Chief Information Security Officer
4 days ago
JOB PURPOSE:
Drive the Information Technology (IT) and Operational Technology (OT) cybersecurity strategy development and implementation to protect the business from security threats and cyber-attacks. Oversee the Governance, Risk, and Compliance (GRC) with the Security Operations Center (SOC) to lead a program of continues improvements in response to changing security risks and threats to ensure that the organization's intellectual, IT/OT assets and information are safeguarded against internal and external threats. Ensure SASREF is holding a robust cybersecurity program and is complying with regulatory cybersecurity requirements.
KEY ACCOUNTABILITIES:
- Assist in the development and drive for the achievement of the IT/OT Information Security mission and vision.
- Define, develop, and maintain an information Security Strategy that is aligned with SASREF objectives that covers all cybersecurity related assets and risks.
- Establish and maintain information security policies, procedures, and guidelines for implementing and safeguarding the company's infrastructure while in alignment with the relevant legislation and industry standards.
- Implement and oversee the cybersecurity risk management program and risk registers for operational and strategic cybersecurity risks.
- Align the cybersecurity risk management program with the enterprise risk management program
- Develop a regulatory compliance framework and register to be assessed and monitored.
- Ensure compliance with the changing laws and applicable regulations.
- Drive to achieve the yearly cybersecurity maturity KPIs targets for IT/OT by conducting gap assessments and regular monitoring.
- Brief senior management on the cybersecurity strategy, risks and compliance status for SASREF
- Manage the cybersecurity committee meetings as the cybersecurity committee secretary.
- Define and implement the Third-party cybersecurity risk management program through integration with the contracting cycles for evaluation.
- Oversee and drive the continues cybersecurity evaluations such as penetration tests, vulnerability scans, red team exercises, and compromise assessments. While monitoring the gaps and remediation actions until closure.
- Report cybersecurity incidents to the management and regulating entities while providing regular communication reports.
- Oversee cybersecurity incidents and high-level security alerts until closure; ensure and recommend mitigating actions for avoiding recurrence.
- Act as the focal point of communication with National Cybersecurity Authority (NCA).
- Maintain the Information Security Management Systems (ISMS) to sustain the ISO27001 certification.
- Initiate, facilitate, and promote cybersecurity awareness program and ensure proper implementation of all its aspects including training, phishing, and consequence management.
- Ensure that incident response plans are in place, up-to-date and tested
- Oversee infrastructure, network, system and application-related technical and architectural changes and design decision to enhance the underlying infrastructure security and alignment with the Enterprise Architecture (EA).
- Oversee logical access management to SASREF assets through the Identity and Access management policy definition and compliance checks.
- Conduct periodic internal security assurance reviews/audits on the SASREF's assets to monitor security compliance with information security policies and procedures, before the scheduled internal/shareholder/NCA/external audits.
- Manage and prepare for the external Information Security audits while monitoring and driving for the closure of all identified gaps.
- Utilize and manage the baseline compliance tools (Tripwire) in both IT and OT
- Define, monitor and aim to achieve the cybersecurity Key Performance Indicators (KPIs) while communicating the KPIs with the cybersecurity committee and SASREF management
- Ensure the business processes and work activities, relevant to position, are executed in compliance with SASREF policy, procedures and best practice to achieve the business objectives in a safe, efficient and cost effective manner.
- Plan and manage the department budget for the cybersecurity activities.
- Lead, motivate, develop and assess the assigned team to achieve business objectives and grow capability.
SAFTEY:
Workplace (WPS) and Process (PSM) Safety:
- Ensure that measures to protect personal safety and well-being are always in place and that personal actions do not jeopardize the safety and well-being of others.
- Adhere strictly to all IOWs, Safe Operating Procedures, and Safe Work Instructions - thus preventing potential WPS and PSM incidents at all times.
- Always comply with the SASREF HSE Policy, the 5 Safety Principles and 8 Life Saving Rules
.
Performance Indicators:
- No personal injury or injury to a third party.
- No WPS or PSM incident caused.
Cybersecurity:
- Maintain SASREF's cybersecurity by implementing security best practices.
- Adhere strictly to all cybersecurity requirements while dealing with SASREF's assets and data
- Comply always with SASREF's information security policies.
- Performance Indicators:
Reporting all suspicious emails including the phishing tests. - 0 Failure to the phishing campaign tests.
- 100% Completion of the assigned cybersecurity awareness courses.
- 0 Cybersecurity violation or negative behavior.
QUALIFICATIONS & EXPERIENCE:
Qualification
- Bachelor's Degree in Computer Science, Cybersecurity or any other related field
- [Preferred] Master's Degree
- CISSP and CISM certifications are required.
Experience
- Minimum of
10
years of experience in Cybersecurity/IT with
2
in management role. - Prior Operational Technology (OT) experience is required.
