We are seeking a highly experienced Senior Information Security / Senior Cyber Security Assessor (Certification) to lead and support cyber security certification and compliance assessment activities. The role is responsible for reviewing certification applications, evaluating organizations’ compliance with national and international security standards, conducting cyber security risk assessments and audits, and ensuring consistency, impartiality, and quality throughout the certification lifecycle.
The ideal candidate will possess strong technical expertise in information security governance, risk management, compliance, auditing, and certification frameworks, along with proven leadership and stakeholder management capabilities.
Key Responsibilities:
Lead and deliver certification assessment and review activities for organizations seeking Information Security / Cyber Security certification.
Manage assessment teams, assign cases, and oversee daily certification operations.
Review and evaluate organizations’ compliance with national and international cyber security standards and frameworks.
Assess the design and operating effectiveness of cyber security and information security controls
Conduct cyber security risk assessments, audits, and compliance reviews.
Maintain accurate, complete, and organized records of certification and assessment activities.
Ensure impartiality, confidentiality, consistency, and compliance throughout certification processes.
Document assessment observations and findings based on objective evidence and ensure traceability.
Develop and maintain certification procedures, methodologies, and supporting tools aligned with national compliance frameworks.
Develop compliance measurement mechanisms and monitoring tools to track improvements.
Provide recommendations and assessment outcomes to stakeholders and decision-makers.
Manage external communication throughout the audit and certification lifecycle, from application to final decision issuance.
Stay updated on emerging cyber security threats, technologies, standards, and industry best practices.
Develop and deliver internal training sessions and workshops to enhance team capabilities in cyber security, compliance, assurance, and auditing.
Collaborate effectively with internal teams, clients, and stakeholders across multiple projects.
Desired Candidate Profile
Requirements
Education:
Bachelor’s degree in Information Technology, Computer Information Systems, Cyber Security, or a related field.
Professional Certifications:
One or more relevant professional certifications are preferred, such as:
Experience:
Minimum 7 years of professional experience in Information Security / Cyber Security.
Minimum 4 years of experience in one or more of the following areas:
Experience in consulting or implementing cyber security programs aligned with national or international standards is highly desirable.
Technical Skills & Knowledge:
Strong knowledge of cyber security governance, risk assessment, and audit methodologies.
Experience with security frameworks and standards such as:
ISO 27001
NIST
NIA Controls
CSF Q2022
Familiarity with certification and audit standards including:
ISO/IEC 17021
ISO/IEC 17024
ISO/IEC 27006
ISO/IEC 17065
ISO 19011
ITAF
ISA
Hands-on experience in Information Security Auditing and Information Security Management.
Strong understanding of cyber security trends, threats, and emerging technologies.
Excellent technical report writing and documentation skills.
Soft Skills:
Strong analytical and problem-solving abilities.
Excellent communication and stakeholder management skills.
Ability to work independently and manage multiple priorities effectively.
High attention to detail and ability to work under pressure and meet deadlines.
Strong interpersonal and team collaboration skills.
Experience in delivering workshops, training sessions, and awareness programs.
Language Requirement:
نحن نبحث عن كبير مسؤولي أمن المعلومات / كبير مختبري الأمن السيبراني (الشهادة) ذوي خبرة عالية لقيادة ودعم أنشطة الحصول على الاعتماد في الأمن السيبراني والتقييم والامتثال. المسؤولية تشمل مراجعة طلبات الاعتماد، وتقييم امتثال المؤسسات للمعايير الوطنية والدولية للأمن، وإجراء تقييمات ومراجعات مخاطر الأمن السيبراني، وضمان الاتساق والحيادية والجودة خلال دورة الاعتماد.
سيكون المرشح المثالي متمتعاً بخبرة تقنية قوية في حوكمة أمن المعلومات وإدارة المخاطر والامتثال والتدقيق وأطر الاعتماد، إلى جانب قدرات قيادية وإدارة أصحاب المصلحة مثبتة.
