Cybersecurity Specialist
Listed on 2026-06-17
-
IT/Tech
Cybersecurity, Information Security, Network Security
Cybersecurity Specialist - Riyadh, Saudi Arabia
About Saudi Gold RefinerySaudi Gold Refinery (SGR) is a Saudi mining and precious‑metals company specialized in the refining of gold and precious metals, bullion production, and value‑added precious‑metal services. Operating within the Kingdom's mining value chain, SGR is aligned to the Vision 2030 mining pillar and to the regulatory framework set by the Ministry of Industry and Mineral Resources (MIM) and applicable Saudi and international standards.
We produce responsibly sourced, traceable, and certified bullion, operate to LBMA Good Delivery and ISO‑aligned quality standards, and invest in the people, processes, and controls behind every bar we produce.
Saudi Gold Refinery (SGR) is seeking a Cybersecurity Specialist in Riyadh, Saudi Arabia to protect our digital infrastructure and sensitive geological data. This role secures the IT and operational technology systems supporting our exploration projects and refining operations. The specialist ensures compliance with National Cybersecurity Authority regulations and safeguards critical business information from cyber threats.
The Cybersecurity Specialist will report directly to the IT Manager and will play a key role in implementing security controls and monitoring threats. This position drives the technical execution of our cybersecurity strategy to support SGR's growth and operational continuity.
Key ResponsibilitiesThe Cybersecurity Specialist will perform the following duties to ensure the security and resilience of SGR's information systems.
Security MonitoringThe role monitors security information and event management (SIEM) logs to detect and respond to potential threats in real time.
This position investigates security alerts and performs root cause analysis to prevent recurrence of incidents and minimize business impact.
Vulnerability ManagementThe specialist executes monthly vulnerability scans on all network assets and prioritizes remediation efforts based on risk severity.
Access ControlThe role administers user accounts and access rights in Active Directory to enforce least‑privilege principles for all employees.
Regulatory ComplianceThis position ensures IT security practices align with National Cybersecurity Authority Essential Cybersecurity Controls and internal policies.
Security TrainingThe specialist delivers quarterly cybersecurity awareness sessions to employees covering phishing, password hygiene, and data protection.
The role conduct periodic risk assessments to identify gaps in security controls for IT and operational technology environments.
This position reviews third‑party vendor security postures to ensure supply chain risks are managed effectively and documented.
Qualifications- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Minimum of three years of experience in cybersecurity operations, incident response, or vulnerability management.
- Proven knowledge of network security protocols, firewalls, intrusion detection systems, and endpoint protection.
- Experience with security information and event management (SIEM) tools and log analysis.
- Familiarity with National Cybersecurity Authority (NCA) regulations and Saudi data protection laws.
- Strong understanding of identity and access management principles and Active Directory administration.
- Ability to communicate technical security concepts to non-technical stakeholders clearly and effectively.
- Valid Saudi driving license and willingness to travel to exploration sites within the Kingdom as required.
- Experience securing operational technology (OT) or industrial control systems in mining or industrial environments.
- Knowledge of cloud security principles for Azure or AWS environments.
- Previous experience in the mining, refining, or natural resources sector.
- Proficiency in Arabic language for local regulatory correspondence and staff training.
- Certifications such as CompTIA Security+, CISSP, or CEH.
- Achieves full compliance with NCA Essential Cybersecurity Controls for all corporate IT systems within 12 months.
- Reduces mean time to detect (MTTD) and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).