وظائف مفتش أمن - جدة السعودية
١٦٣٤ وظائف شاغرة
Cybersecurity Specialist / Expert Job Description About the Role We are looking for a seasoned Cybersecurity Specialist to lead the protection of our systems, data, and infrastructure, and to drive our compliance with the cybersecurity regulations of the Kingdom of Saudi Arabia. In this hands-on expert role you will own the full cybersecurity lifecycle — implementing and testing the National Cybersecurity Authority (NCA) controls across the organization, uncovering and closing security vulnerabilities before they can be exploited, conducting security testing of critical systems, and operating the cybersecurity platforms that defend our environment around the clock. You will be the organization’s reference point for cybersecurity: advising leadership on risk, guiding IT and application teams on secure design and remediation, representing the organization before regulators and auditors, and building a security-first culture across the business. Key Responsibilities• Lead the implementation of the NCA regulatory frameworks — the Essential Cybersecurity Controls (ECC) and related control sets (CSCC for critical systems, CCC for cloud, DCC for data, TCC for telework, OTCC for operational technology) — across all organizational domains.• Assess compliance with NCA controls: perform gap analyses, define remediation roadmaps, implement corrective actions, and test/validate control effectiveness on an ongoing basis.• Prepare and maintain the evidence required for NCA self-assessments, regulator reporting, and internal and external cybersecurity audits, and act as the technical counterpart during those engagements.• Run the vulnerability management program end to end: scheduled scanning, risk-based prioritization, coordinating and verifying remediation with system owners, and closing findings within defined SLAs.• Conduct security testing of systems and applications — penetration tests, configuration reviews, and secure-baseline (hardening) assessments — before go-live and periodically in production.• Operate and tune cybersecurity systems and platforms: SIEM, EDR/XDR, next-generation firewalls, IPS/IDS, WAF, email and web security, NAC, and data loss prevention.• Monitor, detect, and respond to cybersecurity incidents: triage alerts, contain and eradicate threats, perform root-cause analysis and forensics, and produce post-incident reports with lessons learned.• Define and maintain cybersecurity policies, standards, and procedures aligned with NCA requirements and international best practices (ISO/IEC 27001, NIST CSF, CIS).• Perform cybersecurity risk assessments for projects, systems, and third parties, and embed security requirements into procurement, development, and change management.• Review and govern identity and access management: privileged access (PAM), MFA enforcement, periodic access recertification, and least-privilege design.• Deliver cybersecurity awareness activities and phishing simulations, and raise the security maturity of technical teams through guidance and training.• Track the threat landscape (threat intelligence, CVE advisories, NCA alerts) and proactively drive protective measures before threats materialize. Required Qualifications• 7+ years of hands-on cybersecurity experience, including a senior/expert role in an enterprise or government environment.• Deep, demonstrable knowledge of the Saudi National Cybersecurity Authority (NCA) frameworks — ECC as a minimum, with CSCC/CCC/DCC exposure — including a proven track record of materially contributing to their implementation and testing in a real organization.• Strong practical expertise in identifying, analyzing, and closing security vulnerabilities across operating systems, networks, databases, and applications.• Proven experience conducting security testing of systems: penetration testing, vulnerability assessment, and secure configuration review.• Strong hands-on experience operating cybersecurity systems: SIEM, EDR/XDR, firewalls, IPS/IDS, WAF, email security, and vulnerability management platforms.• Solid incident response capability: detection, containment, eradication, recovery, and reporting.• Working knowledge of ISO/IEC 27001 and international standards (NIST, CIS) and how they map to NCA controls.• Ability to produce high-quality technical reports and compliance documentation in Arabic and English.• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent proven experience). Preferred / Nice-to-Have Qualifications• Professional certifications: CISSP, CISM, CEH, OSCP, GIAC (GSEC/GPEN/GCIH), Comp TIA Security+, or SABSA; ISO/IEC 27001 Lead Implementer/Auditor is a strong plus.• Direct experience preparing organizations for NCA compliance reviews or working with sector regulators (e.g., SAMA CSF, CST) in the Kingdom.• Experience securing cloud environments (Azure, AWS, OCI) and hybrid architectures, including cloud-native security services.• Scripting and automation for security tasks (Power Shell, Python, Bash) and familiarity with security orchestration (SOAR).• Knowledge of secure software development practices (Dev Sec Ops, OWASP SAMM) and application security testing tools (SAST/DAST).• Experience with data protection technologies: encryption, PKI/certificate management, and database security.• Exposure to operational technology (OT/ICS) security and to business continuity / disaster recovery planning. Technical Skills Summary Area Skill Expected Level Regulatory Compliance NCA Essential Cybersecurity Controls (ECC) implementation Expert Regulatory Compliance NCA CSCC / CCC / DCC / TCC / OTCC control frameworks Expert Regulatory Compliance Compliance assessment, gap analysis, and audit support Expert Vulnerability Management Vulnerability scanning, prioritization, and remediation Expert Vulnerability Management Hardening and secure configuration baselines (CIS) Advanced Security Testing Penetration testing and security assessment of systems Expert Security Testing Web/application security testing (OWASP) Advanced Security Operations SIEM operation and use-case tuning (Splunk / QRadar / Sentinel) Advanced Security Operations EDR / XDR platforms and endpoint protection Expert Security Operations Incident response, digital forensics, and threat hunting Advanced Network Security NGFW, IPS/IDS, WAF, NAC, email and web security gateways Expert Identity & Access IAM / PAM, MFA, and least-privilege access governance Advanced Governance & Risk Cybersecurity policies, risk assessment, and awareness Advanced Governance & Risk ISO/IEC 27001 and international best practices Advanced Soft Skills• Strong analytical and investigative mindset, with the discipline to trace an alert or a finding to its root cause.• Clear written and verbal communication in Arabic and English; able to brief executives, regulators, and auditors as confidently as technical teams.• High integrity, confidentiality, and sound judgment when handling sensitive information and incidents.• Ownership mindset — drives findings from discovery through verified closure, and works to prevent recurrence.• Calm and structured under pressure, especially during live security incidents.• Collaborative influence: builds security into projects by working with, not against, IT and business teams.• Continuous learner who keeps pace with the evolving threat landscape and regulatory requirements.
