×
Register Here to Apply for Jobs or Post Jobs. X

Information Security Risk Assessment Manager

Job in Riyadh, Riyadh Region, Saudi Arabia
Listing for: SAB
Full Time position
Listed on 2026-09-13
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 240000 - 420000 SAR Yearly SAR 240000.00 420000.00 YEAR
Job Description & How to Apply Below

Job Title: Information Security Risk Assessment Manager

Division: Cybersecurity / Risk

Location: Riyadh

Working Hours: 8:00 AM to 5:00 PM (Sunday to Thursday)

Role:

Cybersecurity Risk Management to support in managing the enterprise-wide cybersecurity risk management program. This position is responsible for conducting threat modeling, developing and maintaining risk assessment methodologies under the risk management team, Also play a critical role in protecting the organization’s information assets by identifying, assessing cybersecurity risks.

Key Responsibilities
  • Cybersecurity Risk Assessment
    :
    Conduct detailed and risk-based Cybersecurity Risk Assessment, meeting SLA commitments during IT and cybersecurity engagements.
  • Maintains a close awareness of best practices and industry standards in Information Security assesses potential policy gaps and/or loopholes and responding risks to SAB IT infrastructure, systems, network and data and recommends any improvements in policies.
  • Liaises closely with end users, explains Cybersecurity risks and the business role in preventing Cybersecurity risks and drives initiatives to sensitize end-users on Cybersecurity risks.
  • Advise IT and business on the optimal way of dealing the identified Cybersecurity risks and mitigation.
  • Final Cybersecurity Risk Assessment:
    Execute comprehensive Cybersecurity Risk Assessment before go-live.
  • Conduct detailed Cybersecurity Threat Modeling
  • Threat Modeling & Risk Assessments:
    Conduct detailed cybersecurity risk assessments and threat modeling for IT projects and systems – at early project stages, before major changes, for new technologies, and periodically for existing assets. Identify threats, vulnerabilities, and controls for critical information assets and document these risks in a centralized risk register.
  • Cybersecurity Risk Assessment Validation:
    Review, analyze, and validate Cybersecurity Risk Assessment results to align the result with Cybersecurity issues raised by other Cybersecurity teams.
  • Raise application security related defect
  • Enhance Cybersecurity pattern during engagements, periodic assessments or Ad-Hoc assessments by highlighting new risks to domain owners
  • All engaged/assigned engagements, periodic assessments or Ad-Hoc assessments should be assessed in accordance to the Cybersecurity Risk Management Methodology, Cybersecurity Risk Pattern and Cybersecurity Change Review and Engagement Process and within the agreed timeline (SLA)
  • Cybersecurity Risk Assessment platform Tuning:
    Customize and fine-tune Cybersecurity risk assessment platform for optimal compatibility and accuracy.
  • Cybersecurity Risk Management Maturity
    :
  • Enhance the existing Risk Management process and documentation
  • Review and update the existing Cybersecurity Risk Management documentation (methodology, FIM section, standards, guidelines)
  • Ensure that both Cybersecurity Risk Management process and documentation are aligned with Group latest practices, regulatory practice/framework such as NCA , SAMA CSF …etc
  • Cybersecurity Risk Management Policy and Design
    :
    Ensure all Cybersecurity Risk Management design documents are maintained and aligned with regulators and internal policies.
  • Cybersecurity Risk Management domain Ownership:
    Develop, unify, and maintain the cybersecurity risk management methodology and procedures, aligned with enterprise risk management and regulatory requirements. Regularly review and update risk management policies, design documents, and tools to reflect changes in the threat landscape or laws. Ensure that risk treatment plans (mitigation, transfer, acceptance, avoidance) are in place and tracked through completion.
  • Periodic Cybersecurity Risk and Crown Jewels assessment:
    Ensure all required IT Services assessed as per the annual plan
  • Cyb…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary