Gentis
Gentis
Accueil

JobsMissionsMédiaÉtudes de cas
Contactez-nous à tout moment via
hello@gentis.com

Nos dernières offres

Rechercher une opportunité par mot-clé

Security Solution Analyst - GRC Cybersecurity

30/10/2024
PermanentSaudi ArabiaOn site17000 SR21000 SR
Lien copié
Description du poste

A leading organization in Saudi Arabia is seeking a Cybersecurity Compliance Officer to join their GRC team. The role focuses on developing and maintaining security governance frameworks, policies, and procedures to ensure alignment with regulatory requirements. The candidate will drive compliance with national cybersecurity regulations, data protection laws, and international security standards.


Key responsibilities include monitoring regulatory compliance, conducting internal security assessments, managing GRC technology platforms, and coordinating external audit engagements. The position requires regular reporting to GRC leadership and supporting organizational certification initiatives.


The ideal candidate will have experience in implementing and maintaining comprehensive security compliance programs while ensuring adherence to industry and regulatory requirements.


Detailed Responsibilities:

  • Develop and maintain comprehensive cybersecurity governance frameworks, policies, and procedures ensuring alignment with regulatory requirements, including NCA controls.
  • Drive compliance with key security standards and regulations including PDPL, ISO 27001, and other applicable frameworks. Monitor and implement emerging requirements.
  • Perform technical security reviews of system configurations, network architecture, and control implementations to validate compliance and security best practices.
  • Lead internal security assessments and compliance reviews to identify and remediate control gaps.
  • Implement and administer GRC automation platforms to enhance compliance monitoring efficiency and reporting capabilities.
  • Design and oversee control attestation procedures, working with control owners to validate and document control effectiveness.
  • Develop and execute third-party security assessment program to evaluate and monitor vendor security practices.
  • Generate regular security status reports for GRC management. Effectively communicate security risks, issues and recommendations to key stakeholders.
  • Manage external audit engagements and certification processes to ensure successful outcomes and continued compliance.
Description du profil

Key Competencies:

  • Information Security Governance: Advanced knowledge of security frameworks, policies, and strategic integration of security with business operations. Strong understanding of cyber resilience principles.
  • Regulatory & Standards Expertise: Comprehensive understanding of data protection laws, international security standards (ISO), and industry regulations. Ability to interpret and apply evolving requirements.
  • Technical Security Knowledge: Proficiency in assessing system security configurations, network architecture, and control implementations. Deep understanding of security best practices.
  • Security Assessment: Expert capability in conducting security assessments and compliance reviews. Strong analytical skills in control effectiveness evaluation.
  • GRC Technology: Advanced knowledge of GRC platforms and automation solutions. Expertise in optimizing compliance monitoring and reporting processes.
  • Control Framework: Deep understanding of control validation procedures and attestation processes. Knowledge of control documentation best practices.
  • Third-Party Security: Expert knowledge of vendor security assessment methodologies and supply chain risk management principles.
  • Strategic Communication: Strong ability to articulate complex security concepts to various stakeholders. Excellence in security status reporting and presentation.
  • Audit Management: In-depth knowledge of external audit and certification processes. Strong understanding of audit evidence requirements and remediation approaches.
  • Policy Architecture: Expert understanding of control frameworks and their relationship to organizational policies. Proficiency in mapping security requirements to operational controls.


Core Responsibilities:

  • Information Security Governance: Develop and oversee security frameworks, policies, and procedures aligned with business objectives. Integrate security strategy with operations to maintain business continuity and cyber resilience.
  • Regulatory & Standards Management: Ensure adherence to data protection laws, international security standards (ISO), and industry regulations. Monitor evolving requirements and update security practices accordingly.
  • Technical Security Oversight: Assess and validate system security configurations, network architecture, and control implementations against security requirements and industry best practices.
  • Security Assurance: Lead internal security assessments and compliance reviews. Evaluate control effectiveness and drive continuous improvement initiatives.
  • Technology & Process Optimization: Implement and manage GRC platforms and automation solutions to enhance compliance monitoring and reporting efficiency.
  • Control Management: Design and maintain control validation procedures, ensuring proper documentation and attestation from control owners.
  • Third-Party Risk Management: Develop and execute vendor security assessment programs. Evaluate and monitor external partner security postures to manage supply chain risks.
  • Stakeholder Management: Deliver regular status updates to GRC leadership on security posture and program effectiveness. Drive clear communication channels with key stakeholders.
  • Audit Coordination: Support external audit engagements and certification processes. Partner with auditors and internal teams to facilitate successful outcomes.
  • Policy Framework Administration: Maintain unified control framework mapping security requirements to organizational policies. Establish clear relationships between policies, standards, and operational controls.


