Role Summary:
Responsible for leading the development of SAFE’s cyber security program, advising and directing Corporate IT and Technology Solutions on implementing and operating cyber security measures and safeguards.
Main Responsibilities:
- Lead the development of SAFE’s cyber security program, including policies, procedures and protocols, regulations, standards, etc.
- Provide guidance and direction to Corporate IT and Technology Solutions regarding setting up and operating cyber security safeguards and measures.
- Understand and interact with related disciplines through committees to ensure the consistent application of policies and standards across all technology projects, systems, and services.
- Partner with business stakeholders across the company to raise awareness of cybersecurity risk management concerns.
Managerial Accountability:
Human Capital Development
- Foster a culture of cooperation, learning and development, and leadership.
- Deliver ongoing feedback and address performance issues.
- Attract, recruit, and retain a high-performance management team; provide mentoring as a cornerstone to the management career development program.
Required Qualifications:
- Minimum bachelor’s degree, Computer sciences, cybersecurity or another related field.
- +10 years of experience in various rules.
Leadership Competency:
Driving Success:
- Translates SAFE vision and goals into clear, specific, and achievable objectives. Takes control of projects, leading on key tasks and monitoring others to ensure they fulfill their roles effectively.
- Demonstrates belief in and personal commitment to SAFE vision and mission. Fulfils commitments while maintaining high levels of productivity and output for self and team.
Building Relationships:
- Builds an understanding of key stakeholders (including shareholders), their needs, drivers, and constraints. Develop common understanding across widely competing needs.
- Interacts well with others, quickly establishing rapport and maintaining useful relationships with internal and external stakeholders for the organization’s benefit.
Engaging Individuals:
- Creates a team identity and shared purpose among team members. Articulates the vision for the future to motivate others to action. Finds effective ways to empower individuals and help them succeed.
- Focuses on developing, coaching, and mentoring talent to enhance skills, knowledge, and abilities to improve individual and organizational performance.
Core Competency:
Dependability:
- Self-driven and takes action proactively.
- Pursues goals with persistence and stamina, works on tasks thoroughly, ensuring accuracy and meeting standards.
- Maintains high levels of quality and effectiveness of work outputs and achieves outstanding results.
Collaboration:
- Collaborates constructively with people at all levels across the organization.
- Helps colleagues, is always available to the team, and delivers on team commitments.
- Trusts the guidance and direction of colleagues and senior members of the team.
Analytical Thinking:
- Examines, evaluates, and analyses different types of information objectively.
- Spots trends and patterns, establishes key facts clearly and interprets numerical data effectively.
- Provides insights and identifies ways to improve things. Trusts intuition about which methods will work bestways to improve things. Trusts intuition about which methods will work best.
Effective Communication:
- Listens attentively and seeks to understand before being understood.
- Explains things clearly and articulates and presents information effectively and confidently.
- Challenges ideas effectively and presents persuasive arguments by presenting a strong case.
Functional Competency:
Threat Analysis
Knowledge of structure, approach, and strategy of exploitation tools (e.g., sniffers, keyloggers) and techniques (e.g., gaining backdoor access, collecting/exfiltrating data, conducting vulnerability analysis of other systems in the network). Skill in deeply analyzing captured malicious code (e.g., malware forensics).
Vulnerability Assessment
Ability to identify systemic security issues based on vulnerability and configuration data analysis.
Data Privacy and Protection
Demonstrates knowledge of data privacy and protection infrastructure, standards, and procedures and engages with stakeholders to raise organizational data privacy and protection capability and awareness.
Incident Management
Demonstrates knowledge of incident categories, incident responses, and timelines for responses.
Cyber Risk Management
Demonstrates knowledge of information technology (IT) supply chain security and supply chain risk management policies, requirements, and procedures to identify relevant threats and vulnerabilities, assess the potential threat’s impact, and develop mitigation plans.
Cyber Security Strategy & Governance
Leverage understanding of cybersecurity regulatory requirements, industry standards, and the national cybersecurity strategy to develop and enhance the SAFE cybersecurity strategy, governance model, and controls and ensure robust threat monitoring and incident management policies and procedures are in place.
Cyber Security Audit & Compliance
Ability to conduct security compliance audits to verify that information processes meet the security criteria (requirements or policy, standards, and procedures).
Data Analysis
Demonstrates knowledge of analytic tools and techniques for Network traffic, system artifacts, and infrastructure logs.
ملخص الدور:
مسؤول عن قيادة تطوير برنامج الأمن السيبراني في SAFE، وتقديم المشورة وتوجيه قسم تكنولوجيا المعلومات المؤسسية والحلول التقنية بشأن تطبيق وتشغيل إجراءات وحماية الأمن السيبراني.
المسؤوليات الرئيسية:
- قيادة تطوير برنامج الأمن السيبراني لـ SAFE، بما في ذلك السياسات والإجراءات والبروتوكولات والتنظيمات والمعايير، وغيرها.
- تقديم الإرشاد والتوجيه لقسم تقنية المعلومات المؤسسية والحلول التقنية فيما يتعلق بإعداد وتشغيل الضمانات والإجراءات الأمن السيبراني.
- فهم والتفاعل مع التخصصات ذات الصلة من خلال اللجان لضمان التطبيق المتسق للسياسات والمعايير عبر جميع مشاريع وتقنيات وأنظمة وخدمات التكنولوجيا.
- التعاون مع أصحاب المصلحة من الأعمال في جميع الشركة لرفع الوعي بمخاطر إدارة الأمن السيبراني.
المساءلة الإدارية:
تطوير رأس المال البشري
- تعزيز ثقافة التعاون والتعلم والتطوير والقيادة.
