Talent.com
No longer accepting applications
Sr. Manager - Information Security Engineer

Sr. Manager - Information Security Engineer

National Bank of KuwaitJeddah, Saudi Arabia
14 days ago
Job description

Job Purpose

Manage and maintain internal and external bank systems security. Promote the adherence to the information system security policies, procedures & guidelines. Promote system security education for internal or external parties. Present system security status across the organization periodically. Maintain internal and external regulatory requirements. Maintain physical security requirements. Ensure cybersecurity controls and defense measures are effectively implemented. Responsibilities

Security Defense and Engineering

Develop and implement a comprehensive cybersecurity systems and structure aligned with organizational goals, group architecture and SAMA requirements. Analyze security requirements and develop data and system protection strategies. Review the implementation of security controls (firewalls, encryption, identity management, endpoint security, mail security, etc.) to meet required effectiveness. Evaluate new technologies for security risks and benefits and make recommendations. Analyze security risks, impacts, and mitigation options to support risk management and business decisions. Provide effective security solutions for bank systems. Maintain confidential and sensitive information register. Develop and manage security programs such as identity and access management, encryption, anomaly detection, and cyber incident response. Research and evaluate emerging security technologies. Provide guidance to other IT personnel on security best practices. Identify security threats and vulnerabilities in existing IT systems and recommend appropriate mitigation strategies. Threat Management and Incident Response

Support information system security initiatives based on security assessments. Support mitigation plans for technology vulnerabilities and build a layered security approach (Network, OS, Application, Database). Proactively hunt for indicators of compromise, anomalous behavior, and potential threats. Identify, analyze, and mitigate cyber threats; conduct proactive threat research. Analyze detected threats using threat intelligence, malware analysis, and other techniques. Research new and emerging threats through open-source intelligence, dark web monitoring, and security communities. Develop and implement intelligence-driven detection and prevention controls. Continuously refine threat detection systems and processes. Conduct penetration testing to identify vulnerabilities and weaknesses. Assess security control effectiveness and recommend improvements. Conduct forensic investigations of cybersecurity incidents (data breaches, malware, phishing). Respond to incidents by isolating impacted systems, reimaging, disabling credentials, and removing malware. Develop and execute incident response plans, processes, and workflows. Support the Security Incident Response Team. Maintain chain of custody and adhere to forensics best practices. Security Operations and Monitoring

Supervise information systems security projects and services. Monitor system performance and ensure security policy compliance. Monitor security systems for threats, policy violations, and anomalies. Investigate and respond to security alerts and incidents. Coordinate with the Security Operations Center (SOC). Track patch management effectiveness. Measure cybersecurity KPIs. Monitor and analyze endpoint activity for threats, malware, and data breaches. Cybersecurity Governance

Develop and implement an information security governance framework to manage cybersecurity risks for the organization. This includes policies, standards, and procedures. Ensure compliance with relevant information security laws, industry standards, and best practices. Monitor system performance and ensure compliance with security policies. Manage the organization's security policies and assist in enforcing security protocols. Cybersecurity Compliance

Develop and implement a cybersecurity compliance program that ensures compliance with relevant laws, regulations, and industry standards including SAMA CSF, PCI DSS, ISO 27001, CMA CSF and other compliance mandates from SAMA. Lead the system-wide information security compliance program, ensuring IT activities, the banks projects processes, and procedures meet defined requirements, policies, and regulations. Develop and implement effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation. Execute strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal / external auditors. Cybersecurity Risk Management

Identify risks on data protection. Cybersecurity Matrix, Risk Register, Appetite & Reporting. Participate in understanding the enterprise objectives and translate them in defining annual Information Security strategy, roadmap and objectives recommendations. Establishing and maintaining Information Security KPI and metrics, risk register and risk appetite. Maintaining overall security remediation plans and managing Information Security exceptions. Participate in the control effectiveness review of processes. Responsible for identifying compliance risks and to recommends, implements, and maintains technical and procedural controls to provide regulatory compliance in the most reasonable and cost-effective manner. Continuous Improvement

Research and evaluate emerging security technologies. Stay updated on latest threats via information security forums / bulletins. Develop and maintain cybersecurity policies and procedures. Identify vulnerabilities in existing systems and recommend mitigation strategies. Perform security assessments and audits to identify gaps and improvement opportunities. Develop recommendations to strengthen defenses, mitigate risks, and ensure compliance. Automate security tasks and workflows. Maintain documentation of security configurations, policies, and processes. Test and evaluate new endpoint security technologies. Maintain SARIE system security. Competencies