Education & Professional Certifications:


· Advanced degree in Computing/Technology field (Bachelor's/Master's in Computer Science or related)

· Governance, Risk & Compliance certification (ISC2 GRC)

· CISSP (Certified Information Security Professional)

· CISA (Certified Information Systems Auditor)

· Security Controls Framework certification (SANS SEC566)

· OSCP (Offensive Security Certified Professional)

Lieu de travail:
Al Khobar, Saudi Arabia
Lien copié

Opportunités similaires

ICT
10/10/2025

Infrastructure Engineer

Job ScopeThe IT Support Specialist is the single point of contact (SPOC) for all local IT matters, ensuring effective support across the organization’s applications (including SAP and non-ERP business-specific systems) and infrastructure (desktop, laptop, networking, and telecom systems).This role is responsible for incident management, service coordination, and user satisfaction, while supporting infrastructure upgrades, business application rollouts, and continuous service improvements.Shift work and on-call support may be required for Priority 1 & 2 incidents.Key DimensionsBudget: No direct responsibility, but must track run-and-maintain costs through time reporting.Support coverage: Local business hours for normal operations; on-call mobile rotation for high-priority incidents.Application scope: SAP and non-ERP business-specific applications.Infrastructure scope: Desktop/Laptop fleet, network estate, telecommunications, and related hardware.Principal AccountabilitiesIncident & Request ManagementReceive, log, and track requests for support from end-users and service delivery staff.Monitor progress of incidents and escalations, keeping stakeholders informed.Conduct initial problem diagnosis and apply known solutions or escalate to specialized teams.Update incident logs and knowledge base in line with ITIL standards.Customer Engagement & Service CoordinationAct as the SPOC for all local IT issues, ensuring user needs are understood and addressed.Coordinate local escalations with global teams or external service providers.Provide advice on available systems, products, and services.Application & Infrastructure MonitoringMonitor applications and infrastructure performance, detect issues, and take corrective action.Collaborate with development/support teams and software vendors to address known problems or deliver enhancements.End-User Support & TrainingAssist users in effective use of desktop systems and applications.Deliver end-user training on business applications upon request.Participate in “transition to support” activities for new applications and updates.Vendor & Asset ManagementAct as point of contact for third-party vendors (ISPs, hardware service providers) and ensure HSSE compliance.Arrange preventive maintenance for IT equipment (servers, UPS, air conditioning, etc.).Manage local IT stock levels and coordinate with business focal points for replenishment.Business Continuity & SecuritySupport disaster recovery and business continuity activities.Ensure compliance with corporate IT security policies and standards.Key ChallengesKeeping technical skills aligned with evolving business application portfolio and infrastructure upgrades.Managing stakeholder relationships while constructively challenging for service improvement.Delivering results through virtual teams without direct authority.Operating effectively in a multi-application, multi-vendor environment.Skills & ExperienceTechnical Support & IT Service Management2–3 years’ experience in end-user IT support or help desk environments.Solid understanding of ITIL v4 processes and incident/problem management.Experience with ticketing systems and knowledge management tools.Strong troubleshooting, root cause analysis, and problem-solving skills.Applications & InfrastructureSAP GUI and non-ERP business applications.MS Office 365 Suite, Teams, collaboration tools.Operating Systems: Windows Server (2016–2022), Linux, MS SQL Database.Networking & Telecom: Cisco/Aruba switches & routers, PABX.Security: FortiClient, Fortigate firewalls, IRM Security Compliance.Hardware: Lenovo desktops/laptops, Nutanix, Fortigate appliances.Middleware, application integration, application security, and data architecture knowledge.Business & Soft SkillsFluent English (spoken and written).Strong interpersonal and customer service skills.Effective time management and ability to prioritize under pressure.Experience working in global/virtual and cross-functional teams.Preferred Senior ProfileCertification in a relevant technology area.Advanced troubleshooting and mentoring skills.Knowledge of ITIL and business processes in a similar industry.

PermanentMoroccoOn site
ICT
10/10/2025

Architecte Consultant – CRM & Solutions SaaS (Salesforce)

Missions principalesConception & ArchitectureConcevoir et proposer des architectures techniques et fonctionnelles, avec un focus sur Salesforce.Garantir l’intégration fluide des solutions SaaS avec les systèmes existants.Gestion de projets & conseilIntervenir sur des projets CRM complexes en tant qu’expert.Piloter des projets IT et digitaux en assurant l’interface entre les besoins métiers et les solutions techniques.Accompagner les clients dans toutes les phases des projets, de la définition des besoins à la mise en production.Collaboration & CoordinationTravailler étroitement avec les parties prenantes internes et externes (utilisateurs, experts techniques, éditeurs…).Animer des ateliers et contribuer à la validation des solutions livrées.Participer à la conduite du changement pour garantir l’adoption des solutions.Méthodologies & ProcessusAppliquer les méthodologies Agile / SAFe pour optimiser les cycles de livraison.Contribuer à l’amélioration continue des pratiques et à la standardisation des processus.Compétences techniques clésSalesforce : Certification Integration Architect obligatoireCRM : Expertise sur les solutions et architectures CRMAPI & intégration : REST, SOAP, patterns d’intégration (sans développement avancé)Méthodologies : Agile, SAFe (obligatoire), ITIL/ITSM (souhaité)Gestion de solutions SaaS et intégration multi-systèmesAnalyse fonctionnelle et rédaction de spécificationsCertifications recommandéesObligatoire : Salesforce Certified Integration ArchitectSouhaitées : PMP, PRINCE2, ITIL Foundation, Agile/Scrum Master

