Role Summary:
Leading the cybersecurity and privacy program for SAFE. This role will involve developing and implementing security and privacy policies and procedures, managing security and privacy incidents, and ensuring compliance with relevant regulations and standards.
Main Responsibilities:
- Develop and implement cybersecurity and privacy programs that align with business objectives and industry best practices.
- Manage and oversee SAFE security and privacy incident response program, including incident reporting, investigation, and resolution.
- Conduct risk assessments and vulnerability assessments to identify potential security and privacy risks and develop mitigation strategies.
- Develop and implement security and privacy policies and procedures, including data protection policies, access controls, and incident response plans.
- Stay up to date on emerging cybersecurity and privacy threats and trends and develop strategies to address them.
- Manage relationships with external vendors and partners to ensure compliance with security and privacy requirements.
- Provide guidance and support to employees on security and privacy issues, including training and awareness.
- Monitor and report on key cybersecurity and privacy metrics, including vulnerability assessments, security incidents, and compliance status.
- Ensure compliance with relevant security and privacy regulations and standards such as CITC, NCA, SAMA, SDAIA.
- Perform additional tasks as assigned.
Managerial Accountability:
Human Capital Development
- Create strategy, goals or plans for the team as appropriate, in alignment with SAFE goals.
- Set priorities and manage workload for self and staff.
- Recognize training needs and ensure that staff gain needed skills.
- Create strategy, goals or plans for the team as appropriate, in alignment with SAFE goals.
Required Qualifications:
- Minimum bachelor’s degree, Cybersecurity, Computer Science, Information Technology, or a related field.
- 10+ years of experience in various roles, including at least 3 years in a leadership role.
- CISSP, CISM, or CISA, are a plus.
Leadership Competency:
Driving Success:
- Translates SAFE vision and goals into clear, specific and achievable objectives. Takes control of projects, leading on key tasks and monitoring others to ensure they fulfil their roles effectively.
- Demonstrates belief in and personal commitment to SAFE vision and mission. Fulfils commitments while maintaining high levels of productivity and output for self and team.
Building Relationships:
- Builds an understanding of who key stakeholders are (including shareholders), their needs, drivers and constraints. Develop common understanding across widely competing needs.
- Interacts well with others, quickly establishing rapport and maintaining useful relationships with internal and external stakeholders for the benefit of the organization.
Engaging Individuals:
- Creates a team identity and shared purpose among team members. Articulates the vision for the future in a way to motivate others to action. Finds effective ways to empower individuals and help them succeed.
- Focuses on developing, coaching and mentoring talent to enhance skills, knowledge and abilities to improve individual and organizational performance.
Core Competency:
Dependability:
- Self-driven and acts proactively.
- Pursues goals with persistence and stamina, works on tasks thoroughly, ensuring accuracy and meeting standards.
- Maintains high levels of quality and effectiveness of work outputs and achieves outstanding results.
Collaboration:
- Collaborates constructively with people at all levels across the organization.
- Helps colleagues, always available to the team, and delivers on team commitments.
- Trusts the guidance and direction of colleagues and senior members of the team.
Analytical Thinking:
- Examines evaluates and analyses different types of information objectively.
- Spots trends and patterns, establishes key facts clearly and interprets numerical data effectively.
- Provides insights and identifies ways to improve things. Trusts your intuition about which methods will work best.
Effective Communication:
- Listens attentively and seeks to understand before being understood.
- Explains things clearly, articulates and presents information effectively and confidently.
- Challenges ideas effectively and presents persuasive arguments by presenting a strong case.
Functional Competency:
Threat Analysis
Knowledge of structure, approach, and strategy of exploitation tools (e.g., sniffers, keyloggers) and techniques (e.g., gaining backdoor access, collecting/exfiltrating data, conducting vulnerability analysis of other systems in the network). Skill in the deep analysis of captured malicious code (e.g., malware forensics).
Vulnerability Assessment
Ability to identify systemic security issues based on the analysis of vulnerability and configuration data.
Data Privacy and Protection
Demonstrates knowledge of data privacy and protection infrastructure, standards, and procedures and engages with stakeholders to raise organizational data privacy and protection capability and awareness.
Incident Management
Demonstrates knowledge of incident categories, incident responses, and timelines for responses.
Cyber Risk Management
Demonstrates knowledge of information technology (IT) supply chain security and supply chain risk management policies, requirements, and procedures to identify relevant threats and vulnerabilities, assess the potential threat’s impact, and develop mitigation plans.
