Req ID:  4446

Senior Officer, Delivery

Date:  5 Oct 2026
Company:  Saudi Xerox Agencies Co.
Location: 

Riyadh, SA

Department:  Commercial
Sub Department:  Commercial – Project Delivery
Number of Openings:  1

Role Purpose:

 

Design, deploy, secure, operate and continuously improve enterprise network and cybersecurity environments across on-premises, private-cloud, public-cloud and hybrid infrastructures. Provide hands-on technical delivery and managed-services support for network security, cloud networking, endpoint security, data protection, encryption, identity controls, monitoring and incident response. Translate business and security requirements into resilient, scalable and compliant solutions while maintaining documentation and agreed service levels.

 

Key Accountabilities

Key Activities

Network Security Operations

• Manage enterprise firewalls, security gateways and secure remote access across data centers, branches and cloud environments.

• Configure and monitor IDS/IPS, threat prevention, web filtering, application control and network malware protection.

• Design segmentation and micro-segmentation using VLANs, VRFs, subnets, security zones, security groups and access-control policies.

• Support routing, switching, DNS, DHCP, load balancing, wireless, SD-WAN, site-to-site VPN, client VPN and private connectivity.

• Monitor availability, capacity and security events; troubleshoot complex issues and perform root-cause analysis.

Cloud & Hybrid Network Engineering

• Design and manage virtual networks across supported public and private cloud platforms, including approved subnets and security zones.

• Configure security groups, cloud firewall controls, route tables, gateways, private endpoints and platform connectivity services.

• Manage IP addressing, DNS, network interfaces and deployment of cloud resources into approved network segments.

• Configure cloud peering and secure hybrid connectivity through VPN, dedicated circuits, interconnect services and routing gateways.

• Maintain cloud-network diagrams, IP plans, dependency maps, configuration baselines and runbooks.

Endpoint Security & Hardening

• Administer EDR/XDR, anti-malware, host firewall, application control, device control and endpoint-detection policies.

• Implement server and endpoint hardening, security baselines, patching controls, vulnerability remediation and compliance policies.

• Investigate alerts, isolate affected devices when authorized, coordinate containment and recovery, and document findings.

• Support mobile-device management, unified endpoint management and secure access controls.

Data Protection, DLP & Classification

• Implement DLP policies across endpoints, email, collaboration platforms, cloud services and supported applications.

• Enforce classification, sensitivity labeling, handling, retention and secure information-sharing controls.

• Configure encryption for data at rest and in transit across disks, files, databases, storage, backup and communications.

• Support discovery, policy tuning, exceptions, alert investigation and compliance evidence collection.

Key, Vault, Certificate & Secrets Management

• Manage enterprise or cloud vaults, key stores, HSM integrations and secrets-management services.

• Generate or securely import cryptographic material and manage key lifecycle, rotation, revocation, archival and retirement.

• Manage secrets, service credentials, tokens and certificates, including permissions, expiry, renewal and audit logs.

• Assign encryption keys to supported storage, database, backup, virtual-disk and application resources.

Identity, Access & Cloud Security Governance

• Configure and review IAM users, roles, groups, service identities, policies and privileged access using least privilege and segregation of duties.

• Implement MFA, conditional access and secure administrative access where supported.

• Apply cloud-security posture, workload protection, logging, monitoring, configuration and compliance controls.

• Participate in architecture reviews, risk and vulnerability assessments, and remediation planning.

Security Monitoring & Incident Response

• Integrate network, cloud, endpoint, identity and security platforms with centralized monitoring, SIEM, SOC and managed-detection services.

• Monitor alerts and logs, triage incidents, collect evidence and coordinate escalation, containment, recovery and post-incident actions.

• Maintain use cases, alert rules, dashboards, health checks and operational reports.

• Perform root-cause analysis and recommend preventive improvements.

Deployment, Managed Services & Documentation

• Deliver implementation, migration, configuration, testing, handover and ongoing support for cloud and on-premises network-security projects.

• Prepare HLD/LLD, method statements, implementation, test and rollback plans, as-built records and operational runbooks.

• Execute incidents, requests, changes and problems within agreed SLAs and change-management procedures.

• Coordinate with customers, internal teams, OEMs, cloud providers, carriers and security partners.

• Provide workshops, knowledge transfer, technical discovery, estimation, bills of materials and pre-sales support when required.

 

 

JOB SPECIFICATIONS

Industry / Domain

Enterprise networking, cloud and hybrid infrastructure, cybersecurity, managed services, network operations, security operations and technical consulting.

Necessary Knowledge and Experience

• Minimum 7 years of hands-on experience in network, security, infrastructure or cloud engineering roles.

• Experience supporting enterprise or managed-services environments across cloud and on-premises infrastructure.

• Hands-on implementation and troubleshooting of firewalls, routing, switching, VPNs, segmentation, endpoint protection and security controls.

• Practical experience with at least one major public-cloud platform and ability to work across additional platforms.

• Experience producing implementation documents, operational runbooks and customer-facing technical reports.

Education and Certification Requirements

• Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, Information Systems or a related discipline; equivalent certified experience may be considered.

• Preferred: recognized cloud architecture, cloud security or cloud networking certification.

• Preferred: CCNP Enterprise/Security, Fortinet, Palo Alto Networks, Check Point or equivalent network-security certification.

• Preferred: CISSP, CISM, Security+, CySA+ or equivalent cybersecurity certification.

• Endpoint, identity, information-protection, SIEM, security-operations or ITIL certification is advantageous.

Job Specific Technical Skills

• TCP/IP, IPv4/IPv6, VLAN, VRF, BGP, OSPF, DNS, DHCP, VPN, SD-WAN, load balancing, wireless and hybrid connectivity.

• Next-generation firewalls, IDS/IPS, segmentation, Zero Trust, remote access and security-rule governance.

• Cloud virtual networking, compute, storage, databases, IAM, logging, monitoring, vaults and key management.

• EDR/XDR, endpoint hardening, vulnerability remediation, patching and compliance.

• DLP, classification, labeling, encryption, PKI, certificates, key lifecycle, secrets management and secure data handling.

• SIEM/SOC integration, incident response, problem and change management, capacity, availability and DR awareness.

• Scripting and Infrastructure as Code using PowerShell, Python, Terraform or equivalent is preferred.

• Architecture diagrams, HLD/LLD, as-built configurations, implementation plans, test evidence and operational reports.