Sr. Specialist, IT Security
ArcelorMittal Tubular Products Al-Jubail
ROLE SUMMARY:
The Senior Specialist, IT Security implements, administers, and maintains the organisation's enterprise
security technologies to protect the confidentiality, integrity, and availability of information systems and data.
The role provides advanced technical expertise across security operations, threat monitoring, incident
response, vulnerability management, access governance, and compliance. The incumbent enforces corporate
security standards aligned with international frameworks (ISO/IEC 27001, NIST) and Saudi national
regulations (NCA ECC and OTCC), working closely with Infrastructure, Network, Cloud, Application,
Service Desk, Cybersecurity, and Audit teams to strengthen the organisation's cyber resilience.
ROLES & RESPONSIBILITIES:
• Develop and maintain IT security reference architectures aligned with ISO/IEC 27001, NIST SP 800-53,
COBIT 2019, and applicable Saudi regulations (NCA ECC and OTCC).
• Implement, administer, and maintain enterprise security technologies including endpoint protection
(EDR), next-generation firewalls, IDS/IPS, anti-malware, email and web security gateways, DLP,
vulnerability scanners, and SIEM solutions.
• Continuously monitor security alerts, logs, and events; perform triage, investigation, escalation, and
remediation of threats and incidents.
• Lead and support security incident response and forensic investigations, including containment,
eradication, recovery, and root-cause analysis.
• Conduct risk assessments, vulnerability scans, and configuration reviews across systems, endpoints,
networks, and cloud workloads; track findings through to closure.
• Experience IT Infrastructure, Network, Applications, Cloud and Service Desk teams to embed security by
design principles into project systems and patch management processes.
• Apply security baselines, configuration hardening, and patch-management policies across servers,
endpoints, and cloud environments (e.g., CIS Benchmarks).
• Administer identity and access governance, including access provisioning, privileged access management
(PAM), and periodic user access reviews.
• Ensure secure deployment and configuration of firewalls, network security layers, proxies, and security
appliances.
• Develop, enforce, and maintain security policies, standards, and procedures aligned with enterprise
governance.
• Support internal and external audits (e.g., ISO 27001, SOC 2, NCA compliance) through evidence
collection, access reviews, and remediation tracking with Audit and Compliance teams.
• Maintain and periodically test disaster recovery and business continuity plans for security systems.
• Advise IT leadership on risk-mitigation strategies, emerging threats, and control improvements.
• Experience in IT Infrastructure, Network, Applications, Cloud, and Service Desk teams to embed
security-by-design principles into projects, systems, and change management processes.
• Participate in cross-functional projects to embed security-by-design into business systems and processes.
• Maintain accurate documentation, runbooks, and knowledge-base articles, and drive continuous
improvement of security operations.
QUALIFICATION & EDUCATION:
• Bachelor’s degree in computer science, Information Technology, Cybersecurity, Information Security, or
a related field.
EXPERIENCE:
• Minimum 6 years of progressive experience in IT security / cybersecurity, including hands-on experience
in security operations, SIEM monitoring, incident response, vulnerability management, and
administration of enterprise security technologies. Experience in an industrial or manufacturing (OT/IT)
environment and with regulatory compliance (ISO 27001, NCA ECC/OTCC) is preferred.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Sr Planner IV, TAM planning Job
Medical Sales Representative Saudi Arabia
Aviation Electrician (AE) MH-60R