???? We’re Hiring "Senior SOC Analyst" to join our team in KSA????<br>Zone a market leader in IT services, is excited to expand its team! We are looking for Senior SOC Analyst to join us in KSA.<br>We are seeking a highly skilled and proactive Senior SOC Analyst to join our Cybersecurity team. The successful candidate will be responsible for maturing our detection capabilities through proactive threat hunting, developing complex SIEM use cases, and integrating threat intelligence to stay ahead of sophisticated adversaries.<br><br>???? Key Responsibilities:-Continuous Monitoring:Monitor security alerts and network traffic to detect suspicious activities and potential breaches.-Threat Hunting:Proactively search for hidden threats and vulnerabilities within the network that may bypass traditional security controls.-Incident Response:Support the incident response team by providing technical analysis of detected threats and assisting in containment and remediation. SIEM Management: Manage and fine-tune Security Information and Event Management (SIEM) tools to improve detection accuracy and reduce false positives.-Log Analysis:Analyze logs from various sources (firewalls, servers, endpoints) to reconstruct the timeline of security incidents.-Reporting:Prepare detailed technical reports on detected threats, trends, and the effectiveness of current security measures for management.-Compliance:Ensure all detection activities align with Saudi Arabian cybersecurity regulations (e.g., NCA and SAMA frameworks).<br><br>???? Required Skills & Qualifications:-Bachelor’s degree in computer science, Cybersecurity, Information Technology, or a related field.-Saudi Nationality.-Minimum of 2-4 years of specialized experience in SOC operations, with a proven track record in L2 or L3 responsibilities.-Advanced proficiency in SIEM & EDR solutions (e.g., Splunk ES, Crowd Strike, Microsoft Sentinel).-Expertise in the MITRE ATT&CK framework for mapping and detecting adversary behavior.-Strong knowledge of memory forensics, network forensics, and log correlation.-Scripting proficiency in Python or Power Shell for automation and tool development.<br>Professional Certifications Highly preferred:· GCIA (GIAC Certified Intrusion Analyst) or GCIH (GIAC Certified Incident Handler).· GCFA (GIAC Certified Forensic Analyst).· CHFI (Computer Hacking Forensic Investigator).· OSCP (Offensive Security Certified Professional) - valued for understanding attacker mindsets.· CCTHP (Certified Cyber Threat Hunting Professional).<br><br>???? Interested? Send your CV on zeina.kira@zone.net.sa Feel free to share this post with your connections who might be interested in this opportunity! Join Zone for a collaborative environment and elevate your career in the realm of IT. ????#Cyber Security#SOCAnalyst#Senior SOCAnalyst#Security Operations Center#Information Security#Blue Team#Threat Detection#Incident Response#SIEM#Threat Hunting#Cyber Defense#Network Security#Security Monitoring#DFIR#Security Engineer#Cyber Threat Intelligence#Log Analysis#Splunk#QRadar#Azure Security
<h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">حول الدور</h3>
<p style="margin:0 0 12px; ************;">تبحث هيلتون عن شخص مDedicated للانضمام إلى فريقنا كـ <strong style="font-weight:700;">بطل الأمن</strong>. هذا المنصب بدوام كامل مقره في جدة ومكة المكرمة، المملكة العربية السعودية، وهو جزء أساسي من ضمان سلامة وأمن منشآت الفندق ونزلائه. الدور مناسب للمرشحين الذين لديهم 0-1 سنوات من الخبرة، مع فرصة للمساهمة في بيئة آمنة ومرحِّبة.</p> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">ملخص الدور</h3>
<p style="margin:0 0 12px; ************;">يلعب <strong style="font-weight:700;">بطل الأمن</strong> دوراً حيوياً في الحفاظ على بيئة آمنة ومأمونة لجميع النزلاء وأعضاء الفريق. يركّز هذا المنصب على تدابير الأمن الاستباقية، وتنسيق الاستجابات الفعّالة للطوارئ، وتعزيز ثقافة السلامة داخل الفندق. سيكون المرشح الناجح مسؤولاً عن تقديم تجارب لا تُنسى من خلال الالتزام بأعلى معايير السلامة والضيافة.</p> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">المسؤوليات الرئيسية</h3>
<ul style="margin:0 0 12px; padding-inline-start:24px; list-style-type:disc; list-style-position:outside;">
<li style="margin:0 0 6px;">إجراء دوريات أمنية، ومراقبة مباني الفندق الداخلية والخارجية لتحديد المخاطر والسلوكيات غير الآمنة ومعالجتها.</li>
<li style="margin:0 0 6px;">دعم الاستجابات للطوارئ، وتنسيق الإجراءات في حوادث مثل الحرائق والطوارئ الطبية والتهديدات الأمنية.</li>
<li style="margin:0 0 6px;">إشراف وتطوير فريق الأمن، بما في ذلك التدريب، والجدولة، وتقديم الإرشاد لخبراء الأمن لضمان الأداء العالي.</li>
<li style="margin:0 0 6px;">فتح التحقيقات في الحوادث بإجراء استقصاءات أولية، وجمع المعلومات ذات الصلة، وتوثيق النتائج، وضمان دقة تقارير الحوادث الأمنية.</li>
<li style="margin:0 0 6px;">تعزيز السلامة في مكان العمل من خلال تشجيع الالتزام ببروتوكولات السلامة وأفضل الممارسات بين جميع أعضاء الفريق.</li>
<li style="margin:0 0 6px;">توفير دعم أمني من خلال تنفيذ مسؤوليات ضابط الأمن عند الحاجة للحفاظ على تغطية تشغيلية.</li>
</ul> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">ملف المرشح</h3>
<p style="margin:0 0 12px; ************;">نبحث عن مرشحين لديهم 0-1 سنوات من الخبرة في مجال ذي صلة. يجب أن يعكس الفرد المثالي التزاماً بالسلامة وبروتوكولات الأمن، مع قدرة على الاستجابة بفعالية لمختلف الحالات. فهم أساسي لعمليات الأمن ونهج استباقي في حل المشكلات ضروريان للنجاح في هذا الدور.</p> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">القيم الأساسية لهيلتون</h3>
<p style="margin:0 0 12px; ************;">في هيلتون، توجه قيمنا الأساسية عملياتنا وتحدد الصفات التي نبحث عنها في كل عضو فريق. يجب أن يجسد المرشحون هذه المبادئ:</p>
<ul style="margin:0 0 12px; padding-inline-start:24px; list-style-type:disc; list-style-position:outside;">
<li style="margin:0 0 6px;">شغف بنشر نور ودفء <strong style="font-weight:700;">الضيافة</strong>.</li>
<li style="margin:0 0 6px;">التصرف بـ <strong style="font-weight:700;">النزاهة</strong> والقيام بالشيء الصحيح باستمرار.</li>
<li style="margin:0 0 6px;">إلهام الآخرين من خلال <strong style="font-weight:700;">القيادة</strong>.</li>
<li style="margin:0 0 6px;">إيمان بأن <strong style="font-weight:700;">العمل الجماعي</strong> يحقق أفضل النتائج.</li>
<li style="margin-top:0; margin-bottom:6px;">إحساس قوي بـ <strong style="font-weight:700;">الملكية</strong> والمسؤولية.</li>
<li style="margin-top:0; margin-bottom:6px;">تركيز على <strong style="font-weight:700;">الآن</strong>، مع إحساس بالعجلة والانضباط في كل لحظة، مع الاعتراف بتأثيرها الدائم.</li>
</ul> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">الموقع ونوع العمل</h3>
<p style="margin:0 0 12px; ************;">هذا منصب دوام كامل مقره جدة ومكة المكرمة، المملكة العربية السعودية. يتطلب الدور حضوراً ميدانياً لإدارة عمليات الأمن بفعالية ودعم فريق الفندق.</p>
About us Inspira Enterprise combines global delivery, deep platform expertise, and strategic OEM alliances to drive large‑scale digital and cybersecurity transformation for enterprises worldwide. Our cybersecurity services are comprehensive ranging from basic perimeter security to advanced incident management and response. Through global partnerships with best-in-class technology providers, we deliver cutting-edge cybersecurity solutions designed to detect, predict, and manage cyber incidents effectively. Our five state-of-the-art Cyber Fusion Centers (CFCs) enable us to provide 24/7 support to clients across the globe. We are certified as the “Best Place to Work” and we have achieved this recognition for the 8th time!<br>Role: Consultant (Access Management)<br>Purpose:To design, implement, and support secure, scalable identity and access management solutions using the IBM Security Verify suite, ensuring seamless authentication, governance, and compliance across the organization.<br>Main Priorities:Implement and configure IBM Security Verify solutions (ISVA/ISVG/Verify Saa S) to meet business and security requirements. Enable secure authentication, authorization, SSO, MFA, and adaptive access across applications. Integrate enterprise applications and directories with IBM Verify for seamless identity lifecycle management. Troubleshoot, optimize, and support IAM environments to ensure high availability and performance. Develop and maintain access policies, workflows, connectors, and provisioning rules. Ensure alignment of IAM implementations with security standards, compliance needs, and architectural guidelines. Prepare technical documentation, solution designs, and operational runbooks to support ongoing IAM operations.<br>Key Requirements:1–3 years of experience in IAM, SSO, or Security Administration. Hands-on expertise with IBM Security Verify Access (ISVA), IBM Security Verify Governance (ISVG), or IBM Security Verify Saa S. Strong understanding of IAM concepts including SSO, MFA, RBAC, provisioning, de-provisioning, and identity lifecycle management. Knowledge of authentication and federation standards: OAuth 2.0, OIDC, SAML, and web security protocols. Experience with LDAP/Active Directory, directory integrations, and identity data models. Proficiency in scripting (Java Script, Shell, Python) for customization and automation. Exposure to IBM ISVA/ISAM implementations preferred. Experience supporting enterprise authentication and access management solutions. Knowledge of application onboarding and SSO integrations is an advantage.<br>Certifications (if any):IBM Security Verify Certification (preferred).
