عن الدور الوظيفي
نحن نبحث عن قائد لعمليات وأمن تكنولوجيا المعلومات يتولى مسؤولية جميع عمليات تكنولوجيا المعلومات وأمن المعلومات لمكتبنا المحلي.
نحن ننظر فقط في طلبات المرشحين الذين لديهم حق العمل الفعلي في الدولة التي يقع فيها مقر العمل. كفالة التأشيرة غير متوفرة لهذا المنصب.
يتطلب هذا الدور خبرة عملية عميقة ومساوية في كل من عمليات تكنولوجيا المعلومات وأمن المعلومات.
المسؤوليات
- امتلاك وتشغيل الحد الأدنى الأساسي المكتمل لضوابط أمن المعلومات للمكتب المحلي: إدارة الثغرات الأمنية، وتحصين الأجهزة الطرفية، وأنظمة EDR/XDR، وأمن الهويات، والحماية من البريد الإلكتروني والتصيد الاحتيالي، والتوعية الأمنية
- العمل كمستجيب أول للحوادث الأمنية: الاكتشاف، والفرز والتصنيف، والاحتواء، وحفظ الأدلة، والتصعيد، ومراجعة ما بعد الحادث
- إدارة شبكة المكتب بالكامل من البداية إلى النهاية: التوجيه والتحويل، وتقسيم شبكات VLAN، وجدران الحماية من الجيل الجديد (NGFW)، وأنظمة IDS/IPS، والشبكات الافتراضية الخاصة (VPN)، وشبكات Wi-Fi، والعلاقات مع مزودي خدمة الإنترنت
- إدارة Microsoft 365 وEntra ID وإدارة الأجهزة المحمولة (MDM): دورة حياة الهوية، والوصول المشروط، والمصادقة متعددة العوامل (MFA)، وامتثال الأجهزة، وإجراءات الانضمام والمغادرة
- العمل كجهة الاتصال الرئيسية لتقديم دعم تكنولوجيا المعلومات لمقرات دول مجلس التعاون الخليجي، وتولي حل التذاكر، وتجهيز الأجهزة الطرفية، وضمان جودة الخدمة
- إدارة الموردين المحليين، والمشتريات، وسجل أصول تكنولوجيا المعلومات على مدار دورة حياتها الكاملة
- تطبيق ضوابط تكنولوجيا المعلومات والأمن المطلوبة من قبل المنظم المالي المحلي وقانون حماية البيانات، والحفاظ على أدلة جاهزة للمراجعة والتدقيق
- قيادة فريق تكنولوجيا معلومات محلي صغير و/أو شركاء الخدمات المدارة؛ وإدارة مشاريع تكنولوجيا المعلومات المحلية وتوسعات المكتب
- تقديم تقارير عن الوضع الأمني، والمخاطر، وتقدم إجراءات المعالجة إلى رئيس السحابة والعمليات / رئيس قسم الامتثال (CCO) وإدارة الأمن العالمية
المتطلبات
- خبرة تتراوح بين 6 إلى 8 سنوات أو أكثر في عمليات تكنولوجيا المعلومات، تتضمن 2 إلى 3 سنوات كمتخذ قرار رئيسي لتكنولوجيا المعلومات لموقع أو فرع محلي
- خبرة عملية في أمن المعلومات متوازنة مع خبرة العمليات: أنظمة EDR، وإدارة الثغرات والتحديثات، ومعايير التحصين، والحماية من البريد الإلكتروني والتصيد الاحتيالي، وفرز سجلات وتنبيهات الأمن
- خبرة كمستجيب للحوادث الأمنية: الاكتشاف، والفرز، والاحتواء، وحفظ الأدلة، والتصعيد، ومراجعة ما بعد الحادث
- خبرة عملية في هندسة وأمن الشبكات: التوجيه والتحويل، وتصميم VLAN، وإدارة NGFW (Fortinet أو Palo Alto أو Cisco أو ما يعادلها)، وأنظمة IDS/IPS، ووصلات VPN بين المواقع وعن بُعد، ونشر وحدات التحكم بشبكات Wi-Fi
- إدارة قوية لـ Microsoft 365 وEntra ID: دورة حياة الهوية، والوصول المشروط، والمصادقة متعددة العوامل (MFA)، وExchange Online، وSharePoint، وIntune/MDM
- إدارة الأجهزة الطرفية وتحصينها عبر أنظمة Windows وmacOS: تثبيت الصور، وتواتر التحديثات، وتشفير الأقراص، ووكلاء EDR، وقواعد التكوين الأساسية
- خبرة عملية بإحدى أطر عمل ضوابط الأمن المعترف بها (ISO 27001 أو SOC 2 أو NIST CSF أو CIS Controls) وإعداد أدلة الضوابط لغايات التدقيق
- خبرة في بيئة خاضعة للتنظيم — الخدمات المالية، أو التكنولوجيا المالية، أو المصارف، أو التأمين — مع التعامل المباشر مع أعمال التدقيق والامتثال
- خبرة في قيادة الأفراد: مرؤوسون مباشرون، أو مقاولون، أو فرق الخدمات المدارة
- إتقان مهني للغة الإنجليزية بالإضافة إلى لغة الأعمال الرئيسية في السوق المحلي
المؤهلات المفضلة
- شهادات أمنية: CompTIA Security+، أو CySA+، أو GCIH، أو ISO 27001 Lead Implementer، أو CISSP، أو CISM
- شهادات الشبكات: CCNA/CCNP، أو CompTIA Network+، أو Fortinet NSE
- شهادات مايكروسوفت: SC-200، أو SC-300، أو MD-102، أو MS-102، أو AZ-104
- خبرة في أنظمة SIEM/SOAR: Microsoft Sentinel، أو Splunk، أو Elastic
- معرفة بالأطر التنظيمية المالية المحلية (BNM RMiT، أو MAS TRM، أو HKMA TM-G-1، أو ما يعادلها) وقانون حماية البيانات المعمول به
- إدارة السحابة وأمنها على مستوى العمليات: AWS أو GCP
- كتابة البرامج النصية للأتمتة: PowerShell أو Bash أو Python
- خبرة في تأسيس مكتب وإنشاء معاييره الأمنية الأساسية من الصفر كأول موظف تكنولوجيا معلومات في السوق
