📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

الماجد للعود تعلن عن وظيفة مدير أمن سيبراني في الرياض

Cybersecurity Manager
🕒 نُشرت: (منذ يومين) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

يسر شركة الماجد للعود بمدينة الرياض الإعلان عن توفر وظيفة مدير الأمن السيبراني (Cybersecurity Manager)؛ وذلك لقيادة استراتيجية الأمن السيبراني الشاملة وحماية البنية الرقمية وضمان الالتزام بأنظمة الهيئة الوطنية للأمن السيبراني (NCA).

المهام والمسؤوليات

  • القيادة والإستراتيجية وحماية الأصول الرقمية: يقود ويعتمد استراتيجية الأمن السيبراني الشاملة بما يتوافق مع التوجهات العامة واستراتيجية التحول الرقمي؛ ويحدد متطلبات وضوابط الأمن للبنية التحتية والشبكات والخوادم والبيئات السحابية، ويشرف على تنفيذها بالتنسيق مع إدارة العمليات والبنية التحتية. يعتمد خطط الاستجابة للحوادث والطوارئ والأزمات التقنية لضمان استمرارية الأعمال، ويوجه تنفيذ تقييمات الثغرات واختبارات الاختراق الدورية ويقر خطط المعالجة. يحكم ويشرف على تأمين سلاسل التوريد الرقمية وعقود مزودي الخدمات التقنية وأنظمة الشركات الخارجية، ويشرف على مركز عمليات الأمن (SOC) ويراقب مؤشرات الإنذار المبكر وكشف التهديدات على مدار الساعة. يعتمد متطلبات بنية الأمن السيبراني بالتنسيق مع فريق بنية المؤسسة.
  • الحوكمة وإدارة المخاطر والامتثال السيبراني: يحكم ويضمن الامتثال الكامل لضوابط الهيئة الوطنية للأمن السيبراني (NCA) مثل الضوابط الأساسية (ECC) وضوابط الأنظمة الحرجة (CSCC). يعتمد ويحدث سجل المخاطر السيبرانية للشركة ويصدق على استراتيجيات المعالجة وخطط تخفيف المخاطر التشغيلية والفنية. يصدق على السياسات الأمنية الداخلية والمعايير والضوابط ويشرف على نشرها وتطبيقها في جميع قطاعات الشركة. يوجه ويشرف على برامج التوعية الأمنية وحملات محاكاة التصيد لرفع مستوى الوعي الأمني للموظفين. ينسق مع الجهات التنظيمية والسلطات والمدققين المستقلين، ويعتمد تقارير الامتثال والتدقيق السيبراني الدورية. يراقب ويقيم مشاريع حماية البيانات الشخصية وسرية المعاملات التجارية لضمان توافقها مع اللوائح المعتمدة.
  • إدارة الميزانية والرقابة المالية: يعد الميزانية السنوية التقديرية لإدارة الأمن السيبراني بما في ذلك تكاليف التراخيص والبرامج الأمنية والبنية التحتية الأمنية. يشرف على تنظيم وتتبع النفقات التشغيلية والرأسمالية (OPEX/CAPEX) للمشاريع الأمنية لضمان الالتزام بالميزانية المعتمدة. يقيم الجدوى الفنية والمالية للحلول والأدوات الأمنية المستهدفة لتعظيم العائد على الاستثمار (ROI) في حماية الأصول الرقمية.
  • إدارة الموارد البشرية: يقود ويوجه فريق الأمن السيبراني ويراقب تحقيق الأهداف التشغيلية. يضع أهدافًا فردية ذكية (SMART) ومؤشرات أداء رئيسية (KPIs) للمرؤوسين، ويعتمد تقييمات الأداء السنوية واحتياجات التدريب. يوجه ويضمن إنشاء خطط التعاقب وتطوير المواهب الفنية وإعداد قادة سيبرانيين من المستوى الثاني. يعزز ثقافة الامتثال واليقظة الأمنية ويشجع بيئة عمل محفزة تدعم الأداء المتميز والمواءمة مع أهداف الشركة.
  • السياسات والعمليات والإجراءات: يراقب تنفيذ السياسات والعمليات وإجراءات التشغيل القياسية (SOPs) وضوابط إدارة الهوية وصلاحيات الوصول. يقود المبادرات التطويرية لأتمتة الاستجابة للحوادث والتحسين المستمر لأدوات الدفاع والتحليل السيبراني.

الشروط والمتطلبات

  • خبرة عملية متخصصة في الأمن السيبراني وحماية البنية الرقمية والحوكمة تتراوح بين 8 إلى 12 سنة، منها 3 سنوات على الأقل في دور إشرافي أو قيادي.
  • يفضل خبرة سابقة كمنفذ رئيسي أو مدقق رئيسي لنظام إدارة أمن المعلومات (ISO 27001 Lead Implementer / Lead Auditor).
  • درجة البكالوريوس في الأمن السيبراني أو هندسة الحاسوب أو علوم الحاسب أو تقنية المعلومات أو أي مجال معادل.
  • الشهادات المهنية المطلوبة: شهادة CISM أو CISSP (إلزامية).
  • الشهادات المهنية المفضلة: شهادة CRISC.

