Get more replies from employers
Send a job-specific resume in minutes.
AECOM Riyadh is seeking a Security and ICT Inspector - Risk and Compliance to lead independent inspections of security controls, ICT infrastructure, and regulatory compliance across facilities. You will perform structured risk assessments, identify vulnerabilities, document findings, and provide actionable recommendations to reduce technology risk and strengthen resilience.
The role requires a minimum of 8 years of experience in security audits, ICT inspections, and risk management within
Role: Security and ICT Inspector - Risk and Compliance
Location: Riyadh, Saudi Arabia
Industry: Computer and Network Security
Function: Security Intelligence & Analysis
Experience: Minimum 8 years
Job Type: Full-time
Position Overview: Security and ICT Inspector - Risk and Compliance in Riyadh, Saudi Arabia is a Computer and Network Security opportunity focused on security inspections, ICT infrastructure assessments, vulnerability identification, regulatory compliance, and technology risk mitigation. AECOM is hiring an experienced inspector to evaluate network and security controls, conduct structured risk assessments, investigate incidents, document compliance gaps, and provide practical recommendations that strengthen organizational security and technology resilience.
Job Details: Country: Saudi Arabia City: Riyadh Industry: Computer and Network Security Function: Security Intelligence & Analysis Salary: 16000-25000 Estimated salary range based on similar jobs in the job city; please confirm the final offer with the employer. Gender: Any Candidate Nationality: Any Job Type: Full-time
Role Context: The Security and ICT Inspector will provide independent oversight of security controls and technology environments, helping ensure that organizational systems, facilities, and digital infrastructure operate in accordance with approved policies, regulatory requirements, and recognized security practices. The position is centered on evidence-based inspection. Network configurations, access controls, security protocols, protection measures, incident records, and operational procedures must be reviewed systematically to identify weaknesses before they develop into significant operational or information-security risks. Working closely with ICT, cybersecurity, security operations, and management teams, the inspector will convert technical findings into prioritized corrective actions. Effective follow-up will be essential to verify that identified vulnerabilities are addressed and that improvements produce measurable reductions in organizational risk.
Ideal Profile Candidates should have at least 8 years of professional experience conducting security audits, ICT inspections, security assessments, or comparable technology assurance activities within corporate or complex organizational environments. Strong knowledge of ICT infrastructure, network systems, information-security architecture, and security-control design is required. Candidates should be able to understand how vulnerabilities within individual systems can affect wider operational and business risks. Practical expertise in risk assessment, vulnerability analysis, and threat identification is essential. The successful candidate should be capable of distinguishing minor technical issues from weaknesses that require urgent corrective action. A solid understanding of security compliance frameworks, regulatory requirements, access-control principles, and data protection measures is expected. Candidates should have strong technical reporting and documentation capabilities. Findings must be recorded accurately, supported by appropriate evidence, and communicated clearly to management and technical teams. Experience with vulnerability assessment tools and structured security testing methodologies is preferred. Knowledge of incident response procedures and business continuity planning will provide additional value. Professional credentials such as ISO 27001, CISSP, or equivalent recognized security certifications are preferred rather than mandatory. Project management experience involving security-related initiatives will be advantageous, particularly where multiple remediation activities or inspection programs must be coordinated simultaneously. The role requires independent judgment, strong analytical ability, disciplined organization, and the confidence to communicate security concerns objectively to diverse stakeholders.
Organizations operating complex facilities and digital environments increasingly require independent assurance that security controls are functioning as intended and that ICT risks are identified before they disrupt operations. This Riyadh role provides broad exposure to infrastructure security, technology risk, compliance assessment, vulnerability management, incident review, and corrective-action verification. AECOM 's multidisciplinary environment creates opportunities to collaborate with ICT specialists, engineers, security professionals, project teams, and senior stakeholders across technically demanding programs. The experience can support progression toward senior security assurance, cybersecurity governance, ICT risk management, security compliance, or broader technology-resilience leadership.
AECOM is a global infrastructure consulting firm with more than 50000 professionals working across planning, design, engineering, digital technology, program management, and construction management. The company supports complex buildings, transportation, water, energy, and environmental projects, combining technical expertise with structured risk management, digital delivery, sustainable solutions, and coordinated project execution across Saudi Arabia and international markets.