وصف الوظيفة
الغرض من العمل: امتلاك جاهزية البناء، تنظيم الاختبار، والتسليم المُتحكم به، بالتنسيق مع فريق التصميم للحصول على المدخلات.
فرض بوابات، إغلاق العيوب، وإنتاج حزم تحقق جاهزة للمراجعة للمسارات المقررة عبر برامج تكنولوجيا معلومات الأمان المؤسسية والأصول.
المسؤوليات الأساسية: حوكمة الجاهزية والبوابات · تشغيل حوكمة بوابات الخروج عبر البيئات؛ التحقق من المتطلبات الأساسية (الوصول، الشهادات، النسخ الاحتياطي، التراجع).
· إشراف منتديات البدء/التوقف وضمان توثيق المخاطر والاستثناءات والضوابط التعويضية بتوقيع الأمن السيبراني.
· الحفاظ على تقاويم التغيير الم aligned مع نوافذ الأصول وفترات الانقطاع الإعلامي.
تخطيط الاختبار والبيانات والبيئات · إشراف بناء خطط الاختبار الشاملة من البداية للنهاية التي تغطي السيناريوهات الوظيفية والسلبية والمرونة والتكامل.
· ضمان مشاركة المراقب (عمليات، خبراء النظام الأساسي) لمصداقية الاختبار.
إدارة العيوب والمخاطر والقضايا · إدارة فرز العيوب؛ تعيين المالكين/الأولوية؛ تتبع اتفاقيات مستوى الإصلاح وإعادة الاختبار.
· الحفاظ على سجلات RAID؛ تصعيد العوائق؛ قياس المخاطر المتبقية عند الإصدار.
حزم التحقق والتتبع · إشراف تجميع حزم التحقق (الخطط والنتائج والأدلة ومصفوفات التتبع)؛ ضمان التخزين بإصدار والموافقات.
· ضمان تحقيق القبول من QA/Excellence من الجولة الأولى وضمان الحل السريع للإرجاعات.
التسليم وجاهزية التشغيل · التحقق من دفاتر التشغيل، المراقبة/التنبيه، وإتمام تدريب المستويات L1/L2؛ تأكيد خدمات الأداء التشغيلية وقطع العمل للمستمرات (SLOs) وقطع DR.
· تأكيد تطابق SIEM/SOAR ومسارات الحالات قبل البدء الفعلي.
التنسيق مع أصحاب المصلحة والاتصالات · تيسير بروتوكولات الانتقال؛ نشر خطط الاتصالات، RACI، وجداول العناية الفائقة.
· تقديم لوحات جاهزية أسبوعية وملخصات المخاطر إلى منتديات الحوكمة.
التحسين المستمر · تتبع معدل نجاح التغيير وقوائم التحقق وفقاً لذلك.
تقييم ضوابط الأمن، دليل إثبات المفهوم، والتنفيذ · قيادة تقييم ضوابط أمن تكنولوجيا المعلومات والتقنيات والحلول لضمان التوافق مع الاستراتيجية التنظيمية ومتطلبات الأمن السيبراني وأولويات الأعمال والاحتياجات التشغيلية.
· الإشراف على أنشطة دليل إثبات المفهوم، بما في ذلك تعريف النطاق، معايير النجاح، توافق أصحاب المصلحة، إشراف التنفيذ، وتقرير النتائج.
· تقييم ملاءمة الحل بناءً على فعالية الأمن، وقدرة التكامل، والقابلية للتوسع، والتوافق مع التنظيم، والتأثير التشغيلي، والدعم، والقيمة طويلة الأجل.
· التوصية بضوابط وأدوات تكنولوجيا المعلومات الأمنية الملائمة وفق النتائج وقيمة تقليل المخاطر وجاهزية التشغيل والاتجاه المؤسسي.
المؤهلات: شهادة البكالوريوس في علوم الحاسوب أو الأمن السيبراني أو ما يعادلها من جامعة معترف بها ومرخصة مطلوبة.
يفضل الحصول على شهادة ماجستير في علوم الكمبيوتر أو الأمن السيبراني أو ما يعادلها من جامعة معترف بها ومرخصة.
سنوات الخبرة: 6-8 سنوات في صناعة ذات صلة، ويفضل الغالبية في توصيل أمان تكنولوجيا المعلومات عبر بيئات الشركة والأصول.
المرشح المفضل
سنوات الخبرة
لا خبرة مطلوبة
المؤهل
بكالوريوس/ دبلوم عالٍ
Job description
JOB PURPOSE: Own build readiness, testing orchestration, and controlled handover, coordinating with the Design team for inputs.
Enforce gates, close defects, and produce audit-ready validation packs for assigned programs across corporate and asset IT Security programs.
Core Responsibilities: Readiness governance and gates · Operate exit-gate governance across environments; verify prerequisites (access, certs, backups, rollback).
· Supervise Go/No-Go forums and ensure documentation of risks, exceptions, and compensating controls with Cybersecurity sign-off.
· Maintain change calendars aligned to asset windows and blackout periods.
Test planning, data, and environments · Supervise the build of end-to-end test plans covering functional, negative, resilience, and integration scenarios.
· Ensure observer participation (Ops, platform SMEs) for test credibility.
Defect, risk, and issue management · Manage defect triage; assign owners/severity; track fix SLAs and re-tests.
· Maintain RAID logs; escalate blockers; quantify residual risk at release.
Validation packs and traceability · Supervise compilation of validation packs (plans, results, evidence, traceability matrices); ensure versioned storage and approvals.
· Ensure achievement of first-pass acceptance by QA/Excellence and ensure quick resolution of returns.
Handover and run readiness · Validate runbooks, monitoring/alerting, and L1/L2 training completion; confirm operational SLOs and DR artifacts.
· Confirm SIEM/SOAR mappings and case workflows prior to go-live.
· Stakeholder coordination and communications · Facilitate cutover rehearsals; publish comms plans, RACI, and hyper care schedules.
· Provide weekly readiness dashboards and risk summaries to governance forums.
Continuous improvement · Track change success rate and checklists accordingly.
Security Control Evaluation, POC, and Implementation · Lead the evaluation of IT Security controls, technologies, and solutions to ensure alignment with organizational strategy, Cybersecurity requirements, business priorities, and operational needs.
· Oversee Proof of Concept activities, including scope definition, success criteria, stakeholder alignment, execution oversight, and outcome reporting.
· Assess solution suitability based on security effectiveness, integration capability, scalability, compliance alignment, operational impact, supportability, and long-term value.
· Recommend fit-for-purpose IT Security controls and technology solutions based on outcomes, risk reduction value, operational readiness, and enterprise direction.
Qualifications: Bachelor’s degree in Computer Science, Cybersecurity or equivalent from a recognized and accredited university is required.
Master’s degree in Computer Science, Cybersecurity or equivalent from a recognized and accredited university is preferred.
Years of Experience: 6-8 years in a relevant industry, preferably with majority in IT security delivery across corporate and asset environments.
Preferred candidate
Years of experience
No experience required
Degree
Bachelor's degree / higher diploma