PermanentMoroccoHybrid
ICT
10/10/2025

Product Manager – Cybersécurité

Mission principaleDéfinir et mettre en œuvre la stratégie de développement du portefeuille Cybersécurité destiné aux clients entreprises, en interne ou via des partenaires stratégiques.Traduire cette stratégie en roadmaps de lancement de solutions et produits sur le marché, avec pour objectif de générer une croissance durable des revenus.Responsabilités principalesStratégie & RoadmapÉlaborer les plans marketing pour la gamme de produits et solutions Cybersécurité, alignés sur le plan stratégique de l’entreprise.Définir et piloter la roadmap marketing Cybersécurité.Développement & Lancement d’OffresConcevoir, lancer et faire évoluer les solutions de cybersécurité selon les processus en vigueur.Assurer la mise en place des partenariats stratégiques dans le domaine de la Cybersécurité.Adapter les offres en fonction des besoins clients et de l’évolution des menaces.Veille & ConcurrenceRéaliser une veille constante sur les tendances du marché, les innovations et les évolutions réglementaires.Analyser la concurrence et recommander des actions pour maintenir la compétitivité des solutions.Collaboration & CoordinationTravailler en étroite collaboration avec les équipes techniques et commerciales pour concevoir des offres répondant aux besoins du marché.Piloter les demandes business liées aux spécifications, certifications et prérequis pour le développement des services de Cybersécurité.Contribuer à l’élaboration du budget et des prévisions annuelles, suivre et analyser les KPI pour sécuriser et développer les revenus.Support & FormationAssurer les formations, transferts de compétences et développement d’outils d’aide à la vente.Soutenir les équipes commerciales et avant-vente dans la promotion et le déploiement des offres.Suivre et piloter le pipeline d’opportunités en coordination avec les équipes commerciales.Résultats attendusLancement réussi de nouvelles offres Sécurité destinées au marché B2B.Contribution significative à la croissance du chiffre d’affaires ICT.Simplification du parcours client et amélioration de l’expérience B2B (outils self-care, extranet…).Participation à l’industrialisation des processus internes (vente, déploiement, facturation, SAV).

PermanentMoroccoOn site
ICT
10/10/2025

Ingénieur DevSecOps / Site Reliability Engineer (SRE)

Missions principalesSécurité dans le cycle DevOpsIntégrer la sécurité dans toutes les étapes du pipeline CI/CD (shift-left security).Mettre en place et automatiser les contrôles de sécurité (SAST, DAST, SCA, IaC scanning).Définir et appliquer les normes de codage sécurisé et les politiques de livraison.Automatisation & Infrastructure sécuriséeConcevoir et maintenir des pipelines CI/CD sécurisés pour les environnements cloud et on-premises.Déployer et gérer des environnements de développement, test et production avec contrôle d’accès, journalisation et surveillance.Sécuriser les configurations d’infrastructure et orchestrer les déploiements via Infrastructure as Code (Terraform, Ansible).Surveillance & RéponseIntégrer les solutions de monitoring, alerting et logging dans les pipelines et environnements.Surveiller les KPIs de performance et de sécurité, analyser les incidents et piloter les plans de remédiation.Participer aux exercices de simulation d’incidents de sécurité et contribuer aux retours d’expérience.Collaboration & Amélioration continueTravailler en étroite collaboration avec les équipes Développement, Sécurité, Réseau et Ops.Identifier les goulots d’étranglement dans le processus CI/CD et proposer des plans d’amélioration.Participer aux communautés techniques et promouvoir les bonnes pratiques DevSecOps.Compétences techniques clésLangages & Frameworks : Java, Kotlin, Go, JavaScript, PythonSécurité applicative : OWASP Top 10, API Security, SAST (SonarQube, Checkmarx), DAST (Burp Suite, ZAP), SCAConteneurs & orchestration : Docker, Kubernetes, OpenShift, IstioCI/CD : Jenkins, GitLab CI, GitHub Actions, AWS CodePipelineInfrastructure as Code : Terraform, AnsibleCloud : AWS, Azure, GCP avec sécurité et conformité intégréesSurveillance : Prometheus, Grafana, ELK, SIEMCertifications recommandées (optionnelles)DevOps & Cloud : AWS Certified DevOps Engineer, Kubernetes CKA/CKADSécurité : CSSLP, DevSecOps Foundation, GIAC GCSAOutillage : GitLab Certified CI/CD Specialist, HashiCorp Terraform Associate

PermanentMoroccoHybrid

Le job de vos rêves n’est plus qu’à un clic.

Envoyez-nous votre CV et nous vous mettrons directement en contact avec l'un de nos recruteurs spécialisés qui vous guidera dans la recherche de l'emploi de vos rêves !

Numéro de téléphone
Phone
Candidats

Témoignages

Rejoignez notre communauté active de professionnels et découvrez votre potentiel.

Pour vous tenir au courant de nos dernières actualités.