Knowledge and Understanding : Cybersecurity principles and best practices (threat modeling, risk assessment, security controls, frameworks like SAMA CSF NIST, ISO, CIS). Regulatory compliance requirements (PDPL,GDPR, , PCI-DSS). Emerging technologies (blockchain, AI, machine learning) and their security implications. (preferable) Network protocols, operating systems, and databases. Security incident response processes and procedures. Communication and Interpersonal Skills : Working effectively with cross-functional teams, stakeholders, and clients. Qualification & Experience

Bachelor degree in information technology or equivalent. 8 – 10 years total system security banking experience ISO27000 & PCI-DSS understanding. One or more of the following qualifications

are desirable : Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), ISO27001 Lead implementer / auditor Certified Ethical Hacker (CEH) GIAC Certified Forensic Examiner (GCFE) GIAC Certified Incident Handler (GCIH) Offensive Security Certified Professional (OSCP) Skills

Technical Skills : Knowledge of secure systems, networks, and applications (firewalls, IDS / IPS, access control, encryption, authentication). Using security technologies and tools (vulnerability scanners, penetration testing tools, SIEM, endpoint). Designing and implementing secure cloud architectures ( Oracle, AWS, Azure,). Implementing security controls for DevOps processes (CI / CD, containerization, automation). Developing and implementing security policies, procedures, and standards. Conducting security audits and assessments. Knowledge of security assessments and penetration testing of network, systems and databases. Developing and testing incident response plans. Providing security training and awareness programs. Analytical / Problem-Solving Skills : Identifying and mitigating security risks and vulnerabilities. Project Management Skills : Managing multiple projects and priorities simultaneously.

#J-18808-Ljbffr

Create a job alert for this search

Security Manager • Jeddah, Saudi Arabia

Related jobs
  • Promoted
  • New!
Risk Manager II, Regulatory Intelligence, Safety & Compliance

Risk Manager II, Regulatory Intelligence, Safety & Compliance

AmazonJeddah, Makkah Region, Saudi Arabia
Come build the future with us! At Amazon we expect no more and no less from you.Our aim is to become the most customer-centric company in the world by ensuring customers can find what they need onl...Show moreLast updated: 7 hours ago
  • Promoted
Senior Solution Architect - Physical Security Systems

Senior Solution Architect - Physical Security Systems

ThalesJeddah, Makkah Region, Saudi Arabia
Senior Solution Architect - Physical Security Systems.Senior Solution Architect - Physical Security Systems.Senior Solution Architect - Physical Security Systems. Senior Solution Architect - Physica...Show moreLast updated: 30+ days ago
  • Promoted
Data Manager – Expert in Data Governance, Cyber Security & Digital Transformation

Data Manager – Expert in Data Governance, Cyber Security & Digital Transformation

Big Fish ConsultJeddah, Saudi Arabia
Overview Data Manager – Expert in Data Governance, Cyber Security & Digital Transformation.Will lead the development, implementation, and optimization of data governance, cyber security, and ICT in...Show moreLast updated: 7 days ago
  • Promoted
Engineering Manager - Ubuntu Security

Engineering Manager - Ubuntu Security

CanonicalJeddah, Makkah Region, Saudi Arabia
Engineering Manager - Ubuntu Security.Be among the first 25 applicants.Engineering Manager - Ubuntu Security.Get AI-powered advice on this job and more exclusive features.As the most widely used Li...Show moreLast updated: 30+ days ago
  • Promoted
Cyber Security Engineer Jobs in Saudi Arabia (Oct 2025) - Bayt.com

Cyber Security Engineer Jobs in Saudi Arabia (Oct 2025) - Bayt.com

CAREJeddah, Saudi Arabia
Cyber Security Engineer Jobs in Saudi Arabia.Relevance Create a job alert for similar positions Summary : An IT Security Specialist position is open in Jeddah, Saudi Arabia, focusing on protecting i...Show moreLast updated: 27 days ago
  • Promoted
Senior Manager - Information Security

