وصف الوظيفة
خبير عمليات الأمن السيبراني المسؤول عن دعم خط الدفاع الأول من خلال التنفيذ اليومي والمراقبة وتحسين ضوابط الأمن التشغيلي عبر بيئات تقنية المعلومات المؤسسية.
يركز الدور على حماية الأنظمة والشبكات ونهايات الأجهزة والتطبيقات والمستخدمين من خلال اكتشاف التهديدات والاستجابة لفعاليات الأمان وتنسيق أنشطة الإصلاح والحفاظ على تشغيل أمني سيبراني فعال.
وتشمل المسؤوليات الرئيسية المراقبة المستمرة لتنبيهات وأحداث الأمن، وأمن البريد الإلكتروني، ومنصات الأمن التشغيلي الأخرى، وضمان اتخاذ إجراءات احتواء واسترداد في الوقت المناسب.
كما يدعم الدور إدارة الثغرات من خلال تتبع النتائج وتنسيق الإصلاح مع فرق البنية التحتية والتطبيق والتأكد من إغلاق المخاطر المحددة.
يعمل خبير عمليات الأمن السيبراني عن كثب مع فرق عمليات تقنية المعلومات والشبكات والسحابة والخادم ونهايات الأجهزة والتطبيقات لضمان تنفيذ وضبط ضوابط الأمن بشكل فعال كجزء من عمليات الأعمال والتكنولوجيا اليومية.
كما تشمل المسؤوليات دعم عمليات الهوية وإدارة الوصول، ومراجعة أنشطة الوصول المميز، وفرض خطوط الأساس الأمنية، والحفاظ على دفاتر التشغيل وإجراءات التشغيل، والمساهمة في الوعي الأمني من منظور تشغيلي.
هذا المنصب جزء من خط الدفاع الأول وبالتالي يركز على تشغيل وتنفيذ الضوابط بدلاً من إجراء إشراف مستقل، حوكمة السياسات، ضمان الامتثال التنظيمي، أو أنشطة التدقيق الداخلي المرتبطة بالخطوط الدفاعية الثانية أو الثالثة.
المسؤوليات: مراقبة وتحليل تنبيهات وأحداث وحوادث الأمن السيبراني.
إجراء فرز أولي، تحقيق، دعم الاحتواء، وتصعيد حوادث الأمن.
دعم عمليات أمان نقاط النهاية والشبكة والسحابة والبريد الإلكتروني.
تنسيق إصلاح الثغرات مع الفرق الفنية المعنية.
تنفيذ وصيانة ضوابط الأمن التشغيلي وحالات استخدام المراقبة.
مراقبة ودعم تطبيقات التصحيح المرتبطة بالأمان وتحديثات المنصة وعمليات تجديد التقنية التشغيلية لضمان الحد الأدنى من التعرض للأمان والانقطاع عن الخدمة.
دعم أنشطة الأمن خلال ترحيلات الأنظمة والأدوات والبنية التحتية، بما في ذلك تحقق من الضوابط ومراجعات التكوين وفحص الأمان بعد الترحيل.
مراجعة والتحقق من تكاملات الأمان بين أدوات الأمن السيبراني وأنظمة تكنولوجيا المعلومات ومنصات السحابة وحلول جهات خارجية لضمان التتبع الصحي والتأهب والاتصال الفعّال وضبط الضوابط.
دعم مراجعات التحكم في الوصول ومراقبة الوصول المميز وعمليات الأمن المرتبطة بالهوية.
الحفاظ على إجراءات استجابة الحوادث ودفاتر التشغيل والوثائق التشغيلية.
تتبع إجراءات الإصلاح والمتابعة مع أنشطة تقليل المخاطر.
المساهمة في التحسين المستمر لأنشطة وعمليات الأمن السيبراني.
دعم مرونة الأعمال من خلال تقليل تعرض مخاطر الأمن السيبراني التشغيلية.
