ASMO
Riyadh, Saudi ArabiaPosted today
ASMO is a groundbreaking joint venture between DHL and Saudi Aramco. Inheriting DHL’s logistics excellence and Saudi Aramco’s extensive supply chain ecosystem, we are here to set a new benchmark and redefine the procurement and supply chain landscape, enabling growth. ASMO aims to be operational in 2025 and provide reliable end-to-end integrated procurement and supply chain services for companies across the industrial, energy, chemical, and petrochemical sectors. Our focus customers in the short term will be Saudi Aramco and its Affiliates. In the long term, all the industrial sectors within Saudi Arabia aim to reach the MENA region. Objective The Cybersecurity Third Party Analyst is responsible for managing and overseeing cybersecurity activities related to third parties throughout the vendor lifecycle. The role ensures that third-party organizations including suppliers, vendors, service providers, partners, and outsourced providers comply with the ASMO’s cybersecurity requirements. The position supports third-party cybersecurity governance, security assessments, compliance validation, risk identification, continuous monitoring, and assurance activities. General Responsibilities • Conduct cybersecurity Third-Party risk assessments for new and existing third parties using approved methodologies. • Review third-party security questionnaires, certifications, audit reports, and evidence. • Ensure cybersecurity requirements are incorporated into third-party engagements and contracts. • Verify third-party compliance with applicable security policies, standards, and regulatory obligations. • Monitor critical third parties for cybersecurity posture changes, incidents, and security risks. • Maintain accurate inventory of third parties subject to cybersecurity oversight. • Support integration of third-party cybersecurity controls within the ISMS framework. • Support internal audits, external audits, and regulatory reviews involving third parties. Qualifications • Bachelor’s degree in information technology, or equivalent from a recognized and accredited university is required. • ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, Security+, CISA, CISM, CRISC, CISSP or equivalent. • Minimum 5 years' experience in similar or related field. • Experience in Information Technology / Data Solutions / Networking / Cybersecurity preferred. • Understanding of cybersecurity controls, cloud security, identity and access management, data protection, and vulnerability management. • Demonstrated proficiency in oral and written English. Deadline: 30 days from posting. Show more Show less
Bachelor’s degree in information technology, or equivalent from a recognized and accredited university is required. ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, Security+, CISA, CISM, CRISC, CISSP or equivalent. Minimum 5 years' experience in similar or related field. Experience in Information Technology / Data Solutions / Networking / Cybersecurity preferred. Understanding of cybersecurity controls, cloud security, identity and access management, data protection, and vulnerability management. Demonstrated proficiency in oral and written English.
Not sure you fit this role?
Upload your CV and see how you score against ASMO and every other live job. It's free.
Get my free matchesAED 6k–8k a month· est.