Our client is a government-owned entity in Saudi Arabia focused on strengthening cybersecurity across critical industrial infrastructure. The organization is responsible for implementing cybersecurity governance, risk management, and compliance measures aligned with national and international cybersecurity standards.
The organization works closely with internal and external stakeholders to ensure regulatory compliance, operational resilience, and the protection of critical systems and infrastructure across multiple sites.
Position Purpose
The Cybersecurity Operations Manager is responsible for supporting the development and execution of the organization's cybersecurity strategy in alignment with business objectives and applicable regulatory requirements.
The role oversees cybersecurity risk management, compliance, protection and detection capabilities, vulnerability management, incident response, and cybersecurity operations. The position also promotes cybersecurity awareness and ensures that appropriate security controls are incorporated across systems, processes, procurement activities, and third-party engagements.
The role operates in accordance with the strategic direction and guidelines established by the Cybersecurity Director.
Key Responsibilities
Cybersecurity Strategy & Governance
- Support the development and implementation of the cybersecurity strategy in alignment with organizational objectives and applicable national cybersecurity requirements.
- Ensure cybersecurity initiatives, policies, procedures, and controls are aligned with the organization's strategic objectives.
- Develop and maintain cybersecurity policies, standards, procedures, and supporting documentation.
- Regularly review cybersecurity assumptions, requirements, and controls to ensure continued effectiveness.
- Support cybersecurity governance and compliance activities across the organization.
- Identify, assess, monitor, and manage cybersecurity risks through established risk governance processes.
- Ensure cybersecurity decisions are based on sound risk management principles.
- Communicate cybersecurity risks, threats, and their potential financial and operational impact to senior management and relevant third parties.
- Track audit findings, recommendations, and remediation activities to ensure timely closure.
- Support compliance with applicable cybersecurity laws, regulations, standards, and organizational requirements.
Cybersecurity Operations
- Oversee cybersecurity operations, protection, detection, and monitoring capabilities.
- Ensure cybersecurity architecture and IT security requirements are aligned with organizational cybersecurity strategy and policies.
- Identify potential security incidents and ensure appropriate reporting, escalation, and response.
- Coordinate cybersecurity inspections, assessments, testing, and reviews across the network environment.
- Ensure appropriate cybersecurity data collection, monitoring, and reporting against defined requirements.
- Support the organization's operational resilience and cybersecurity readiness.
Vulnerability & Security Management
- Effectively manage vulnerability identification, assessment, prioritization, and remediation activities.
- Coordinate with relevant technical teams to ensure identified vulnerabilities are addressed within appropriate timelines.
- Monitor the effectiveness of security controls and recommend improvements where required.
- Support continuous improvement of cybersecurity protection and detection capabilities.
Technology & Third-Party Security
- Evaluate and approve cybersecurity capabilities and security controls for new systems, technologies, processes, and proposed acquisitions.
- Ensure appropriate cybersecurity controls and supply chain risk management practices are incorporated into technology procurement and implementation.
- Integrate cybersecurity requirements into procurement, outsourcing, mergers, acquisitions, and third-party operations.
- Assess cybersecurity risks associated with external suppliers, service providers, and third parties.
Business Continuity & Resilience
- Collaborate with relevant stakeholders to ensure business continuity and disaster recovery programs meet organizational cybersecurity requirements.
- Support the development of resilient cybersecurity processes capable of maintaining critical operations during disruptions.
- Identify cybersecurity-related risks that may impact operational continuity and coordinate appropriate mitigation measures.
Cybersecurity Awareness
- Promote the importance and value of cybersecurity across the organization.
- Support the development and delivery of cybersecurity awareness, training, and education programs.
- Advocate cybersecurity best practices among employees, management, and relevant stakeholders.
- Provide guidance to senior management regarding emerging cybersecurity risks and threats.
Budget & Resource Management
- Support the planning and management of cybersecurity budgets and resources.
- Ensure appropriate resources are available to develop and implement effective cybersecurity processes.
- Monitor resource utilization and support cost-effective delivery of cybersecurity initiatives.
- Identify opportunities to improve cybersecurity processes, controls, policies, and operational effectiveness.
- Support the implementation of new cybersecurity initiatives, technologies, and processes.
- Monitor emerging cybersecurity threats, regulatory developments, and industry practices.
- Recommend improvements to strengthen the organization's overall cybersecurity posture.
Managerial Responsibilities
- Ensure team members comply with organizational policies, procedures, quality standards, and applicable safety and security requirements.
- Cascade departmental objectives and KPIs to team members and establish challenging yet achievable performance targets.
- Monitor team performance and identify opportunities to improve productivity, efficiency, and cost effectiveness.
- Support workforce planning and selection in alignment with business and operational requirements.
- Provide regular feedback, coaching, and guidance to team members to enhance engagement and capability development.
- Review departmental performance against budgets and KPIs and initiate corrective actions where required.
- Support the management of government and regulatory matters in accordance with applicable policies and legal requirements.
- Coordinate with internal and external stakeholders to ensure effective adherence to cybersecurity policies, procedures, and requirements.
Qualifications & Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- Minimum of 5 years of relevant cybersecurity experience.
- Experience in cybersecurity operations, risk management, governance, compliance, vulnerability management, or information security.
- Experience working with cybersecurity policies, controls, audits, and regulatory requirements.
- Experience within critical infrastructure, industrial, government, or highly regulated environments is advantageous.
- Strong understanding of cybersecurity principles, risk management, and security operations.
- Proficiency in Microsoft Office and standard computer applications.
- Strong cybersecurity and risk management knowledge.
- Excellent analytical and problem-solving skills.
- Strong communication and stakeholder management abilities.
- Ability to communicate cybersecurity risks and technical concepts to senior management.
- Strong organizational and time-management skills.
- Ability to manage multiple priorities and projects effectively.
- Strong leadership and team-management capabilities.
- High level of attention to detail and accountability.
- Strong teamwork and cross-functional collaboration skills.
- Excellent verbal and written communication skills.
- Excellent command of Arabic and English .