Cyber Security Strategy & Governance
Leverage understanding of cybersecurity regulatory requirements, industry standards, and the national cybersecurity strategy to develop and enhance the SAFE cybersecurity strategy, governance model, and controls and ensure robust threat monitoring and incident management policies and procedures are in place.
Cyber Security Audit & Compliance
Ability to conduct security compliance audits to verify that information processes meet the security criteria (requirements or policy, standards, and procedures).
Data Analysis
Demonstrates knowledge of analytic tools and techniques for Network traffic, system artifacts, and infrastructure logs.
ملخص الدور:
قيادة برنامج الأمن السيبراني والخصوصية في SAFE. يتضمن هذا الدور تطوير وتنفيذ سياسات وإجراءات الأمن والخصوصية، وإدارة حوادث الأمن والخصوصية، وضمان الامتثال للوائح والمعايير ذات الصلة.
المسؤوليات الرئيسية:
- تطوير وتنفيذ برامج الأمن السيبراني والخصوصية بما يتماشى مع أهداف العمل وأفضل ممارسات الصناعة.
- إدارة والإشراف على برنامج الاستجابة لحوادث الأمن والخصوصية في SAFE، بما في ذلك الإبلاغ عن الحوادث والتحقيق فيها وحلها.
- إجراء تقييمات المخاطر وتقييمات الثغرات الأمنية لتحديد مخاطر الأمن والخصوصية المحتملة وتطوير استراتيجيات التخفيف منها.
- تطوير وتنفيذ سياسات وإجراءات الأمن والخصوصية، بما في ذلك سياسات حماية البيانات، وضوابط الوصول، وخطط الاستجابة للحوادث.
- مواكبة التهديدات والاتجاهات الناشئة في مجال الأمن السيبراني والخصوصية وتطوير استراتيجيات لمعالجتها.
- إدارة العلاقات مع البائعين والشركاء الخارجيين لضمان الامتثال لمتطلبات الأمن والخصوصية.
- تقديم التوجيه والدعم للموظفين بشأن قضايا الأمن والخصوصية، بما في ذلك التدريب والتوعية.
- مراقبة وتقديم تقارير حول المقاييس الرئيسية للأمن السيبراني والخصوصية، بما في ذلك تقييمات الثغرات الأمنية، والحوادث الأمنية، وحالة الامتثال.
- ضمان الامتثال للوائح ومعايير الأمن والخصوصية ذات الصلة مثل هيئة الاتصالات والفضاء والتقنية (CITC)، والهيئة الوطنية للأمن السيبراني (NCA)، والبنك المركزي السعودي (SAMA)، والهيئة السعودية للبيانات والذكاء الاصطناعي (SDAIA).
- تنفيذ مهام إضافية حسب التكليف.
المساءلة الإدارية:
تنمية رأس المال البشري
- إنشاء استراتيجية أو أهداف أو خطط للفريق حسب الاقتضاء، بما يتماشى مع أهداف SAFE.
- تحديد الأولويات وإدارة عبء العمل للنفس وللموظفين.
- تحديد احتياجات التدريب وضمان اكتساب الموظفين للمهارات اللازمة.
- إنشاء استراتيجية أو أهداف أو خطط للفريق حسب الاقتضاء، بما يتماشى مع أهداف SAFE.
المؤهلات المطلوبة:
- درجة البكالوريوس كحد أدنى في الأمن السيبراني، أو علوم الحاسب، أو تقنية المعلومات، أو مجال ذي صلة.
- 10+ سنوات من الخبرة في أدوار متنوعة، بما في ذلك 3 سنوات على الأقل في دور قيادي.
- تعد شهادات CISSP أو CISM أو CISA ميزة إضافية.
الكفاءة القيادية:
دفع النجاح:
- ترجمة رؤية وأهداف SAFE إلى أهداف واضحة ومحددة وقابلة للتحقيق. تولي مسؤولية المشاريع، والقيادة في المهام الرئيسية ومراقبة الآخرين لضمان قيامهم بأدوارهم بفعالية.
- إظهار الإيمان والالتزام الشخصي برؤية ورسالة SAFE. الوفاء بالالتزامات مع الحفاظ على مستويات عالية من الإنتاجية والمخرجات للنفس وللفريق.
بناء العلاقات:
- بناء فهم لأصحاب المصلحة الرئيسيين (بما في ذلك المساهمين)، واحتياجاتهم ودوافعهم وقيودهم. تطوير فهم مشترك عبر الاحتياجات المتعارضة على نطاق واسع.