About the Role
We are looking for an IT & Security Lead to own all IT operations and information security for our market office.
We consider only candidates with an existing right to work in the country where the role is based. Visa sponsorship is not available for this position.
The role demands equally deep practical expertise in both IT operations and information security.
Responsibilities
- Own and operate the full information security control baseline for the market: vulnerability management, endpoint hardening, EDR/XDR, identity security, email and phishing defence, and security awareness
- Serve as first responder for security incidents: detection, triage, containment, evidence preservation, escalation, and post-incident review
- Own the office network end-to-end: routing and switching, VLAN segmentation, NGFW, IDS/IPS, VPN, Wi-Fi, and ISP relationships
- Administer Microsoft 365, Entra ID, and MDM: identity lifecycle, conditional access, MFA, device compliance, and onboarding/offboarding
- Serve as the primary IT support contact for the GCC market, owning ticket resolution, endpoint provisioning, and service quality
- Manage local vendors, procurement, and the IT asset register across the full lifecycle
- Operate IT and security controls required by the market's financial regulator and data protection law, and maintain audit-ready evidence
- Lead a small local IT team and/or managed-service partners; drive local IT projects and office expansions
- Report security posture, risks, and remediation progress to the Head of Cloud & Operations / CCO and the global Security function
Requirements
- 6–8+ years of progressive IT operations experience, including 2–3 years as the primary IT decision-maker for a site or market
- Hands-on information security experience weighted equally with operations: EDR, vulnerability and patch management, hardening baselines, email and phishing defence, security log and alert triage
- Incident response experience as a responder: detection, triage, containment, evidence preservation, escalation, and post-incident review
- Hands-on network engineering and security: routing and switching, VLAN design, NGFW administration (Fortinet, Palo Alto, Cisco, or equivalent), IDS/IPS, site-to-site and remote-access VPN, Wi-Fi controller deployments
- Strong Microsoft 365 and Entra ID administration: identity lifecycle, conditional access, MFA, Exchange Online, SharePoint, Intune/MDM
- Endpoint management and hardening across Windows and macOS: imaging, patch cadence, disk encryption, EDR agents, configuration baselines
- Practical experience with a recognised security control framework (ISO 27001, SOC 2, NIST CSF, or CIS Controls) and producing control evidence for audit
- Experience in a regulated environment — financial services, fintech, banking, or insurance — with direct exposure to audit and compliance
- People leadership experience: direct reports, contractors, or managed-service teams
- Professional working proficiency in English plus the primary business language of the market
Preferred
- Security certifications: CompTIA Security+, CySA+, GCIH, ISO 27001 Lead Implementer, CISSP, or CISM
- Networking certifications: CCNA/CCNP, CompTIA Network+, or Fortinet NSE
- Microsoft certifications: SC-200, SC-300, MD-102, MS-102, or AZ-104
- SIEM/SOAR experience: Microsoft Sentinel, Splunk, or Elastic
- Familiarity with local financial regulatory frameworks (BNM RMiT, MAS TRM, HKMA TM-G-1, or equivalent) and applicable data protection law
- Cloud administration and security at an operations level: AWS or GCP
- Scripting for automation: PowerShell, Bash, or Python
- Experience standing up an office and its security baseline from scratch as the first IT hire in a market