Skip to content

Open nowPosted 97 days ago

Head of Security

Workable (global search)108,016 open roles

Where
Makkah, Makkah Province, Saudi Arabia
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowHead of SecurityWorkable (global search) · Makkah, Makkah Province, Saudi Arabia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 97 days ago

Workable (global search) median: 7 days open

The posting

Role Purpose

As Head of Security at Salla, you are the most senior security authority at Salla. You set the strategy, build the team, and own the controls that keep our platform, our people, and our merchants safe. You translate risk into business language for the executive team and the Board, and you make security a competitive advantage rather than a constraint. You will lead end to end across every security domain and represent Salla's security posture to auditors, regulators, partners, and customers.

Please not that we are looking for Saudi Nationals only for this role.

Key Responsibilities

Security Strategy & Leadership

  • Own and evolve the enterprise security strategy, roadmap, and operating model across cloud, network, endpoint, physical, and GRC, aligned to Salla's growth and public-listing readiness.
  • Act as the organization's principal security advisor; brief the executive team and the Board on cyber risk posture, investment priorities, and regulatory exposure.
  • Define and steward the security budget, headcount plan, and tooling portfolio; drive measurable return on security investment.
  • Establish security KPIs, OKRs, and a metrics-driven reporting cadence for leadership and audit committees.

Cloud Security

  • Lead cloud security across the platform, including landing-zone hardening, network segmentation, secrets management, and workload protection (AWS strongly preferred).
  • Govern Infrastructure-as-Code security, container and Kubernetes security (image scanning, admission control, runtime protection), and CI/CD pipeline integrity.
  • Drive Cloud Security Posture Management, workload protection, and continuous compliance against recognized cloud control frameworks and CIS benchmarks.
  • Partner with SRE and Platform Engineering to embed secure-by-default guardrails that protect velocity rather than slow it.

Network Security

  • Own network security architecture, including edge protection, DDoS mitigation, web application firewall, segmentation, and zero-trust network access.
  • Govern the CDN and edge security stack, bot management, rate limiting, and origin lockdown for high-traffic, merchant-facing services.
  • Oversee secure connectivity, private connectivity, VPN, and DNS security.

Endpoint Security

  • Lead endpoint protection across corporate and engineering fleets, including EDR/XDR, device hardening, mobile device management, and disk encryption.
  • Run a continuous vulnerability and patch management program with clear remediation SLAs.
  • Define and enforce endpoint baselines and data loss prevention controls.

Physical & Facility Security

  • Own physical security for Salla's offices and facilities in Makkah and other sites, including access control, CCTV, visitor management, and environmental controls.
  • Align physical and logical access policies; govern physical access to sensitive areas and equipment.
  • Coordinate with Facilities, HR, and local authorities on safety, badging, and on-site incident response.

Identity & Access Management (Zero Trust)

  • Lead IAM strategy across cloud and corporate systems, including single sign-on, multi-factor authentication, privileged access management, and least-privilege enforcement.
  • Automate joiner, mover, and leaver workflows and run periodic access recertification.
  • Advance the organization toward a mature zero-trust architecture.

Security Operations & Incident Response

  • Build and run the security operations capability, including SIEM, detection engineering, threat intelligence, and continuous monitoring.
  • Own the incident response lifecycle from preparation through detection, containment, eradication, recovery, and blameless post-incident review.
  • Lead tabletop exercises, red and purple teaming, and breach-readiness drills; maintain crisis-communication and breach-notification playbooks.

Governance, Risk & Compliance (GRC)

  • Own the GRC function and the enterprise risk register; run the risk assessment and treatment lifecycle.
  • Lead certification and audit programs spanning ISO/IEC 27001, SOC 2, and PCI DSS, with alignment to the NCA Essential Cybersecurity Controls and Cloud Cybersecurity Controls, and to the SAMA Cyber Security Framework where applicable.
  • Own data protection and privacy compliance under the Saudi Personal Data Protection Law and SDAIA requirements, including data inventories, processing agreements, and cross-border transfer controls.
  • Prepare Salla's security and IT-governance posture for Tadawul listing, including controls maturity, evidence collection, and auditor readiness.
  • Author, ratify, and maintain the full lifecycle of security policies, standards, and procedures.

Third-Party & Vendor Risk

  • Establish and run the third-party risk program, including security due diligence, contractual security terms, and continuous monitoring of critical suppliers.
  • Embed security requirements into procurement and vendor onboarding.

Security Awareness & Culture

  • Build a company-wide security awareness, training, and phishing-simulation program.
  • Champion a positive, blameless security culture in which security is a shared responsibility.

Team Leadership & Organization Building

  • Lead, mentor, and grow a multidisciplinary security organization spanning cloud security, SecOps, GRC, and physical security.
  • Set objectives, develop talent, and build the hiring plan to scale the function with the business.
  • Forge cross-functional partnerships with Engineering, SRE, IT, Legal, HR, and Finance.

Requirements

  • 12+ years in information and cyber security, including 5+ years in senior security leadership (Head of Security, Director, or CISO-track) at a SaaS, fintech, or e-commerce organization.
  • Demonstrated ownership of security across multiple domains: cloud, network, endpoint, physical, and GRC.
  • Deep hands-on and architectural knowledge of cloud security (AWS strongly preferred), including Kubernetes and modern CI/CD.
  • Proven track record building and operating security operations and incident response at scale.
  • Strong GRC experience across ISO 27001, PCI DSS, GDPR and Saudi regulatory frameworks (NCA ECC and CCC, PDPL and SDAIA; SAMA CSF a plus).
  • Experience leading audits and certifications, ideally including IPO or regulatory-readiness programs.
  • Excellent executive communication; able to translate technical risk into business and regulatory language for the Board.
  • Bachelor's degree in Computer Science, Engineering, Information Security, or a related field.
  • Willingness and eligibility to work on-site in Makkah, Saudi Arabia.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.