Senior IT & Cybersecurity Auditor
OptiClaim · Riyad
وصف الوظيفة
About the role
We are seeking a Senior IT & Cybersecurity Auditor to lead audit engagements across a diverse technology landscape. The role involves assessing infrastructure, controls, and governance processes to strengthen the organization’s security posture and regulatory compliance.
Key responsibilities
- Plan and execute risk‑based IT and cybersecurity audit engagements.
- Evaluate design and operating effectiveness of IT General Controls such as logical access, privileged access, password policies, change management, backup/recovery, and monitoring.
- Assess cybersecurity controls across network, endpoint, server, database, cloud, and infrastructure environments.
- Review identity and access management, privileged access management, MFA, and access governance.
- Perform vulnerability, patch, security monitoring, incident response, threat detection, and SOC capability assessments.
- Examine network security architecture including firewalls, segmentation, VPN, email security, and secure configurations.
- Validate cloud security controls for Azure, AWS, Microsoft 365, GCP, and hybrid environments.
- Prepare audit workpapers, risk assessments, reports, and executive presentations.
- Monitor remediation actions and verify closure of audit findings.
Required profile
- 10‑12 years of experience in IT audit, cybersecurity audit, information security, technology risk, or internal audit.
- Bachelor’s degree in Computer Science, IT, Cybersecurity, Information Systems or related field.
- Professional certifications such as CISA, CISM, CRISC, CISSP, or ISO/IEC 27001 Lead Auditor.
- Consulting background preferred, ideally with a Big 4 firm.
Required skills
- IT General Controls (ITGC) – logical access, privileged access, password controls, change management, backup/recovery, logging, monitoring.
- Identity & Access Management (IAM), Privileged Access Management (PAM), Multi‑Factor Authentication (MFA).
- Cloud platforms: Azure, AWS, Microsoft 365, GCP, hybrid environments.
- Active Directory, Microsoft Entra ID, VMware.
- Frameworks: NCA ECC & DCC, SAMA CSF, PDPL, ISO/IEC 27001, NIST CSF, COBIT, CIS Controls, PCI DSS.
- Security tools: SIEM, SOC, vulnerability management, patch management, firewall, VPN, email security, network segmentation.
- Backup/DR, data encryption, incident response, threat detection.
Questions fréquentes
لماذا تبلغ عن هذا العرض؟
اكتشف المزيد
الرواتب والأدلة وعمليات البحث في المملكة العربية السعودية.
الرواتب حسب المهنة
قدم طلبك في 30 ثانية
أدخل بريدك الإلكتروني للتقديم. سيتم إنشاء حساب تلقائياً.
بالمتابعة، أنت توافق على شروط الاستخدام.
لديك حساب بالفعل؟ تسجيل الدخول
لديك سؤال حول هذا العرض؟
اطرحه هنا: ستصلك تفاصيل العرض كاملة عبر البريد الإلكتروني، فوراً.
عزز فرصك
حمّل سيرتك الذاتية وسنقترح عليك الوظائف التي تناسب ملفك.
جاري تحليل سيرتك الذاتية...
OptiClaim
Riyad