- توفير تعليقات مستمرة ومعالجة قضايا الأداء.
- جذب وتوظيف والحفاظ على فريق إدارة عالي الأداء؛ توفير التوجيه كركيزة لبرنامج تطوير المسار الإداري.
المؤهلات المطلوبة:
- درجة البكالوريوس على الأقل، علوم الحاسوب أو الأمن السيبراني أو مجال ذي صلة.
- +10 سنوات من الخبرة في أدوار متنوعة.
الكفاءات القيادية:
قيادة النجاح:
- يترجم رؤية SAFE وأهدافها إلى أهداف واضحة ومحددة وقابلة للتحقيق. يتحكم في المشاريع، يقود المهام الرئيسية ويراقب الآخرين لضمان قيامهم بأدوارهم بفعالية.
- يظهر إيماناً بالالتزام برؤية SAFE ومهمتها. يفي بالالتزامات مع الحفاظ على مستويات عالية من الإنتاجية والإنتاج للفرد والفريق.
بناء العلاقات:
- يبني فهمًا لأصحاب المصلحة الرئيسيين (بما في ذلك المساهمين)، واحتياجاتهم، ومحفّزاتهم، وقيودهم. يطور فهماً مشتركاً عبر احتياجات متباينة على نطاق واسع.
- يتفاعل بشكل جيد مع الآخرين، ويكوّن سريعاً علاقة ويحتفظ بعلاقات مفيدة مع أصحاب المصلحة داخلياً وخارجياً لصالح المؤسسة.
إشراك الأفراد:
- يخلق هوية فريق وهدفاً مشتركاً بين أعضاء الفريق. يوضح الرؤية للمستقبل لتحفيز الآخرين على العمل. يجد طرقاً فعالة لتمكين الأفراد ومساعدتهم على النجاح.
- يركّز على تطوير وتوجيه وتربية المواهب لتعزيز المهارات والمعرفة والقدرات لتحسين الأداء الفردي والتنظيمي.
الكفاءة الأساسية:
الاعتمادية:
- مبادر ويأخذ المبادرة.
- يسعى نحو الأهداف بعزيمة ونشاط، يعمل على المهام بدقة ويضمن الدقة والالتزام بالمعايير.
- يحافظ على مستويات عالية من الجودة وفعالية مخرجات العمل ويحقق نتائج مميزة.
التعاون:
- يتعاون بشكل بنّاء مع الأشخاص على جميع المستويات في المؤسسة.
- يساعد الزملاء، وهو دائماً متاح للفريق، ويؤدي الالتزامات الجماعية.
- يثق بتوجيه وإرشاد الزملاء وأعضاء الفريق الكبار.
التفكير التحليلي:
- يفحص ويقيّم ويحلل أنواعاً مختلفة من المعلومات بشكل موضوعي.
- يلاحظ الاتجاهات والأنماط، ويضع حقائق رئيسة بوضوح ويفسر البيانات الرقمية بفعالية.
- يقدم رؤى ويحدد طرق تحسين الأمور. يثق ببديهته حول الطرق الأنسب للعمل.
التواصل الفعال:
- يستمع بانتباه ويسعى لفهم قبل أن يُفهم.
- يشرح الأشياء بوضوح ويعبر ويقدم المعلومات بشكل فعال وواثق.
- يتحدى الأفكار بشكل فعال ويقدم حجج مقنعة من خلال تقديم حالة قوية.
الكفاءة الوظيفية:
تحليل التهديدات
معرفة بنية واستراتيجية أدوات الاستغلال (مثلاً أدوات الاستنشاق، مسجّلات المفاتيح) والتقنيات (مثلاً الوصول الخلفي، جمع/تسريب البيانات، إجراء تحليل الثغرات في أنظمة أخرى في الشبكة). مهارة في تحليل الشيفرات الخبيثة المحملة بشكل عميق (مثلاً علم الأدلة الجنائية للبرمجيات الخبيثة).
تقييم الثغرات
قدرة على تحديد قضايا أمان النظام استناداً إلى تحليل الثغرات والبيانات الخاصة بالتكوين.
خصوصية البيانات وحمايتها
يظهِر معرفة بالبنية التحتية لخصوصية البيانات وحمايتها والمعايير والإجراءات ويتواصل مع أصحاب المصلحة لتعزيز قدرات ووعي خصوصية البيانات protection للمؤسسة.
إدارة الحوادث
يظهر معرفة بفئات الحوادث واستجابات الحوادث والجداول الزمنية للردود.
إدارة مخاطر الأمن السيبراني
يظهر معرفة بأمن سلسلة توريد تكنولوجيا المعلومات وسياسات وإجراءات إدارة مخاطر سلسلة التوريد لتحديد التهديدات والثغرات ذات الصلة وتقييم تأثير التهديد المحتمل ووضع خطط التخفيف.
استراتيجية وأمن الأمن السيبراني والحوكمة
يستفيد من فهمه للمتطلبات التنظيمية للأمن السيبراني والمعايير الصناعية والاستراتيجية الوطنية للأمن السيبراني لتطوير وتعزيز استراتيجية SAFE للأمن السيبراني ونموذج الحوكمة والضوابط والتأكد من وجود سياسات وإجراءات رصد التهديدات وإدارة الحوادث بشكل قوي.
مراجعة الامتثال للأمن السيبراني
القدرة على إجراء مراجعات امتثال أمني للتحقق من أن عمليات المعلومات تفي بمعايير الأمن (المتطلبات أو السياسة، المعايير، والإجراءات).
تحليل البيانات
يظهر معرفة بأدوات وتقنيات تحليل حركة الشبكة وآثار النظام وسجلات البنية التحتية.