Cyber Security Specialist
Summary
A senior cyber security specialist (5+ years) who monitors security systems, runs vulnerability assessments and penetration tests, responds to incidents, manages IAM and security tooling (SIEM, EDR, firewalls), and ensures compliance with frameworks like ISO 27001, NIST, and KSA regulations. Based in Egypt, working remotely to support the organization's operations in Saudi Arabia.
- Monitor security systems, networks, and applications for suspicious activity and potential threats
- Conduct vulnerability assessments and penetration testing on systems, networks, and applications
- Investigate, respond to, and remediate security incidents and breaches
- Implement and manage security tools such as firewalls, IDS/IPS, SIEM, EDR, and antivirus solutions
- Perform regular security audits and risk assessments across infrastructure and applications
- Develop, update, and enforce security policies, standards, and procedures
- Manage identity and access management (IAM), including user provisioning, role-based access, and
privileged access management
- Conduct security awareness training and phishing simulation campaigns for employees
- Collaborate with IT and development teams to embed security into system design and SDLC (DevSecOps)
- Perform log analysis and threat hunting to detect anomalies proactively
- Manage patch management and vulnerability remediation processes
- Ensure compliance with regulatory and industry standards (ISO 27001, NIST, GDPR, PCI-DSS, etc.)
- Prepare incident reports, security assessments, and documentation for audits
- Stay current with emerging threats, vulnerabilities, and security technologies
- Support KSA regulatory compliance efforts (NCA ECC, PDPL, SAMA CSF where applicable), including
audits and coordination with the KSA sister entity's compliance team
Requirements
- Bachelor's degree in Computer Science, Information Security, or related field
- 5+ years of hands-on experience in cyber security, information security, or a related role
- Strong knowledge of network security concepts (firewalls, VPNs, IDS/IPS, network segmentation)
- Experience with SIEM tools (Splunk, QRadar, ArcSight, or similar) for monitoring and analysis
- Hands-on experience with vulnerability assessment and penetration testing tools (Nessus, Qualys, Burp
Suite, Metasploit)
- Solid understanding of endpoint security, EDR/XDR solutions, and antivirus management
- Experience with identity and access management (IAM), MFA, and privileged access management (PAM)
- Knowledge of security frameworks and standards (ISO 27001, NIST CSF, CIS Controls)
- Understanding of cloud security principles (AWS/Azure/GCP security controls)
- Familiarity with incident response processes and digital forensics fundamentals
- Knowledge of encryption, PKI, and secure communication protocols
- Scripting skills (Python, PowerShell, or Bash) for automation and analysis
- Strong understanding of OWASP Top 10 and secure coding principles
- Knowledge of KSA regulatory requirements, including NCA Essential Cybersecurity Controls (ECC),
SDAIA's Personal Data Protection Law (PDPL), and SAMA Cyber Security Framework where applicable to
financial operations