Job description
Introduction
The Digital Security Senior Managing Consultant will be responsible for assessing and developing customer relationship, security design and implementation of digital security services for our clients in KSA. This requires demonstrating thought leadership, delivery expertise and wide understanding of cloud native as well as hybrid/3rd party security controls.
This role mainly focuses on how to assist IBM clients with the transformation in Cloud Security, Identity and Access Management (IAM) and in securing cloud workloads. These cover a range of service models deployed across private, public, hybrid and/or multi-cloud (off and on-prem) environments, and on major hyperscalers such as Microsoft Azure, Amazon Web Services (AWS),and Google Cloud Platform.
Your role and responsibilities
Responsible for managing all the activities related to delivering a digital security solution for the duration of their engagement, including but not limited to:
- Consulting - comfortable in facilitating workshops, giving presentations, producing high quality deliverables and managing large delivery engagements.
- Leadership - supporting all aspects of the solution, consulting colleagues, the technical team, managing client requirements and linking those requirements to IBM's solution,
- Creating & delivering the solution element of Cloud & Data Security and IAM proposals, this could be administrative, operational or technical,
- Supporting the definition and creation of a solution that meets the client's requirements,
- Understanding the Digital Security Posture of the client, including their drivers and appetite, risk, legal, regulatory and compliance drivers for the client
- Providing visibility and understanding the functional and non-functional requirements of the solution
- Assisting client facing colleagues with responding to requests for proposals
- Detailed knowledge of architecting and delivery of cloud native delivery methods and blueprints, security and deployment models for IaaS, PaaS, and SaaS across one or more hyperscalers.
- Delivery should centre around adopting agile approach, leveraging automation across infrastructure security via IaC (Infrastructure as a Code) driven approach.
- Working with global and local teams, help organize project approaches and teams for client delivery.
- Help resolve program issues as they arise with senior leadership
- Good understanding of cloud architecture and industry standards are required
- Establish strong client relationships in key accounts to help progress the Security Services portfolio
Practice & People
.Contribute content and advice to the offering development process
.Help establish capability and skills models for the core domain, partner with wider team to develop expertise
Required education
Bachelor's Degree
Required technical and professional expertise
Bachelor's Degree
.Cloud Certification in for at least:
oOne hyperscaler, security specialist certifications preferred and
oone leading security certificate like CISA, CISSP, CISM, etc.
.Working experience of industry compliance and security standards including KSA NCA ECC, CSA CSM, PCI DSS, ISO 27001, NIST, CIS, etc.
.Working experience in conducting security architecture and configuration reviews leveraging Zero Trust Security principles to identify security gaps and develop high-quality assessment reports.
.Extensive knowledge in security solutions such as IAM, Data Protection and Cloud Security Solutions.
.Develop high-quality security projects design documentation, etc.
.Working experience on cloud service models (IaaS, PaaS, SaaS etc), infrastructure and technology
.Background knowledge to KSA NCA ECC and other regulations and standards related to the cloud (e.g. ISO/IEC 27018)
.Extensive track record in delivering large-scale, complex and multi-year security transformation programs / projects in various capacities (e.g. cloud security architect, senior delivery/technical lead)
.Experience working across diverse teams to facilitate solutions
.Readiness to travel 25-50%
.At least 5 years' experience in working in international deployment roles and interlocking with client on hybrid/multi cloud security engagements
.At least 8 years' experience in working with security consulting and/or architecture roles
.At least 10 years' experience overall, across IT and Cyber Security.
.English: Fluent.
Preferred technical and professional experience
Hiring manager and Recruiter should collaborate to create the relevant verbiage.
Preferred candidate
Years of experience
No experience required
Degree
Bachelor's degree / higher diploma
وصف الوظيفة
مقدمة
سيكون مستشار الأمان الرقمي الأعلى Managing Senior مسؤولا عن تقييم وتطوير علاقة العملاء، وتصميم الأمن وتنفيذ خدمات الأمن الرقمي لعملائنا في المملكة العربية السعودية. يتطلب ذلك إظهار قدرة قيادية فكرية، وخبرة في التنفيذ وفهم واسع للأمن السحابي إلى جانب ضوابط الأمان الهجينة/الطرف الثالث.
يركز هذا الدور بشكل رئيسي على كيفية مساعدة عملاء IBM في التحول في أمان السحابة، والهويات وإدارة الوصول (IAM) وتأمين أحمال العمل السحابية. وتشمل هذه النماذج الخدمية المعتمدة عبر بيئات خاصة وعامة وهجينة ومتعددة السحابات (في الموقع وخارجه)، وعلى مقدمي الخدمات الرئيسيين مثل Microsoft Azure وAmazon Web Services (AWS) وGoogle Cloud Platform.
