Lucidya | لوسيديا logo
Lucidya | لوسيديا

The leading Customer Experience Management platform geared towards Arab.

GRC and Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteMid LevelTeam 51-200H1B No SponsorCompany SiteLinkedIn

Location

Northern America + 1 moreAll locations: Northern America | Western Asia (Middle East)

Posted

9 days ago

Salary

0

Seniority

Mid Level

Job Description

GRC and Security Analyst

Lucidya | لوسيديا

Role Description As Lucidya grows internationally, maintaining strong security controls and achieving global compliance certifications is mission-critical. This role will directly contribute to implement and achieve security compliance frameworks, ensuring Lucidya meets the highest standards of data protection and information security. You’ll work at the intersection of GRC and Security Engineering, supporting compliance initiatives, strengthening internal controls, and enabling secure product development across cross-functional teams. What You’ll Be Doing - Work closely with GRC and Security Engineering teams to support security, privacy, and compliance initiatives across Saudi Arabia, Qatar, international regions, and the U.S. market. - Assist in the implementation and ongoing maintenance of ISO/IEC 27001, ISO/IEC 42001 (AI Management Systems), NCA and SOC 2 controls. - Support U.S. market migration efforts by helping align security and compliance practices with SOC 2, NIST frameworks, and U.S. data privacy requirements. - Contribute to regional data protection compliance activities, including KSA PDPL, Qatar PDPL, and U.S. states privacy laws, under guidance from senior team members. - Participate in the creation, update, and maintenance of security, privacy, and AI governance policies, procedures, and control documentation. - Help with document control, evidence collection, and audit readiness for internal reviews, customer assessments, and external audits. - Work cross-functionally with engineering, product, and operations teams. Day-to-Day Responsibilities - Support daily security, privacy, and compliance activities across KSA, MEA and the U.S. - Assist with maintaining and updating controls for ISO/IEC 27001, ISO/IEC 42001, NCA, DCC, NIST. - Help align systems and processes with U.S & Saudi market requirements, including SOC 2 evidence, NIST-aligned controls, and U.S & Saudi data privacy obligations. - Review security controls for cloud infrastructure, SaaS environments, APIs, and integrations. - Maintain policies, procedures, and control documentation, ensuring accuracy and version control. - Collect, organize, and validate audit evidence for internal reviews, customer questionnaires, and external audits. - Track compliance tasks, findings, and remediation actions in coordination with GRC and Security Engineering teams. - Collaborate with engineering, product, and operations teams to address security and compliance requirements in day-to-day workflows. - Support incident response documentation, risk assessments, and compliance reporting as needed. Success Metrics - ISO & AI Governance Compliance: ISO/IEC 27001 and ISO/IEC 42001 (AI Management System) controls assigned to the role remain implemented and evidenced, with zero high-risk audit findings related to security or AI governance. - NIST Alignment & Risk Reduction: Systems and processes mapped to NIST frameworks (e.g., NIST CSF / NIST AI RMF) show measurable risk reduction, with identified gaps documented and remediated within agreed timelines. - Achieve ISO27001 or ISO 42001 lead implementor. - Independent progression and ownership of assigned tasks. What We’re Looking For Experience & Background - 2 - 4 years of experience in a similar Security Analyst / GRC role. - Experience working with US-based SaaS companies. - Strong understanding of AI and US compliance frameworks: - ISO/IEC 42001 - NIST - US data privacy regulations - Experience in B2B SaaS environments. Compliance & Security Knowledge - ISO/IEC ISO 27001, ISO/IEC 42001 implementation knowledge (Implementer certification preferred). - SOC 2 understanding. - NCA understanding and practical experience. - GDPR knowledge is a plus. - Penetration testing & vulnerability assessment knowledge. Technical Skills - API security & integrations. - Basic scripting (Python, Bash). - Code review support for deployments (automated tools). - Security reviews of CI/CD pipelines. - Ruby / Rails code review experience is highly advantageous. Certifications - CISM (preferred). - ISO/IEC 24001 Lead Implementer (mandatory). - ISO/IEC 27001 Lead Implementer (mandatory). Soft Skills - Excellent professional documentation skills. - Strong organizational and follow-up abilities. - Experience with document control and audit evidence. - Ability to work effectively across distributed, cross-functional teams. Nice-to-Have Experience - Prior remote work with US-based teams. - Experience supporting global compliance programs. - Hands-on involvement in multiple certification cycles. Hiring Process - Screening Interview by Mawhub - “Esraa Adel - Senior Talent Acquisition Partner”. - First Technical interview - “Mostafa Asaad - Security Delivery Manager”. - Culture Fit Interview - Youssef Okal - “TA Lead @ Lucidya”. Why Join Us? This role offers the opportunity to influence and enhance Lucidya’s governance, risk, and compliance practices at scale. You will contribute to strengthening security controls, driving compliance initiatives, mitigating organizational risk, and supporting a culture of security across the company.

