Job Summary
To build and implement Cybersecurity related solutions for all end-users within the CARE Policies and Procedures.
Major Duties and Responsibilities:Implement detection, prevention, and recovery controls to protect against malicious and mobile code Configure and install firewalls and intrusion detection systems. Perform vulnerability testing, risk analyses and security assessments. Assist with investigations to determine how security breaches happened. Establish and maintain virus protection arrangements throughout CARE. Ensure the implementation of technical vulnerability management. Provide support for technical audit and review exercise. Ensure the availability of timely information about technical vulnerabilities. Conduct vulnerability scanning when needed or as scheduled. Create detailed reports to provide clear information about vulnerabilities. Monitor SIEM key logs. Monitor and implement SIEM updates. Identify, promptly validate, and investigate, record, review and report Cybersecurity incidents. Follow detailed operational processes and procedures to analyze, escalate, and support the remediation of cybersecurity incidents. Maintain and keep threat and vulnerability database up to date to ensure environmental threats are captured, updated. Measure the effectiveness of technical vulnerability management implementation Create detailed reports to provide clear information about vulnerabilities remediation steps. Create and enhance detailed operational processes and procedures to Identify, validate, investigate, record, review and report cybersecurity incidents. Work actively on security incidents raised by security operation center (SOC) following approved incident response plan. Creates and enhances detailed operational processes and procedures to analyze, escalate, and support the remediation of cybersecurity incidents. Perform additional job-related tasks and duties as assigned. Reporting to
Director, Cybersecurity
Supervises
None
Skills In-depth knowledge of hard skills (e.g. secure network architectures, secure coding practices, protocols. Basic knowledge of (e.g. secure network architectures, secure coding practices, protocols. Strong understanding of network security systems and technologies. A relevant certification such as CCIE Security, CCNP R&S, CISSP, CISA or CISM. Fluency in verbal and written English & Arabic. Exhibits excellent interpersonal communication skills. Qualifications
Master’s Degree in Cybersecurity, Computer Science, Computer Engineering or similar degree. Certified CCIE Security, CCNP, R&S, CISSP, CISA or CISM is preferred Bachelor Degree in Cybersecurity, Computer Science/Engineering, or similar degree. Experience:Master’s Degree : Zero (0) to Three (3) years of experience Bachelor Degree : Two (2) years of experience Cybersecurity Training.
ملخص الوظيفة
بناء وتنفيذ الحلول المتعلقة بالأمن السيبراني لجميع المستخدمين النهائيين ضمن سياسات وإجراءات CARE.
الواجبات والمسؤوليات الرئيسية: تنفيذ ضوابط الكشف والوقاية والاسترداد للحماية من البرمجيات الضارة والمتنقلة. تكوين وتثبيت جدران الحماية وأنظمة كشف التسلل. إجراء اختبارات الضعف وتحليل المخاطر وتقييمات الأمان. المساعدة في التحقيقات لتحديد كيفية حدوث الخروقات الأمنية. إنشاء والحفاظ على ترتيبات الحماية من الفيروسات في جميع أنحاء CARE. ضمان تنفيذ إدارة الثغرات التقنية. توفير الدعم للتدقيق التقني وتمارين المراجعة. ضمان توفر معلومات في الوقت المناسب حول الثغرات التقنية. إجراء مسح للثغرات الأمنية عند الحاجة أو حسب الجدول الزمني. إنشاء تقارير مفصلة لتوفير معلومات واضحة حول الثغرات الأمنية. مراقبة سجلات SIEM الرئيسية. مراقبة وتنفيذ تحديثات SIEM. تحديد حوادث الأمن السيبراني والتحقق منها فوراً والتحقيق فيها وتسجيلها ومراجعتها والإبلاغ عنها. اتباع العمليات والإجراءات التشغيلية المفصلة لتحليل حوادث الأمن السيبراني وتصعيدها ودعم معالجتها. الحفاظ على قاعدة بيانات التهديدات والثغرات الأمنية وتحديثها لضمان التقاط التهديدات البيئية وتحديثها. قياس فعالية تنفيذ إدارة الثغرات التقنية. إنشاء تقارير مفصلة لتوفير معلومات واضحة حول خطوات معالجة الثغرات الأمنية. إنشاء وتعزيز العمليات والإجراءات التشغيلية المفصلة لتحديد حوادث الأمن السيبراني والتحقق منها والتحقيق فيها وتسجيلها ومراجعتها والإبلاغ عنها. العمل بفاعلية على الحوادث الأمنية التي يرفعها مركز العمليات الأمنية (SOC) باتباع خطة الاستجابة للحوادث المعتمدة. إنشاء وتعزيز العمليات والإجراءات التشغيلية المفصلة لتحليل حوادث الأمن السيبراني وتصعيدها ودعم معالجتها. أداء مهام وواجبات إضافية متعلقة بالوظيفة حسب التكليف.
التقارير إلى
مدير الأمن السيبراني
الإشراف على
لا يوجد
المهارات: معرفة متعمقة بالمهارات الصعبة (مثل بنيات الشبكات الآمنة، ممارسات الترميز الآمن، البروتوكولات). معرفة أساسية بـ (مثل بنيات الشبكات الآمنة، ممارسات الترميز الآمن، البروتوكولات). فهم قوي لأنظمة وتقنيات أمن الشبكات. شهادة ذات صلة مثل CCIE Security أو CCNP R&S أو CISSP أو CISA أو CISM. طلاقة في اللغة الإنجليزية والعربية تحدثاً وكتابةً. إظهار مهارات تواصل شخصية ممتازة.
المؤهلات
درجة الماجستير في الأمن السيبراني أو علوم الحاسوب أو هندسة الحاسوب أو درجة مماثلة. يفضل الحصول على شهادة CCIE Security أو CCNP أو R&S أو CISSP أو CISA أو CISM. درجة البكالوريوس في الأمن السيبراني أو علوم/هندسة الحاسوب أو درجة مماثلة. الخبرة: درجة الماجستير: صفر (0) إلى ثلاث (3) سنوات من الخبرة. درجة البكالوريوس: سنتان (2) من الخبرة في تدريب الأمن السيبراني.