Jobs Companies Qiddiya Investment Company Associate Director - Cybersecurity Risk and Compliance

About this Associate Director - Cybersecurity Risk and Compliance role at Qiddiya Investment Company

Qiddiya Investment Company · Onsite · Riyadh, Riyadh Province, Saudi Arabia
  • Roles and Responsibilities:
    • Conduct periodic and ad hoc cybersecurity risk assessments across IT and OT environments
    • Perform OT-specific risk assessments on assets such as PLCs, HMIs, RTUs, and engineering systems
    • Identify and document OT-relevant risk scenarios (e.g., control system disruption, unauthorized access, safety manipulation)
    • Coordinate risk reviews as part of major IT/OT changes, such as system upgrades or new deployments
    • Reassess risk posture following major changes, incidents, or regulatory updates
    • Review and validate existing controls to calculate residual risk and prioritize treatment actions
    • Provide standardized tools and guidance to support self-assessments by IT, OT, and business teams
    • Support integration of assessment outcomes into control design, zoning, segmentation, and system deployment
    • Track risk treatment progress and escalate overdue or high-priority items as needed
    • Coordinate with performance management to define and monitor key risk indicators (KRIs) to proactively track changes in cybersecurity risk exposure
    • Maintain the cybersecurity risk register, including OT-specific entries, capturing identified risks, likelihood and impact ratings, treatment plans, ownership, and status
    • Coordinate and execute internal cybersecurity compliance assessments across all relevant domains and functions
    • Serve as the lead interface for external audits and regulatory inspections, including preparation, execution, and response
    • Conduct periodic compliance assessments of OT environments, including SCADA, DCS, PLCs, and associated network infrastructure
    • Maintain an inventory of compliance-relevant OT assets and map them to applicable control requirements and standards
    • Monitor adherence to cybersecurity policies, escalate non-compliance, and coordinate corrective actions with relevant teams
    • Track and manage remediation plans for compliance gaps, non-conformities, and audit findings through closure
    • Validate the effectiveness of implemented controls or mitigation plans before closing compliance gaps
    • Review and validate configuration baselines for OT systems (e.g., firewall rules, firmware versions) to ensure alignment with compliance standards
    • Coordinate evidence collection, documentation, and remediation planning for compliance-related findings
    • Report OT and IT cybersecurity compliance status and risks to leadership and cybersecurity governance
    • Support compliance awareness and training for teams with control responsibilities in both IT and OT
    • Maintain a centralized compliance register, covering both IT and OT, that maps regulatory requirements to policies, controls, responsible teams, and evidence sources
    • Govern third-party cybersecurity risk by maintaining standardized assessment processes, due diligence criteria, and remediation tracking
    • Coordinate and conduct third-party cybersecurity assessments across IT and OT suppliers to ensure alignment with internal policies and regulatory requirements
    • Review vendor-supplied OT systems and supporting documentation to ensure inclusion of security controls and compliance with applicable standards (e.g., NCA OTCC, IEC 62443)
    • Ensure third-party risk findings are documented, risk-rated, and tracked through resolution, including acceptance or application of compensating controls
    • Maintain a register of assessed vendors, associated risks, control gaps, and remediation status for ongoing oversight and reporting
    • Collaborate with procurement, legal, and compliance to embed cybersecurity requirements into third-party agreements, including OT-specific clauses where applicable
    • Contribute to the development and review of third-party security policy and minimum control requirements for use in procurement and onboarding
    • Support internal and external audit requests related to third-party cybersecurity risk management

Requirements

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
  • Master's degree is preferred.
  • 10–12+ years of cybersecurity experience.
  • Strong experience in cybersecurity risk management, compliance, assessments, and assurance.
Ready to apply to Qiddiya Investment Company?
Apply to Qiddiya Investment Company

About Qiddiya Investment Company

The Qiddiya Investment Company (QIC) is the holding company that contains all the for-profit investments of the enterprise (including Qiddiya City and its offerings as well as Saudi Entertainment Ventures) and the overall strategic direction of the collective company. As a global leader in entertainment and the developer of the concept of play, QIC, along with its subsidiaries, is driving the development of the Entertainment, Sports and Culture sector in Saudi Arabia.

See all jobs at Qiddiya Investment Company →

Similar jobs

Qiddiya Investment Company
Senior Manager - HSE - Racecourse (RAC-040)
Qiddiya Investment Company
⚡ Apply early Riyadh, Riyadh Province, Saudi... Onsite
● New 👁 Seen ✓ Applied 4h ago
Qiddiya Investment Company
Manager - Asset Operations systems
Qiddiya Investment Company
⚡ Apply early Riyadh, Riyadh Province, Saudi... Onsite
● New 👁 Seen ✓ Applied 4h ago
Qiddiya Investment Company
Senior Manager - Commercial - 20000778 AG6
Qiddiya Investment Company
⚡ Apply early Riyadh, Saudi Arabia Onsite
● New 👁 Seen ✓ Applied 13h ago
Qiddiya Investment Company
Senior Expert - Software Engineer
Qiddiya Investment Company
⚡ Apply early Riyadh, Riyadh Province, Saudi... Onsite
● New 👁 Seen ✓ Applied 13h ago
Qiddiya Investment Company
Director - Entertainment Strategy
Qiddiya Investment Company
⚡ Apply early Riyadh, Riyadh Province, Saudi... Onsite
● New 👁 Seen ✓ Applied 13h ago
Qiddiya Investment Company
Director - Governance, Risk, and Control Lead - 50012080 - DA3
Qiddiya Investment Company
⚡ Apply early Riyadh, Riyadh Province, Saudi... Onsite
● New 👁 Seen ✓ Applied 13h ago
Qiddiya Investment Company
Director - Asset & Site Management
Qiddiya Investment Company
⚡ Apply early Riyadh, Riyadh Province, Saudi... Onsite
● New 👁 Seen ✓ Applied 13h ago
Qiddiya Investment Company
Manager - Operations (DEL2)
Qiddiya Investment Company
⚡ Apply early Riyadh, Riyadh Province, Saudi... Onsite
● New 👁 Seen ✓ Applied 1d ago
Qiddiya Investment Company
Senior Manager - Development Business Solutions
Qiddiya Investment Company
⚡ Apply early Riyadh, Riyadh Province, Saudi... Onsite
● New 👁 Seen ✓ Applied 1d ago

Sign up for suggestions tailored to the jobs you open and the searches you save.

More jobs at Qiddiya Investment Company

See all jobs at Qiddiya Investment Company →

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get an edge on your job hunt.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free