وظيفة قائد عمليات تقنية المعلومات والأمن شاغرة لدى Skyro في الرياض
تفاصيل الوظيفة
تعلن شركة Skyro عن توفر وظيفة IT Operations and Security Lead في الرياض، السعودية.
نبذة عن الوظيفة
نبحث عن قائد لتقنية المعلومات والأمن ليتولى جميع عمليات تقنية المعلومات وأمن المعلومات في مكتبنا في السوق. نأخذ في الاعتبار فقط المرشحين الذين لديهم حق العمل الحالي في البلد الذي توجد فيه الوظيفة. لا تتوفر إصدار تأشيرة لهذا المنصب. يتطلب الدور خبرة عملية عميقة ومتوازنة في كل من عمليات تقنية المعلومات وأمن المعلومات.
المهام والمسؤوليات
- إدارة وتشغيل خط الأساس الكامل لضوابط أمن المعلومات في السوق: إدارة الثغرات، تعزيز نقاط النهاية، EDR/XDR، أمن الهوية، الدفاع ضد البريد الإلكتروني والتصيد، والتوعية الأمنية
- العمل كأول مستجيب للحوادث الأمنية: الكشف، الفرز، الاحتواء، الحفاظ على الأدلة، التصعيد، ومراجعة ما بعد الحادثة
- إدارة شبكة المكتب بالكامل: التوجيه والتبديل، تجزئة VLAN، إدارة NGFW، IDS/IPS، VPN، Wi-Fi، وعلاقات مزودي خدمة الإنترنت
- إدارة Microsoft 365 وEntra ID وMDM: دورة حياة الهوية، الوصول المشروط، MFA، الامتثال للأجهزة، وعمليات الإعداد وإلغاء الإعداد
- العمل كدعم تقني أساسي لسوق دول مجلس التعاون الخليجي، مع تولي حل التذاكر، توفير نقاط النهاية، وجودة الخدمة
- إدارة الموردين المحليين، المشتريات، وسجل أصول تقنية المعلومات عبر دورة الحياة الكاملة
- تشغيل ضوابط تقنية المعلومات والأمن المطلوبة من قبل المنظم المالي للسوق وقانون حماية البيانات، والحفاظ على أدلة جاهزة للتدقيق
- قيادة فريق تقنية معلومات محلي صغير و/أو شركاء خدمات مُدارة؛ قيادة مشاريع تقنية المعلومات المحلية وتوسعات المكاتب
- تقديم تقارير عن الوضع الأمني، المخاطر، وتقدم المعالجة إلى رئيس العمليات السحابية والعمليات / مدير العمليات الرئيسي وفريق الأمن العالمي
الشروط والمتطلبات
- خبرة تراكمية من 6 إلى 8+ سنوات في عمليات تقنية المعلومات، بما في ذلك 2-3 سنوات كصانع القرار التقني الأول لموقع أو سوق
- خبرة عملية في أمن المعلومات موزونة بالتساوي مع العمليات: EDR، إدارة الثغرات والتصحيحات، خطوط الأساس للتعزيز، الدفاع ضد البريد الإلكتروني والتصيد، فرز السجلات والتنبيهات الأمنية
- خبرة في الاستجابة للحوادث كمستجيب: الكشف، الفرز، الاحتواء، الحفاظ على الأدلة، التصعيد، ومراجعة ما بعد الحادثة
- خبرة عملية في هندسة وأمن الشبكات: التوجيه والتبديل، تصميم VLAN، إدارة NGFW (Fortinet، Palo Alto، Cisco، أو ما يعادلها)، IDS/IPS، VPN من موقع إلى موقع وعن بعد، نشر وحدات تحكم Wi-Fi
- إدارة قوية لـ Microsoft 365 وEntra ID: دورة حياة الهوية، الوصول المشروط، MFA، Exchange Online، SharePoint، Intune/MDM
- إدارة نقاط النهاية وتعزيزها عبر Windows وmacOS: التصوير، دورة التصحيح، تشفير القرص، وكلاء EDR، خطوط الأساس للتكوين
- خبرة عملية مع إطار عمل معترف به لضوابط الأمن (ISO 27001، SOC 2، NIST CSF، أو CIS Controls) وإنتاج أدلة رقابية للتدقيق
- خبرة في بيئة خاضعة للتنظيم - الخدمات المالية، التكنولوجيا المالية، الخدمات المصرفية، أو التأمين - مع تعرض مباشر للتدقيق والامتثال
- خبرة في قيادة الأفراد: تقارير مباشرة، مقاولون، أو فرق خدمات مُدارة
- إجادة مهنية للغة الإنجليزية بالإضافة إلى لغة الأعمال الأساسية للسوق
المهارات المفضلة
- شهادات أمنية: CompTIA Security+، CySA+، GCIH، ISO 27001 Lead Implementer، CISSP، أو CISM
- شهادات شبكات: CCNA/CCNP، CompTIA Network+، أو Fortinet NSE
- شهادات Microsoft: SC-200، SC-300، MD-102، MS-102، أو AZ-104
- خبرة في SIEM/SOAR: Microsoft Sentinel، Splunk، أو Elastic
- الإلمام بالأطر التنظيمية المالية المحلية (BNM RMiT، MAS TRM، HKMA TM-G-1، أو ما يعادلها) وقانون حماية البيانات المعمول به
- إدارة السحابة والأمن على المستوى التشغيلي: AWS أو GCP
- البرمجة النصية للأتمتة: PowerShell، Bash، أو Python
- خبرة في تأسيس مكتب وخط الأساس الأمني من الصفر كأول موظف تقنية معلومات في السوق
عرض النص الأصلي للإعلان
About the Role
We are looking for an IT & Security Lead to own all IT operations and information security for our market office.