دورك ومسؤولياتك
مسؤول عن إدارة جميع الأنشطة المتعلقة بتقديم حل أمان رقمي طوال مدة تعاقدهم، بما في ذلك على سبيل المثال لا الحصر:
- الاستشارات - الراحة في تسهيل ورش العمل، وتقديم العروض، إنتاج مخرجات عالية الجودة وإدارة مشاريع التسليم الكبيرة.
- القيادة - دعم جميع جوانب الحل، واستشارة الزملاء الفنيين، والفريق التقني، وإدارة متطلبات العميل وربط تلك المتطلبات بحل IBM،
- إنشاء وتقديم عنصر الحل في مقترحات Cloud & Data Security وIAM، وقد يكون إداريًا أو تشغيليًا أو تقنيًا،
- دعم تعريف وإنشاء حل يلبي متطلبات العميل،
- فهم وضع الأمن الرقمي للعميل، بما في ذلك دوافعه وشهيته للمخاطر والدوافع القانونية والتنظيمية والامتثال للعميل
- توفير الرؤية وفهم المتطلبات الوظيفية وغير الوظيفية للحل
- مساعدة زملاء العملاء في الرد على طلبات العروض
- معرفة تفصيلية بتصميم وتنفيذ أساليب التوصيل السحابية والرسوم الهندسية وخطط الأمان والتشغيل لـ IaaS وPaaS وSaaS عبر واحد أو أكثر من مقدمي الخدمات الرئيسيين.
- يجب أن يتركز التسليم حول اعتماد نهج أجايل، والاستفادة من الأتمتة عبر أمان البنية التحتية من خلال نهج مبني على البُنية كمَ رمز (IaC)
- العمل مع فرق عالمية ومحلية، ومساعدة في تنظيم أساليب المشروع والفرق لتسليم العميل.
- مساعدة في حل مشكلات البرنامج عند ظهورها مع القيادة العليا
- فهم جيد لهندسة السحابة والمعايير الصناعية مطلوبة
- إقامة علاقات قوية مع العملاء في الحسابات الرئيسية للمساعدة في تقدم محفظة خدمات الأمن
الممارسة والموظفين
.المساهمة بمحتوى ونصائح في عملية تطوير العرض
.المساعدة في تأسيس نماذج القدرات والمهارات للمجال الأساسي، الشراكة مع الفريق الأوسع لتطوير الخبرة
التعليم المطلوب
درجة البكالوريوس
الخبرة الفنية والمهنية المطلوبة
درجة البكالوريوس
.شهادة سحابة في الأقل:
oإحدى مزودي الخدمة الرئيسيين، شهادات الأمان مفضلة و
oشهادة أمان قيادية مثل CISA، CISSP، CISM، إلخ.
.خبرة عملية في الامتثال الصناعي والمعايير الأمنية بما في ذلك KSA NCA ECC، CSA CSM، PCI DSS، ISO 27001، NIST، CIS، إلخ.
.خبرة عملية في إجراء مراجعات هندسة وتكوين الأمان مستندة إلى مبادئ الثقة الصفرية لتحديد فجوات الأمان وتطوير تقارير تقييم عالية الجودة.
.معرفة واسعة في حلول الأمان مثل IAM، حماية البيانات وحلول أمان السحابة.
.تطوير وثائق تصميم مشاريع أمان عالية الجودة، إلخ.
.خبرة عملية في نماذج خدمات السحابة (IaaS, PaaS, SaaS الخ)، والبنية التحتية والتكنولوجيا
.معرفة خلفية بنطاق KSA NCA ECC واللوائح والمعايير الأخرى المتعلقة بالسحابة (مثل ISO/IEC 27018)
.سجل حافل في تقديم برامج/مشروعات تحول أمان كبيرة النطاق ومعقدة وعلى مدى سنوات عديدة بأدوار مختلفة (مثل مهندس أمان سحابي، قائد تسليم/فني كبير)
.خبرة في العمل مع فرق متنوعة لتسهيل الحلول
.الجاهزية للسفر 25-50%
.خبرة لا تقل عن 5 سنوات في العمل في أدوار نشر دولية والتعاون مع العميل في مشاريع أمان هجينة/متعددة السحاب
.خبرة لا تقل عن 8 سنوات في العمل مع استشارات الأمان و/أو أدوار الهندسة
.خبرة لا تقل عن 10 سنوات بشكل عام، عبر تكنولوجيا المعلومات والأمن السيبراني.
.الإنجليزية: طلاقة.
التفضيلات الفنية والمهنية المطلوبة
يجب أن يتعاون مدير التوظيف والموظف لجعل الصياغة ملائمة.