📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

Hays تعلن عن وظيفة أخصائي استخبارات التهديدات ومطاردتها في الرياض (عقد 12 شهراً)

Threat Intelligence & Threat Hunting Specialist - 12 Months Contract
🏢 Hays
🕒 نُشرت: (أمس) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة Hays عن فرصة تعيين أخصائي استخبارات التهديدات والصيد السيبراني (Threat Intelligence & Threat Hunting Specialist) للعمل في الرياض، بعقد لمدة 12 شهراً. يهدف الدور إلى إنشاء وتشغيل وظيفة استخبارات التهديدات السيبرانية (CTI) مع تنفيذ أنشطة الصيد السيبراني الاستباقي عبر بيئة التقنية في المؤسسة.

المهام والمسؤوليات

  • تطوير وتنفيذ وتشغيل برنامج استخبارات التهديدات السيبرانية (CTI).
  • جمع وتقييم وتحليل استخبارات التهديدات من مصادر متعددة بما في ذلك: خلاصات التهديدات التجارية ومفتوحة المصدر، ومراكز ISAC المالية ومجتمعات تبادل المعلومات، والتنبيهات الأمنية من البائعين، ومصادر مراقبة الويب المظلم والمنتديات السرية.
  • إنتاج استخبارات قابلة للتنفيذ تتعلق بحملات الاحتيال السيبراني، وهجمات التصيد، والإصابة بالبرمجيات الخبيثة، وتهديدات برامج الفدية، والتهديدات المتقدمة المستمرة (APT).
  • مراقبة المشهد التهديدي الخارجي وتقييم تأثيره المحتمل على المؤسسة.
  • الحفاظ على ملفات شخصيات المهاجمين، ومؤشرات الاختراق (IOCs)، ومستودعات تتبع الخصوم.
  • إجراء أنشطة صيد سيبراني استباقية عبر بيئات نقاط النهاية والشبكة والهوية.
  • تحليل بيانات تتبع EDR وسجلات SIEM وسجلات أمان الشبكة وسجلات إدارة الهوية والوصول.
  • تحديد والتحقيق في أنشطة المستخدمين المشبوهة، ومحاولات الوصول غير المصرح بها، وآليات الثبات المخفية، وتقنيات التنقل الجانبي، وتصعيد الامتيازات، ومؤشرات الاختراق.
  • تطوير وتحسين منهجيات وفرضيات وأدلة العمل (playbooks) الخاصة بالصيد السيبراني.
  • التعاون مع فرق SOC وMSSP لتعزيز قدرات المراقبة وتطوير وتحسين حالات كشف SIEM وضبط وتقييم التنبيهات الأمنية وقواعد الكشف.
  • تحديد الثغرات في تغطية الكشف والتوصية بالتحسينات.
  • دعم تطوير وتحسين محتوى الكشف في EDR وSIEM.
  • إنتاج تقارير شهرية لاستخبارات التهديدات تغطي التهديدات الناشئة واتجاهات تهديدات القطاع المالي وحملات التهديدات النشطة والثغرات المكتشفة حديثاً وأنشطة المهاجمين والإجراءات التخفيفية الموصى بها.
  • عرض نتائج الاستخبارات على قيادة الأمن السيبراني وأصحاب المصلحة، وإنشاء إحاطات تنفيذية وفنية عند الحاجة.
  • دعم تحقيقات الحوادث السيبرانية من خلال تحليل الاستخبارات وتوفير السياق حول المهاجمين وTTPs والمؤشرات وأنماط الهجوم، ومساعدة فرق SOC أثناء أنشطة الاحتواء والتعافي، وربط استخبارات التهديدات بالأحداث والحوادث الأمنية.

الشروط والمتطلبات

  • درجة البكالوريوس في الأمن السيبراني، أمن المعلومات، علوم الحاسب، تقنية المعلومات، أو مجال ذي صلة.
  • خبرة من 4 إلى 8 سنوات في استخبارات التهديدات السيبرانية، الصيد السيبراني، عمليات SOC، الاستجابة للحوادث، أو عمليات الأمن السيبراني.
  • خبرة في القطاع المصرفي أو الخدمات المالية أو التكنولوجيا المالية (Fintech) أو أي قطاع منظم آخر مفضلة للغاية.
  • خبرة مثبتة في إجراء تحقيقات صيد سيبراني مدفوعة بالاستخبارات.