<h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">حول الحلول المبتكرة</h3>
<p style="margin:0 0 12px; ************;">تُعَد Innovative Solutions (IS) شركة رائدة في مجال الأمن السيبراني خالصة الوجهة في مجلس التعاون الخليجي، تأسست عام 2003. مقرها في الرياض، وتتمتع بحضور في الدمام، جدة، دبي، وأبوظبي. تشمل حلول وخدمات الأمن السيبراني للشركة الاستشارات، الضمان الفني، نشر الحلول، الخدمات المهنية، وخدمات الأمن المُدارة. تلتزم Innovative Solutions بتقديم خدمات رقمية آمنة وعقلانية تمكّن المؤسسات.</p> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">دور محلل الأمن السيبراني - المستوى 1</h3>
<p style="margin:0 0 12px; ************;">تبحث Innovative Solutions عن <strong style="font-weight:700;">محلل أمن سيبراني بدوام كامل - المستوى 1</strong> لينضم إلى فريق مركز العمليات الأمنية (SOC) المخصص لديها. مقره في <strong style="font-weight:700;">الرياض، الدمام، أو جدة</strong>، يتضمن الدور مراقبة أحداث الأمن والحوادث وإجراء التقييم الأولي وتنفيذ إجراءات الاستجابة. سيستخدم المحلل أدوات أمان مختلفة لاكتشاف وتحليل والاستجابة للتهديدات المحتملة، والعمل بشكل تعاوني مع زملائه لضمان موقف أمني قوي.</p> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">المسؤوليات الرئيسية</h3>
<ul style="margin:0 0 12px; padding-inline-start:24px; list-style-type:disc; list-style-position:outside;">
<li style="margin:0 0 6px;">مراقبة أحداث وتحذيرات الأمن من مصادر أمان مختلفة.</li>
<li style="margin:0 0 6px;">التقييم الأولي للحوادث الأمنية وتحديد إجراءات الاستجابة الملائمة.</li>
<li style="margin:0 0 6px;">تنفيذ مهام الاستجابة الأولية للحوادث، بما في ذلك الاحتواء والإصلاح.</li>
<li style="margin:0 0 6px;">التعاون مع أعضاء فريق SOC للتحقيق في الحوادث الأمنية وحلها.</li>
<li style="margin:0 0 6px;">توثيق وتقارير عن الحوادث الأمنية وأنشطة الاستجابة.</li>
<li style="margin:0 0 6px;">الحفاظ على وتحديث وثائق عمليات وإجراءات الأمن.</li>
<li style="margin:0 0 6px;">إجراء تحليل بسيط لحركة مرور الشبكة وبيانات السجلات لتحديد التهديدات المحتملة.</li>
<li style="margin:0 0 6px;">البقاء على اطلاع بأحدث التهديدات والثغرات واتجاهات الصناعة.</li>
<li style="margin:0 0 6px;">المشاركة في تدريبات دورية وجلسات تبادل المعرفة.</li>
</ul> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">المؤهلات والخبرة</h3>
<ul style="margin:0 0 12px; padding-inline-start:24px; list-style-type:disc; list-style-position:outside;">
<li style="margin:0 0 6px;">درجة البكالوريوس أو ما يعادلها في علوم الحاسوب أو أمن المعلومات أو مجال ذي صلة.</li>
<li style="margin:0 0 6px;"><strong style="font-weight:700;">من 0-1 سنة</strong> من الخبرة في مجال ذي صلة.</li>
<li style="margin:0 0 6px;">فهم لبروتوكولات الشبكة وأسس TCP/IP.</li>
</ul> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">المهارات والقدرات المطلوبة</h3>
<ul style="margin:0 0 12px; padding-inline-start:24px; list-style-type:disc; list-style-position:outside;">
<li style="margin:0 0 6px;">القدرة على التعاون بفعالية مع فرق متعددة التخصصات.</li>
<li style="margin:0 0 6px;">مهارات تحليلية وحل المشكلات القوية.</li>
<li style="margin:0 0 6px;">مهارات تواصل مكتوبة وشفوية ممتازة.</li>
<li style="margin:0 0 6px;">دقة ملاحظة عالية والقدرة على العمل في بيئة سريعة الإيقاع.</li>
<li style="margin:0 0 6px;">الاستعداد للعمل بنظام المناوبات والمشاركة في الدوريات على الهاتف.</li>
</ul> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">بيئة العمل والموقع</h3>
<p style="margin:0 0 12px; ************;">هذه وظيفة <strong style="font-weight:700;">دوام كامل</strong> ضمن فريق مركز العمليات الأمنية. تتوفر الوظيفة في <strong style="font-weight:700;">الرياض، الدمام، وجدة</strong>، لدعم عمليات Innovative Solutions عبر منطقة الخليج.</p>
Managed.sa is seeking a hands-on Penetration Tester to conduct security assessments, identify and validate vulnerabilities, and provide practical remediation recommendations across client environments.<br><br>The ideal candidate has strong offensive-security skills, practical testing experience, and the ability to prepare clear and professional technical reports.<br><br>Key Responsibilities<br><br>Conduct penetration testing across web applications, APIs, networks, infrastructure, and cloud environments Perform manual and automated vulnerability assessments Safely exploit identified vulnerabilities to assess their technical and business impact Test authentication, authorization, session management, and application logic Participate in red-team and adversary-simulation activities when required Conduct source-code security reviews and identify insecure coding practices Document findings with supporting evidence, risk ratings, and remediation recommendations Present and explain technical findings to clients and internal stakeholders Conduct retesting to verify that vulnerabilities have been properly remediated Stay updated on emerging vulnerabilities, exploitation techniques, and offensive-security tools<br><br>Requirements<br><br>Bachelor's degree in Cybersecurity, Computer Science, Information Security, or a related field2-3 years of practical experience in penetration testing or offensive security Hands-on experience in web application and network penetration testing Strong knowledge of vulnerability assessment and exploitation techniques Good understanding of network protocols, including TCP/IP, DNS, and HTTPStrong working knowledge of Linux and Windows environments Strong understanding of web technologies, APIs, authentication mechanisms, and the OWASP Top 10Experience with tools such as Burp Suite, Metasploit, Nmap, Wireshark, and Nessus Scripting skills in Python, Bash, Power Shell, Ruby, or a similar language Strong technical-reporting and communication skills Ability to work full-time on-site in Riyadh<br><br>Preferred Experience<br><br>Cloud security assessments Red-team operations Source-code security reviews Client-facing penetration-testing engagements<br><br>Preferred Certifications<br><br>One or more of the following certifications would be an advantage:<br><br>Offensive Security Certified Professional (OSCP) Certified Ethical Hacker (CEH) GIAC Penetration Tester (GPEN) Offensive Security Experienced Penetration Tester (OSEP) Certified Red Team Professional (CRTP) Certified Red Team Operator (CRTO)
Design and maintain enterprise cybersecurity architecture frameworks and standards. Review solution, infrastructure, cloud, and application architectures to ensure security requirements are embedded throughout the project lifecycle. Define security architecture principles, patterns, and reference architectures. Conduct architecture risk assessments and recommend appropriate security controls. Collaborate with Enterprise Architecture, Infrastructure, Cloud, Network, and Application teams to integrate security-by-design principles. Evaluate emerging technologies and recommend secure implementation approaches. Support cloud security architecture across Azure, AWS, and/or Google Cloud environments. Define requirements for Identity & Access Management (IAM), Zero Trust, network segmentation, encryption, and privileged access. Ensure compliance with cybersecurity frameworks and regulatory requirements (NCA ECC, NIST CSF, ISO 27001, CIS Controls). <br><br>Requirements<br><br> Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field. Master's degree is preferred. Minimum 3-4 years in Cybersecurity Architecture or Security Engineering
Design and maintain enterprise cybersecurity architecture frameworks and standards. Review solution, infrastructure, cloud, and application architectures to ensure security requirements are embedded throughout the project lifecycle. Define security architecture principles, patterns, and reference architectures. Conduct architecture risk assessments and recommend appropriate security controls. Collaborate with Enterprise Architecture, Infrastructure, Cloud, Network, and Application teams to integrate security-by-design principles. Evaluate emerging technologies and recommend secure implementation approaches. Support cloud security architecture across Azure, AWS, and/or Google Cloud environments. Define requirements for Identity & Access Management (IAM), Zero Trust, network segmentation, encryption, and privileged access. Ensure compliance with cybersecurity frameworks and regulatory requirements (NCA ECC, NIST CSF, ISO 27001, CIS Controls). <br><br>Requirements<br><br> Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field. Master's degree is preferred. Minimum 3-4 years in Cybersecurity Architecture or Security Engineering
