Skip to main content
Back to jobs

Security Analyst

External
Lucidya logoLucidya · Saudi Arabia
Full-timeRemoteToday
Information Security Analyst
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

About Lucidya Lucidya is an AI-native Customer Experience Intelligence platform empowering enterprises to understand, engage, and retain customers at scale. As we expand, security, compliance, and trust are at the core of our growth strategy. To support this expansion, we are strengthening our security organization and are looking for a Security Analyst to play a key role in bridging GRC, security engineering, and global compliance efforts. About the role As Lucidya grows internationally, maintaining strong security controls and achieving global compliance certifications is mission-critical. This role will directly contribute to implement and achieve security compliance frameworks, ensuring Lucidya meets the highest standards of data protection and information security. You'll work at the intersection of GRC and Security Engineering, supporting compliance initiatives, strengthening internal controls, and enabling secure product development across cross-functional teams. What You'll Be Doing Work closely with GRC and Security Engineering teams to support security, privacy, and compliance initiatives across Saudi Arabia, Qatar, international regions, and the U.S. market Assist in the implementation and ongoing maintenance of ISO/IEC 27001, ISO/IEC 42001 (AI Management Systems), NCA and SOC 2 controls Support U.S. market migration efforts by helping align security and compliance practices with SOC 2, NIST frameworks, and U.S. data privacy requirements Contribute to regional data protection compliance activities, including KSA PDPL, Qatar PDPL, and U.S. states privacy laws, under guidance from senior team members Participate in the creation, update, and maintenance of security, privacy, and AI governance policies, procedures, and control documentation Help with document control, evidence collection, and audit readiness for internal reviews, customer assessments, and external audits Work cross-functionally with engineering, product, and operations teams Day-to-Day Responsibilities Support daily security, privacy, and compliance activities across KSA, MEA and the U.S. Assist with maintaining and updating controls for ISO/IEC 27001, ISO/IEC 42001, NCA, DCC, NIST Help align systems and processes with U.S & Saudi market requirements, including SOC 2 evidence, NIST-aligned controls, and U.S & Saudi data privacy obligations Review security controls for cloud infrastructure, SaaS environments, APIs, and integrations Maintain policies, procedures, and control documentation, ensuring accuracy and version control Collect, organize, and validate audit evidence for internal reviews, customer questionnaires, and external audits Track compliance tasks, findings, and remediation actions in coordination with GRC and Security Engineering teams Collaborate with engineering, product, and operations teams to address security and compliance requirements in day-to-day workflows Support incident response documentation, risk assessments, and compliance reporting as needed Success Metrics ISO & AI Governance Compliance ISO/IEC 27001 and ISO/IEC 42001 (AI Management System) controls assigned to the role remain implemented and evidenced, with zero high-risk audit findings related to security or AI governance. NIST Alignment & Risk Reduction Systems and processes mapped to NIST frameworks (e.g., NIST CSF / NIST AI RMF) show measurable risk reduction, with identified gaps documented and remediated within agreed timelines. Achieve ISO27001 or ISO 42001 lead implementor Independent progression and ownership of assigned tasks First 90 Days Develop a comprehensive understanding of Lucidya 's security tools, processes, and system architecture. Actively contribute to the implementation of the ISO/IEC 42001 framework. Support ongoing compliance initiatives and audit activities. Requirements What We're Looking For Experience & Background 2 - 4 years of experience in a similar Security Analyst / GRC role Experience working with US-based SaaS companies Strong understanding of AI and US compliance frameworks: ISO/IEC 42001 NIST US data privacy regulations Experience in B2B SaaS environments Compliance & Security Knowledge ISO/IEC ISO 27001, ISO/IEC 42001 implementation knowledge (Implementer certification preferred) SOC 2 understanding NCA understanding and practical experience. GDPR knowledge is a plus Penetration testing & vulnerability assessment knowledge Technical Skills API security & integrations Basic scripting (Python, Bash) Code review support for deployments (automated tools) Security reviews of CI/CD pipelines Ruby / Rails code review experience is highly advantageous Certifications CISM (preferred) ISO/IEC 24001 Lead Implementer (mandatory) ISO/IEC 27001 Lead Implementer (mandatory) Soft Skills Excellent professional documentation skills Strong organizational and follow-up abilities Experience with document control and audit evidence Ability to work effectively across distributed, cross-functional teams Nic


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at Lucidya? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect