ملخص الوظيفة
بناء وتنفيذ الحلول المتعلقة بالأمن السيبراني لجميع المستخدمين النهائيين وفقاً لسياسات وإجراءات منظمة كير (CARE).
الواجبات والمسؤوليات الرئيسية: تنفيذ ضوابط الكشف والوقاية والاسترداد للحماية من البرمجيات الضارة والمتنقلة. تهيئة وتثبيت جدران الحماية وأنظمة كشف التسلل. إجراء اختبارات الثغرات وتحليل المخاطر وتقييمات الأمان. المساعدة في التحقيقات لتحديد كيفية وقوع الخروقات الأمنية. إنشاء وصيانة ترتيبات الحماية من الفيروسات في جميع أنحاء منظمة كير. ضمان تنفيذ إدارة الثغرات التقنية. توفير الدعم لتمارين التدقيق والمراجعة التقنية. ضمان توفر معلومات دقيقة حول الثغرات التقنية. إجراء مسح للثغرات عند الحاجة أو وفقاً للجدول الزمني. إنشاء تقارير مفصلة لتوفير معلومات واضحة حول الثغرات. مراقبة سجلات نظام إدارة الأحداث والمعلومات الأمنية (SIEM). مراقبة وتنفيذ تحديثات نظام (SIEM). تحديد والتحقق الفوري من حوادث الأمن السيبراني والتحقيق فيها وتسجيلها ومراجعتها والإبلاغ عنها. اتباع العمليات والإجراءات التشغيلية المفصلة لتحليل وتصعيد ودعم معالجة حوادث الأمن السيبراني. صيانة وتحديث قاعدة بيانات التهديدات والثغرات لضمان التقاط التهديدات البيئية وتحديثها. قياس فعالية تنفيذ إدارة الثغرات التقنية. إنشاء تقارير مفصلة لتوفير معلومات واضحة حول خطوات معالجة الثغرات. إنشاء وتحسين العمليات والإجراءات التشغيلية المفصلة لتحديد والتحقق من حوادث الأمن السيبراني والتحقيق فيها وتسجيلها ومراجعتها والإبلاغ عنها. العمل بفاعلية على الحوادث الأمنية التي يرفعها مركز العمليات الأمنية (SOC) وفقاً لخطة الاستجابة للحوادث المعتمدة. إنشاء وتحسين العمليات والإجراءات التشغيلية المفصلة لتحليل وتصعيد ودعم معالجة حوادث الأمن السيبراني. أداء مهام وواجبات وظيفية إضافية حسب التكليف. يرفع تقاريره إلى
مدير الأمن السيبراني
الإشراف على
لا يوجد
المهارات معرفة متعمقة بالمهارات التقنية (مثل: بنى الشبكات الآمنة، ممارسات البرمجة الآمنة، البروتوكولات). معرفة أساسية بـ (مثل: بنى الشبكات الآمنة، ممارسات البرمجة الآمنة، البروتوكولات). فهم قوي لأنظمة وتقنيات أمن الشبكات. الحصول على شهادة ذات صلة مثل CCIE Security أو CCNP R&S أو CISSP أو CISA أو CISM. إتقان التحدث والكتابة باللغتين الإنجليزية والعربية. إظهار مهارات تواصل شخصية ممتازة. المؤهلات
درجة الماجستير في الأمن السيبراني، علوم الحاسب، هندسة الحاسب أو درجة مماثلة. يفضل الحصول على شهادة CCIE Security أو CCNP R&S أو CISSP أو CISA أو CISM. درجة البكالوريوس في الأمن السيبراني، علوم/هندسة الحاسب، أو درجة مماثلة. الخبرة: درجة الماجستير: من صفر (0) إلى ثلاث (3) سنوات من الخبرة. درجة البكالوريوس: سنتان (2) من الخبرة في تدريب الأمن السيبراني.
Job Summary
To build and implement Cybersecurity related solutions for all end-users within the CARE Policies and Procedures.
Major Duties and Responsibilities:Implement detection, prevention, and recovery controls to protect against malicious and mobile code Configure and install firewalls and intrusion detection systems. Perform vulnerability testing, risk analyses and security assessments. Assist with investigations to determine how security breaches happened. Establish and maintain virus protection arrangements throughout CARE. Ensure the implementation of technical vulnerability management. Provide support for technical audit and review exercise. Ensure the availability of timely information about technical vulnerabilities. Conduct vulnerability scanning when needed or as scheduled. Create detailed reports to provide clear information about vulnerabilities. Monitor SIEM key logs. Monitor and implement SIEM updates. Identify, promptly validate, and investigate, record, review and report Cybersecurity incidents. Follow detailed operational processes and procedures to analyze, escalate, and support the remediation of cybersecurity incidents. Maintain and keep threat and vulnerability database up to date to ensure environmental threats are captured, updated. Measure the effectiveness of technical vulnerability management implementation Create detailed reports to provide clear information about vulnerabilities remediation steps. Create and enhance detailed operational processes and procedures to Identify, validate, investigate, record, review and report cybersecurity incidents. Work actively on security incidents raised by security operation center (SOC) following approved incident response plan. Creates and enhances detailed operational processes and procedures to analyze, escalate, and support the remediation of cybersecurity incidents. Perform additional job-related tasks and duties as assigned. Reporting to
Director, Cybersecurity
Supervises
None
Skills In-depth knowledge of hard skills (e.g. secure network architectures, secure coding practices, protocols. Basic knowledge of (e.g. secure network architectures, secure coding practices, protocols. Strong understanding of network security systems and technologies. A relevant certification such as CCIE Security, CCNP R&S, CISSP, CISA or CISM. Fluency in verbal and written English & Arabic. Exhibits excellent interpersonal communication skills. Qualifications
Master’s Degree in Cybersecurity, Computer Science, Computer Engineering or similar degree. Certified CCIE Security, CCNP, R&S, CISSP, CISA or CISM is preferred Bachelor Degree in Cybersecurity, Computer Science/Engineering, or similar degree. Experience:Master’s Degree : Zero (0) to Three (3) years of experience Bachelor Degree : Two (2) years of experience Cybersecurity Training.