Design and maintain enterprise cybersecurity architecture frameworks and standards. Review solution, infrastructure, cloud, and application architectures to ensure security requirements are embedded throughout the project lifecycle. Define security architecture principles, patterns, and reference architectures. Conduct architecture risk assessments and recommend appropriate security controls. Collaborate with Enterprise Architecture, Infrastructure, Cloud, Network, and Application teams to integrate security-by-design principles. Evaluate emerging technologies and recommend secure implementation approaches. Support cloud security architecture across Azure, AWS, and/or Google Cloud environments. Define requirements for Identity & Access Management (IAM), Zero Trust, network segmentation, encryption, and privileged access. Ensure compliance with cybersecurity frameworks and regulatory requirements (NCA ECC, NIST CSF, ISO 27001, CIS Controls). <br><br>Requirements<br><br> Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field. Master's degree is preferred. Minimum 3-4 years in Cybersecurity Architecture or Security Engineering
We are looking for an experienced Senior SOC Analyst to join our Cybersecurity Operations Center (SOC). You will play a key role in monitoring, investigating, and responding to cybersecurity threats while mentoring junior analysts and improving detection capabilities. This role requires hands-on experience in security operations, incident response, and threat hunting.<br>Key Responsibilities Monitor and analyze security events using SIEM and security monitoring platforms. Investigate security incidents and coordinate response activities. Lead incident investigations and root cause analysis. Perform proactive threat hunting and malware analysis. Develop and optimize SIEM detection rules and use cases. Review and improve SOC playbooks and operational procedures. Mentor junior SOC analysts and support knowledge sharing. Prepare incident reports and communicate findings to stakeholders. Collaborate with infrastructure and security teams to improve security controls. Stay informed on emerging cyber threats, attack techniques, and industry best practices.<br>Requirements Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field.4–7 years of experience in a Security Operations Center. Hands-on experience with SIEM solutions such as Microsoft Sentinel, Splunk, or QRadar. Strong knowledge of incident response, threat hunting, endpoint security, and network security. Familiarity with MITRE ATT&CK, Cyber Kill Chain, and threat intelligence. Professional certifications such as CySA+, GCIH, GCIA, SC-200, CEH, or CISSP are preferred.<br>What We're Looking For Strong analytical and investigative mindset. Ability to make sound decisions under pressure. Excellent communication and documentation skills. Leadership and mentoring capabilities. Strong attention to detail and commitment to continuous learning. Ability to work collaboratively in a fast-paced SOC environment.
Managed.sa is seeking an experienced SOC Manager to lead Security Operations Center activities, strengthen threat detection and incident-response capabilities, and ensure the effective delivery of SOC services.<br><br>The ideal candidate combines hands-on cybersecurity expertise with strong leadership, stakeholder management, and operational reporting skills.<br><br>Key Responsibilities<br><br>Lead daily SOC operations, including security monitoring, alert triage, investigation, escalation, and incident response Manage, coach, and support SOC analysts while ensuring compliance with defined procedures and service levels Lead the investigation and response to major security incidents Work with SIEM platforms such as Splunk, QRadar, or Elastic Develop and improve detection rules, use cases, playbooks, and escalation procedures Conduct root-cause analysis and post-incident reviews Support digital forensics and evidence-handling activities Monitor emerging cyber threats, attack vectors, and adversary techniques Track SOC performance through SLAs, KPIs, and operational metrics Prepare incident, operational, and management reports Coordinate with clients and internal technical teams during security incidents Identify team development and training needs<br><br>Requirements<br><br>Bachelor's degree in Cybersecurity, Information Security, Computer Science, or a related field5-7 years of cybersecurity experience, with strong exposure to SOC operations and incident response Previous experience leading SOC activities, security operations, or technical teams Hands-on experience with Splunk, QRadar, Elastic, or similar SIEM platforms Strong knowledge of cyber threats, attack vectors, detection techniques, and defense strategies Strong understanding of incident response and digital forensics Familiarity with MITRE ATT&CK, threat intelligence, endpoint security, and network-security monitoring Strong leadership, analytical, communication, and stakeholder-management skills Ability to work full-time on-site in Riyadh<br><br>Preferred Certifications<br><br>Relevant certifications such as:<br><br>GIAC Certified Incident Handler (GCIH) GIAC Certified Intrusion Analyst (GCIA) Certified Information Systems Security Professional (CISSP) Certified Ethical Hacker (CEH) Equivalent cybersecurity certifications
Managed.sa is seeking an experienced OT Cybersecurity Engineer to support the security of operational technology and industrial control system environments.<br><br>The successful candidate will assess OT security risks, design and implement security controls, support compliance activities, and work closely with technical and operational stakeholders to strengthen industrial cybersecurity resilience.<br><br>Key Responsibilities<br><br>Conduct cybersecurity assessments for OT, ICS, and SCADA environments Identify vulnerabilities, risks, and security gaps within industrial networks Review OT network architecture, segmentation, remote access, and security controls Develop OT cybersecurity policies, procedures, standards, and remediation plans Support the implementation of OT security controls and monitoring solutions Conduct risk assessments and maintain OT cybersecurity risk registers Support incident response and investigation activities involving OT environments Coordinate with engineering, operations, IT, vendors, and client stakeholders Prepare technical reports, assessment findings, and management presentations Support compliance with applicable cybersecurity and industrial security standards Contribute to OT cybersecurity projects from assessment through implementation<br><br>Requirements<br><br>Bachelor's degree in Cybersecurity, Information Technology, Engineering, or a related field3-5 years of relevant experience in OT, ICS, SCADA, or industrial cybersecurity Strong understanding of industrial networks, systems, and communication protocols Experience assessing or securing OT and ICS environments Knowledge of network segmentation, firewalls, access control, and security monitoring Experience conducting risk assessments and developing remediation recommendations Strong technical documentation and stakeholder-management skills Good written and spoken English Ability to work on-site in Riyadh<br><br>Preferred Qualifications<br><br>Knowledge of IEC 62443, NIST SP 800-82, NCA OTCC, or similar standards Experience within utilities, energy, manufacturing, oil and gas, or critical infrastructure Experience with OT security tools, industrial firewalls, SIEM, or network monitoring solutions Relevant certifications such as GICSP, GRID, ISA/IEC 62443, CISSP, or similar
