Lucidya logo
Security Analyst
full-timeRiyadh

Summary

Location

Riyadh

Type

full-time

Explore Jobs

About this role

About Lucidya

Lucidya is an AI-native Customer Experience Intelligence platform empowering enterprises to understand, engage, and retain customers at scale. As we expand, security, compliance, and trust are at the core of our growth strategy.

To support this expansion, we are strengthening our security organization and are looking for a Security Analyst to play a key role in bridging GRC, security engineering, and global compliance efforts.

About the role

As Lucidya grows internationally, maintaining strong security controls and achieving global compliance certifications is mission-critical. This role will directly contribute to achieving multiple compliance certifications per quarter, ensuring Lucidya meets the highest standards of data protection and information security.

You’ll work at the intersection of GRC and Security Engineering, supporting compliance initiatives, strengthening internal controls, and enabling secure product development across cross-functional teams.

What You’ll Be Doing
  • Work closely with GRC and Security Engineering teams to support security, privacy, and compliance initiatives across Saudi Arabia, Qatar, international regions, and the U.S. market
  • Assist in the implementation and ongoing maintenance of ISO/IEC 27001, ISO/IEC 42001 (AI Management Systems), and SOC 2 controls
  • Support U.S. market migration efforts by helping align security and compliance practices with SOC 2, NIST frameworks, and U.S. data privacy requirements
  • Contribute to regional data protection compliance activities, including KSA PDPL, Qatar PDPL, and U.S. state privacy laws, under guidance from senior team members
  • Participate in the creation, update, and maintenance of security, privacy, and AI governance policies, procedures, and control documentation
  • Support penetration testing, vulnerability management, and security assessments, and help track remediation actions
  • Help with document control, evidence collection, and audit readiness for internal reviews, customer assessments, and external audits
  • Work cross-functionally with engineering, product, and operations teams
Day-to-Day Responsibilities
  • Support daily security, privacy, and compliance activities across KSA, Qatar, international regions, and the U.S.
  • Assist with maintaining and updating controls for ISO/IEC 27001, ISO/IEC 42001, and SOC 2
  • Help align systems and processes with U.S. market requirements, including SOC 2 evidence, NIST-aligned controls, and U.S. data privacy obligations
  • Review security controls for cloud infrastructure, SaaS environments, APIs, and integrations
  • Support vulnerability management, penetration testing coordination, and remediation tracking
  • Maintain policies, procedures, and control documentation, ensuring accuracy and version control
  • Collect, organize, and validate audit evidence for internal reviews, customer questionnaires, and external audits
  • Track compliance tasks, findings, and remediation actions in coordination with GRC and Security Engineering teams
  • Collaborate with engineering, product, and operations teams to address security and compliance requirements in day-to-day workflows
  • Support incident response documentation, risk assessments, and compliance reporting as needed
Success Metrics
  • ISO & AI Governance Compliance
    • ISO/IEC 27001 and ISO/IEC 42001 (AI Management System) controls assigned to the role remain implemented and evidenced, with zero high-risk audit findings related to security or AI governance.
  • NIST Alignment & Risk Reduction
    • Systems and processes mapped to NIST frameworks (e.g., NIST CSF / NIST AI RMF) show measurable risk reduction, with identified gaps documented and remediated within agreed timelines.
  • Achieve ISO27001 lead implementor
  • Independent progression and ownership of assigned tasks
  • First 90 Days
    • Gain a strong understanding of Lucidya’s security tools, processes, and architecture
    • Actively contribute to ISO 27001 policy and procedure creation
    • Support ongoing compliance initiatives and audits
    What We’re Looking For

    Experience & Background

    • 2 - 4 years of experience in a similar Security Analyst / GRC role
    • Experience working with US-based SaaS companies
    • Strong understanding of US compliance frameworks:
      • NIST
      • US data privacy regulations
    • Experience in B2B SaaS environments

    Compliance & Security Knowledge

    • ISO 27001, ISO42001 implementation knowledge (Implementer certification preferred)
    • SOC 2 (NCE) understanding
    • GDPR knowledge is a plus
    • Penetration testing & vulnerability assessment knowledge

    Technical Skills

    • API security & integrations
    • Basic scripting (Python, Bash)
    • Code review support for deployments (automated tools)
    • Security reviews of CI/CD pipelines
    • Ruby / Rails code review experience is highly advantageous

    Certifications

    • CISM (preferred)
    • ISO 24001 Lead Implementer (preferred)

    Soft Skills

    • Excellent professional documentation skills
    • Strong organizational and follow-up abilities
    • Experience with document control and audit evidence
    • Ability to work effectively across distributed, cross-functional teams

    Nice-to-Have Experience

    • Prior remote work with US-based teams
    • Experience supporting global compliance programs
    • Hands-on involvement in multiple certification cycles

    If you’re passionate about security, compliance, and global scale, and want to help shape the security foundation of a fast-growing AI company -  we’d love to hear from you

    Other facts

    Tech stack
    Security Analyst,GRC,Compliance,ISO 27001,SOC 2,NIST,Data Privacy,Vulnerability Management,Penetration Testing,API Security,SaaS,Documentation,Organizational Skills,Cross-Functional Collaboration,Risk Assessment,Audit Readiness

    About Lucidya

    Lucidya is an AI-powered unified customer experience platform (CXM) designed to support CX and Marketing leaders in large enterprises, governments, and SMEs. Our platform is tailored for organizations in the Arab world that need a unified, easy-to-use platform to manage their customer experiences and make data-driven decisions.

    Lucidya’s AI-powered technology, combined with a deep understanding of the Arabic language and culture—with a remarkable 92% analysis accuracy of 15 different dialects and slang—allows businesses to engage with their customers in ways that are both accurate and personal. By offering real-time insights and engagement, Lucidya helps organizations optimize customer lifecycles, reduce costs, and drive growth—all in one single platform.

    Lucidya is fully compliant with global and regional data privacy and security regulations, including SOC2 for data management standards, the SDAIA Personal Data Protection Law (PDPL) in Saudi Arabia, and GDPR for customers in the EU. Lucidya also adheres to the NIST Cybersecurity Framework (CSF), ensuring robust risk management practices, and complies with key US data privacy regulations such as CCPA/CPRA, UCPA, CTDPA, CPA, and VCDPA. This commitment ensures that our platform not only delivers actionable insights but also operates securely and protects the privacy of our customers’ data.

    Team size: 201-500 employees
    LinkedIn: Visit
    Industry: Software Development
    Founding Year: 2016

    What you'll do

    • The Security Analyst will support security, privacy, and compliance initiatives across various regions, ensuring adherence to standards like ISO/IEC 27001 and SOC 2. They will also assist in maintaining security controls and documentation for audits and compliance assessments.

    Ready to join Lucidya?

    Take the next step in your career journey

    Frequently Asked Questions

    What does a Security Analyst do at Lucidya?

    As a Security Analyst at Lucidya, you will: the Security Analyst will support security, privacy, and compliance initiatives across various regions, ensuring adherence to standards like ISO/IEC 27001 and SOC 2. They will also assist in maintaining security controls and documentation for audits and compliance assessments..

    Why join Lucidya as a Security Analyst?

    Lucidya is a leading Software Development company.

    Is the Security Analyst position at Lucidya remote?

    The Security Analyst position at Lucidya is based in Riyadh, Riyadh Region, Saudi Arabia. Contact the company through Clera for specific work arrangement details.

    How do I apply for the Security Analyst position at Lucidya?

    You can apply for the Security Analyst position at Lucidya directly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process. You can also learn more about Lucidya on their website.