وصف الوظيفة
الأدوار والمسؤوليات
الغرض من الوظيفة: قيادة وإدارة عمليات الأمن السيبراني في المؤسسة، إدارة الثغرات، أمان السحابة والبنية التحتية، وأنشطة أتمتة الأمن من خلال تنفيذ ضوابط أمن فعالة، وضمان الامتثال لمعايير الأمن السيبراني، وتقوية قدرات الكشف عن التهديدات والاستجابة للحوادث، وتضمين ممارسات آمنة عبر عمليات التكنولوجيا لحماية أنظمة المؤسسة وتطبيقاتها وموارد معلوماتها.
الأدوار والمسؤوليات
- إجراء تدقيقات أمنية شاملة لتحديد الثغرات وتنفيذ تحسينات قابلة للتنفيذ.
- تطوير وتطبيق استراتيجيات قوية لإدارة وصول الامتيازات (PAM) لحماية الموارد الحساسة.
- إنشاء وصيانة إرشادات تعزيز الأمان بما يتوافق مع معايير CIS أو SITG، لضمان تهيئة آمنة عبر جميع الأنظمة.
- تصميم ونشر عمليات آلية للمهام السيبرانية باستخدام برمجة بايثون.
- إدارة برنامج إدارة الثغرات في المنظمة، بما في ذلك الفحص المنتظم والتقييم والتصحيح والتقارير.
- تنفيذ والإشراف على عمليات أتمتة الأمن لتبسيط الكشف عن التهديدات والاستجابة للحوادث والتدقيق والامتثال.
- المراقبة المستمرة لأنظمة الأمن لاكتشاف الحوادث والرد عليها وحلها بسرعة.
- الاستجابة لحوادث الأمن السيبراني بالاحتواء الفعال والحل والتقرير المفصل بعد الحدث.
- التعاون مع تقنية المعلومات، DevOps، وفرق أخرى لدمج ممارسات الأمن في جميع مراحل دورة حياة تطوير البرمجيات (SDLC).
- مراقبة وصيانة أدوات الأمان مثل SIEM، IDS/IPS، DLP، وحلول حماية نقطة النهاية.
- الإشراف على تصميم وتنفيذ وإدارة معماريات الأمان للبنى التحتية القائمة على السحابة والمحلية.
- إجراء مراجعات دورية لتكوينات الجدار الناري، وضوابط وصول المستخدم، وآليات الأمان الأخرى لتحسين الحماية.
- الحفاظ على إطار عمل الأمن السيبراني للمنظمة وضمان التوافق مع المعايير والتنظيمات الصناعية.
- تقييم وتبنّي تقنيات الأمن السيبراني الناشئة بشكل استباقي للحد من التهديدات المتطورة.
- العمل كجهة اتصال رئيسية للحوادث الأمنية والتعاون مع الفرق الخارجية للحصول على دعم مُصعد.
- قيادة في تنفيذ استراتيجيات استخبارات التهديدات، وضمان التحسين المستمر لموقف أمن المنظمة.
المهارات والتقنيات المطلوبة
- الكشف عن التهديدات والاستجابة باستخدام أي من هذه الأدوات (Microsoft Defender XDR، Microsoft Sentinel، Microsoft Defender for Cloud، Microsoft Defender for Endpoint).
- إدارة الثغرات باستخدام أي من هذه الأدوات (Nessus، Qualys، OpenVAS).
- إدارة وصول الامتيازات (PAM) باستخدام أي من هذه الأدوات (Wallix، CyberArk، BeyondTrust).
- أتمتة الأمن والتنسيق باستخدام أي من هذه الأدوات (Python، Splunk Phantom، Cortex XSOAR، Azure Sentinel).
- DevSecOps باستخدام أي من هذه الأدوات (SonarQube، GitHub Actions، AWS CodePipeline).
- التعزيز والأمان والامتثال باستخدام أي من هذه الأدوات (CIS Benchmarks، SITG Benchmarks، Qualys Policy Compliance).