- التفاعل الجيد مع الآخرين، وتأسيس علاقات سريعة والحفاظ على علاقات مفيدة مع أصحاب المصلحة الداخليين والخارجيين لصالح المنظمة.
إشراك الأفراد:
- خلق هوية للفريق وهدف مشترك بين أعضاء الفريق. صياغة رؤية المستقبل بطريقة تحفز الآخرين على العمل. إيجاد طرق فعالة لتمكين الأفراد ومساعدتهم على النجاح.
- التركيز على تطوير وتدريب وتوجيه المواهب لتعزيز المهارات والمعرفة والقدرات لتحسين الأداء الفردي والتنظيمي.
الكفاءة الأساسية:
الاعتمادية:
- دوافع ذاتية والعمل بشكل استباقي.
- السعي لتحقيق الأهداف بمثابرة وقوة تحمل، والعمل على المهام بدقة، وضمان الدقة والوفاء بالمعايير.
- الحفاظ على مستويات عالية من الجودة والفعالية في مخرجات العمل وتحقيق نتائج متميزة.
التعاون:
- التعاون بشكل بناء مع الأشخاص على جميع المستويات في جميع أنحاء المنظمة.
- مساعدة الزملاء، والتوفر الدائم للفريق، والوفاء بالتزامات الفريق.
- الثقة في توجيهات وإرشادات الزملاء والأعضاء الكبار في الفريق.
التفكير التحليلي:
- فحص وتقييم وتحليل أنواع مختلفة من المعلومات بموضوعية.
- رصد الاتجاهات والأنماط، وتحديد الحقائق الرئيسية بوضوح، وتفسير البيانات الرقمية بفعالية.
- تقديم رؤى وتحديد طرق لتحسين الأمور. الثقة في الحدس بشأن الطرق التي ستعمل بشكل أفضل.
التواصل الفعال:
- الاستماع بانتباه والسعي للفهم قبل أن يتم فهمك.
- شرح الأمور بوضوح، وصياغة وتقديم المعلومات بفعالية وثقة.
- تحدي الأفكار بفعالية وتقديم حجج مقنعة من خلال عرض قضية قوية.
الكفاءة الوظيفية:
تحليل التهديدات
معرفة هيكل ونهج واستراتيجية أدوات الاستغلال (مثل أدوات التلصص sniffers، ومسجلات ضغط المفاتيح keyloggers) والتقنيات (مثل اكتساب وصول خلفي backdoor، وجمع/تسريب البيانات، وإجراء تحليل الثغرات لأنظمة أخرى في الشبكة). المهارة في التحليل العميق للكود الضار المكتشف (مثل تحليل البرمجيات الضارة).
تقييم الثغرات
القدرة على تحديد المشكلات الأمنية النظامية بناءً على تحليل بيانات الثغرات والتكوين.
خصوصية وحماية البيانات
إظهار المعرفة بالبنية التحتية ومعايير وإجراءات خصوصية وحماية البيانات، والتفاعل مع أصحاب المصلحة لرفع قدرة المنظمة ووعيها بخصوصية وحماية البيانات.
إدارة الحوادث
إظهار المعرفة بفئات الحوادث، واستجابات الحوادث، والجداول الزمنية للاستجابة.
إدارة المخاطر السيبرانية
إظهار المعرفة بأمن سلسلة توريد تكنولوجيا المعلومات (IT) وسياسات ومتطلبات وإجراءات إدارة مخاطر سلسلة التوريد لتحديد التهديدات والثغرات ذات الصلة، وتقييم تأثير التهديد المحتمل، وتطوير خطط التخفيف.
استراتيجية وحوكمة الأمن السيبراني
الاستفادة من فهم المتطلبات التنظيمية للأمن السيبراني، ومعايير الصناعة، واستراتيجية الأمن السيبراني الوطنية لتطوير وتعزيز استراتيجية SAFE للأمن السيبراني، ونموذج الحوكمة، والضوابط، وضمان وجود سياسات وإجراءات قوية لمراقبة التهديدات وإدارة الحوادث.
تدقيق وامتثال الأمن السيبراني
القدرة على إجراء تدقيق لامتثال الأمن للتحقق من أن عمليات المعلومات تلبي معايير الأمن (المتطلبات أو السياسات، والمعايير، والإجراءات).
تحليل البيانات
إظهار المعرفة بالأدوات والتقنيات التحليلية لحركة مرور الشبكة، وقطع أثر النظام، وسجلات البنية التحتية.