IT Network & Security Senior Specialist<br><br>Location HQ Office – Riyadh<br>About the Role:<br><br>Manage the optimization and security of the Company IT network infrastructure, including networks, systems, and data. Ensure seamless operations and implementation of proactive measures to safeguard the Company IT network and meet organizational requirements.<br><br>KEY ACCOUNTABILITIES & ACTIVITIES<br><br>Network Operations Manage the Company IT network and implement comprehensive security measures to ensure the integrity and confidentiality of network data. Drive the design, deployment, and maintenance of the Company IT network infrastructure, ensuring scalability, efficiency, and alignment with organizational goals. Conduct thorough capacity planning exercises to anticipate and address future network requirements, proposing scalable solutions that align with the organization's growth strategy. Identify and recommend solutions for optimal network performance based on industry best practices and a thorough understanding of organizational requirements. Collaborate with cross-functional teams to integrate network solutions seamlessly into the overall IT infrastructure. Communicate effectively with end-users, providing expert technical support and addressing concerns promptly and professionally.<br>Stay informed about industry trends and emerging technologies in network administration, integrating relevant advancements to ensure optimal performance. Provide inputs and implement policies, systems, and procedure for the assigned team so that all relevant procedural/legislative requirements are fulfilled while delivering a quality, cost-effective service. Support the development and implementation of policies, procedures, and strategic plans, incorporating a robust and clearly defined security incident response program to anticipate potential risks, enhance organizational resilience, and safeguard the Company Assets. Create and maintain comprehensive documentation for network configurations, processes, and troubleshooting procedures, adhering to industry standards and internal documentation guidelines. Network Monitoring and Troubleshooting<br>Monitor and assess network performance, ensuring optimal functionality and identifying potential issues for proactive resolution. Demonstrate a prompt and efficient response in diagnosing and resolving network issues to minimize downtime and maintain uninterrupted business operations. Provide support for network-related issues, conducting thorough diagnostics to identify root causes and collaborating with vendors as necessary to ensure timely and effective issue resolution. Ensure the seamless and timely execution of data recovery procedures, utilizing advanced IT network expertise to retrieve, restore, and validate critical data, minimizing potential downtime and ensuring data integrity across the network infrastructure.<br>Network Security<br>Implement security measures to safeguard the Company IT network, including regular audits, assessments, and maintenance of configurations to ensure compliance with security policies. Contribute to routine vulnerability audits, risk assessments, and the establishment of firewalls, actively participating in the development and implementation of mitigation procedures.<br>Threat Detection & Response:Monitor, identify, and respond to cybersecurity threats and incidents.<br>Risk Assessment:Conduct regular security assessments to identify vulnerabilities and recommend mitigation strategies.<br>Security Architecture:Design and implement robust security infrastructures to protect organizational assets.<br>Compliance Management:Ensure adherence to NCA's Essential Cybersecurity Controls (ECC-2) and other relevant regulations.<br>Incident Management:Lead investigations into security breaches and coordinate response efforts.<br>Collaboration:Work closely with IT and other departments to integrate security best practices across all systems.<br>Qualifications/Requirements<br><br>A minimum of 4 years of experience is required. Experience in IT Network & Security. Very good in English.<br><br>Education<br>Bachelor’s degree in information technology, Computer Science, or any related discipline. Certifications (e.g., CCNA, CISSP, Comp TIA Security+, or similar) are considered advantageous.<br>Skills Network Performance Network Infrastructure Firewalls Implementation Of Policies Network Security Network Security Testing Network Security Implementation Network Troubleshooting Computer Network Operations Network Monitoring Tools
About the Company<br>Advanced technology and cybersecurity company (sirar) established by stc, the region’s ICT and digital services provider, sirar by stc is a cutting-edge cybersecurity provider that empowers organization to take control of their cyber capabilities and digital environments. As experts in business security and privacy. We offer a comprehensive range of solutions that help you to operate online safely, securely, and efficiently.<br>Responsibilities:Oversees IT system security as a subject matter expert on IT System security and providing up to level-3 support. Oversees escalations and provide advisory and support function to front office / back office. Acts as technical reviewers in change management process and continuous improvement. Acts as technical reviewers in Fault management process and continuous improvement. Works on problem determination analysis and resolution techniques. Verifies root cause analysis / incident reports prepared by L1 L2 engineers and where needed perform root cause Analysis and generate Incident Reports for complex issues. Opens clients trouble tickets with vendors TSS. Coordinates system changes with appropriate teams to minimize disruption. Coordinates and communicates issues requiring escalation to different teams and initiate follow up procedures pertain Handles/Solves the support tickets (New configuration, change requests, and troubleshooting issues). Monitors security incidents and breaches. Hardens the security systems configuration and settings. Provides technical consultation for onboarding clients. Maintains subject matter expert level of expertise on technologies/platforms deployed in managed networks. Advice in taking actions upon them with the latest vulnerabilities. Contributes to the overall success of the company by performing all other duties and responsibilities as assigned by line manager.<br><br>Academic Qualification :Bachelor’s degree in Cybersecurity, Computer Science/Engineering, Information Technology, or related discipline.<br>Professional Certificate :Industry recognized security certifications such as CCNP Security, CCIE, CISSP or equivalent related certifications are preferred. Technology/Vendor based certifications are preferred. Operating systems certifications such as MCSE and RHCSA is preferred.<br>Years of Experience :7+ years in relevant experience.<br>Skills :Proven experience in network security operations, preferably in a telecom environment Strong understanding with next-generation firewalls (e.g. Forti Gate, Palo Alto, Cisco-FTDs), IPS, NAC, VPNs (IPSEC, Dial-up, SSL etc), NAT. Advance knowledge in IT security infrastructure. Strong endpoint security (DLP, AV, DAM, EDR/NDR and XDR). Strong web and email security understanding. APT, sandboxing, SSLV offloading and PKI fundamentals and concepts. Advance proficiency in communicating effectively with a range of security professionals and to simplify complex technical issues. In-depth knowledge of security protocols and principles. Proficiency in networking technologies, network security and network monitoring solutions. Advanced troubleshooting and diagnostic skills to efficiently resolve complex issues In-depth understanding of TCP/IP, network protocols, packet capture, Wire Shark, tcpdump. ITIL fundamentals, Problem, Incident, Change and Release Management. Virtualization and Storage Solid understanding. Comprehensive understanding of information security policies and best practices in identity management. Advanced troubleshooting and diagnostic skills to efficiently resolve complex issues. Excellent communication, reporting and time management skills.<br>Important Notice for Candidates: <br>By submitting your application, you confirm that you have read and understood sirar's Candidate Privacy Notice and agree to the processing of your personal data in accordance with it.
