Job description
Key Result Areas:
- Under the leadership of the Manager, Cyber Defense & NOC, the CDC Analyst will ensure delivery of the highest level of service in the support of conducting security event monitoring and analysis as well as incident response.
- Analyse security event logs and alerts to determine validity, priority, and impact against both security threat best practices and corporate policies.
- Perform operational ‘eyes on glass’ real-time monitoring and analysis of security events from multiple sources including but not limited to events from SIEM monitoring tools, network and host-based intrusion detection systems, firewall logs, system logs (Unix & Windows).
- Address identified and confirmed security events in a timely manner and provide actionable recommendations for the business to conduct in response.
- Contribute to the development and organization of Cyber Security and Data Protection program management, threat intelligence, Defense monitoring and vulnerability management.
- Manage and maintain the creation, tracking, actioning, and proper closure of alert tickets and reported events to the SOC.
- Maintain up-to-date detailed knowledge of the IT/OT security industry including awareness of new or revised security solutions, improved security processes, new attacks, and threat vectors.
- Documenting security investigations through standard procedures
Assist with tuning SIEM rules and creating custom log source integration with parsing
Bapco Energies operates a portfolio spanning the entire energy value chain in the Kingdom of Bahrain. The portfolio includes wholly-owned subsidiaries and specialized operating companies. Together, these companies drive Bapco Energies' mission to power the next generation.
Responsibilities:
Communications and Working Relationships:
Internal
Communicates regularly and aligns actions with all ITD technical groups to ensure that all systems and networks are operated securely.
Liaises with other relevant stakeholders within I&DT sections and – if needed - with business units, to identify and validate attempts at intrusion or compromise, and provides high quality investigation and response actions.
External
Acts as a focal point for all security related incidents and liaises in with CDC Shift Lead.
Qualifications:
Knowledge Skills and Experience:
Bachelor’s degree in IT or Computer Security or comparable years’ experience.
Must have at least one of the following certifications:
Any Sans security certifications preferred, Security+, or CEH.
3+ years of experience in a SOC or security-related role.
Experience and extensive knowledge of SIEM, EDR, Email Security & Event log analysis.
High understanding of processes related to threat correlation and mitigation.
Deep understanding of cybersecurity principles, technologies, and best practices, as well as knowledge of industry standards and frameworks (e.g., NIST Cybersecurity Framework, MITRE ATT&CK framework).
Dedicated and self-driven desire to research and learn more about the information security landscape and incident response.
Strong troubleshooting, reasoning, and problem-solving skills.
Excellent communication and teamwork abilities.
وصف الوظيفة
مناطق النتائج الأساسية:
- تحت قيادة المدير، الدفاع السيبراني وNOC، سيضمن محلل CDC تقديم أعلى مستوى من الخدمة في دعم مراقبة وتحليل أحداث الأمان بالإضافة إلى الاستجابة للحوادث.
- تحليل سجلات وأشعارات أحداث الأمن لتحديد الصلاحية والأولوية والتأثير وفق أفضل ممارسات تهديدات الأمن وسياسات الشركة.
- إجراء مراقبة وتحليل فوري لـ”العيون على الزجاج“ للأحداث الأمنية من مصادر متعددة بما في ذلك لكن لا تقتصر على أحداث من أدوات مراقبة SIEM، وأنظمة كشف التسلل على الشبكة والمضيف، سجلات الجدار الناري، سجلات النظام (يونكس وويندوز).
- التعامل مع الأحداث الأمنية المحددة والمؤكدة بشكل في الوقت المناسب وتقديم توصيات قابلة للتنفيذ للأعمال للرد.
- المساهمة في تطوير وتنظيم إدارة برامج الأمن السيبراني وحماية البيانات، معلومات التهديدات، المراقبة الدفاعية وإدارة الثغرات.
- إدارة والحفاظ على إنشاء وتتبع وتنفيذ وإغلاق تذاكر الإنذار والأحداث المبلغ عنها إلى SOC.
- الحفاظ على معرفة تفصيلية محدثة بصناعة أمن تكنولوجيا المعلومات/OT بما في ذلك الوعي بحلول الأمن الجديدة أو المحسّنة، وتحسين عمليات الأمن، والهجمات الجديدة، وممرات التهديد.
- توثيق التحقيقات الأمنية من خلال الإجراءات القياسية
المساعدة في ضبط قواعد SIEM وإنشاء تكامل لمصدر سجل مخصص مع التحليل
تشغـل بابكو إنيرجيز محفظة تمتد عبر سلسلة قيمة الطاقة بأكملها في مملكة البحرين. وتشمل المحفظة شركات فرعية مملوكة بالكامل وشركات تشغيـل متخصصة. معًا، تدفع هذه الشركات مهمة بابكو إنيرجيز لتمكين الجيل القادم.
المسؤوليات:
التواصل والعلاقات العملية:
داخلي
يتواصل بشكل منتظم ويتلازم إجراءاته مع جميع المجموعات التقنية ITD لضمان أن جميع الأنظمة والشبكات تُدار بأمان.
يتواصل مع جهات أصحاب المصلحة المعنية الأخرى ضمن أقسام I&DT وإذا لزم الأمر مع وحدات الأعمال، لتحديد والتحقق من محاولات الاختراق أو التعرض، وتقديم تحقيقات عالية الجودة وإجراءات استجابة.
خارجي
يعمل كنقطة محورية لجميع الحوادث الأمنية ويرتبط بقيادة التحول CDC.
المؤهلات:
المعرفة والمهارات والخبرة:
درجة البكالوريوس في تكنولوجيا المعلومات أو أمن الحاسوب أو خبرة معادلة لسنوات عديدة.
يشترط أن يكون لدى المتقدم واحد على الأقل من الشهادات التالية: أي شهادات أمنية من Sans مفضلة، Security+، أو CEH.
3+ سنوات خبرة في SOC أو دور يتعلق بالأمن.
خبرة ومعرفة واسعة بـ SIEM، EDR، أمن البريد الإلكتروني وتحليل سجلات الأحداث.
فهم عالٍ للعمليات المتعلقة بترابط التهديدات والحد من آثارها.
فهم عميق لمبادئ الأمن السيبراني والتقنيات وأفضل الممارسات، إضافة إلى معرفة المعايير والأطر الصناعية (مثل إطار NIST للأمن السيبراني، إطار MITRE ATT&CK).
رغبة موجهة ذاتيًا للبحث وتعلم المزيد عن مشهد أمن المعلومات واستجابة للحوادث.
مهارات قوية في استكشاف الأخطاء والتفكير المنطقي وحل المشكلات.
اتصالات ممتازة وقدرات العمل الجماعي.