Associate Director - Cybersecurity Risk and Compliance

🏢 Qiddiya Investment Company
📍 Riyadh, Saudi ArabiaOn-site
📅 Posted: 4w ago🔄 Updated: 4w ago
CV%
✨ AI Summary
The Associate Director - Cybersecurity Risk and Compliance will be responsible for conducting cybersecurity risk assessments across IT and OT environments, identifying and documenting OT-specific risks, and coordinating risk reviews. They will also lead internal and external compliance assessments, monitor adherence to policies, and manage remediation plans. Additionally, the role involves governing third-party cybersecurity risk through assessment processes and ensuring security controls are embedded in vendor agreements.
Required Skills
Information Technology
Cybersecurity
Finance, Legal & Governance
HR Compliance
Engineering, Construction & Trades
SCADADCSPLC
Other
IEC 62443NCA OTCC
Business, Sales & Management
Risk Management
Nice to have:
Other
IT/OT convergence
Requirements
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field. Master's degree is preferred. 10–12+ years of cybersecurity experience.Strong experience in cybersecurity risk management, compliance, assessments, and assurance.
Description
Roles and Responsibilities:Conduct periodic and ad hoc cybersecurity risk assessments across IT and OT environmentsPerform OT-specific risk assessments on assets such as PLCs, HMIs, RTUs, and engineering systemsIdentify and document OT-relevant risk scenarios (e.g., control system disruption, unauthorized access, safety manipulation)Coordinate risk reviews as part of major IT/OT changes, such as system upgrades or new deploymentsReassess risk posture following major changes, incidents, or regulatory updatesReview and validate existing controls to calculate residual risk and prioritize treatment actionsProvide standardized tools and guidance to support self-assessments by IT, OT, and business teamsSupport integration of assessment outcomes into control design, zoning, segmentation, and system deploymentTrack risk treatment progress and escalate overdue or high-priority items as neededCoordinate with performance management to define and monitor key risk indicators (KRIs) to proactively track changes in cybersecurity risk exposureMaintain the cybersecurity risk register, including OT-specific entries, capturing identified risks, likelihood and impact ratings, treatment plans, ownership, and statusCoordinate and execute internal cybersecurity compliance assessments across all relevant domains and functionsServe as the lead interface for external audits and regulatory inspections, including preparation, execution, and responseConduct periodic compliance assessments of OT environments, including SCADA, DCS, PLCs, and associated network infrastructureMaintain an inventory of compliance-relevant OT assets and map them to applicable control requirements and standardsMonitor adherence to cybersecurity policies, escalate non-compliance, and coordinate corrective actions with relevant teamsTrack and manage remediation plans for compliance gaps, non-conformities, and audit findings through closureValidate the effectiveness of implemented controls or mitigation plans before closing compliance gapsReview and validate configuration baselines for OT systems (e.g., firewall rules, firmware versions) to ensure alignment with compliance standardsCoordinate evidence collection, documentation, and remediation planning for compliance-related findingsReport OT and IT cybersecurity compliance status and risks to leadership and cybersecurity governanceSupport compliance awareness and training for teams with control responsibilities in both IT and OTMaintain a centralized compliance register, covering both IT and OT, that maps regulatory requirements to policies, controls, responsible teams, and evidence sourcesGovern third-party cybersecurity risk by maintaining standardized assessment processes, due diligence criteria, and remediation trackingCoordinate and conduct third-party cybersecurity assessments across IT and OT suppliers to ensure alignment with internal policies and regulatory requirementsReview vendor-supplied OT systems and supporting documentation to ensure inclusion of security controls and compliance with applicable standards (e.g., NCA OTCC, IEC 62443)Ensure third-party risk findings are documented, risk-rated, and tracked through resolution, including acceptance or application of compensating controlsMaintain a register of assessed vendors, associated risks, control gaps, and remediation status for ongoing oversight and reportingCollaborate with procurement, legal, and compliance to embed cybersecurity requirements into third-party agreements, including OT-specific clauses where applicableContribute to the development and review of third-party security policy and minimum control requirements for use in procurement and onboardingSupport internal and external audit requests related to third-party cybersecurity risk management
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00