System Operator – Internet Firewall & External Applications
We are looking for a System Operator – Internet Firewall & External Applications to support the operation, monitoring, and administration of cybersecurity systems within Health Affairs. The role will focus on security monitoring, incident handling, investigation, escalation, compliance, and maintaining the effectiveness of security infrastructure.
Key Responsibilities Operate and support cybersecurity systems, including Firewall, WAF, SIEM, Antivirus (AV), EDR, Proxy, IDS/IPS, and related security technologies. Continuously monitor security alerts, events, and incidents across the environment. Identify, classify, prioritize, and investigate security events collected from:Firewalls and network devices Proxies and IDS/IPS systems Antivirus and EDR solutions Databases, servers, and endpoints Classify incidents according to their type, impact, and severity. Take appropriate action based on incident severity, including:Notifying relevant system administrators. Following established incident response procedures. Escalating incidents in accordance with defined escalation processes. Accurately documenting all incidents and actions taken. Investigate cybersecurity incidents, track cyberattacks, and gather relevant information about potential attackers and attack methods. Analyze cyber events and incidents reported by the National Cybersecurity Authority and coordinate appropriate actions. Create, review, and update SIEM/security monitoring use cases for new systems and applications. Resolve and manage cybersecurity-related service requests and user issues. Coordinate with other departments and technical teams during security incident investigations and resolution. Monitor compliance with applicable MNG-HA technical security standards and support remediation of identified gaps. Maintain and operate the latest approved versions of cybersecurity systems and security technologies within Health Affairs. Prepare and submit monthly cybersecurity reports summarizing major incidents, investigations, actions taken, and key observations. Support continuous improvement of security monitoring, incident response, and cybersecurity operational processes.
Required Skills & Experience Experience in Cybersecurity Operations, SOC, Security Monitoring, or Security Engineering. Hands-on experience with security technologies such as Firewalls, WAF, SIEM, EDR, Antivirus, Proxy, and IDS/IPS. Strong understanding of security event monitoring, incident classification, investigation, escalation, and response. Experience analyzing logs and security events from network devices, servers, endpoints, databases, and security tools. Knowledge of incident response processes and cybersecurity best practices. Ability to develop and maintain security monitoring/SIEM use cases. Strong analytical, troubleshooting, documentation, and communication skills. Experience working in a 24x7 SOC or security operations environment is an advantage. Relevant cybersecurity certifications such as Security+, CySA+, CEH, GCIH, or equivalent are preferred.
مشغل نظام – جدار حماية الإنترنت والتطبيقات الخارجية
نحن نبحث عن مشغل نظام – جدار حماية الإنترنت والتطبيقات الخارجية لدعم تشغيل ومراقبة وإدارة أنظمة الأمن السيبراني داخل الشؤون الصحية. سيركز الدور على المراقبة الأمنية، ومعالجة الحوادث، والتحقيق، والتصعيد، والامتثال، والحفاظ على فعالية البنية التحتية الأمنية.
المسؤوليات الرئيسية: تشغيل ودعم أنظمة الأمن السيبراني، بما في ذلك جدار الحماية (Firewall)، وجدار حماية تطبيقات الويب (WAF)، وإدارة الأحداث والمعلومات الأمنية (SIEM)، ومضاد الفيروسات (AV)، واكتشاف واستجابة النقاط النهائية (EDR)، والوكيل (Proxy)، وأنظمة كشف ومنع الاختراق (IDS/IPS)، والتقنيات الأمنية ذات الصلة. مراقبة التنبيهات والأحداث والحوادث الأمنية بشكل مستمر عبر البيئة. تحديد وتصنيف وترتيب أولويات والتحقيق في الأحداث الأمنية التي يتم جمعها من: جدران الحماية وأجهزة الشبكة، والوكلاء وأنظمة كشف ومنع الاختراق، وحلول مضاد الفيروسات واكتشاف واستجابة النقاط النهائية، وقواعد البيانات والخوادم والنقاط النهائية. تصنيف الحوادث وفقاً لنوعها وتأثيرها وشدتها. اتخاذ الإجراءات المناسبة بناءً على شدة الحادث، بما في ذلك: إخطار مسؤولي النظام المعنيين، واتباع إجراءات الاستجابة للحوادث المحددة، وتصعيد الحوادث وفقاً لعمليات التصعيد المحددة، وتوثيق جميع الحوادث والإجراءات المتخذة بدقة. التحقيق في حوادث الأمن السيبراني، وتتبع الهجمات السيبرانية، وجمع المعلومات ذات الصلة حول المهاجمين المحتملين وأساليب الهجوم. تحليل الأحداث والحوادث السيبرانية المبلغ عنها من قبل الهيئة الوطنية للأمن السيبراني وتنسيق الإجراءات المناسبة. إنشاء ومراجعة وتحديث حالات استخدام المراقبة الأمنية/SIEM للأنظمة والتطبيقات الجديدة. حل وإدارة طلبات الخدمة المتعلقة بالأمن السيبراني ومشكلات المستخدمين. التنسيق مع الإدارات والفرق الفنية الأخرى أثناء التحقيق في الحوادث الأمنية وحلها. مراقبة الامتثال للمعايير الأمنية الفنية المعمول بها في الشؤون الصحية بوزارة الحرس الوطني (MNG-HA) ودعم معالجة الفجوات المحددة. صيانة وتشغيل أحدث الإصدارات المعتمدة من أنظمة الأمن السيبراني والتقنيات الأمنية داخل الشؤون الصحية. إعداد وتقديم تقارير شهرية عن الأمن السيبراني تلخص الحوادث الرئيسية، والتحقيقات، والإجراءات المتخذة، والملاحظات الرئيسية. دعم التحسين المستمر للمراقبة الأمنية، والاستجابة للحوادث، وعمليات الأمن السيبراني التشغيلية.
المهارات والخبرات المطلوبة: خبرة في عمليات الأمن السيبراني، أو مركز العمليات الأمنية (SOC)، أو المراقبة الأمنية، أو هندسة الأمن. خبرة عملية في تقنيات الأمن مثل جدران الحماية، وWAF، وSIEM، وEDR، ومضاد الفيروسات، والوكيل، وIDS/IPS. فهم قوي لمراقبة الأحداث الأمنية، وتصنيف الحوادث، والتحقيق، والتصعيد، والاستجابة. خبرة في تحليل السجلات والأحداث الأمنية من أجهزة الشبكة، والخوادم، والنقاط النهائية، وقواعد البيانات، والأدوات الأمنية. المعرفة بعمليات الاستجابة للحوادث وأفضل ممارسات الأمن السيبراني. القدرة على تطوير وصيانة حالات استخدام المراقبة الأمنية/SIEM. مهارات تحليلية وحل مشكلات وتوثيق وتواصل قوية. تعتبر الخبرة في العمل في مركز عمليات أمنية (SOC) يعمل على مدار الساعة طوال أيام الأسبوع ميزة إضافية. يفضل الحصول على شهادات الأمن السيبراني ذات الصلة مثل Security+، أو CySA+، أو CEH، أو GCIH، أو ما يعادلها.