الوصف الوظيفي
الأدوار والمسؤوليات
خبير عمليات الأمن السيبراني مسؤول عن دعم خط الدفاع الأول من خلال التنفيذ اليومي، والمراقبة، وتحسين ضوابط الأمان التشغيلية عبر بيئات تكنولوجيا المعلومات المؤسسية. يركز الدور على حماية الأنظمة والشبكات والحواسيب والواجهات والتطبيقات والمستخدمين من خلال اكتشاف التهديدات والاستجابة لحداث الأمان، وتنسيق أنشطة الإصلاح، والحفاظ على عمليات الأمن السيبراني الفعالة. تشمل المسؤوليات الرئيسية المراقبة المستمرة لتحذيرات وأحداث الأمان والبريد الإلكتروني ومنصات الأمان التشغيلية الأخرى، وضمان اتخاذ إجراءات الإح containment والتعافي في الوقت المناسب. كما يدعم دور الأمن السيبراني إدارة الثغرات من خلال تتبع النتائج، وتنسيق الإصلاح مع فرق البنية التحتية والتطبيقات، والتحقق من إغلاق المخاطر المحددة. يعمل خبير عمليات الأمن السيبراني عن كثب مع عمليات تكنولوجيا المعلومات، وفرق الشبكة، والسحابة، والخادمات، والحواسيب الطرفية، والتطبيقات لضمان تنفيذ الضوابط الأمنية وفاعليتها كجزء من العمليات اليومية للأعمال والتكنولوجيا. كما تشمل المسؤوليات دعم عمليات الهوية والتحكم في الوصول، ومراجعة أنشطة الوصول المتميز، وفرض معايير الأمان، والحفاظ على دفاتر التشغيل وإجراءات التشغيل، والمساهمة في وعي الأمان من منظور تشغيلي. هذا المنصب جزء من خط الدفاع الأول وبالتالي يركز على التشغيل والتنفيذ للضوابط بدلاً من إجراء إشراف مستقل، حوكمة السياسة، ضمان الامتثال التنظيمي، أو أنشطة التدقيق الداخلي المتعلقة بخطوط الدفاع الثانية أو الثالثة.
المسؤوليات:
- مراقبة وتحليل تنبيهات وأحداث وأحداث الأمن السيبراني.
- إجراء الفرز الأولي، والتحقيق، ودعم الاحتواء، وتصعيد حوادث الأمن.
- دعم عمليات أمان نقاط النهاية، والشبكة، والسحابة، والبريد الإلكتروني.
- تنسيق إصلاح الثغرات مع فرق التقنية المعنية.
- تنفيذ وصيانة ضوابط الأمن التشغيلية وحالات استخدام الرصد.
- مراقبة ودعم التصحيح المرتبط بالأمان، وترقيات المنصة، وتحديثات التكنولوجيا التشغيلية لضمان الحد الأدنى من التعرض للأمان والتعطل الخدمي.
- دعم أنشطة الأمان خلال ترحيل الأنظمة، والأدوات، والبنية التحتية، بما في ذلك التحقق من الضوابط، ومراجعات التكوين، وفحوصات الأمان بعد الترحيل.
- مراجعة والتحقق من الاندماجات الأمنية بين أدوات الأمن السيبراني، وأنظمة تكنولوجيا المعلومات، ومنصات السحابة، والحلول من الجهات الخارجية لضمان التسجيل المناسب، والتنبيه، والاتصال، وفاعلية الضبط.
- دعم مراجعات الوصول، ومراقبة الوصول المميز، وعمليات الأمن المرتبطة بالهوية.
- الحفاظ على إجراءات الاستجابة للحوادث ودفاتر التشغيل والوثائق التشغيلية.
- تتبع إجراءات الإصلاح والمتابعة في أنشطة تقليل المخاطر.
- الإسهام في التحسين المستمر لأنشطة وعمليات الأمن السيبراني.
- دعم المرونة التشغيلية للأعمال من خلال تقليل التعرض لمخاطر الأمن السيبراني.
