Senior Manager - Third Party Security

Saudi ArabiaSaudi Arabia·RiyadhFull-timesenior
EngineeringSecurity
0 views0 saves0 applied

Quick Summary

Overview

Lead and manage Qiddiya's Third-Party Security Risk Management program to ensure vendors, partners, consultants,

Technical Tools
EngineeringSecurity

Lead and manage Qiddiya's Third-Party Security Risk Management program to ensure vendors, partners, consultants, and service providers comply with cybersecurity requirements and do not introduce unacceptable risks to Qiddiya's information assets, systems, and operations. The role is responsible for establishing security assessment frameworks, overseeing vendor security reviews, and driving remediation of identified risks. This aligns with industry practices for cybersecurity risk management and third-party oversight.

Responsibilities

~1 min read
  • → Develop and maintain the Third-Party Security Risk Management (TPSRM) framework.
  • → Conduct cybersecurity due diligence and risk assessments for vendors and suppliers.
  • → Review security requirements during procurement, RFP, and contract stages.
  • → Assess cloud providers, SaaS platforms, managed service providers, and strategic partners.
  • → Define vendor security controls aligned with NCA ECC, ISO 27001, NIST, and Qiddiya cybersecurity standards.
  • → Establish vendor risk classification and assessment methodologies.
  • → Monitor remediation plans and track closure of identified security gaps.
  • → Collaborate with Procurement, Legal, Compliance, Enterprise Risk, and Technology teams.
  • → Lead periodic reassessments of critical vendors.
  • → Report third-party cyber risks, trends, and KPIs to senior management.
  • → Manage external security audits, questionnaires, and assurance activities.
  • → Lead and develop the Third-Party Security team.

Requirements

~1 min read
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, or related field.
  • 8–12 years of cybersecurity experience.
  • Minimum 4 years in Third-Party Security, Vendor Risk Management, Cybersecurity Risk Management, or GRC.
  • Experience within large enterprises, giga projects, banking, telecom, government, or critical infrastructure environments.
  • Experience managing teams and stakeholder engagement at senior levels.

Location & Eligibility

Where is the job
Riyadh, Saudi Arabia
On-site at the office

Listing Details

Posted
September 22, 2026
First seen
September 29, 2026
Last seen
September 29, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
30%
Scored at
September 30, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Senior Manager - Third Party Security