Job Summary
We are seeking an experienced Technology Risk Vice President to strengthen and enhance Lesha Group s cybersecurity risk management and assurance capabilities across its business entities and technology environments. The role will be responsible for conducting and overseeing cybersecurity risk assessments, evaluating the effectiveness of security controls, performing cybersecurity assurance and compliance reviews, monitoring technology and cyber risk exposure, and supporting the remediation of identified vulnerabilities, control deficiencies, and emerging threats. The position will also contribute to the ongoing enhancement of the Group s cybersecurity governance, risk management, and regulatory compliance framework. The successful candidate will possess a strong blend of cybersecurity risk management, security assurance, and technical security expertise, with the ability to assess complex technology environments and engage effectively with business stakeholders, technology teams, project managers, third-party service providers, auditors, and regulatory authorities to strengthen the Group s overall cyber resilience and risk posture.
Key Responsibilities
Security Architecture & Technology Risk Conduct security reviews of enterprise infrastructure, applications, cloud environments, networks, databases, middleware, and security solutions. Review proposed technology solutions and architectures to ensure security requirements are incorporated by design. Perform threat modelling and security risk assessments for new technologies and business initiatives. Define and assess security baselines and configuration standards. Provide security recommendations for enterprise architecture and technology transformation initiatives.
Cloud, AI & Emerging Technology Security Assess and strengthen security controls across Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure environments. Conduct cloud security assessments covering identity, network security, workloads, containers, data protection, logging, and monitoring. Support security governance for container environments. Conduct security and risk assessments of AI, Generative AI, Machine Learning, and emerging technology solutions. Assess security controls and compliance requirements for AI-powered applications and third-party AI service providers. Establish appropriate security controls for cloud-native, AI-enabled, and emerging technology environments.
Application Security & DevSecOps Lead application security assessments throughout the software development lifecycle. Establish and enhance secure SDLC and DevSecOps practices. Integrate security testing and controls into CI/CD pipelines. Oversee SAST, DAST, SCA, penetration testing, and application security reviews. Work closely with development teams to identify and remediate application security vulnerabilities. Promote security-by-design principles across application development and technology projects.
Vulnerability & Security Testing Oversee enterprise vulnerability management and risk-based vulnerability remediation. Manage penetration testing activities for applications, infrastructure, and external-facing systems. Coordinate internal and external penetration testing engagements and track remediation. Establish vulnerability management KPIs, KRIs, risk acceptance processes, and remediation timelines. Chair or facilitate vulnerability remediation governance forums where required. Identify recurring vulnerabilities and drive improvements to the organization s overall security posture.
Security Operations & Incident Management Provide governance and oversight of security monitoring and incident response capabilities. Work with SOC and security operations teams to improve detection, response, and remediation processes. Review SIEM use cases, security monitoring requirements, and incident management processes. Support major cybersecurity incident investigations and post-incident improvement activities. Ensure lessons learned from incidents are incorporated into security controls and risk management processes.
Cybersecurity Governance, Risk & Compliance Support Act as a deputy to the Information Security Officer when required, ensuring business continuity and ongoing execution of cybersecurity governance, risk management, compliance, and assurance activities. Provide analytical and administrative support to cybersecurity governance forums, risk committees, and management review meetings, including the preparation of presentations, reports, and action tracking. Support internal, external, and regulatory audits through evidence collection, stakeholder coordination, tracking of findings, and monitoring of remediation activities. Prepare and maintain cybersecurity metrics, dashboards, risk reports, KPIs, KRIs, and management reporting materials for governance and oversight purposes. Perform cybersecurity assurance activities and control effectiveness reviews to support the evaluation of the Group s cybersecurity maturity and control environment.
Preferred Certifications OSCP Offensive Security Certified Professional CEH Certified Ethical Hacker CHFI Computer Hacking Forensic Investigator CISSP Certified Information Systems Security Professional CISM Certified Information Security Manager
Technical and Professional Skills Required Enterprise Security Architecture Cybersecurity Risk Assessments Cloud Security AI Security Application Security DevSecOps Vulnerability Management Penetration Testing Threat Modelling Security Operations & Incident Response SIEM and Security Monitoring Executive Reporting and Stakeholder Management
Key Competencies Strong analytical and risk-based decision-making capability. Ability to translate technical cybersecurity issues into business risks. Strong understanding of regulatory and compliance requirements. Ability to lead cybersecurity initiatives across multiple business and technology functions. Excellent stakeholder and executive communication skills. Ability to balance governance requirements with practical technology and business needs. Strong leadership, influencing, and problem-solving capabilities.