درجة البكالوريوس في الأمن السيبراني، أمان المعلومات، علوم الحاسوب، تكنولوجيا المعلومات، الهندسة، أو مجال ذو صلة.
أكثر من 5 سنوات خبرة في عمليات الأمن السيبراني، مراقبة الأمن، استجابة للحوادث، إدارة الثغرات، أو وظائف هندسة الأمن.
خبرة عملية مع تقنيات أمان المؤسسات، بما في ذلك SIEM، EDR/XDR، أمان البريد الإلكتروني، إدارة الهوية والوصول، أمان الشبكات، أمان السحابة، ومنصات إدارة الثغرات.
فهم قوي لإطارات الأمن السيبراني، تقنيات الهجوم، منهجيات اكتشاف التهديدات، وممارسات تشغيل الأمن
خبرة في العمل في بيئات هجينة تجمع بنية محلية و منصات سحابية وخدمات طرف ثالث.
الشهادات المفضلة محترف أمن نظم معلومات معتمد (CISSP)، مدير أمن معلومات معتمد (CISM)
المرشح المفضل
سنوات الخبرة
لا يوجد خبرة مطلوبة
المؤهل
درجة البكالوريوس / دبلوم عالي
Job description
Cybersecurity Operations Expert responsible for supporting the first line of defense through the day-to-day execution, monitoring, and improvement of operational security controls across enterprise IT environments.
The role focuses on protecting systems, networks, endpoints, applications, and users by detecting threats, responding to security events, coordinating remediation activities, and maintaining effective cybersecurity operations.
Key responsibilities include continuous monitoring of security alerts and events, email security, and other operational security platforms, and ensuring timely containment and recovery actions.
The role also supports vulnerability management by tracking findings, coordinating remediation with infrastructure and application teams, and validating closure of identified risks.
The Cybersecurity Operations Expert works closely with IT operations, network, cloud, server, endpoint, and application teams to ensure security controls are implemented and functioning effectively as part of daily business and technology operations.
Responsibilities also include supporting identity and access security operations, reviewing privileged access activities, enforcing security baselines, maintaining playbooks and operational procedures, and contributing to security awareness from an operational perspective.
This position is part of the first line of defense and is therefore focused on operating and executing controls rather than performing independent oversight, policy governance, regulatory compliance assurance, or internal audit activities associated with the second or third lines of defense.
Rsponsibilities: Monitor and analyze cybersecurity alerts, events, and incidents.
Perform initial triage, investigation, containment support, and escalation of security incidents.
Support endpoint, network, cloud, and email security operations.
Coordinate vulnerability remediation with relevant technical teams.
Execute and maintain operational security controls and monitoring use cases.
Monitor and support security-related patching, platform upgrades, and operational technology refresh activities to ensure minimal security exposure and service disruption.
Support security activities during system, tool, and infrastructure migrations, including validation of controls, configuration reviews, and post-migration security checks.
Review and validate security integrations between cybersecurity tools, IT systems, cloud platforms, and third-party solutions to ensure proper logging, alerting, connectivity, and control effectiveness.
Support access control reviews, privileged access monitoring, and identity-related security operations.
Maintain incident response procedures, runbooks, and operational documentation.
Track remediation actions and follow up on risk reduction activities.
Contribute to continuous improvement of cybersecurity activities and processes.
Support business resilience by reducing operational cyber risk exposure.
Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field.
5+ years of experience in cybersecurity operations, security monitoring, incident response, vulnerability management, or security engineering functions.
Hands-on experience with enterprise security technologies, including SIEM, EDR/XDR, email security, identity and access management, network security, cloud security, and vulnerability management platforms.
Strong understanding of cybersecurity frameworks, attack techniques, threat detection methodologies, and security operations best practices.
Experience working in hybrid environments spanning on-premises infrastructure, cloud platforms, and third-party services.
Preferred Certifications Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM)
Preferred candidate
Years of experience
No experience required
Degree
Bachelor's degree / higher diploma