance and application security compliance.
  • Oversee security patching and vulnerability remediation activities.
  • Manage application and cloud security assessments for compliance.

Skills

Cloud Security Compliance
Application Security Governance
Secure Software Development Lifecycle (SSDLC)
Patch Management
Vulnerability Management
Security Assessment
Policy Development
Stakeholder Collaboration

Education

Bachelor’s degree in Cybersecurity
Bachelor’s degree in Computer Science
Bachelor’s degree in Information Security

Tools

ISO 27001
NIST
AWS Security
Microsoft Azure Security
Google Cloud Security
GIAC Web Application Penetration Tester (GWAPT)
Offensive Security Web Expert (OSWE)

Job description

Job Description:

The Cybersecurity Compliance Operations Head is responsible for ensuring security compliance across cloud environments and enterprise applications. This role leads cloud security governance, application security compliance, patch management, vulnerability management, and the implementation of the Secure Software Development Lifecycle (SSDLC). The position focuses on strengthening security controls, managing risks related to cloud services and applications, and ensuring adherence to security standards without managing or operating SOC functions.

Core Functional Skills:

  • Cloud Security Compliance: Implement and monitor security controls across public and private cloud environments ensuring alignment with cybersecurity policies and regulatory frameworks.
  • Application Security Governance: Establish secure coding guidelines, manage application security assessments, and enforce compliance with secure software development standards.
  • Secure Software Development Lifecycle (SSDLC) Implementation: Lead the rollout of SSDLC frameworks ensuring that security is embedded across development, testing, deployment, and operations.
  • Patch Management and Vulnerability Remediation: Oversee security patching, vulnerability scanning, and remediation activities across cloud services and application portfolios.
  • Security Assessment and Compliance Audits: Manage application and cloud security assessments, ensuring compliance with ISO 27001, NIST, NCA ECC, and other standards.
  • Policy Development and Enforcement: Develop, update, and enforce security policies related to cloud computing, application security, patching, and vulnerability management.
  • Stakeholder Collaboration: Work closely with application development, cloud engineering, risk management, and cybersecurity teams to ensure end-to-end compliance.

Experience & Education:

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Security, or a related field.
  • 10+ years of experience in cloud security, application security, and cybersecurity compliance leadership roles.
  • Proven expertise in implementing Secure Software Development Lifecycle (SSDLC) and vulnerability management programs.
  • Certifications preferred: Certified Cloud Security Professional (CCSP), Certified Secure Software Lifecycle Professional (CSSLP), AWS Certified Security Specialty, Microsoft Certified Azure Security Engineer Associate, Google Professional Cloud Security Engineer, GIAC Web Application Penetration Tester (GWAPT), Offensive Security Web Expert (OSWE) (optional but preferred).
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.