Cybersecurity Architect – KSAWe are seeking an experienced Cybersecurity Architect to lead security governance, compliance, risk management, and technical security initiatives across the organization.<br>Key Responsibilities Lead ISO 27001:2022 implementation, risk assessments, and compliance programs. Ensure compliance with SAMA-CSF, NCA, PDPL, CST CRF, and related regulations. Develop and maintain cybersecurity policies, standards, and procedures. Conduct vendor security assessments and third-party risk reviews. Perform penetration testing and vulnerability assessments for web, mobile, API, and IoT environments. Manage SIEM, threat monitoring, incident response, and security operations. Support secure architecture for cloud, applications, APIs, and IoT solutions. Deliver cybersecurity awareness and secure coding training. Prepare executive reports, security metrics, and risk dashboards.<br>Requirements Bachelor's or Master's degree in Cybersecurity, Computer Science, or a related field.8–12 years of experience in Cybersecurity, Security Architecture, or GRC. Strong expertise in ISO 27001, OWASP Top 10, PTES, and MITRE ATT&CK. Hands-on experience in penetration testing, vulnerability management, and security operations. Excellent communication and stakeholder management skills.candidate has to be in KSA.<br>Preferred Certifications CISMCISAISO 27001 Lead Auditor/Lead Implementer CAP (Certified App Sec Practitioner) or equivalent
About noon<br>We’re building an ecosystem of digital products and services that power everyday life across the Middle East—fast, scalable, and deeply customer-centric. Our mission is to deliver to every door every day. We want to redefine what technology can do in this region, and we’re looking for a SLP Supervisor who can help us strengthen security, minimize losses, and support operational excellence.<br>Noon’s fastest hyper-local delivery platform, Noon Minutes, offers a localized assortment of FMCG & grocery products with delivery within 15 minutes. Currently live across the UAE and Saudi Arabia, offering thousands of products to customers in record time.<br>noon’s mission: Every door, every day.<br>What you’ll do<br>Team noon has some of the fastest, smartest, and hardest-working people we’ve encountered. With a young, aggressive, and talented team, we’re driving major missions forward.<br>As an SLP Supervisor, you will oversee day-to-day Security & Loss Prevention operations, ensuring the safety of people, protection of assets, and compliance with security standards while supporting business continuity across the site.<br>Key Responsibilities:<br>Supervise daily Security & Loss Prevention operations to ensure effective coverage across the site. Lead and coordinate Security Officers and CCTV Operators, ensuring adherence to company policies and procedures. Monitor access control, visitor management, and CCTV surveillance to maintain a secure environment. Respond to and investigate security incidents, accidents, theft, fraud, and policy violations, ensuring timely escalation and documentation. Conduct routine security inspections, audits, and patrols to identify and mitigate potential risks. Support inventory protection initiatives, stock counts, and shrinkage prevention activities. Prepare incident reports, daily security logs, and operational summaries with accuracy and timeliness. Coordinate with Operations, HR, Facilities, and other stakeholders to resolve security-related concerns. Provide on-the-job coaching and guidance to team members to maintain high performance and compliance. Ensure emergency response procedures are followed and support business continuity during critical incidents. Promote a culture of safety, security, and continuous improvement across the site.<br>What you’ll need<br>Bachelor’s degree or equivalent experience in Security Management, Criminal Justice, Business Administration, or a related field.2–4 years of experience in Security, Loss Prevention, or Asset Protection, preferably within a logistics, warehousing, retail, or e-commerce environment. Previous supervisory experience is preferred. Strong knowledge of security operations, incident management, investigations, and risk mitigation. Experience with CCTV systems, access control systems, and security reporting. Strong leadership, communication, and interpersonal skills. Good analytical and problem-solving abilities with attention to detail. Proficiency in Microsoft Office applications, particularly Excel and Word. Ability to work under pressure and manage multiple priorities in a fast-paced environment. Flexibility to work rotating shifts, weekends, and public holidays as operationally required.<br>Who will excel?<br>We’re looking for people with high standards, who understand that hard work matters. You need to be relentlessly resourceful and operate with a deep bias for action. We need people with the courage to be fiercely original.noon is not for everyone; readiness to adapt, pivot, and learn is essential.
Job Description We are seeking a new talent to join the Security team where you will have the opportunity to collaborate in the project Security Engineering Managed Services. A company operating in the aviation sector providing airline services and related operations.<br>Work Location: Jeddah, Al Murjanah Tower<br>Responsibilities:As a Vulnerability Management Practitioner, you will be responsible for delivering and managing security services across client environments to ensure protection, compliance, and operational resilience. You are expected to perform independently and become a subject matter expert. Active participation and contribution in team discussions are required, along with providing solutions to work-related problems. Expert proficiency in Tenable Nessus Vulnerability Scanner Operations and Vulnerability Management Process is required. Analyze security vulnerabilities and contribute to the development of effective mitigation strategies. Collaborate with team members to identify recurring security challenges and propose innovative solutions. Support continuous improvement initiatives by sharing insights and lessons learned from operational experiences. Engage with stakeholders to ensure alignment of security services with organizational goals and client expectations.<br>Required Qualifications & Experience:4–8 years of relevant experience in cybersecurity, vulnerability management, security operations, or a related field. Saudi is mandatory Strong hands-on experience with Tenable Nessus Vulnerability Scanner. Strong understanding of the Vulnerability Management Lifecycle. Relevant cybersecurity certifications such as CISSP, CEH, Security+, Tenable certifications, or equivalent would be an advantage.
