وصف الوظيفة
خبير عمليات الأمن السيبراني المسؤول عن دعم خط الدفاع الأول من خلال التنفيذ اليومي، والمراقبة، وتحسين ضوابط الأمن التشغيلي عبر بيئات تكنولوجيا المعلومات المؤسسية. يركز الدور على حماية الأنظمة والشبكات ونقاط النهاية والتطبيقات والمستخدمين من خلال اكتشاف التهديدات، والاستجابة لوقائع الأمن، وتنسيق أنشطة التصحيح، والحفاظ على عمليات الأمن السيبراني الفعالة.
تشمل المسؤوليات الرئيسية المراقبة المستمرة لتنبيهات وأحداث الأمن، وأمن البريد الإلكتروني، وغيرها من منصات الأمن التشغيلي، وضمان اتخاذ إجراءات احتواء واسترداد في الوقت المناسب. كما يدعم الدور إدارة الثغرات من خلال تتبع النتائج وتنسيق التصحيح مع فرق البنية التحتية والتطبيق، والتحقق من إغلاق المخاطر المحددة.
يعمل خبير عمليات الأمن السيبراني بشكل وثيق مع فرق تشغيل تقنية المعلومات، والشبكة، والحوسبة السحابية، والخادمات، ونقاط النهاية، والتطبيقات لضمان تنفيذ الضوابط الأمنية ووظيفتها بفاعلية كجزء من عمليات الأعمال والتكنولوجيا اليومية.
تشمل المسؤوليات أيضاً دعم عمليات الهوية والوصول، ومراجعة أنشطة الوصول المتميز، وتطبيق خطوط الأساس الأمنية، والحفاظ على دفاتر التشغيل وإجراءات التشغيل، والمساهمة في رفع الوعي الأمني من منظور تشغيلي.
هذا المنصب جزء من خط الدفاع الأول وبالتالي يركز على تشغيل وتنفيذ الضوابط بدلاً من المراقبة المستقلة، وحوكمة السياسات، وضمان الامتثال التنظيمي، أو أنشطة التدقيق الداخلي المرتبطة بالخطين الثاني والثالث من الدفاع.
المسؤوليات:
- مراقبة وتحليل تنبيهات الأمن السيبراني والأحداث والحوادث.
- إجراء التصنيف الأول والتقصي، وتقديم دعم الاحتواء، وتصعيد الحوادث الأمنية.
- دعم عمليات أمان نقاط النهاية والشبكات والحوسبة السحابية والبريد الإلكتروني.
- تنسيق التصحيح المتعلق بالثغرات مع الفرق الفنية المعنية.
- تنفيذ والحفاظ على ضوابط الأمن التشغيلي وحالات استخدام الرصد.
- مراقبة ودعم التصحيحات المتعلقة بالأمان، وتحديثات المنصة، وعمليات تحديث التكنولوجيا التشغيلية لضمان الحد الأدنى من التعرض للأمان وتوقف الخدمة.
- دعم الأنشطة الأمنية أثناء هجرات النظام أو الأداة أو البنية التحتية، بما في ذلك التحقق من الضوابط، واستعراضات التكوين، وفحوصات الأمان بعد الهجرة.
- مراجعة والتحقق من الدمج الأمني بين أدوات الأمن السيبراني، وأنظمة تكنولوجيا المعلومات، ومنصات السحابة، والحلول الطرف ثالث لضمان التسجيل الصحيح، والتنبيه، والاتصال، وفعالية الضوابط.
- دعم مراجعات وصول الوصول، ومراقبة الوصول المتميز، وعمليات الأمن المرتبطة بالهوية.
- الحفاظ على إجراءات الاستجابة للحوادث، ودفاتر التشغيل، والوثائق التشغيلية.
- تتبع إجراءات التصحيح والمتابعة على أنشطة تقليل المخاطر.
- المساهمة في تحسين مستمر لأنشطة وعمليات الأمن السيبراني.
- دعم مرونة الأعمال من خلال تقليل تعرض المخاطر السيبرانية التشغيلية.
المرشح المفضل
سنوات الخبرة
لا خبرة مطلوبة
المؤهل
درجة البكالوريوس / دبلوم أعلى
Job description
Cybersecurity Operations Expert responsible for supporting the first line of defense through the day-to-day execution, monitoring, and improvement of operational security controls across enterprise IT environments. The role focuses on protecting systems, networks, endpoints, applications, and users by detecting threats, responding to security events, coordinating remediation activities, and maintaining effective cybersecurity operations.
Key responsibilities include continuous monitoring of security alerts and events, email security, and other operational security platforms, and ensuring timely containment and recovery actions. The role also supports vulnerability management by tracking findings, coordinating remediation with infrastructure and application teams, and validating closure of identified risks.
The Cybersecurity Operations Expert works closely with IT operations, network, cloud, server, endpoint, and application teams to ensure security controls are implemented and functioning effectively as part of daily business and technology operations.
Responsibilities also include supporting identity and access security operations, reviewing privileged access activities, enforcing security baselines, maintaining playbooks and operational procedures, and contributing to security awareness from an operational perspective.
This position is part of the first line of defense and is therefore focused on operating and executing controls rather than performing independent oversight, policy governance, regulatory compliance assurance, or internal audit activities associated with the second or third lines of defense.
Rsponsibilities:
- Monitor and analyze cybersecurity alerts, events, and incidents.
- Perform initial triage, investigation, containment support, and escalation of security incidents.
- Support endpoint, network, cloud, and email security operations.
- Coordinate vulnerability remediation with relevant technical teams.
- Execute and maintain operational security controls and monitoring use cases.
- Monitor and support security-related patching, platform upgrades, and operational technology refresh activities to ensure minimal security exposure and service disruption.
- Support security activities during system, tool, and infrastructure migrations, including validation of controls, configuration reviews, and post-migration security checks.
- Review and validate security integrations between cybersecurity tools, IT systems, cloud platforms, and third-party solutions to ensure proper logging, alerting, connectivity, and control effectiveness.
- Support access control reviews, privileged access monitoring, and identity-related security operations.
- Maintain incident response procedures, runbooks, and operational documentation.
- Track remediation actions and follow up on risk reduction activities.
- Contribute to continuous improvement of cybersecurity activities and processes.
- Support business resilience by reducing operational cyber risk exposure.
Preferred candidate
Years of experience
No experience required
Degree
Bachelor's degree / higher diploma