الملف المرشح المطلوب
- درجة البكالوريوس في الأمن السيبراني، أو أمن المعلومات، أو علوم الحاسوب، أو تكنولوجيا المعلومات، أو الهندسة، أو مجال ذو صلة.
- 5+ سنوات من الخبرة في عمليات الأمن السيبراني، مراقبة الأمن، الاستجابة للحوادث، إدارة الثغرات، أو وظائف هندسة الأمن.
- خبرة عملية مع تقنيات الأمن المؤسسي، بما في ذلك SIEM، EDR/XDR، أمان البريد الإلكتروني، إدارة الهوية والوصول، أمان الشبكات، أمان السحابة، ومنصات إدارة الثغرات.
- فهم قوي للأطر الأمنية السيبرانية، وتقنيات الهجوم، وطرق اكتشاف التهديدات، وأفضل ممارسات عمليات الأمن.
- خبرة في العمل ضمن بيئات هجينة تمتد عبر البنى التحتية المحلية، ومنصات السحابة، وخدمات الأطراف الثالثة.
- الشهادات المفضلة Certified Information Systems Security Professional (CISSP) و Certified Information Security Manager (CISM)
Job Description
Roles & Responsibilities
Cybersecurity Operations Expert responsible for supporting the first line of defense through the day-to-day execution, monitoring, and improvement of operational security controls across enterprise IT environments. The role focuses on protecting systems, networks, endpoints, applications, and users by detecting threats, responding to security events, coordinating remediation activities, and maintaining effective cybersecurity operations. Key responsibilities include continuous monitoring of security alerts and events, email security, and other operational security platforms, and ensuring timely containment and recovery actions. The role also supports vulnerability management by tracking findings, coordinating remediation with infrastructure and application teams, and validating closure of identified risks. The Cybersecurity Operations Expert works closely with IT operations, network, cloud, server, endpoint, and application teams to ensure security controls are implemented and functioning effectively as part of daily business and technology operations. Responsibilities also include supporting identity and access security operations, reviewing privileged access activities, enforcing security baselines, maintaining playbooks and operational procedures, and contributing to security awareness from an operational perspective. This position is part of the first line of defense and is therefore focused on operating and executing controls rather than performing independent oversight, policy governance, regulatory compliance assurance, or internal audit activities associated with the second or third lines of defense.
Responsibilities:
- Monitor and analyze cybersecurity alerts, events, and incidents.
- Perform initial triage, investigation, containment support, and escalation of security incidents.
- Support endpoint, network, cloud, and email security operations.
- Coordinate vulnerability remediation with relevant technical teams.
- Execute and maintain operational security controls and monitoring use cases.
- Monitor and support security-related patching, platform upgrades, and operational technology refresh activities to ensure minimal security exposure and service disruption.
- Support security activities during system, tool, and infrastructure migrations, including validation of controls, configuration reviews, and post-migration security checks.
- Review and validate security integrations between cybersecurity tools, IT systems, cloud platforms, and third-party solutions to ensure proper logging, alerting, connectivity, and control effectiveness.
- Support access control reviews, privileged access monitoring, and identity-related security operations.
- Maintain incident response procedures, runbooks, and operational documentation.
- Track remediation actions and follow up on risk reduction activities.
- Contribute to continuous improvement of cybersecurity activities and processes.
- Support business resilience by reducing operational cyber risk exposure.
Desired Candidate Profile
- Bachelor s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field.
- 5+ years of experience in cybersecurity operations, security monitoring, incident response, vulnerability management, or security engineering functions.
- Hands-on experience with enterprise security technologies, including SIEM, EDR/XDR, email security, identity and access management, network security, cloud security, and vulnerability management platforms.
- Strong understanding of cybersecurity frameworks, attack techniques, threat detection methodologies, and security operations best practices.
- Experience working in hybrid environments spanning on-premises infrastructure, cloud platforms, and third-party services.
- Preferred Certifications Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM)