Associate Director - Cybersecurity Risk and Compliance

🗓️ Posted 2026-08-18 Riyadh, Eastern Province, Riyadh, Riyadh Province, Saudi Arabia, Saudi Arabia Full-time Hybrid ICT

Company shared salary

NA

Market rate

SAR 35,000–SAR 65,000/mo (SAR 420,000–SAR 780,000/yr)

Based on similar roles (title + domain + location).

Responsibilities

  • Roles and Responsibilities:
  • Conduct periodic and ad hoc cybersecurity risk assessments across IT and OT environments
  • Perform OT-specific risk assessments on assets such as PLCs, HMIs, RTUs, and engineering systems
  • Identify and document OT-relevant risk scenarios (e.g., control system disruption, unauthorized access, safety manipulation)
  • Coordinate risk reviews as part of major IT/OT changes, such as system upgrades or new deployments
  • Reassess risk posture following major changes, incidents, or regulatory updates
  • Review and validate existing controls to calculate residual risk and prioritize treatment actions
  • Provide standardized tools and guidance to support self-assessments by IT, OT, and business teams
  • Support integration of assessment outcomes into control design, zoning, segmentation, and system deployment
  • Track risk treatment progress and escalate overdue or high-priority items as needed
  • Coordinate with performance management to define and monitor key risk indicators (KRIs) to proactively track changes in cybersecurity risk exposure
  • Maintain the cybersecurity risk register, including OT-specific entries, capturing identified risks, likelihood and impact ratings, treatment plans, ownership, and status
  • Coordinate and execute internal cybersecurity compliance assessments across all relevant domains and functions
  • Serve as the lead interface for external audits and regulatory inspections, including preparation, execution, and response
  • Conduct periodic compliance assessments of OT environments, including SCADA, DCS, PLCs, and associated network infrastructure
  • Maintain an inventory of compliance-relevant OT assets and map them to applicable control requirements and standards
  • Monitor adherence to cybersecurity policies, escalate non-compliance, and coordinate corrective actions with relevant teams
  • Track and manage remediation plans for compliance gaps, non-conformities, and audit findings through closure
  • Validate the effectiveness of implemented controls or mitigation plans before closing compliance gaps
  • Review and validate configuration baselines for OT systems (e.g., firewall rules, firmware versions) to ensure alignment with compliance standards