FNRCO تعلن عن وظيفة مطور سيناريوهات تمارين المحاكاة السيبرانية في الرياض
تفاصيل الوظيفة
FNRCO تعلن عن وظيفة مطور سيناريوهات تمارين المحاكاة السيبرانية في الرياض.
نبذة عن الوظيفة
يتولى المطور تصميم وبناء وتقديم تمارين محاكاة سيبرانية واسعة النطاق (مثل Threat Hunting Event وLive Fire Exercises وCapture the Flag) لرفع كفاءة القوى العاملة السيبرانية. تشمل المسؤوليات تطوير سيناريوهات واقعية على منصة cyber range، وإنشاء مستلزمات وinjects للتمارين، وبناء وصيانة البنية التحتية الداعمة للمختبرات لتمكين التدريب القابل للتكرار والقياس على نطاق واسع.
المهام والمسؤوليات
- تصميم تمارين محاكاة سيبرانية متكاملة تتوافق مع أهداف رفع الكفاءة التنظيمية (مثل التعامل مع التصيد وبرامج الفدية وسوء تكوين السحابة والتهديد الداخلي وتنسيق الاستجابة للحوادث).
- ترجمة أهداف التعلم إلى قصص جذابة وأهداف تقنية ونتائج قابلة للقياس، وتطوير سيناريوهات متعددة المسارات تناسب مختلف الجماهير (تقنية معلومات، مركز عمليات أمنية، قادة استجابة، تنفيذيين).
- إنتاج حزم تمارين كاملة تشمل أدلة الميسرين وتعليمات المشاركين وأدلة التشغيل وجداول زمنية وسجلات التقييم ومواد الإحاطة، وإنشاء مستلزمات واقعية كالبريد الإلكتروني وسجلات الدردشة والتذاكر وسجلات الأنظمة والتنبيهات والاستخبارات الإعلامية والموجزات التنفيذية.
- إنشاء وإدارة injects التمرين (التقنية وغير التقنية) لدفع اتخاذ القرارات والإجراءات أثناء المحاكاة، وتنفيذ آليات إطلاق injects (مشغلات تلقائية، إصدارات موقوتة، injects مدفوعة بالأحداث).
- بناء وتكوين بيئات المختبر المطلوبة للسيناريوهات (شبكات، أجهزة طرفية، خوادم، خدمات هوية، أدوات أمنية)، ودمج أدوات الأمان ومصادر القياس عن بُعد الشائعة (SIEM، EDR، IDS، أمن البريد الإلكتروني، ماسحات الثغرات).
- دعم الاختبارات التجريبية والجلسات التجريبية والتنفيذ الفعلي، واستكشاف المشكلات التقنية وإصلاحها أثناء التمارين الحية، وتحديد مؤشرات الأداء الرئيسية ونماذج التسجيل (وقت الكشف، وقت الاحتواء، جودة القرار، الالتزام بالعملية، فعالية الاتصال)، وإعداد تقارير ما بعد التمرين وتوصيات التحسين.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو نظم المعلومات أو خبرة عملية معادلة.
- خبرة مثبتة في تطوير تمارين المحاكاة السيبرانية على منصة cyber range (عملية).
- قدرة مثبتة على إنشاء injects ومستلزمات التمارين التي تحفز سلوك المشاركين الواقعي.
- خبرة في بناء وتشغيل البنية التحتية للمختبرات (افتراضية أو سحابية) للسيناريوهات السيبرانية.
- فهم قوي لدورة حياة الاستجابة للحوادث وتقنيات الهجوم الشائعة والضوابط الدفاعية.
المهارات المطلوبة
- منصات Cyber Range: خبرة عملية مع حل واحد على الأقل تجاري أو مفتوح المصدر (بغض النظر عن المنصة، ولكن مع خبرة تنفيذية حقيقية).
- البنية التحتية: أساسيات المحاكاة الافتراضية والشبكات (التقسيم، التوجيه، DNS، أساسيات Active Directory).
- أنظمة التشغيل والتقنيات المؤسسية: أساسيات إدارة Windows/Linux ومفاهيم Active Directory.
- الأتمتة والبرمجة النصية: PowerShell، Python، Bash (إتقان واحدة منها على الأقل).
- مفاهيم التسجيل والمراقبة: قدرات SIEM/EDR ومصادر السجلات ومنطق التنبيه.
عرض النص الأصلي للإعلان
Summary:
The Cyber Simulation Exercises Scenario Developer designs, builds, and delivers large-scale cybersecurity simulation exercises (Threat Hunting Event, Live Fire Exercises, Capture the Flag) to uplift workforce cyber capability. This role develops realistic scenarios on a cyber range platform, creates exercise “injects” and artifacts, and builds/maintains the supporting lab infrastructure to enable repeatable, measurable training at scale.
Key Responsibilities:
1) Cyber Range Exercise & Scenario Development
- Design end-to-end cyber simulation exercises aligned to organizational capability uplift goals (e.g., phishing response, ransomware, cloud misconfigurations, insider threat, incident response coordination).
- Translate learning objectives into engaging storylines, technical objectives, and measurable outcomes.
- Develop multi-track scenarios for different audiences (IT, SOC, incident commanders, and executives) with appropriate complexity and realism.
- Ensure scenarios reflect current threat landscape and common enterprise environments (Windows/Linux, AD, email, web applications, cloud, endpoints).
2) Content Creation (Exercise Materials & Artifacts)
- Produce complete exercise packages including: facilitator guides, participant instructions, runbooks, timelines, scoring rubrics, and debrief materials.
- Create realistic artifacts: emails, chat transcripts, tickets, logs, alerts, threat intel snippets, media statements, executive briefings, and policy references.
- Build assessment content (pre/post checks, knowledge validations, performance-based evaluation criteria).
3) Inject Design & Orchestration
- Create and manage exercise injects (technical and non-technical) to drive decision-making and actions during the simulation.
- Implement inject delivery mechanisms within the cyber range (automated triggers, timed releases, event-driven injects).
- Coordinate inject timing, escalation paths, and branching logic based on participant actions.
4) Cyber Range Infrastructure Build & Maintenance
- Build and configure lab environments required for scenarios (networks, endpoints, servers, identity services, security tooling).
- Integrate common security tools and telemetry sources (SIEM, EDR, IDS, email security, vulnerability scanners) as required by the exercise.
5) Exercise Delivery Support & Facilitation Enablement
- Support dry runs, pilot sessions, and production execution; troubleshoot technical issues during live exercises.
- Provide facilitators with clear runbooks, decision points, and expected participant actions.
- Capture exercise telemetry and participant performance data for reporting and continuous improvement.
6) Measurement, Reporting & Continuous Improvement
- Define KPIs and scoring models (time-to-detect, time-to-contain, decision quality, process adherence, communication effectiveness).
- Produce post-exercise reports and lessons learned; recommend improvements to content, controls, and processes.
Required Qualifications:
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or equivalent practical experience.
- Proven experience developing cybersecurity simulation exercises on a cyber range platform (hands-on).
- Demonstrated ability to create injects and exercise artifacts that drive realistic participant behavior.
- Experience building and operating lab infrastructure (virtualized or cloud-based) for cyber scenarios.
- Strong understanding of incident response lifecycle, common attack techniques, and defensive controls.
Required Technical Skills:
- Cyber range platforms: hands-on experience with at least one commercial or open cyber range solution (platform-agnostic, but must have real implementation experience).
- Infrastructure: virtualization and networking fundamentals (segmentation, routing, DNS, AD basics).
- OS & enterprise tech: Windows/Linux administration basics; Active Directory concepts.
- Automation/scripting: PowerShell, Python, Bash (at least one strong).
- Logging/monitoring concepts: SIEM/EDR telemetry, log sources, alerting logic.
Also, you can submit your CV through the link below for more upcoming job vacancies:
https://cv-fnrco.com
رقم الإعلان لدى المصدر: 4466776208