We consider only candidates with an existing right to work in the country where the role is based. Visa sponsorship is not available for this position.
The role demands equally deep practical expertise in both IT operations and information security.
Responsibilities
- Own and operate the full information security control baseline for the market: vulnerability management, endpoint hardening, EDR/XDR, identity security, email and phishing defence, and security awareness
- Serve as first responder for security incidents: detection, triage, containment, evidence preservation, escalation, and post-incident review
- Own the office network end-to-end: routing and switching, VLAN segmentation, NGFW, IDS/IPS, VPN, Wi-Fi, and ISP relationships
- Administer Microsoft 365, Entra ID, and MDM: identity lifecycle, conditional access, MFA, device compliance, and onboarding/offboarding
- Serve as the primary IT support contact for the GCC market, owning ticket resolution, endpoint provisioning, and service quality
- Manage local vendors, procurement, and the IT asset register across the full lifecycle
- Operate IT and security controls required by the market's financial regulator and data protection law, and maintain audit-ready evidence
- Lead a small local IT team and/or managed-service partners; drive local IT projects and office expansions
- Report security posture, risks, and remediation progress to the Head of Cloud & Operations / CCO and the global Security function
Requirements
- 6-8+ years of progressive IT operations experience, including 2-3 years as the primary IT decision-maker for a site or market
- Hands-on information security experience weighted equally with operations: EDR, vulnerability and patch management, hardening baselines, email and phishing defence, security log and alert triage
- Incident response experience as a responder: detection, triage, containment, evidence preservation, escalation, and post-incident review
- Hands-on network engineering and security: routing and switching, VLAN design, NGFW administration (Fortinet, Palo Alto, Cisco, or equivalent), IDS/IPS, site-to-site and remote-access VPN, Wi-Fi controller deployments
- Strong Microsoft 365 and Entra ID administration: identity lifecycle, conditional access, MFA, Exchange Online, SharePoint, Intune/MDM
- Endpoint management and hardening across Windows and macOS: imaging, patch cadence, disk encryption, EDR agents, configuration baselines
- Practical experience with a recognised security control framework (ISO 27001, SOC 2, NIST CSF, or CIS Controls) and producing control evidence for audit
- Experience in a regulated environment - financial services, fintech, banking, or insurance - with direct exposure to audit and compliance
- People leadership experience: direct reports, contractors, or managed-service teams
- Professional working proficiency in English plus the primary business language of the market
Preferred
- Security certifications: CompTIA Security+, CySA+, GCIH, ISO 27001 Lead Implementer, CISSP, or CISM
- Networking certifications: CCNA/CCNP, CompTIA Network+, or Fortinet NSE
- Microsoft certifications: SC-200, SC-300, MD-102, MS-102, or AZ-104
- SIEM/SOAR experience: Microsoft Sentinel, Splunk, or Elastic
- Familiarity with local financial regulatory frameworks (BNM RMiT, MAS TRM, HKMA TM-G-1, or equivalent) and applicable data protection law
- Cloud administration and security at an operations level: AWS or GCP
- Scripting for automation: PowerShell, Bash, or Python
- Experience standing up an office and its security baseline from scratch as the first IT hire in a market
رقم الإعلان لدى المصدر: 4465766440