المهارات المطلوبة

  • قدرة عالية على القيادة الإستراتيجية لإدارة وتوجيه منظومة الأمن السيبراني والتحول الرقمي.
  • كفاءة متميزة في صياغة واعتماد أطر الحوكمة السيبرانية والسياسات ومعايير الامتثال الوطنية.
  • مهارة استثنائية في إعداد وإدارة الميزانيات التقديرية للأمن السيبراني والتحكم في تكاليف التراخيص والمشاريع.
  • خبرة عميقة في بنية أمن الشبكات والأنظمة السحابية ومنصات التجارة الإلكترونية.
  • إتقان إدارة المخاطر السيبرانية وبناء سجلات المخاطر واستراتيجيات المعالجة.
  • القدرة على قيادة عمليات الاستجابة للحوادث السيبرانية وإدارة الأزمات واستعادة التعافي من الكوارث.
  • معرفة شاملة بأنظمة الهيئة الوطنية للأمن السيبراني (NCA) والمعايير الدولية للأمن الرقمي.
  • مهارات تواصل وتنسيق إستراتيجية عالية المستوى مع الإدارة العليا والجهات التنظيمية.
عرض النص الأصلي للإعلان

Job Objective:

To lead and develop the comprehensive cybersecurity strategy, govern the protection of digital infrastructure and technical assets, ensure compliance with the National Cybersecurity Authority (NCA) regulations, manage risks and budgets, and build capacities for Al Majed Oud Company.


Scope of Responsibilities and Key Duties:


1. Leadership, Strategy, and Digital Asset Protection

  • Leads and approves the comprehensive cybersecurity strategy in alignment with the company’s general directives and digital transformation strategy.
  • Defines and adopts cybersecurity requirements and controls for infrastructure, networks, servers, and cloud environments, and monitors their implementation in coordination with the Operations and Infrastructure Department.
  • Approves response plans for cyber incidents, emergencies, and technical crises to ensure business continuity and mitigate risks.
  • Directs the execution of vulnerability assessments and periodic penetration testing for digital infrastructure and applications, and approves remediation plans.
  • Governs and oversees the securing of digital supply chains, technology service provider contracts, and external company systems.
  • Supervises the Security Operations Center (SOC) and monitors 24/7 early warning and threat detection indicators.
  • Approves cybersecurity architecture requirements in coordination with the Enterprise Architecture team.


2. Governance, Risk Management, and Cyber Compliance

  • Governs and ensures full compliance with the National Cybersecurity Authority (NCA) controls, such as Essential Cybersecurity Controls (ECC) and Critical Systems Cybersecurity Controls (CSCC).
  • Approves and updates the corporate cyber risk register and endorses treatment strategies and operational/technical risk mitigation plans.
  • Endorses internal security policies, standards, and controls, and oversees their dissemination and implementation across all sectors of the company.
  • Directs and oversees cybersecurity awareness programs and phishing simulation campaigns to elevate employees' security awareness.
  • Coordinates with regulatory bodies, authorities, and independent auditors, and approves periodic compliance and cyber audit reports.
  • Monitors and evaluates personal data protection and commercial transaction confidentiality projects to ensure alignment with approved regulations.


3. Budget Management and Financial Control

  • Prepares the annual estimated budget for the Cybersecurity Department, including license costs, security software, and security infrastructure.
  • Oversees the regulation and tracking of operational and capital expenditures (OPEX/CAPEX) for security projects to ensure strict compliance with the approved budget.
  • Evaluates the technical and financial feasibility of targeted security solutions and tools to maximize the return on investment (ROI) in digital asset protection.


4. People Management

  • Leads and directs the cybersecurity team and monitors the achievement of operational goals.
  • Sets SMART individual goals and Key Performance Indicators (KPIs) for subordinates, and approves annual performance evaluations and training needs.
  • Directs and ensures the creation of succession plans, development of technical talents, and preparation of second-line cyber leaders.
  • Fosters a culture of compliance and security vigilance, and promotes a motivating work environment that supports outstanding performance and corporate alignment.


5. Policies, Operations, and Procedures

  • Monitors the implementation of policies, processes, standard operating procedures (SOPs), identity management controls, and access privileges.
  • Leads developmental initiatives to automate incident response and continuously improve cyber defense and analysis tools.



Qualifications and Requirements:


Experience:

  • 8 to 12 years of specialized practical experience in cybersecurity, digital infrastructure protection, and governance, including at least 3 years in a supervisory or leadership role.
  • Previous experience as an ISO 27001 Lead Implementer / Lead Auditor is preferred.


Educational Qualifications:

  • Bachelor’s degree in Cybersecurity, Computer Engineering, Computer Science, Information Technology, or an equivalent field.


Professional Certifications:

  • Mandatory: CISM or CISSP
  • Preferred: CRISC


Skills:

  • High leadership and strategic ability to manage and direct the cybersecurity and digital transformation ecosystem.
  • Superior competence in formulating and approving cyber governance frameworks, policies, and national compliance standards.
  • Exceptional skill in preparing and managing estimated budgets for cybersecurity, and controlling license and project costs.
  • Deep experience in the security architecture of networks, cloud systems, and e-commerce platforms.
  • Mastery of cyber risk management, building risk registers, and treatment strategies.
  • Ability to lead cyber incident response operations, crisis management, and disaster recovery.
  • Comprehensive knowledge of the National Cybersecurity Authority (NCA) regulations and international digital security standards.
  • High-level strategic communication and coordination skills with executive management and regulatory authorities.


المصدر: LinkedIn - أُضيفت للموقع في 8 سبتمبر 2026
رقم الإعلان لدى المصدر: 4464466728