المسؤوليات الأساسية:
قيادة وتنفيذ أنشطة تقييم الاعتماد ومراجعة المؤسسات التي تسعى للحصول على اعتماد أمن معلومات / أمن سيبراني.
إدارة فرق التقييم، وتخصيص الحالات، والإشراف على عمليات الاعتماد اليومية.
مراجعة وتقييم امتثال المؤسسات للمعايير وال\إطارات الأمن السيبراني الوطنية والدولية.
تقييم تصميم وكفاءة التحكمات في الأمن السيبراني وأمن المعلومات
إجراء تقييمات مخاطر الأمن السيبراني، والتدقيق، ومراجعات الامتثال.
الحفاظ على سجلات دقيقة وكاملة ومنظمة لأنشطة الاعتماد والتقييم.
ضمان الحياد والخصوصية والاتساق والالتزام طوال عمليات الاعتماد.
توثيق ملاحظات ونتائج التقييم استناداً إلى أدلة موضوعية وضمان إمكانية التتبع.
تطوير والحفاظ على إجراءات الاعتماد والمنهجيات والأدوات الداعمة المتوافقة مع أطر الامتثال الوطنية.
تطوير آليات قياس الامتثال وأدوات الرصد لتتبع التحسينات.
تقديم التوصيات ونتائج التقييم لأصحاب المصلحة وصانعي القرار.
إدارة الاتصالات الخارجية طوال دورة حياة التدقيق والاعتماد، من التقديم حتى إصدار القرار النهائي.
البقاء على اطلاع بتهديدات الأمن السيبراني الناشئة والتقنيات والمعايير وأفضل الممارسات في الصناعة.
تطوير وتقديم جلسات تدريب داخلية وورش عمل لتعزيز قدرات الفريق في الأمن السيبراني والامتثال والضمان والتدقيق.
التعاون بفاعلية مع الفرق الداخلية والعملاء وأصحاب المصلحة عبر مشاريع متعددة.
المصدر من المرشح المطلوب
المتطلبات
التعليم:
الشهادات المهنية:
يفضل الحصول على شهادة مهنية واحدة على الأقل من الشهادات التالية أو ما يعادلها:
الخبرة:
خبرة مهنية لا تقل عن 7 سنوات في أمن المعلومات / الأمن السيبراني.
خبرة لا تقل عن 4 سنوات في أحد المجالات التالية على الأقل:
تدقيق أمن المعلومات
تدقيق الأمن السيبراني
إدارة المخاطر
إدارة أمن المعلومات
الخبرة في الاستشارات أو تنفيذ برامج الأمن السيبراني المتوافقة مع المعايير الوطنية أو الدولية مرغوبة بشدة.
المهارات الفنية والمعرفة:
معرفة قوية بحوكمة الأمن السيبراني وتقييم المخاطر ومنهجيات التدقيق.
الخبرة في أطر ومعايير الأمن مثل:
ISO 27001
NIST
NIA Controls
CSF Q2022
الإلمام بمعايير الاعتماد والتدقيق بما في ذلك:
ISO/IEC 17021
ISO/IEC 17024
ISO/IEC 27006
ISO/IEC 17065
ISO 19011
ITAF
ISA
خبرة عملية في تدقيق أمن المعلومات وإدارة أمن المعلومات.
فهم قوي لاتجاهات Threats وتكنولوجيا الأمن السيبراني الناشئة.
مهارات كتابة تقارير تقنية وتوثيق ممتازة.
المهارات الناعمة:
قدرات تحليلية وحل مشاكل قوية.
مهارات اتصال وإدارة أصحاب المصلحة ممتازة.
القدرة على العمل بشكل مستقل وإدارة أولويات متعددة بفعالية.
انتباه عالي للتفاصيل وقدرة على العمل تحت الضغط والالتزام بالمواعيد.
مهارات تفاعل بين الأشخاص والتعاون ضمن الفريق.
خبرة في تقديم ورش عمل وجلسات تدريب وبرامج توعية.
متطلب اللغة: