IT Security Engineer
نبذة عن الوظيفة
Job Description: The IT Security Engineer supports the implementation of security standards, monitoring activities, and basic compliance requirements to help protect IT systems, applications, and data. This role is suitable for a fresh graduate who will learn and assist in security awareness, code scanning before deployments, vulnerability follow-up, and applying Saudi cybersecurity regulations under the guidance of senior IT team members.
Responsibilities: Security Governance & Compliance Support: • Assist in implementing IT security standards and internal security policies. • Support compliance activities related to Saudi cybersecurity regulations and internal requirements. • Help maintain security documentation, checklists, and basic audit evidence. • Coordinate with senior team members to follow up on required security actions. Threat & Vulnerability Management: • Monitor security alerts and escalate suspicious activities to senior IT team members. • Assist in vulnerability scanning and follow up on remediation status. • Support patching and corrective actions by tracking findings and sharing updates. • Maintain security incident logs and coordinate with relevant teams for incident resolution. Application & Infrastructure Security: • Secure all application and infrastructure layers, including web, backend, APIs, databases, and client applications. • Perform basic code security scanning before deployments and report identified risks. • Implement access control, authentication, encryption, and secure configurations. • Collaborate with DevOps and Infra teams to ensure secure deployment of pipelines. Knowledge Management & Training: • Develop security guidelines, SOPs, and documentation. • Conduct training sessions and workshops to raise awareness among internal users and technical teams. • Promote a security-conscious culture across the organization. Collaboration & Technical Delivery: • Work closely with Infra, DevOps, and Development teams for secure architecture and operations. • Review and approve security measures for new tools, applications, and integrations. • Advice on security requirements for new projects, features, or customer integrations.
Job Relations: • Reports to: IT Infrastructure Lead / IT Manager. • Internal Relations: DevOps Engineer, Infra Engineer, QA, Development Teams, IT Support.
External Communications: • Communicate with regulators and auditors to ensure compliance and provide reports. • Liaise with external vendors for security assessments, penetration tests, and certifications. • Escalate critical security risks to IT leadership and management.
Requirements • Bachelor’s degree in Computer Engineering, Computer Science, Cybersecurity, Information Technology, or related field. • Fresh graduate or up to 2 years of experience in Information Security, Cybersecurity, or IT. • Relevant cybersecurity certifications or training, such as CompTIA Security+, CEH, ISO 27001 Foundation, or equivalent certifications . • Basic understanding of security governance, risk management, and compliance concepts.
Knowledge of: • Network and infrastructure security (Firewalls, VPNs, IDS/IPS). • Application security (Web, APIs, Mobile Applications). • Security monitoring and SIEM platforms. • Backup, Disaster Recovery (DR), and Business Continuity concepts. • Secure Software Development Lifecycle (SSDLC). • Security code scanning and vulnerability management. • Saudi cybersecurity regulations and frameworks (NCA ECC, PDPL, ISO 27001) awareness is preferred.
Competencies: • Willingness to learn and develop technical security skills. • Risk-aware mindset with attention to detail. • Basic ability to understand security standards and translate them into daily operational tasks. • Collaboration and influence across technical and non-technical teams. • Proactive attitude toward security awareness, documentation, and continuous improvement.
Skills & Languages: • Vulnerability management, penetration testing, and threat intelligence • Security monitoring and SIEM tools • Network security, firewalls, VPNs, encryption, IAM • Application security best practices. • Backup, disaster recovery, and business continuity planning • Fluent in English (required). • Arabic proficiency (preferred).