Related Job Pages

More Security Analyst Jobs

UTMB Health - University of Texas Medical Branch logo

Cyber Security Analyst

UTMB Health - University of Texas Medical Branch

UTMB Health, also known as The University of Texas Medical Branch, is an award-winning healthcare system based in Galveston, Texas. A nationally recognized teaching hospital, UTMB

Title: Cyber-Security Analyst - IS-Security Location: Galveston United States Job Description: Minimum Qualifications: Bachelor's degree and one (1) year of IT or security experience. An equivalent combination of education and experience relevant to the role may be considered for this position. Preferred Qualifications: - 3 years of cybersecurity experience. - Python, Rust, C, C+, Java, and/or PowerShell. - Academic and/or working experience with TCP/IP networking, and networking services such as DNS, SMTP, DHCP, etc. - Windows, MacOS, Linux-variant operating systems, such as the file system structure, system services, and typical behavior of endpoints and servers - Cloud-based services such as Microsoft Office 365 and Azure productivity tools. Job Summary: The Security Analyst on the Governance, Risk, and Compliance (GRC) team plays a critical role in safeguarding sensitive information resources and data, ensuring organizational compliance with industry regulations. This position supports the development, implementation, and monitoring of security policies, risk management processes, and compliance frameworks such as HIPAA, TAC 202, UTS 165, and NIST cybersecurity standards. Job Duties: Under direct supervision, the Security Analyst supports the organization's information resources, security environments, and applications to ensure they remain adequately protected and aligned with the NIST Cybersecurity Framework (CSF). The role assists in activities across the CSF functions: Identify, Protect, Detect, Respond, and Recover, including supporting asset classification, implementing security controls, monitoring for anomalous activity, and participating in 24/7 incident response processes. - Complete CompTIA CySA+ certification training and successfully pass the exam within 90 days of hire. - Work assigned shifts supporting 24x7x365 Tier 1 SOC operations. - Perform alert triage across on-premises and cloud security technologies, including SIEM, IDS, antivirus, cloud services, Windows servers, network infrastructure, DLP, UBA, and user-submitted security reports. - Apply basic security controls to contain malicious activity and prevent unauthorized disclosure of sensitive information. - Escalate alerts to Tier 2 based on severity and priority, supporting follow-on incident response activities. - Contribute to SOC workflow improvements by identifying false positives and recommending process enhancements. - Assist with incident response through resolution and help develop after-action reports. - Participate in ongoing skill development to strengthen investigation and response capabilities. - Adhere to internal controls, reporting structures, and all applicable standards, processes, and procedures. - Perform other related duties as assigned by management. Working Environment: Any qualifications to be considered as equivalents in lieu of stated minimums require the prior approval of the Chief Human Resources Officer or designee. The University of Texas Medical Branch at Galveston is an Equal Opportunity / Affirmative Action University. Specific job requirements or physical location of some positions allocated to this classification may render this position security sensitive, and thereby subject to the provisions of Section 51.215, Texas Education Code. To the extent this position qualifies as a position that researches, works on, or has access to critical infrastructure as defined in Section 117.001(2) of the Texas Business and Commerce Code, there is a requirement for any applicant, employee, or contractor to have the ability to maintain the security or integrity of the infrastructure. Therefore, if applicable, anyone hired in this position or continued to be employed in this position must be routinely reviewed to determine whether they are able to maintain the security or integrity of the infrastructure. Salary Range: Actual salary commensurate with experience. Work Schedule: Remote local position, rotating shifts, including nights and weekends. Equal Employment Opportunity UTMB Health strives to provide equal opportunity employment without regard to race, color, religion, age, national origin, sex, gender, sexual orientation, gender identity/expression, genetic information, disability, veteran status, or any other basis protected by institutional policy or by federal, state or local laws unless such distinction is required by law.