Desired Candidate Profile
Educational Qualifications Required
Bachelor or Master degree in Computer or IT or any related fields
Experience Requirements
More than 10 years of experience in Cybersecurity / Technology Risk Assessment and Assurance Experience supporting compliance with recognized frameworks and regulations such as ISO 27001, NIST, NIA, QCSF, PCI DSS, GDPR, PDPL, or similar standards. Hands-on experience conducting cybersecurity risk assessments, control reviews, and security assurance activities. Skilled in enterprise security architecture reviews, cloud, AI, emerging technologies security reviews, application security reviews, DevSecOps, vulnerability assessment, penetration testing, security operations and information security incident management.
ملخص الوظيفة
نحن نبحث عن نائب رئيس لمخاطر التكنولوجيا ذو خبرة لتعزيز وتطوير قدرات إدارة مخاطر الأمن السيبراني والضمان في مجموعة لشا عبر كيانات أعمالها وبيئاتها التكنولوجية. سيكون هذا الدور مسؤولاً عن إجراء والإشراف على تقييمات مخاطر الأمن السيبراني، وتقييم فعالية ضوابط الأمن، وإجراء مراجعات الضمان والامتثال للأمن السيبراني، ومراقبة التعرض للمخاطر التكنولوجية والسيبرانية، ودعم معالجة الثغرات الأمنية المحددة، ونقاط ضعف الضوابط، والتهديدات الناشئة. كما ستساهم هذه الوظيفة في التحسين المستمر لإطار حوكمة الأمن السيبراني، وإدارة المخاطر، والامتثال التنظيمي للمجموعة. وسيمتلك المرشح الناجح مزيجاً قوياً من الخبرة في إدارة مخاطر الأمن السيبراني، وضمان الأمن، والخبرة الأمنية التقنية، مع القدرة على تقييم البيئات التكنولوجية المعقدة والتفاعل بفعالية مع أصحاب المصلحة في الأعمال، وفرق التكنولوجيا، ومديري المشاريع، ومزودي الخدمات من الأطراف الخارجية، والمدققين، والجهات التنظيمية لتعزيز المرونة السيبرانية الإجمالية وموقف المخاطر للمجموعة.
المسؤوليات الرئيسية
هندسة الأمن & مخاطر التكنولوجيا إجراء مراجعات أمنية للبنية التحتية للمؤسسة، والتطبيقات، والبيئات السحابية، والشبكات، وقواعد البيانات، والبرامج الوسيطة، والحلول الأمنية. مراجعة الحلول والمهندسات التكنولوجية المقترحة لضمان دمج المتطلبات الأمنية منذ التصميم. إجراء نمذجة التهديدات وتقييمات المخاطر الأمنية للتكنولوجيات والمبادرات التجارية الجديدة. تحديد وتقييم القواعد الأمنية الأساسية ومعايير التهيئة. تقديم توصيات أمنية لهندسة المؤسسات ومبادرات التحول التكنولوجي.
أمن السحابة والذكاء الاصطناعي & التكنولوجيات الناشئة تقييم وتدعيم ضوابط الأمن عبر بيئات Microsoft Azure وGoogle Cloud Platform وOracle Cloud Infrastructure. إجراء تقييمات أمن السحابة التي تغطي الهوية، وأمن الشبكات، وأحمال العمل، والحاويات، وحماية البيانات، وتسجيل الأحداث، والمراقبة. دعم حوكمة الأمن لبيئات الحاويات. إجراء تقييمات الأمن والمخاطر لحلول الذكاء الاصطناعي، والذكاء الاصطناعي التوليدي، وتعلم الآلة، والتكنولوجيات الناشئة. تقييم ضوابط الأمن ومتطلبات الامتثال للتطبيقات المدعومة بالذكاء الاصطناعي ومزودي خدمات الذكاء الاصطناعي من الأطراف الخارجية. إنشاء ضوابط أمنية مناسبة للبيئات السحابية الأصلية، والمدعومة بالذكاء الاصطناعي، والتكنولوجيات الناشئة.
أمن التطبيقات & DevSecOps قيادة تقييمات أمن التطبيقات طوال دورة حياة تطوير البرمجيات. إنشاء وتعزيز ممارسات دورة حياة تطوير البرمجيات الآمنة (SDLC) وDevSecOps. دمج الاختبارات والضوابط الأمنية في أنابيب CI/CD. الإشراف على اختبارات SAST وDAST وSCA واختبارات الاختراق ومراجعات أمن التطبيقات. العمل عن كثب مع فرق التطوير لتحديد ومعالجة ثغرات أمن التطبيقات. تعزيز مبادئ الأمن بواسطة التصميم عبر مشاريع تطوير التطبيقات والتكنولوجيا.
إدارة الثغرات & الاختبارات الأمنية الإشراف على إدارة الثغرات في المؤسسة ومعالجة الثغرات القائمة على المخاطر. إدارة أنشطة اختبار الاختراق للتطبيقات، والبنية التحتية، والأنظمة المواجهة للخارج. تنسيق مهام اختبار الاختراق الداخلية والخارجية ومتابعة المعالجة. إنشاء مؤشرات الأداء الرئيسية (KPIs)، ومؤشرات المخاطر الرئيسية (KRIs)، وعمليات قبول المخاطر، والجداول الزمنية للمعالجة لإدارة الثغرات. رئاسة أو تيسير منتديات حوكمة معالجة الثغرات عند الحاجة. تحديد الثغرات المتكررة والدفع بنحو تحسينات في الموقف الأمني الإجمالي للمؤسسة.
