Tabbio
Login to App
yesterday

IT Security Engineer

National Parcel Stations Network Co. · Riyadh, Riyadh Province, Saudi Arabia
WorkableApply on company site
Full Time
Onsite

Role overview

Job Description: The IT Security Engineer supports the implementation of security standards, monitoring activities, and basic compliance requirements to help protect IT systems, applications, and data. This role is suitable for a fresh graduate who will learn and assist in security awareness, code scanning before deployments, vulnerability follow-up, and applying Saudi cybersecurity regulations under the guidance of senior IT team members.

Responsibilities: Security Governance & Compliance Support: • Assist in implementing IT security standards and internal security policies. • Support compliance activities related to Saudi cybersecurity regulations and internal requirements. • Help maintain security documentation, checklists, and basic audit evidence. • Coordinate with senior team members to follow up on required security actions. Threat & Vulnerability Management: • Monitor security alerts and escalate suspicious activities to senior IT team members. • Assist in vulnerability scanning and follow up on remediation status. • Support patching and corrective actions by tracking findings and sharing updates. • Maintain security incident logs and coordinate with relevant teams for incident resolution. Application & Infrastructure Security: • Secure all application and infrastructure layers, including web, backend, APIs, databases, and client applications. • Perform basic code security scanning before deployments and report identified risks. • Implement access control, authentication, encryption, and secure configurations. • Collaborate with DevOps and Infra teams to ensure secure deployment of pipelines. Knowledge Management & Training: • Develop security guidelines, SOPs, and documentation. • Conduct training sessions and workshops to raise awareness among internal users and technical teams. • Promote a security-conscious culture across the organization. Collaboration & Technical Delivery: • Work closely with Infra, DevOps, and Development teams for secure architecture and operations. • Review and approve security measures for new tools, applications, and integrations. • Advice on security requirements for new projects, features, or customer integrations.

Job Relations: • Reports to: IT Infrastructure Lead / IT Manager. • Internal Relations: DevOps Engineer, Infra Engineer, QA, Development Teams, IT Support.

External Communications: • Communicate with regulators and auditors to ensure compliance and provide reports. • Liaise with external vendors for security assessments, penetration tests, and certifications. • Escalate critical security risks to IT leadership and management.

Requirements • Bachelor’s degree in Computer Engineering, Computer Science, Cybersecurity, Information Technology, or related field. • Fresh graduate or up to 2 years of experience in Information Security, Cybersecurity, or IT. • Relevant cybersecurity certifications or training, such as CompTIA Security+, CEH, ISO 27001 Foundation, or equivalent certifications . • Basic understanding of security governance, risk management, and compliance concepts.

Knowledge of: • Network and infrastructure security (Firewalls, VPNs, IDS/IPS). • Application security (Web, APIs, Mobile Applications). • Security monitoring and SIEM platforms. • Backup, Disaster Recovery (DR), and Business Continuity concepts. • Secure Software Development Lifecycle (SSDLC). • Security code scanning and vulnerability management. • Saudi cybersecurity regulations and frameworks (NCA ECC, PDPL, ISO 27001) awareness is preferred.

Competencies: • Willingness to learn and develop technical security skills. • Risk-aware mindset with attention to detail. • Basic ability to understand security standards and translate them into daily operational tasks. • Collaboration and influence across technical and non-technical teams. • Proactive attitude toward security awareness, documentation, and continuous improvement.

Skills & Languages: • Vulnerability management, penetration testing, and threat intelligence • Security monitoring and SIEM tools • Network security, firewalls, VPNs, encryption, IAM • Application security best practices. • Backup, disaster recovery, and business continuity planning • Fluent in English (required). • Arabic proficiency (preferred).

Responsibilities

1Assist in implementing IT security standards and internal security policies.
2Support compliance activities related to Saudi cybersecurity regulations and internal requirements.
3Help maintain security documentation, checklists, and basic audit evidence.
4Coordinate with senior team members to follow up on required security actions.
5Monitor security alerts and escalate suspicious activities to senior IT team members.
6Assist in vulnerability scanning and follow up on remediation status.
7Support patching and corrective actions by tracking findings and sharing updates.
8Maintain security incident logs and coordinate with relevant teams for incident resolution.

Requirements

1Bachelor’s degree in Computer Engineering, Computer Science, Cybersecurity, Information Technology, or related field.
2Fresh graduate or up to 2 years of experience in Information Security, Cybersecurity, or IT.
3Relevant cybersecurity certifications or training, such as CompTIA Security+, CEH, ISO 27001 Foundation, or equivalent certifications .
4Basic understanding of security governance, risk management, and compliance concepts.
5Network and infrastructure security (Firewalls, VPNs, IDS/IPS).
6Application security (Web, APIs, Mobile Applications).
7Security monitoring and SIEM platforms.
8Backup, Disaster Recovery (DR), and Business Continuity concepts.
9Secure Software Development Lifecycle (SSDLC).
10Security code scanning and vulnerability management.
11Saudi cybersecurity regulations and frameworks (NCA ECC, PDPL, ISO 27001) awareness is preferred.
12Willingness to learn and develop technical security skills.
13Risk-aware mindset with attention to detail.
14Basic ability to understand security standards and translate them into daily operational tasks.

Skills and tags

Information TechnologySADevOpsCybersecurityAuditComplianceEnglish

Claim your tabbio link
before it's taken