Texas

Junior Security Analyst

NTT DATA Services

NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers, and application services. Our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.

Role Description The Junior Security Analyst, working closely with other analysts, will be a key contributor in providing cyber security advisory services. These services include: - Evaluating the effectiveness of security programs - Assessing risks and vulnerabilities - Identifying control gaps - Reviewing vendor reports for consistency and accuracy - Managing remediation efforts - Conducting independent security and privacy assessments - Contributing to security independent verification and validation (IV&V) activities - Reporting/presenting findings to senior state staff Job Responsibilities Include: - Analysis and comprehension of client’s overall security program and posture - Assessing technical compliance of systems against specified frameworks/requirements - Contributing to the discovery, assessment, analysis, and management of network and application vulnerabilities and remediation efforts - Identifying and documenting detailed remediation recommendations - Understanding relevant laws and regulations for security and privacy requirements - Providing consultation and framework gap analysis of vendor deliverables to the client - Drafting or recommending updates to policies, standards, procedures, and related security and privacy deliverables Qualifications - Minimum five years’ combined experience working with: - IT Audits and Assessments - Vulnerability management and/or assessing firewalls and networks, including VPN, DLP, IDS/IPS - HIPAA, CMS MARS-E, NIST, ARC-AMPE Security and Privacy control frameworks - IT governance, risk, compliance (GRC), auditing, drafting security plans and conducting risk assessments - Hold one or more privacy or security certifications such as IAPP, CHPC, CIPP, CISA, CISM, CISSP - Undergraduate degree or 4 years’ additional relevant experience Requirements - Master’s degree in computer science, management information systems, or related fields - Experience working with State DHS Privacy and/or Security - Comprehensive understanding of security and privacy controls - Exceptional analytical, communication, and collaboration skills - Thorough understanding of NIST, MARS-E, CMS Certification Frameworks - Ability to understand and translate technical jargon - Advanced client and vendor relationship management Benefits - Medical, dental, and vision insurance with an employer contribution - Flexible spending or health savings account - Life and AD&D insurance - Short and long term disability coverage - Paid time off - Employee assistance - Participation in a 401k program with company match - Additional voluntary or legally-required benefits

United States
$70K - $115K / year

Security Analyst

NTT DATA Services

NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers, and application services. Our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.