المهارات المطلوبة

  • خبرة عملية في استخبارات التهديدات السيبرانية (CTI).
  • منهجيات الصيد السيبراني.
  • منصات SIEM (Microsoft Sentinel، Splunk، QRadar، ArcSight، إلخ).
  • حلول الكشف والاستجابة لنقاط النهاية (EDR).
  • إطار MITRE ATT&CK.
  • تحليل مؤشرات الاختراق (IOC Analysis).
  • توصيف المهاجمين (Threat Actor Profiling).
  • تحليل البرامج الضارة والتصيد.
  • التحقيق في الحوادث الأمنية.
  • هندسة الكشف (Detection Engineering).
  • تحليل السجلات وربطها (Log Analysis and Correlation).
  • عمليات مركز عمليات الأمن (SOC Processes).
عرض النص الأصلي للإعلان

We are looking for a Cyber Threat Intelligence & Threat Hunting Specialist to establish and operate the Cyber Threat Intelligence (CTI) function while conducting proactive threat hunting activities across the organization's technology environment.

The successful candidate will be responsible for collecting, analyzing, and operationalizing threat intelligence, identifying emerging cyber threats, performing intelligence-driven threat hunting, and enhancing detection capabilities across security monitoring platforms. The role will work closely with SOC, MSSP, IT Security, and Infrastructure teams to strengthen the organization's cyber defense posture and ensure alignment with financial sector security requirements and threat landscapes.

Key Responsibilities

Cyber Threat Intelligence (CTI)

  • Develop, implement, and operate the Cyber Threat Intelligence (CTI) program.
  • Collect, evaluate, and analyze threat intelligence from multiple sources, including:
  • Commercial and open-source threat intelligence feeds
  • Financial sector ISACs and intelligence-sharing communities
  • Vendor security advisories
  • Dark web and underground monitoring sources
  • Produce actionable intelligence related to:
  • Cyber fraud campaigns
  • Phishing attacks
  • Malware infections
  • Ransomware threats
  • Advanced Persistent Threats (APTs)
  • Monitor the external threat landscape and assess its potential impact on the organization.
  • Maintain threat actor profiles, indicators of compromise (IOCs), and adversary tracking repositories.

Threat Hunting

  • Conduct proactive threat hunting activities across endpoint, network, and identity environments.
  • Analyze:
  • EDR telemetry
  • SIEM log data
  • Network security logs
  • Identity and access management logs
  • Identify and investigate:
  • Suspicious user activities
  • Unauthorized access attempts
  • Hidden persistence mechanisms
  • Lateral movement techniques
  • Privilege escalation activities
  • Indicators of compromise
  • Develop and continuously improve threat hunting methodologies, hypotheses, and playbooks.

Detection Engineering & Security Monitoring

  • Collaborate with SOC and MSSP teams to enhance monitoring capabilities.
  • Develop and improve SIEM detection use cases.
  • Tune and validate security alerts and detection rules.
  • Identify gaps in detection coverage and recommend improvements.
  • Support the development and enhancement of EDR and SIEM detection content.

Reporting & Intelligence Products

  • Produce Monthly Threat Intelligence Reports covering:
  • Emerging cyber threats
  • Financial sector threat trends
  • Active threat campaigns
  • Newly disclosed vulnerabilities
  • Threat actor activities
  • Recommended mitigation actions
  • Present intelligence findings to cybersecurity leadership and stakeholders.
  • Create executive and technical threat briefings when required.

Incident Response Support

  • Support cyber incident investigations through intelligence analysis.
  • Provide context on threat actors, TTPs, indicators, and attack patterns.
  • Assist SOC teams during containment and remediation activities.
  • Correlate threat intelligence with security events and incidents.

Required Qualifications

Education

  • Bachelor's Degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.

Experience

  • 4-8 years of experience in Cyber Threat Intelligence, Threat Hunting, SOC Operations, Incident Response, or Cybersecurity Operations.
  • Experience within banking, financial services, fintech, or other regulated industries is highly preferred.
  • Demonstrated experience conducting intelligence-driven threat hunting investigations.

Required Technical Skills

Candidates should have hands-on experience with:

  • Cyber Threat Intelligence (CTI)
  • Threat Hunting Methodologies
  • SIEM Platforms (Microsoft Sentinel, Splunk, QRadar, ArcSight, etc.)
  • Endpoint Detection & Response (EDR) Solutions
  • MITRE ATT&CK Framework
  • Indicator of Compromise (IOC) Analysis
  • Threat Actor Profiling
  • Malware and Phishing Analysis
  • Security Incident Investigation
  • Detection Engineering
  • Log Analysis and Correlation
  • Security Operations Center (SOC) Processes


المصدر: LinkedIn - أُضيفت للموقع في 9 سبتمبر 2026
رقم الإعلان لدى المصدر: 4463042184