Risk Assessment Specialist

at Saudi Recruit
Published April 23, 2025
Expires May 30, 2025
Location Riyadh, Saudi Arabia
Category Computer & IT  
Job Type Full Time  
Salary Unit Hour

Description

We are seeking a detail-oriented and analytical Cybersecurity Risk Assessment Specialist to identify, assess, and mitigate information security risks across our IT environment.

The ideal candidate will work closely with technical and business teams to evaluate vulnerabilities, assess potential threats, and ensure alignment with industry security standards and regulatory frameworks.

Preferred Candidates: Saudi Nationals > Arabic-speaking professionals > Experienced Indian candidates.

Key Responsibilities:
Conduct end-to-end cybersecurity risk assessments across systems, networks, applications, and business units.
Identify and evaluate potential threats, vulnerabilities, and risks impacting the confidentiality, integrity, and availability of information assets.
Recommend risk mitigation strategies and controls to reduce exposure.
Support compliance efforts related to standards such as ISO 27001, NIST, CIS, PCI-DSS, GDPR, etc.
Perform third-party/vendor risk assessments and advise on remediation.
Develop and maintain risk registers and risk treatment plans.
Collaborate with system owners and technical teams to integrate security into system design (e.g., secure architecture reviews).
Prepare risk assessment reports and communicate findings to stakeholders and senior leadership.
Contribute to the development of security policies, standards, and procedures.
Stay up-to-date on emerging threats, vulnerabilities, and security trends.
Skills & Qualifications:
Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field.
3–7 years of experience in cybersecurity risk assessment, information security, or IT audit.
Strong understanding of cybersecurity frameworks and methodologies
Familiarity with tools such as risk management platforms (e.g., Archer, MetricStream, RiskLens), vulnerability scanners (e.g., Qualys, Nessus), and SIEM systems.
Experience conducting both technical and business-level risk assessments.
Strong communication skills with the ability to translate technical risks into business language.
Ability to prioritize risks and develop practical mitigation strategies.

Please send your resume/CV

Drop files here browse files ...