Manager - Cybersecurity, Application Security

Elm Co

Riyadh

On-site

SAR 320,000 - 520,000

Full time

12 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Elm Co is seeking a Manager of Cybersecurity in Riyadh to lead governance, risk, compliance, and protection across the organization. The role focuses on setting direction, overseeing controls, enabling regulatory alignment, and improving cybersecurity maturity.

The role collaborates with stakeholders to protect Elm's information assets and digital operations, ensuring practices align with policies and regulatory requirements. A strong background in governance and risk management is essential.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, IT, or related field.
  • Master's degree in a relevant field is preferred.
  • Professional cybersecurity certifications are preferred.

Responsibilities

  • Lead Cybersecurity Strategy and Governance within the assigned scope.
  • Oversee Cybersecurity Risk Assessments for systems and processes.
  • Drive risk treatment plans with stakeholders for timely mitigation.
  • Oversee design, implementation and effectiveness of cybersecurity controls.
  • Ensure compliance with regulations, policies and standards.
  • Provide cybersecurity advisory to business and tech stakeholders.
  • Balance enablement with risk-based controls in solutions.
  • Oversee monitoring activities and incident response coordination.
  • Coordinate with teams during incidents for containment and remediation.
  • Lead vulnerability and threat management and improvement actions.

Skills

Governance
Risk management
Compliance
Security operations
Incident response

Education

Bachelor's degree
Master's degree preferred
Certifications preferred

Job description

Select how often (in days) to receive an alert:

Date: 7 Oct 2026

Custom Field 1: 701431

Location: Riyadh, SA

Facility: Others

Job Description
OVERVIEW

Job Title: Manager

Job Code: 701431

Grade: T1

Group: -

Department: Cybersecurity

ROLE PURPOSE

The aim is to state the overall significance of the job from the organization's perspective.

The role exists to lead cybersecurity governance, risk, compliance, and protection activities across the assigned scope by setting direction, overseeing security controls, enabling regulatory alignment, and driving cybersecurity maturity. The role contributes to protecting Elm's information assets, digital services, and business operations by ensuring cybersecurity practices are implemented, monitored, and continuously improved in alignment with Elm's approved policies, procedures, strategic objectives, and applicable regulatory requirements.

KEY ACCOUNTABILITIES & ACTIVITIES

This section describes the principal outputs required from the job.

Key Activities
1. Cybersecurity Strategy and Governance
  • Lead the development and execution of cybersecurity plans, initiatives, and governance activities within the assigned scope.
  • Ensure cybersecurity objectives are aligned with Elm's strategic priorities, business requirements, and regulatory expectations.
  • Provide direction and guidance on cybersecurity policies, standards, procedures, and control requirements.
2. Cybersecurity Risk Management
  • Oversee cybersecurity risk assessments for systems, services, processes, and business initiatives.
  • Validate key cybersecurity risks, control gaps, threats, and vulnerabilities that may impact confidentiality, integrity, or availability.
  • Drive risk treatment plans and follow up with stakeholders to ensure timely mitigation and effective risk reduction.
3. Security Controls and Compliance Oversight
  • Oversee the design, implementation, and effectiveness of cybersecurity controls across the assigned environment.
  • Ensure compliance with applicable cybersecurity regulations, internal policies, and relevant standards.
  • Review compliance gaps, remediation plans, and evidence to support audit readiness and management reporting.
4. Cybersecurity Advisory and Business Enablement
  • Provide cybersecurity advisory support to business and technical stakeholders on initiatives, projects, and services.
  • Ensure cybersecurity requirements are embedded into solutions, processes, and business decisions from early stages.
  • Balance business enablement with risk-based cybersecurity controls and practical implementation guidance.
5. Security Monitoring and Incident Response Oversight
  • Oversee cybersecurity monitoring activities and ensure security events are reviewed, escalated, and handled appropriately.
  • Coordinate with relevant teams during cybersecurity incidents to support investigation, containment, remediation, and reporting.
  • Review incident outcomes and ensure lessons learned are translated into improvement actions.
6. Vulnerability and Threat Management
  • Oversee vulnerability management activities, including prioritization, remediation follow-up, and risk-based treatment.
  • Monitor emerging cybersecurity threats and assess their potential impact on Elm's systems, services, and operations.
  • Coordinate with system owners and technical teams to ensure timely closure of critical vulnerabilities and exposure areas.
7. Stakeholder Management and Cybersecurity Awareness
  • Build and maintain effective relationships with internal stakeholders, business owners, technology teams, and governance functions.
  • Promote cybersecurity awareness and support the adoption of secure practices across the assigned scope.
  • Facilitate alignment between cybersecurity requirements, business priorities, and operational delivery needs.
8. Performance Reporting and Continuous Improvement
  • Prepare and review cybersecurity dashboards and management updates covering risks, controls, compliance, incidents, and improvement plans.
  • Analyze cybersecurity performance indicators to identify trends, gaps, and maturity improvement opportunities.
  • Lead continuous improvement initiatives that enhance cybersecurity resilience, governance effectiveness, and operational readiness.
  • Follow all relevant departmental policies, processes, standard operating procedures, and instructions so that work is carried out in a controlled and consistent manner.
  • Comply with all relevant safety, quality, and environmental management policies, procedures, and controls to ensure a healthy and safe work environment.
10. Information Security
  • Comply with all relevant information security practices and standards to ensure data integrity and confidentiality.
JOB SPECIFICATIONS
Academic and professional qualifications
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Computer Engineering, or a related field.
  • Master's degree in a relevant field is preferred.
  • Professional certifications in cybersecurity, information security, risk management, governance, or related fields are preferred.
Years and Nature of Experience
  • 8+ years of relevant experience in cybersecurity, information security, governance, risk and compliance, security operations, vulnerability management, or a related field.
  • Experience in leading cybersecurity activities, overseeing security controls, managing cybersecurity risks, supporting regulatory compliance, coordinating stakeholders, and driving cybersecurity maturity improvement initiatives.

Job Segment: Information Security, Risk Management, Computer Science, Engineer, Manager, Technology, Finance, Engineering, Management

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Consultant - Cybersecurity, Application Architecture
Consultant - Cybersecurity, Application Architecture

Elm Co • Riyadh

On-site
SAR 150,000 - 230,000
Associate Principal - Information Technology & Security Audit
Associate Principal - Information Technology & Security Audit

Elm Co • Riyadh

On-site
SAR 300,000 - 420,000
Cybersecurity Manager - Metro
Cybersecurity Manager - Metro

Egis • Riyadh

On-site
SAR 300,000 - 550,000
Cybersecurity Governance & Risk Manager
Cybersecurity Governance & Risk Manager

Elm Co • Riyadh

On-site
SAR 320,000 - 520,000
Consultant
Consultant

Elm Co • Riyadh

On-site
SAR 180,000 - 300,000
Principal
Principal

Elm Co • Riyadh

On-site
SAR 300,000 - 420,000
Cyber Security Specialist
Cyber Security Specialist

Sahm Capital • Riyadh

On-site
SAR 180,000 - 240,000
Cybersecurity Project Manager
Cybersecurity Project Manager

Confidential • Riyadh

On-site
SAR 250,000 - 390,000
Information Security Specialist | IDM Technologies | Riyadh, Saudi Arabia
Information Security Specialist | IDM Technologies | Riyadh, Saudi Arabia

Tech Junction Ltd • Riyadh

On-site
SAR 180,000 - 300,000
Cybersecurity Engineer
Cybersecurity Engineer

Tibah Airports Operation Co. • Medina

On-site
SAR 180,000 - 300,000