العمليات الأمنية & إدارة الحوادث توفير الحوكمة والإشراف على قدرات المراقبة الأمنية والاستجابة للحوادث. العمل مع مركز العمليات الأمنية (SOC) وفرق العمليات الأمنية لتحسين عمليات الكشف والاستجابة والمعالجة. مراجعة حالات استخدام SIEM، ومتطلبات المراقبة الأمنية، وعمليات إدارة الحوادث. دعم التحقيقات في حوادث الأمن السيبراني الكبرى وأنشطة التحسين ما بعد الحادث. ضمان دمج الدروس المستفادة من الحوادث في ضوابط الأمن وعمليات إدارة المخاطر.
دعم حوكمة الأمن السيبراني والمخاطر & الامتثال القيام بدور نائب مسؤول أمن المعلومات عند الحاجة، مما يضمن استمرارية الأعمال والتنفيذ المستمر لأنشطة حوكمة الأمن السيبراني، وإدارة المخاطر، والامتثال، والضمان. تقديم الدعم التحليلي والإداري لمنتديات حوكمة الأمن السيبراني، ولجان المخاطر، واجتماعات المراجعة الإدارية، بما في ذلك إعداد العروض التقديمية، والتقارير، ومتابعة الإجراءات. دعم عمليات التدقيق الداخلي والخارجي والتنظيمي من خلال جمع الأدلة، وتنسيق أصحاب المصلحة، ومتابعة النتائج، ومراقبة أنشطة المعالجة. إعداد وصيانة مقاييس الأمن السيبراني، ولوحات التحكم، وتقارير المخاطر، ومؤشرات الأداء الرئيسية (KPIs)، ومؤشرات المخاطر الرئيسية (KRIs)، ومواد التقارير الإدارية لأغراض الحوكمة والإشراف. إجراء أنشطة ضمان الأمن السيبراني ومراجعات فعالية الضوابط لدعم تقييم نضج الأمن السيبراني وبيئة الضوابط للمجموعة.
الشهادات المفضلة OSCP - خبير أمن هجومي معتمد CEH - هكر أخلاقي معتمد CHFI - محقق جنائي في اختراق الكمبيوتر CISSP - خبير معتمد في أمن نظم المعلومات CISM - مدير أمن المعلومات المعتمد
المهارات التقنية والمهنية المطلوبة هندسة الأمن للمؤسسات تقييمات مخاطر الأمن السيبراني أمن السحابة أمن الذكاء الاصطناعي أمن التطبيقات DevSecOps إدارة الثغرات اختبار الاختراق نمذجة التهديدات العمليات الأمنية والاستجابة للحوادث SIEM والمراقبة الأمنية التقارير التنفيذية وإدارة أصحاب المصلحة
الكفاءات الرئيسية قدرة قوية على التحليل واتخاذ القرارات القائمة على المخاطر. القدرة على ترجمة مشكلات الأمن السيبراني التقنية إلى مخاطر تجارية. فهم قوي للمتطلبات التنظيمية ومتطلبات الامتثال. القدرة على قيادة مبادرات الأمن السيبراني عبر وظائف متعددة في الأعمال والتكنولوجيا. مهارات ممتازة في التواصل مع أصحاب المصلحة والإدارة التنفيذية. القدرة على الموازنة بين متطلبات الحوكمة والاحتياجات العملية للتكنولوجيا والأعمال. قدرات قوية في القيادة، والتأثير، وحل المشكلات.
الملف الشخصي للمرشح المطلوب
المؤهلات التعليمية المطلوبة
درجة البكالوريوس أو الماجستير في علوم الحاسب أو تكنولوجيا المعلومات أو أي مجالات ذات صلة
متطلبات الخبرة
أكثر من 10 سنوات من الخبرة في الأمن السيبراني / تقييم وضمان مخاطر التكنولوجيا خبرة في دعم الامتثال للأطر والتنظيمات المعترف بها مثل ISO 27001، أو NIST، أو NIA، أو QCSF، أو PCI DSS، أو GDPR، أو PDPL، أو المعايير المماثلة. خبرة عملية في إجراء تقييمات مخاطر الأمن السيبراني، ومراجعات الضوابط، وأنشطة ضمان الأمن. مهارات عالية في مراجعات هندسة الأمن للمؤسسات، ومراجعات أمن السحابة والذكاء الاصطناعي والتكنولوجيات الناشئة، ومراجعات أمن التطبيقات، وDevSecOps، وتقييم الثغرات، واختبار الاختراق، والعمليات الأمنية وإدارة حوادث أمن المعلومات.