<h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">نظرة عامة على الدور</h3>
<p style="margin:0 0 12px; ************;">تسعى CoorB للحصول على <strong style="font-weight:700;">مهندس جدار حماية</strong> لعقد عمل مقيم في جدة، مكة، المملكة العربية السعودية. هذا الدور مركزي لإدارة وتأمين محيط الشبكة التنظيمية ويتطلب من المرشحين خبرة متخصصة تتراوح بين 5-10 سنوات في هندسة جدار الحماية.</p> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">الوظيفة الأساسية والتأثير</h3>
<p style="margin:0 0 12px; ************;">سيكون مهندس جدار الحماية مسؤولاً عن تصميم وتطبيق وإدارة ودعم بنية جدار الحماية المؤسسية ومع بنية الأمان الطرفي. الهدف الرئيسي هو ضمان تدفق حركة آمن ومقسّم ومتوافق مع السياسات عبر مراكز البيانات، الحرم الجامعي، الوصول عن بُعد، والبيئات الهجينة. كما يتضمن الدور الدعم النشط لعمليات الأمن، وعمليات إدارة التغيير، واستجابة الحوادث، والتحسين المستمر لضوابط جدار الحماية.</p> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">المسؤوليات الرئيسية</h3>
<ul style="margin:0 0 12px; padding-inline-start:24px; list-style-type:disc; list-style-position:outside;">
<li style="margin:0 0 6px;">إدارة قواعد جدار الحماية وسياسات الأمن وتكوينات NAT والتحكم في التطبيقات وتصفية الروابط وفق المعايير الأمنية المعتمدة وعمليات إدارة التغيير.</li>
<li style="margin:0 0 6px;">تكوين وصيانة واستكشاف أخطاء حلول الاتصال عبر موقع إلى موقع والوصول عن بُعد لضمان اتصال آمن للمستخدمين والشركاء وأنظمة الأعمال.</li>
<li style="margin:0 0 6px;">مراقبة أداء جدار الحماية وتدفقات الحركة والأحداث الأمنية لتحديد الشذوذات وانتهاكات السياسات والتهديدات المحتملة.</li>
<li style="margin:0 0 6px;">إجراء تحليل حركة المرور والتحقيق في الأسباب الجذرية واستكشاف الأخطاء والإصلاحات لحوادث جدار الحماية وVPN والأمن الطرفي.</li>
<li style="margin:0 0 6px;">دعم أنشطة استجابة الحوادث من خلال توفير سجلات جدار الحماية والتحليل وإجراءات الاحتواء وتوصيات الإصلاح.</li>
<li style="margin:0 0 6px;">تقوية إعدادات جدار الحماية ومعالجة الثغرات المكتشفة من خلال فحوص الأمن والتدقيق والتقييمات والمراجعات الداخلية.</li>
<li style="margin:0 0 6px;">الحفاظ على البر Firmware والتحديثات والتوقيعات ونسخ التكوين لضمان استقرار المنصة وأمنها والامتثال.</li>
</ul> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">التوافر التشغيلي والتوثيق</h3>
<ul style="margin:0 0 12px; padding-inline-start:24px; list-style-type:disc; list-style-position:outside;">
<li style="margin:0 0 6px;">مراجعة طلبات جدار الحماية من حيث الدقة والضرورة والمخاطر والامتثال قبل التنفيذ.</li>
<li style="margin:0 0 6px;">الحفاظ على الوثائق الفنية المحدثة ومخططات الشبكة/الأمان وإجراءات التشغيل القياسية وسجلات التغيير.</li>
<li style="margin:0 0 6px;">المشاركة في نوافذ الصيانة المخطط لها والدعم عند النداء وأنشطة التعافي من الكوارث ومشاريع بنية الأمن التحتية حسب الحاجة.</li>
<li style="margin:0 0 6px;">التعاون مع فرق الشبكة والبنية والتخطيط السحابي والتطبيق والأمن لدعم متطلبات الهندسة الآمنة والاتصال.</li>
</ul> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">متطلبات الخبرة</h3>
<p style="margin:0 0 12px; ************;">يجب أن يمتلك المرشحون لوظيفة مهندس جدار الحماية <strong style="font-weight:700;">5 إلى 10 سنوات من الخبرة</strong> في دور تخصصي في هندسة جدار الحماية أو أمان الشبكات أو دور ذي صلة. يجب أن تشمل تلك الخبرة تصميم وتطبيق وإدارة ودعم حلول جدار الحماية والأمن الطرفي على مستوى المؤسسة.</p> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">ترتيب العمل</h3>
<p style="margin:0 0 12px; ************;">هذا عقد مقيم في جدة، مكة، المملكة العربية السعودية. سيتم مناقشة الراتب لهذا الدور خلال عملية المقابلة.</p>
<h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">حول الدور</h3>
<p style="margin:0 0 12px; ************;">تسعى كلية باترجي الطبية إلى تعيين <strong style="font-weight:700;">مدرب مِهَني في أمان السياحة</strong> لتقديم تدريب قائم على الكفاءة ومتوافق مع الصناعة. هذا المنصب بدوام كامل، مقره في جدة ومكة، ويتطلب خبرة من 2-5 سنوات ويركز على إعداد الطلاب لأدوار الأمن والسلامة ضمن قطاعات السياحة والضيافة والفنادق والمنتجعات وإدارة الوجهات. يشمل الدور دمج الخبرة الأمنية العملية مع مهارات التدريب المهني الفعالة لضمان أن يطور الطلاب الكفاءات الأساسية المتوافقة مع متطلبات TVTC واحتياجات سوق العمل السعودي.</p>
<h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">المسؤوليات الأساسية</h3>
<ul style="margin:0 0 12px; padding-inline-start:24px; list-style-type:disc; list-style-position:outside;">
<li style="margin:0 0 6px;">تقديم تدريب قائم على الكفاءة نظريًا وعمليًا في أمان السياحة والمواد ذات الصلة، وفق منهاج معتمد.</li>
<li style="margin:0 0 6px;">إجراء تمارين عملية وورش عمل ومحاكاة وسيناريوهات تعكس بيئات أمان السياحة والضيافة الواقعية.</li>
<li style="margin:0 0 6px;">دمج إجراءات الصناعة ذات الصلة والمعايير المهنية وأفضل الممارسات الحديثة في جميع أنشطة التدريب.</li>
<li style="margin:0 0 6px;">تطبيق أساليب التدريس العملية والمتمركزة حول الطالب لدعم تطوير كفاءات شاملة.</li>
<li style="margin:0 0 6px;">تطوير وإدارة تقييمات عملية وتقييمات مبنية على السيناريو وقوائم فحص المهارات لتقييم أداء الطلاب.</li>
<li style="margin:0 0 6px;">تقديم تغذية راجعة بناءة وتوجيه وتوجيه لرفع مستوى تعلم الطلاب ومعالجة مجالات تحتاج إلى دعم إضافي.</li>
<li style="margin:0 0 6px;">المساهمة في تطوير ومراجعة وتحسين مواد وبرامج تدريب أمان السياحة بشكل مستمر.</li>
<li style="margin:0 0 6px;">التأكد من امتثال جميع أنشطة التدريب للوائح TVTC والمناهج المعتمدة والسياسات المؤسسية ومعايير الجودة.</li>
<li style="margin:0 0 6px;">الحفاظ على سجلات كاملة ودقيقة لتقديم التدريب والتقييمات والحضور والتدريبات في مكان العمل.</li>
</ul> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">مجالات التدريب المحددة</h3>
<p style="margin:0 0 12px; ************;">سيقدم المدرب تعليمًا في مجالات حاسمة من أمان السياحة، بما في ذلك:</p>
<ul style="margin:0 0 12px; padding-inline-start:24px; list-style-type:disc; list-style-position:outside;">
