Live opening · Posted 7 days ago

Senior Manager - Third Party Security

Qiddiya Investment Company · Riyadh, Riyadh Province, Saudi Arabia
Workable No
You are 7 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 7 days ago
CompanyQiddiya Investment Company
LocationRiyadh, Riyadh Province, Saudi Arabia
Work modeNo
SourceWorkable
Listed7 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
17 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,136 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Lead and manage Qiddiya's Third-Party Security Risk Management program to ensure vendors, partners, consultants, and service providers comply with cybersecurity requirements and do not introduce unacceptable risks to Qiddiya's information assets, systems, and operations. The role is responsible for establishing security assessment frameworks, overseeing vendor security reviews, and driving remediation of identified risks. This aligns with industry practices for cybersecurity risk management and third-party oversight.
Key Responsibilities
Develop and maintain the Third-Party Security Risk Management (TPSRM) framework.
Conduct cybersecurity due diligence and risk assessments for vendors and suppliers.
Review security requirements during procurement, RFP, and contract stages.
Assess cloud providers, SaaS platforms, managed service providers, and strategic partners.
Define vendor security controls aligned with NCA ECC, ISO 27001, NIST, and Qiddiya cybersecurity standards.
Establish vendor risk classification and assessment methodologies.
Monitor remediation plans and track closure of identified security gaps.
Collaborate with Procurement, Legal, Compliance, Enterprise Risk, and Technology teams.
Lead periodic reassessments of critical vendors.
Report third-party cyber risks, trends, and KPIs to senior management.
Manage external security audits, questionnaires, and assurance activities.
Lead and develop the Third-Party Security team.
Requirements
Bachelor's degree in Cybersecurity, Information Security, Computer Science, or related field.
8–12 years of cybersecurity experience.
Minimum 4 years in Third-Party Security, Vendor Risk Management, Cybersecurity Risk Management, or GRC.
Experience within large enterprises, giga projects, banking, telecom, government, or critical infrastructure environments.
Experience managing teams and stakeholder engagement at senior levels.

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App