Senior Manager - Information Security

Michael PageJeddah, Saudi Arabia
Be a part of a well-established financial services organisation in Jeddah.Handle all matters related to information security architecture and engineering. The Senior Manager - Information Security w...Show moreLast updated: 30+ days ago
  • Promoted
Cybersecurity Engineer II

Cybersecurity Engineer II

Scientific Research CorporationJeddah, Makkah Region, Saudi Arabia
Supporting various Cybersecurity efforts related to Command, Control, Communications, Computers and Intelligence (C4I) systems for naval vessels and shore sites in the Kingdom of Saudi Arabia.FILLI...Show moreLast updated: 30+ days ago
  • Promoted
Staff Security Operations Engineer

Staff Security Operations Engineer

CanonicalJeddah, Saudi Arabia
Staff Security Operations Engineer.Canonical We have opened several senior / staff Security Operations Engineer (SOC) positions, creating a new team reporting to the CISO. We are looking for a range o...Show moreLast updated: 30+ days ago
  • Promoted
  • New!
Data Center Security Specialist, HYD DC Security

Data Center Security Specialist, HYD DC Security

AmazonJeddah, Makkah Region, Saudi Arabia
Data Center Security Specialist, HYD DC Security.AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. In other words, we’re the people who...Show moreLast updated: 1 hour ago
  • Promoted
Senior Manager - Information Security | Jeddah, SA

Senior Manager - Information Security | Jeddah, SA

Michael PageJeddah, Saudi Arabia
Be a part of a well-established financial services organisation in Jeddah Handle all matters related to information security architecture and engineering Be a part of a well-established financial s...Show moreLast updated: 30+ days ago
  • Promoted
Senior Security Operations Engineer

Senior Security Operations Engineer

CanonicalJeddah, Saudi Arabia
Senior Security Operations Engineer.Canonical Join to apply for the.Senior Security Operations Engineer.Canonical Get AI-powered advice on this job and more exclusive features.We have opened severa...Show moreLast updated: 30+ days ago
  • Promoted
Head of Security Operations

Head of Security Operations

CanonicalJeddah, Makkah Region, Saudi Arabia
Continue with Google Continue with Google.Get AI-powered advice on this job and more exclusive features.Continue with Google Continue with Google. Continue with Google Continue with Google.Continue ...Show moreLast updated: 30+ days ago
  • Promoted
Engineering Manager - Security Standards and Hardening

Engineering Manager - Security Standards and Hardening

CanonicalJeddah, Saudi Arabia
Engineering Manager - Security Standards and Hardening.Engineering Manager - Security Standards and Hardening.Canonical Engineering Manager - Security Standards and Hardening.Be among the first 25 ...Show moreLast updated: 30+ days ago
  • Promoted
Senior Information Security GRC Specialist

Senior Information Security GRC Specialist

NTT LimitedJeddah, Makkah Region, Saudi Arabia
Senior Information Security GRC Specialist page is loaded.Senior Information Security GRC Specialist.Apply remote type On-site Working locations SAU, Jeddah time type Full time posted on Posted 2 D...Show moreLast updated: 30+ days ago
  • Promoted
Security Analyst - L3

Security Analyst - L3

EventussecurityJeddah, Saudi Arabia
By contacting us you agree with the storage and handling of your data by this website.Key Responsibility Areas – Security Analyst - L3 – SOC. Lead high-priority security investigations and incident ...Show moreLast updated: 6 days ago
  • Promoted
Manager - IT Security

Manager - IT Security

BUPA ArabiaJeddah, Saudi Arabia
To implement and continuously enhance endpoint and cloud security controls across hybrid environments ensuring protection of devices, data, and digital assets through proactive defense, compliance ...Show moreLast updated: 3 days ago
  • Promoted
Infrastructure Manager

Infrastructure Manager

MDLBEASTJeddah, Saudi Arabia
Role Overview We are seeking an Infrastructure Manager to lead MDLBEAST’s cloud, DevOps, and enterprise systems strategy. This role requires someone with deep expertise in Microsoft 365, Azure, DevO...Show moreLast updated: 30+ days ago
  • Promoted
Cybersecurity Assistant Manager / Manager

Cybersecurity Assistant Manager / Manager

TechBiz Global GmbHJeddah, Saudi Arabia
At TechBiz Global, we are providing recruitment service to our TOP clients from our portfolio.We are currently seeking a Cybersecurity Assistant Manager / Manager to join one of our clients' teams....Show moreLast updated: 30+ days ago