<li style="margin:0 0 6px;">إجراءات الأمان والتحكم في الدخول</li>
<li style="margin:0 0 6px;">إجراءات السلامة للضيوف والزوار والموظفين</li>
<li style="margin:0 0 6px;">دوريات الأمن ووعي المراقبة</li>
<li style="margin:0 0 6px;">إبلاغ وتوثيق الحوادث</li>
<li style="margin:0 0 6px;">إجراءات الطوارئ والإخلاء</li>
<li style="margin:0 0 6px;">التعرّف على المخاطر والمخاطر المحتملة</li>
<li style="margin:0 0 6px;">إدارة الجمهور وأمن الفعاليات</li>
<li style="margin:0 0 6px;">إدارة النزاعات والاتصال المهني</li>
<li style="margin:0 0 6px;">التوعية الأمنية والإبلاغ عن سلوك مشبوه</li>
<li style="margin:0 0 6px;">حماية منشآت وممتلكات السياحة</li>
</ul> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">الإشراف على التدريب العملي</h3>
<ul style="margin:0 0 12px; padding-inline-start:24px; list-style-type:disc; list-style-position:outside;">
<li style="margin:0 0 6px;">تنسيق والإشراف على التدريب أثناء العمل (OJT)، والتدريبات داخل مواقع الصناعة المعتمدة.</li>
<li style="margin:0 0 6px;">دعم الطلاب أثناء فترات التدريب العملية في الفنادق والمنتجعات وجهات السياحة وغيرها من البيئات ذات الصلة.</li>
<li style="margin:0 0 6px;">مراقبة حضور الطلاب وأدائهم وسلوكهم المهني خلال فترات التدريب.</li>
<li style="margin:0 0 6px;">الحفاظ على تواصل فعال مع مشرفي مكان العمل وشركاء الصناعة لضمان تعرض الطلاب لعمليات أمان واقعية ذات مغزى.</li>
</ul> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">المؤهلات والمتطلبات</h3>
<ul style="margin:0 0 12px; padding-inline-start:24px; list-style-type:disc; list-style-position:outside;">
<li style="margin:0 0 6px;"><strong style="font-weight:700;">الموافقة كمدرب TVTC إلزامية.</strong></li>
<li style="margin:0 0 6px;">2-5 سنوات من الخبرة في دور أمني ذي صلة أو تدريب مهني.</li>
<li style="margin:0 0 6px;">إظهار خبرة أمنية عملية قوية مقترنة بمهارات تدريب مهنية فعالة.</li>
<li style="margin:0 0 6px;">القدرة على تقديم تعليم عملي ومحاكاة وتعلم قائم على مكان العمل.</li>
</ul> <h3 style="font-size:18px; font-weight:700; margin:16px 0 8px;">الموقع ونوع العمل</h3>
<p style="margin:0 0 12px; ************;">هذا منصب بدوام كامل مقره في جدة ومكة. يتطلب الدور المشاركة النشطة في اجتماعات أعضاء هيئة التدريس وأنشطة التطوير المهني والمبادرات المؤسسية.</p>
<section><p class="heading jdMain">الوصف الوظيفي</p><p class="heading">الأدوار والمسؤوليات</p><div class="paragraph"><p><strong>أمن الشبكات وبنية الحماية المحيطية</strong></p><p>• إدارة، تهيئة، وإدارة جدران الحماية Cisco Firepower وCisco FMC لإدارة السياسات المركزية.<br>• دعم وصيانة جدران الحماية Palo Alto بما في ذلك ضبط السياسات، NAT، وفحص الحركة.<br>• إدارة Web Proxy (Broadcom Bluecoat) للوصول الآمن إلى الإنترنت وتصفية عناوين URL.<br>• إدارة حلول حماية DDoS (Arbor، Akamai) لضمان مرونة الشبكة وتوفرها.<br>• تهيئة ودعم منصات F5 بما في ذلك:</p><ul><li><p>APM (الوصول عن بُعد عبر VPN)</p></li><li><p>ASM (جدار الحماية لتطبيقات الويب)</p></li><li><p>GTM (DNS / إدارة الحركة)<br>• ضمان تقسيم الشبكة بشكل صحيح، تحسين قواعد الجدار الناري، والاتصال الآمن عبر البيئات.</p></li></ul><p><strong>التحكم في وصول الشبكة وبنية الهوية</strong></p><p>• إدارة Cisco ISE (خادم AAA) للمصادقة، التفويض، والمحاسبة.<br>• إدارة ForeScout NAC لرؤية الأجهزة والتحكم في قبول الشبكة.<br>• دعم OneIdentity (IAM و MFA) و Microsoft Azure MFA لآليات المصادقة الآمنة.<br>• إدارة Privileged Access Management (Delinea) لتأمين حسابات المحظورين.<br>• إدارة Microsoft Certificate Authority (CA) لإصدار الشهادات، التجديد، وإدارة دورة الحياة.</p><p><strong>نُظُم الأمان للنقاط الطرفية، الخادم ولب الأمن الأساسي</strong></p><p>• إدارة منصات حماية النقاط الطرفية (Symantec Endpoint Protection، Microsoft Defender).<br>• إدارة مراقبة سلامة الملفات (ChangeTracker) للأنظمة الحرجة.<br>• دعم التكوين الآمن وتحصين الخوادم، الأجهزة الطرفية، وأجهزة الشبكة.<br>• إدارة بوابة أمان البريد الإلكتروني (Symantec Messaging Gateway).</p><p><strong>إدارة الثغرات وأمن البنية التحتية</strong></p><p>• إدارة أدوات إدارة الثغرات بما في ذلك Qualys و Tenable Nessus.<br>• إجراء فحوصات ثغرات منتظمة عبر الشبكة والأنظمة والتطبيقات.<br>• تنسيق التصحيح والمعالجة مع فرق البنية التحتية والتطبيقات.<br>• الحفاظ على إعدادات أمان أساسية والالتزام بت standards التعزيز الأمني.</p><p><strong>أمان البيانات والتطبيقات (من منظور البنية التحتية)</strong></p><p>• دعم تنفيذ Microsoft DLP وMicrosoft Purview (تصنيف البيانات) من منظور تكاملي للبنية التحتية.<br>• إدارة Web Application Firewall (F5 ASM) ودعم أدوات أمان التطبيقات (Checkmarx، SecureEyes) بالتعاون مع فرق التطوير.<br>• إدارة ضوابط أمان قاعدة البيانات (Imperva) لحماية أصول البيانات الحرجة</p></div></section><section><p class="heading">الملف المثالي للمرشح</p><p class="paragraph"></p><ul><li><p>خبرة 5+ سنوات في أمان الشبكات، عمليات الأمن السيبراني، أو أدوار إدارة الأمن.</p></li><li><p>خبرة عملية في إدارة عدة أدوات أمنية، بما في ذلك:</p></li><li><p>جدران الحماية: Cisco Firepower، Palo Alto</p></li><li><p>WAF/VPN/DNS: F5 (ASM, APM, GTM)</p></li><li><p>حماية DDoS: Arbor، Akamai</p></li><li><p>IAM/PAM: OneIdentity, Delinea, Azure MFA</p></li><li><p>إدارة الثغرات: Qualys, Nessus</p></li><li><p>الأمن النهائي للبريد الإلكتروني والنقاط الطرفية: Symantec، Microsoft Defender</p></li><li><p>فهم قوي لمفاهيم الشبكات (TCP/IP، DNS، VPN، التوجيه، التبديل).</p></li><li><p>الخبرة في التكاملات الأمنية عبر SIEM، SOAR، IAM، وأدوات النقاط الطرفية.</p></li><li><p>الإلمام بمنصات استخبارات التهديدات وإجراءات الاستجابة للحوداث.</p></li><li><p>القدرة على إدارة بيئات متعددة البائعين مع حل مشاكل التكامل.</p></li><li><p>الخبرة في التهيئة/الأتمتة (PowerShell، Python) ميزة إضافية.</p></li><li><p>مهارات تحليلية قوية، وحل مشكلات، والتواصل.</p></li><li><p>أداء إدارة كاملة للنظام، وتعديل التهيئة، والتصحيح، وترقيات منصات الأمان.</p></li></ul><p></p></section>