- أمان السحابة باستخدام أي من هذه الأدوات (AWS Security Hub، Azure Security Center، Microsoft Defender for Cloud).
- أمان الشبكة باستخدام أي من هذه الأدوات (Palo Alto Networks، Fortinet، Cisco ASA، Snort، Suricata).
- أمان نقطة النهاية باستخدام أي من هذه الأدوات (Microsoft Defender for Endpoint، CrowdStrike Falcon، SentinelOne).
الملف الشخصي المرغوب فيه للمرشح
- درجة البكالوريوس في علوم الحاسوب، تكنولوجيا المعلومات، الأمن السيبراني، أو مجال ذي صلة (يفضل الحصول على درجة الماجستير).
- شهادات ذات صلة مثل CISSP، CISM، CEH، CompTIA Security+، أو ما يعادلها.
- خبرة لا تقل عن 6 سنوات في المجال ذي الصلة.
Job Description
Roles & Responsibilities
Job Purpose Lead and manage the organization s cyber security operations, vulnerability management, cloud and infrastructure security, and security automation activities by implementing effective security controls, ensuring compliance with cyber security standards, strengthening threat detection and incident response capabilities, and embedding secure practices across technology operations to safeguard organizational systems, applications, and information assets.
Roles & Responsibilities
- Conduct thorough security audits to identify vulnerabilities and implement actionable improvements.
- Develop and enforce robust Privilege Access Management (PAM) strategies to protect sensitive resources.
- Create and maintain Security Hardening Guidelines in compliance with CIS or SITG Benchmarks, ensuring secure configurations across all systems.
- Design and deploy automated processes for cybersecurity tasks using Python scripting.
- Manage the organization s Vulnerability Management Program, including regular scanning, assessment, remediation, and reporting.
- Implement and oversee Security Automation processes to streamline threat detection, incident response, and compliance checks.
- Continuously monitor security systems to detect, respond to, and resolve potential incidents promptly.
- Respond to cybersecurity incidents with effective containment, resolution, and detailed after-action reporting.
- Collaborate with IT, DevOps, and other teams to embed security practices into all phases of the SDLC.
- Monitor and maintain security tools such as SIEM, IDS/IPS, DLP, and endpoint protection solutions.
- Oversee the design, implementation, and management of security architectures for cloud-based and on-premise infrastructures.
- Perform periodic reviews of firewall configurations, user access controls, and other security mechanisms to optimize protection.
- Maintain the organization s cybersecurity framework and ensure alignment with industry standards and regulations.
- Proactively evaluate and deploy emerging cybersecurity technologies to mitigate evolving threats.
- Act as the primary contact for security incidents and collaborate with external teams for escalated support.
- Provide leadership in implementing threat intelligence strategies, ensuring continuous improvement of the organization's security posture.
Skills & Technologies Required
- Threat Detection and Response using any of these tools (Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft Defender for Endpoint).
- Vulnerability Management using any of these tools (Nessus, Qualys, OpenVAS).
- privilege Access Management (PAM) using any of these tools (Wallix, CyberArk, BeyondTrust).
- Security Automation and Orchestration using any of these tools (Python, Splunk Phantom, Cortex XSOAR, Azure Sentinel ).
- DevSecOps using any of these tools (SonarQube, GitHub Actions, AWS CodePipeline).
- Security Hardening and Compliance using any of these tools (CIS Benchmarks, SITG Benchmarks, Qualys Policy Compliance).
- Cloud Security using any of these tools (AWS Security Hub, Azure Security Center, Microsoft Defender for Cloud).
- Network Security using any of these tools (Palo Alto Networks, Fortinet, Cisco ASA, Snort, Suricata).
- Endpoint Security using any of these tools (Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne).
Desired Candidate Profile
- Bachelor s degree in Computer Science, Information Technology, Cybersecurity, or a related field (Master s degree preferred).
- Relevant certifications such as CISSP, CISM, CEH, CompTIA Security+, or equivalent.
- A minimum of 6 years of experience in the related field.