Job Search and Career Advice Platform

Enable job alerts via email!

Security Analyst

Lucidya

Saudi Arabia

On-site

SAR 150,000 - 200,000

Full time

Yesterday
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading AI-native platform in Saudi Arabia is seeking a Security Analyst to enhance compliance and security initiatives. The role involves working closely with GRC and Security Engineering to maintain ISO standards and manage security requirements across international markets. Ideal candidates should have 2-4 years of experience in similar roles, a strong understanding of compliance frameworks, and hold mandatory certifications like CISM. This position contributes significantly to shaping security in a fast-paced AI-driven environment.

Qualifications

  • 2-4 years in a Security Analyst / GRC role.
  • Strong understanding of US compliance frameworks.
  • Experience in B2B SaaS environments.

Responsibilities

  • Support compliance initiatives across multiple regions.
  • Implement and maintain ISO/IEC controls.
  • Document security and compliance processes.

Skills

ISO/IEC 27001 knowledge
ISO/IEC 42001 knowledge
API security
Vulnerability assessment
Technical documentation

Education

CISM certification
ISO/IEC 27001 Lead Implementer certification

Tools

Python
Bash
Job description
Overview

About Lucidya Lucidya is an AI-native Customer Experience Intelligence platform empowering enterprises to understand, engage, and retain customers at scale. As we expand, security, compliance, and trust are at the core of our growth strategy. To support this expansion, we are strengthening our security organization and are looking for a Security Analyst to play a key role in bridging GRC, security engineering, and global compliance efforts. The role contributes to achieving multiple compliance certifications per quarter, ensuring Lucidya meets the highest standards of data protection and information security. You’ll work at the intersection of GRC and Security Engineering, supporting compliance initiatives, strengthening internal controls, and enabling secure product development across cross-functional teams.

What You’ll Be Doing
  • Work closely with GRC and Security Engineering teams to support security, privacy, and compliance initiatives across Saudi Arabia, Qatar, international regions, and the U.S. market.
  • Assist in the implementation and ongoing maintenance of ISO/IEC 27001, ISO/IEC 42001 (AI Management Systems), and SOC 2 controls.
  • Support U.S. market migration efforts by helping align security and compliance practices with SOC 2, NIST frameworks, and U.S. data privacy requirements.
  • Contribute to regional data protection compliance activities, including KSA PDPL, Qatar PDPL, and U.S. state privacy laws, under guidance from senior team members.
  • Participate in the creation, update, and maintenance of security, privacy, and AI governance policies, procedures, and control documentation.
  • Support penetration testing, vulnerability management, security assessments, and track remediation actions.
  • Help with document control, evidence collection, and audit readiness for internal reviews, customer assessments, and external audits.
  • Work cross-functionally with engineering, product, and operations teams.
  • Day-to-Day Responsibilities include: support daily security, privacy, and compliance activities across regions, maintain and update controls for ISO/IEC 27001, ISO/IEC 42001, and SOC 2, align systems with market requirements (SOC 2 evidence, NIST-aligned controls, data privacy obligations), review security controls for cloud infrastructure, SaaS environments, APIs, and integrations, support vulnerability management, and maintain policies, procedures, and control documentation.
  • Collect, organize, and validate audit evidence for internal reviews, customer questionnaires, and external audits; track compliance tasks, findings, and remediation actions in coordination with GRC and Security Engineering teams.
  • Collaborate with engineering, product, and operations teams to address security and compliance requirements in day-to-day workflows.
  • Support incident response documentation, risk assessments, and compliance reporting as needed.
Success Metrics
  • ISO & AI Governance: ISO/IEC 27001 and ISO/IEC 42001 controls assigned to the role remain implemented and evidenced, with zero high-risk audit findings related to security or AI governance.
  • NIST Alignment & Risk Reduction: Systems mapped to NIST frameworks show measurable risk reduction, with identified gaps documented and remediated within timelines.
  • Progression: Independent progression and ownership of assigned tasks; achieve ISO27001 lead implementer status if not already held.
What We’re Looking For
  • Experience & Background: 2 - 4 years in a similar Security Analyst / GRC role; experience with US-based SaaS companies; strong understanding of AI and US compliance frameworks: ISO/IEC 42001, ISO/IEC 27001, NIST, US data privacy regulations; experience in B2B SaaS environments.
  • Compliance & Security Knowledge: ISO/IEC 27001, ISO/IEC 42001 implementation knowledge (Implementer certification preferred), SOC 2 (NCE) understanding, GDPR knowledge a plus; penetration testing & vulnerability assessment knowledge.
  • Technical Skills: API security & integrations, basic scripting (Python, Bash), code review support for deployments (automated tools), security reviews of CI/CD pipelines; Ruby / Rails code review experience is a plus.
  • Certifications: CISM (Mandatory); ISO/IEC 27001 Lead Implementer (Mandatory); ISO/IEC 24001 Lead Implementer (preferred).
  • Soft Skills: Excellent professional documentation skills, strong organizational and follow-up abilities, experience with document control and audit evidence; ability to work effectively across distributed, cross-functional teams.
Nice-to-Have
  • Experience with remote work with US-based teams; experience supporting global compliance programs; hands-on involvement in multiple certification cycles.
  • Passionate about security, compliance, and global scale; interest in shaping the security foundation of a fast-growing AI company.
What We Offer

… (The original description may include benefits and other details. If present in the source, include them here in compliant tags. If not, this section can be omitted in refinement.)

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.