📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

وظيفة أخصائي أول دعم إنتاج الأمن السيبراني شاغرة لدى TAWANTECH في الرياض

Senior Specialist - Cybersecurity Production Support
🕒 نُشرت: (أمس) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة TAWANTECH عن توفر وظيفة Senior Specialist - Cybersecurity Production Support في الرياض.

المهام والمسؤوليات

  • تقديم دعم إنتاجي شامل لمنصات الأمن السيبراني بما في ذلك Splunk (SIEM) وSOAR والبنية التحتية لـ VPN، مع ضمان التوفر العالي وموثوقية الخدمة.
  • مراقبة منصات الأمن ولوحات المعلومات والتنبيهات لضمان الفعالية التشغيلية المستمرة والكشف الاستباقي عن المشكلات.
  • إدارة عمليات الحوادث والمشكلات والتغيير وفقًا لمعايير ITIL، مع ضمان الحل في الوقت المناسب والتصعيد المناسب.
  • إجراء تحليل السبب الجذري (RCA) لانقطاعات النظام وتدهور الأداء والحوادث الأمنية، وضمان تنفيذ الإجراءات التصحيحية والوقائية.
  • إدارة ودعم حالات استخدام Splunk وقواعد الربط وخطوط أنابيب استيعاب السجلات وتحسين الأداء.
  • تشغيل وصيانة قوائم التشغيل (playbooks) وسير العمل ونصوص الأتمتة في SOAR لتعزيز الاستجابة للحوادث وتقليل التدخل اليدوي.
  • دعم تقنيات VPN بما في ذلك الوصول الآمن عن بعد والاتصال بين المواقع وآليات المصادقة وبروتوكولات التشفير.
  • ضمان الامتثال لإطار عمل SAMA للأمن السيبراني وضوابط NCA ECC وقانون حماية البيانات الشخصية (PDPL) ومتطلبات حوكمة البيانات وتصنيفها من NDMO.
  • تنفيذ أنشطة التعافي من الكوارث (DR) واستمرارية الأعمال (BCP) بما يشمل الاختبار المنتظم والتحقق من التبديل وتحديث التوثيق.
  • التعاون مع فرق الأمن الداخلي وفرق البنية التحتية والموردين الخارجيين لحل المشكلات وتطبيق التصحيحات والترقيات وتحسينات النظام.
  • الحفاظ على التوثيق التشغيلي مثل أدلة التشغيل (runbooks) وإجراءات التشغيل القياسية (SOPs) وقوائم التشغيل (playbooks) وتكوينات النظام ومقالات قاعدة المعرفة.
  • تنفيذ المراقبة وضبط التنبيهات والأتمتة لتحسين دقة الكشف وتقليل النتائج الإيجابية الخاطئة وزيادة الكفاءة التشغيلية.
  • تتبع مؤشرات الأداء الرئيسية (KPIs) واتفاقيات مستوى الخدمة (SLAs) ومقاييس أداء النظام لمنصات الأمن السيبراني وإعداد تقارير تشغيلية.

الشروط والمتطلبات

  • درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو علوم الحاسب أو مجال ذي صلة.
  • 4-8 سنوات من الخبرة في دعم الإنتاج الأمني السيبراني داخل بيئات البنوك أو الخدمات المالية.
  • خبرة عملية مع Splunk (Enterprise/ES) ومنصات SOAR (مثل Cortex XSOAR وSplunk SOAR) وحلول VPN (مثل IPSec وSSL VPN).
  • فهم قوي لحالات استخدام SIEM وإدارة السجلات والكشف عن التهديدات وسير عمل الاستجابة للحوادث.
  • خبرة في عمليات ITIL بما في ذلك إدارة الحوادث والمشكلات والتغيير.
  • الإلمام بأنظمة SAMA وضوابط NCA ECC وقانون حماية البيانات الشخصية (PDPL) وأطر حوكمة البيانات من NDMO.
  • خبرة في العمل مع الموردين ومقدمي الخدمات المُدارة لأدوات ومنصات الأمن السيبراني.
  • الإلمام بتخطيط وتنفيذ ومراجعة DR/BCP.
  • يفضل المعرفة الأساسية بالبرمجة النصية أو الأتمتة (Python أو PowerShell أو ما شابه ذلك).
عرض النص الأصلي للإعلان
  • Provide end-to-end production support for cybersecurity platforms including Splunk (SIEM), SOAR, and VPN infrastructure ensuring high availability and service reliability
  • Monitor security platforms, dashboards, and alerts to ensure continuous operational effectiveness and proactive issue detection
  • Manage Incident, Problem, and Change processes in accordance with ITIL standards, ensuring timely resolution and proper escalation
  • Perform root cause analysis (RCA) for system outages, performance degradation, and security incidents, ensuring corrective and preventive actions are implemented
  • Administer and support Splunk use cases, correlation rules, log ingestion pipelines, and performance optimization
  • Operate and maintain SOAR playbooks, workflows, and automation scripts to enhance incident response and reduce manual intervention
  • Support VPN technologies including secure remote access, site-to-site connectivity, authentication mechanisms, and encryption protocols
  • Ensure compliance with SAMA Cybersecurity Framework, NCA ECC, PDPL, and NDMO data governance and classification requirements
  • Execute Disaster Recovery (DR) and Business Continuity Plan (BCP) activities including regular testing, failover validation, and documentation updates
  • Collaborate with internal security teams, infrastructure teams, and external vendors for issue resolution, patching, upgrades, and system enhancements
  • Maintain operational documentation including runbooks, SOPs, playbooks, system configurations, and knowledge base articles
  • Implement monitoring, alert tuning, and automation to improve detection accuracy, reduce false positives, and increase operational efficiency

Track KPIs, SLAs, and system performance metrics for cybersecurity platforms and produce operational reports.

Requirements

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, or related field
  • 4-8 years of experience in cybersecurity production support within banking or financial services environments
  • Hands-on experience with Splunk (Enterprise / ES), SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR), and VPN solutions (e.g., IPSec, SSL VPN)
  • Strong understanding of SIEM use cases, log management, threat detection, and incident response workflows
  • Experience with ITIL processes including Incident, Problem, and Change Management
  • Exposure to SAMA regulations, NCA ECC controls, PDPL, and NDMO data governance frameworks
  • Experience working with vendors and managed service providers for cybersecurity tools and platforms
  • Familiarity with DR/BCP planning, execution, and audit requirements

Basic scripting or automation knowledge (Python, PowerShell, or similar) is preferred...
المصدر: LinkedIn - أُضيفت للموقع في 9 سبتمبر 2026
رقم الإعلان لدى المصدر: 4464995196