Job Description
Responsible for the operational tasks for account administration, e Discovery, incident response, waiver/policy assistance, and implementation of cyber security/protection technologies for the Project information and process systems/applications. Acts as contact with suppliers to develop technical solutions for computer security needs and makes recommendations to management. Develops, maintains, and audits the analytical and technical aspects of major computer security systems. Maintains the confidentiality, integrity, and availability of computer workstations, servers, and local area networks by maintaining user accounts and upgrading systems and software as required. Responsible for secure operations of security equipment, secure transmission of sensitive unclassified information and protection of cryptographic principles and methods. Mitigates threats and vulnerabilities that are associated with potentially compromising corporate and client data. Provides technical support, training, and timely computer system data recovery to end-users. Oversees the investigation of computer security incidents and acts as an assistant for cyber security initiatives. Conducts operations of computer protection measures and creates measurement tools for system vulnerability assessments. Serves on project teams and internal committees to represent cyber security interests. Oversee the client/server/infrastructure group on appropriate procedures for computer/system security.
Qualifications
Required Skills and Experience:
15+ years of professional experience in cybersecurity roles, with at least 5 years in a senior or leadership capacity Advanced knowledge of network security, threat analysis, and incident response procedures Proficiency with security tools and platforms, including firewalls, SIEM systems, and intrusion detection systems Strong understanding of security protocols, vulnerability management, and risk assessment methodologies Experience with security auditing, compliance frameworks, and regulatory requirements Demonstrated expertise in firewall configuration, network segmentation, and access control implementation Excellent analytical and problem-solving skills with the ability to make decisive security decisions Strong organizational and project management capabilities Proficiency in security documentation and technical report writing
Preferred Skills and Experience:
Experience with cloud security platforms and hybrid security architectures Knowledge of penetration testing and ethical hacking methodologies Familiarity with security information and event management (SIEM) tools Understanding of encryption technologies and data protection mechanisms Experience with digital forensics and malware analysis Knowledge of cybersecurity requirements specific to the Middle East region Familiarity with local Saudi Arabian compliance standards and regulations
Certifications and Domain Expertise:
CISSP (Certified Information Systems Security Professional) or equivalent certification preferred CEH (Certified Ethical Hacker) or similar advanced security certification CCNA Security or comparable networking security certification Domain expertise in enterprise security, information security management, and risk management
الوصف الوظيفي
مسؤول عن المهام التشغيلية لإدارة الحسابات، والاكتشاف الإلكتروني (e Discovery)، والاستجابة للحوادث، والمساعدة في التنازلات/السياسات، وتنفيذ تقنيات الأمن السيبراني/الحماية لأنظمة/تطبيقات معلومات وعمليات المشروع. يعمل كجهة اتصال مع الموردين لتطوير حلول تقنية لاحتياجات أمن الكمبيوتر ويقدم توصيات للإدارة. يقوم بتطوير وصيانة وتدقيق الجوانب التحليلية والتقنية لأنظمة أمن الكمبيوتر الرئيسية. يحافظ على سرية وسلامة وتوافر محطات عمل الكمبيوتر والخوادم وشبكات المنطقة المحلية من خلال صيانة حسابات المستخدمين وترقية الأنظمة والبرامج حسب الحاجة. مسؤول عن العمليات الآمنة لمعدات الأمن، والنقل الآمن للمعلومات غير المصنفة الحساسة، وحماية المبادئ والأساليب التشفيرية. يعمل على تخفيف التهديدات والثغرات الأمنية المرتبطة ببيانات الشركة والعملاء التي قد تتعرض للخطر. يقدم الدعم الفني والتدريب واستعادة بيانات نظام الكمبيوتر في الوقت المناسب للمستخدمين النهائيين. يشرف على التحقيق في حوادث أمن الكمبيوتر ويعمل كمساعد لمبادرات الأمن السيبراني. يدير عمليات تدابير حماية الكمبيوتر وينشئ أدوات قياس لتقييم ثغرات النظام. يعمل في فرق المشاريع واللجان الداخلية لتمثيل مصالح الأمن السيبراني. يشرف على مجموعة العميل/الخادم/البنية التحتية بشأن الإجراءات المناسبة لأمن الكمبيوتر/النظام.
المؤهلات
المهارات والخبرات المطلوبة:
أكثر من 15 عاماً من الخبرة المهنية في أدوار الأمن السيبراني، مع ما لا يقل عن 5 سنوات في منصب قيادي أو إشرافي. معرفة متقدمة بأمن الشبكات، وتحليل التهديدات، وإجراءات الاستجابة للحوادث. إتقان أدوات ومنصات الأمن، بما في ذلك جدران الحماية، وأنظمة إدارة الأحداث والمعلومات الأمنية (SIEM)، وأنظمة كشف التسلل. فهم قوي لبروتوكولات الأمن، وإدارة الثغرات الأمنية، ومنهجيات تقييم المخاطر. خبرة في تدقيق الأمن، وأطر الامتثال، والمتطلبات التنظيمية. خبرة مثبتة في تكوين جدران الحماية، وتقسيم الشبكات، وتنفيذ التحكم في الوصول. مهارات تحليلية وحل مشكلات ممتازة مع القدرة على اتخاذ قرارات أمنية حاسمة. قدرات تنظيمية وإدارة مشاريع قوية. إتقان توثيق الأمن وكتابة التقارير الفنية.
المهارات والخبرات المفضلة:
خبرة في منصات أمن السحابة وبنيات الأمن الهجينة. معرفة باختبار الاختراق ومنهجيات القرصنة الأخلاقية. الإلمام بأدوات إدارة المعلومات والأحداث الأمنية (SIEM). فهم تقنيات التشفير وآليات حماية البيانات. خبرة في التحقيقات الجنائية الرقمية وتحليل البرامج الضارة. معرفة بمتطلبات الأمن السيبراني الخاصة بمنطقة الشرق الأوسط. الإلمام بمعايير ولوائح الامتثال المحلية في المملكة العربية السعودية.
الشهادات والخبرة في المجال:
يفضل الحصول على شهادة محترف أمن نظم المعلومات المعتمد (CISSP) أو شهادة معادلة. شهادة هاكر أخلاقي معتمد (CEH) أو شهادة أمنية متقدمة مماثلة. شهادة CCNA Security أو شهادة أمن شبكات مماثلة. خبرة في مجال أمن المؤسسات، وإدارة أمن المعلومات، وإدارة المخاطر.