Role Description The Security Analyst, working closely with other analysts, will be a key contributor in providing cyber security advisory services. These services include: - Evaluating the effectiveness of security programs - Assessing risks and vulnerabilities - Identifying control gaps - Reviewing vendor reports for consistency and accuracy - Managing remediation efforts - Conducting independent security and privacy assessments - Contributing to security independent verification and validation (IV&V) activities - Reporting/presenting findings to senior state staff Job Responsibilities Include: - Analysis and comprehension of client’s overall security program and posture - Assessing technical compliance of systems against specified frameworks/requirements - Contributing to the discovery, assessment, analysis, and management of network and application vulnerabilities and remediation efforts - Identifying and documenting detailed remediation recommendations - Understanding relevant laws and regulations for security and privacy requirements - Providing consultation and framework gap analysis of vendor deliverables to the client - Drafting or recommending updates to policies, standards, procedures, and related security and privacy deliverables Qualifications - Minimum 6 years combined experience working with: - IT Audits and Assessments - Vulnerability management and/or assessing firewalls and networks, including VPN, DLP, IDS/IPS - HIPAA, CMS MARS-E, NIST, ARC-AMPE Security and Privacy control frameworks - IT governance, risk, compliance (GRC), auditing, drafting security plans and conducting risk assessments - Hold one or more privacy or security certifications such as IAPP, CHPC, CIPP, CISA, CISM, CISSP - Undergraduate degree or 4 years’ additional relevant experience Preferred Skills - Masters Degree in Computer Science Management Information Systems, or related fields - Experience working with State DHS Privacy and/or Security - Comprehensive understanding of security and privacy controls - Exceptional analytical, communication, and collaboration skills - Thorough understanding of NIST, MARS-E, CMS Certification Frameworks - Ability to understand and translate technical jargon - Advanced client and vendor relationship management Requirements Where required by law, NTT DATA provides a reasonable range of compensation for specific roles. The starting pay range for this remote role is $80,000 - $130,000. This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on a number of factors, including the candidate’s actual work location, relevant experience, technical skills, and other qualifications. Benefits - Medical, dental, and vision insurance with an employer contribution - Flexible spending or health savings account - Life and AD&D insurance - Short and long term disability coverage - Paid time off - Employee assistance - Participation in a 401k program with company match - Additional voluntary or legally-required benefits

United States
$80K - $130K / year
Fresenius Medical Care logo

Information Security Governance Analyst

Fresenius Medical Care

Fresenius Medical Care provides dialysis treatments, products, and services for individuals living with chronic kidney diseases (CKD). Founded as a result of the 1996 merger of Fre

Role Description The Governance, Risk, and Compliance Analyst will play a key role in facilitating the development and maintenance of the organization's global governance, risk management, and compliance programs. This position will support a broad range of activities across the organization. - Facilitates the development, implementation, and maintenance of an information security framework aligned with industry best practices. - Facilitates the design and documentation of technical, administrative, and physical controls to ensure the business demonstrates compliance with its regulatory and compliance obligations. - Provides advice & counsel as directed within IT and information security initiatives to ensure the delivery of compliant and risk-appropriate solutions following existing department policies, standards, and procedures. - Facilitates examinations by security assessors and auditors for compliance obligations, such as HIPAA and ISO 27001. - Facilitates security risk assessments and recommends controls to mitigate identified security risks. - Communicates risk findings and recommendations to business stakeholders. - Facilitates the development and deployment of workforce security training and awareness. - Facilitates the development and implementation of global cybersecurity policies, standards, and procedures aligned with industry best practices, including NIST CSF and 800-series publications. - Facilitates the lifecycle management of information security policies. - Additional responsibilities may include focus on one or more departments or locations. Qualifications - Bachelor's Degree or an equivalent combination of education and experience. - 2+ years' related experience in cybersecurity governance, risk, compliance, information security, and/or other related roles. - Advanced knowledge of internal control structure, data, and technology. - Advanced knowledge of NIST CSF, NIST SP 800-series, HIPAA, FIPS, and ISO 27001:2022, and other industry best standards and requirements. - Excellent verbal and written communication skills. - Excellent organizational skills. - CISSP, CRISC, CISA, CISM, or other related certifications are preferred. - Demonstrated experience with ServiceNow IRM or a similar tool is preferred. Requirements - The rate of pay for this position will depend on the successful candidate’s work location and qualifications, including relevant education, work experience, skills, and competencies. - Annual Rate: $72,000.00 - $121,000.00 Benefits - This position offers a comprehensive benefits package including medical, dental, and vision insurance. - A 401(k) with company match. - Paid time off. - Parental leave.

United States
$72K - $121K / year