Compensation & Benefits:
SASREF values its people as they are its greatest asset. We shaped our compensation and benefits to provide wide variety of excellent and competitive packages to our diverse employees. We aim to Attract, Maintain, Engage & Retain our employees.
Compensation & Benefits
Post Dates:
Starting Date: 17-Nov-2025
End Date: 16-Dec-2025
-
Chief Officer
2 days ago
Jubail, Eastern Province, Saudi Arabia Telford Offshore Full timeTelford Offshore is looking forChief Officer / SDPO for DP3 Accommodation / Construction bargein KSA.Rotation:6 weeks on / 6 weeks off (1st trip will be 8 weeks including 2 weeks familiarization as per ARAMCO requirements)Joining date:Beg of DecemberRequirements:minimum 2 years' experience in rank on DP Accommodation / construction vessels;experience with...
-
Information Technology Engineer
2 days ago
Jubail, Eastern Province, Saudi Arabia Saken Village Full timeAbout Saken CompanySaken is a leading residential compounds management and operations company based in Jubail, Saudi Arabia, dedicated to providing premium living experiences through exceptional hospitality, facility management, and technology-driven operations.Position: IT EngineerLocation: Jubail, Saudi ArabiaType: Full-TimeAbout the RoleWe are...
-
Information Technology Technician
2 days ago
Jubail, Eastern Province, Saudi Arabia Saken Village Full timeAbout Saken CompanySaken is a leading residential compounds management and operations company based in Jubail, Saudi Arabia, providing premium living environments supported by hospitality, facility management, and smart technology solutions. Our focus is on ensuring comfort, safety, and efficiency for every resident through innovation and reliable...
-
Senior Staff Chief Scientist
1 week ago
Jubail, Eastern Province, Saudi Arabia JTCCS Careers Full time 120,000 - 180,000 per yearJob title: Senior Staff Chief Scientist - Methane Blue AmmoniaIndustry: Global PetrochemicalLocation: Jubail, Saudi ArabiaResponsibilities:Assess unit operation and instruct corrective action to resolve process problems.Develop monthly performance reports for related units in Jubail and Yanbu using tools such as APAC, Ex-aquantum, DCS trends, PRO II,...
-
Information Technology Specialist
2 days ago
Jubail, Eastern Province, Saudi Arabia Al Yamama Advanced Industrial Services Full timeRequirements:• Minimum of 5 years total experience in IT.• Strong skills in hardware and software handling.• Proven experience in cyber security.• Ability to troubleshoot and provide effective IT solutions.
-
Sr Auditor I, Internal Audit Job
2 days ago
Jubail, Eastern Province, Saudi Arabia TASNEE Full timeAn exciting opportunity is available forSr Auditor I, Internal AuditReports to,Chief Internal Audit Officer located inJubail.Job purpose:Conducts assurance and advisory audit assignments with diligence, delivering independent and objective evaluations of governance, risk management, and internal control processes to support business effectivenessRole...
-
GL Specialist
1 week ago
Jubail, Eastern Province, Saudi Arabia ArcelorMittal Full time 40,000 - 80,000 per yearJob Description Daily management of accounting operations (but not limited to):o Maintaining general ledgers and ensuring accurate financial records.o Assist in the month-end and year-end closing processes, ensuring timely and accurate financial reporting. Weekly bank reconciliation preparation for review with Chief Accountant:o Coordinate with...
-
Government Relations officer
4 days ago
Jubail, Eastern Province, Saudi Arabia JAL International Co. Ltd. Full time 120,000 - 180,000 per yearJob Description: Government Relations OfficerPosition Title:Government Relations OfficerEmployment Type:Full-TimeJob PurposeThe Government Relations Officer is responsible for managing and maintaining effective relationships with government entities while ensuring full compliance with all relevant legal and regulatory requirements. This role plays a vital...
-
IT Engineer
1 week ago
Jubail, Eastern Province, Saudi Arabia Tamimi Pre Engineered Buildings Co. Full time 60,000 - 120,000 per yearJob Title:IT EngineerLocation:JubailNationality:Saudi National OnlyExperience Required:3–4 YearsEmployment Type:Full-TimeJob Summary:We are seeking a qualified and proactiveIT Engineerto manage and support the company's IT infrastructure, systems, and networks. The ideal candidate will ensure smooth operation of hardware, software, and communication...
-
OCM Lab Samples Login administrator
4 days ago
Jubail, Eastern Province, Saudi Arabia SGS Full time 40,000 - 80,000 per yearCompany Description We are SGS – the world's leading testing, inspection and certification company. We are recognized as the global benchmark for sustainability, quality and integrity. Our 98,000 employees operate a network of 2,650 offices and laboratories, working together to enable a better, safer and more interconnected world.We are seeking an...