Cybersecurity Specialist

Yanbu Aramco Sinopec Refining Company (YASREF) Ltd.


Date: 4 hours ago
City: Remote
Contract type: Full time
Remote
Job description:

JOB SCOPE

Define communicate and control a strong and robust information security and cybersecurity governance program. Guide and implement cybersecurity practice and governance in the organization. Defending computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks. Establish and implement frameworks and related processes for continual adherence to YASREF's internal and external mandates. Responsible for implementing and auditing the controls needed to protect both company’s information as well as third party information from data breaches and cyber-attacks.

COMMUNICATION

  • Internal : Report and refer on a regular basis with hierarchy. Implement pertinent policies, exchange information, discuss and know relevant KPIs/performance parameters. Provide service to other organizations.
  • External: NA

KEY DUTIES AND RESPONSIBILITIES (2/2)
  • Develop and update guidelines & procedures for Information Security Division to meet the Standard guidelines and compliance requirements.
  • Ensure to follow Risk Assessment process as per ISO 31000 in line with its Corporate Enterprise Risk Management methodology.
  • Conduct internal technical and process risk assessments as part of Self-Assessment activities at regular intervals.
  • Review and measure the performance and effectiveness of the implemented OT & IT controls, mitigating IT Risks / gaps identified on an ongoing basis and build the ability, to prevent security incidents or responding quickly to any crisis situation and recover within agreed timeframe.
  • Research and recommend appropriate technology controls to prevent, detect, respond to security compromise.
  • Review Information Security postures by scheduling internal security audits periodically. Perform random security audits at vendor facilities. Facilitate and maintain audit evidence and closure of audit findings for all Internal Audits that include; Internal Controls Framework, Enterprise Risk Management – ERM, ISO 27001, ISA 99 / IEC 62443 and Corporate Governance Audits.
  • Facilitate and maintain audit evidence and closure of audit findings for all Internal Audits that include; Internal Controls Framework, Enterprise Risk Management – ERM, ISO 27001, ISA 99 / IEC 62443 and Corporate Governance Audits.
  • Adopt and Align the existing IT and OT Controls to meet the National Institute of Standards and Technology Cyber Security Framework (NIST–CSF), 800-82, 800-53 requirements to measure and enhance the i) Joint venture maturity assessment posture ii) Saudi Arabian Monetary Agency (SAMA) iii) National Cyber Security Authority – NCA iv) High Commission for Industrial Security (HCIS), and few other industry renowned best practices covered under ISO 27001 and SANS Top 20 Critical controls.
  • Develop and implement a data classification and privacy framework and assist the business departments with appropriate categorization of the data to ensure adequate technical controls are applied to prevent any potential leakage of confidential information

  • Establish a single IT and OT governance body, along with an advisory board including staff from the IT and the OT domains, to provide an overall oversight to develop a common IT guidelines and procedures for achieving integrated IT/OT security, through IT/OT Convergence

  • Maintain and continually improve IT Governance functions.
  • Review and analyze the existing process including but not limited to; Organizational Information Security, Access Controls, Change Management, Human Resource Security, Incident Management, Asset Management, Operational and Communicational Security, System development and maintenance process, Physical Security, IT Continuity and Compliance controls.
  • Impart Information security awareness trainings and Phishing Simulation exercise at regular intervals to measure the awareness levels of all YASREF users.
  • Design and develop appropriate training programs to enhance their security awareness levels, through all possible media /channels that include, email campaigns, online training modules and cyber security strength assessment programs, class room training programs, digital posters, screen savers etc.
  • Study and Document the resources required including personnel in a disaster scenario and Identify the recovery priorities and categorize each process.
  • Validate and analyze risks of disruptions of the organizations, prioritize activities and evaluate disruptions related risks and mitigate the problem in line with business continuity objectives.
  • Prepare, validate and deliver an extensive OT and IT continuity requirement sheet with Key Risk Areas (KRA), Key Performance Indicators (KPI) with the metrics for measurement and improvement
  • Provide the required support for the Industrial Control Systems, Electrical Automation Systems, Cyber security systems, network, and its operation.
  • Participate in Cybersecurity researches and keep abreast of latest security issues. Actively participate in the higher education Cybersecurity community.
  • Perform other job-related duties as assigned by the direct Supervisor.

EDUCATION & CERTIFICATION REQUIREMENTS

  • Bachelor’s Degree in Computer Science, IT, Computer Engineering or equivalent.
  • Cybersecurity certification
YEARS OF RELEVANT WORK EXPERIENCE

15

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

Airport Manager (East/South East Asia)

Riyadh Air | طيران الرياض, Remote
3 hours ago
Riyadh Air (RX), headquartered in the Saudi Capital, is the new national airline that’s shaping the future of flying. It seeks to lead the aviation industry by transforming Saudi Arabia into a global aviation and trade hub – a digitally native airline that will connect the kingdom to more than 100 destinations.About The RoleDo you love the energy of an...

Cybersecurity Analyst

Yanbu Aramco Sinopec Refining Company (YASREF) Ltd., Remote
4 hours ago
Job description: JOB SCOPE Determine who requires access to which information. Plan, coordinate and implement information security programs. Responsible for Cybersecurity practice and governance in the organization. Defend computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks. Establish and implement frameworks and related processes for continual adherence to YASREF's internal and external security mandates. Responsible for implementing...

Manager Inventory

Riyadh Air | طيران الرياض, Remote
5 days ago
Riyadh Air (RX), headquartered in the Saudi Capital, is the new national airline that’s shaping the future of flying. It seeks to lead the aviation industry by transforming Saudi Arabia into a global aviation and trade hub – a digitally native airline that will connect the kingdom to more than 100 destinations.About The RoleAre you passionate about optimising airline performance...