وظيفة مساعد مدير التحقيق الرقمي والاستجابة للحوادث شاغرة لدى البحر الأحمر الدولية في الرياض
تفاصيل الوظيفة
تعلن البحر الأحمر الدولية (Red Sea Global)، إحدى الشركات الرائدة في التنمية العقارية المتجددة، عن توفر وظيفة مساعد مدير - التحقيقات الرقمية والاستجابة للحوادث (Assistant Manager - Digital Forensics and Incident Response) في مدينة الرياض، المملكة العربية السعودية.
نبذة عن الوظيفة
إدارة والإشراف على وظيفة التحقيقات الرقمية والاستجابة للحوادث (DFIR) في الشركة، بما يشمل فرز الحوادث واحتوائها واستعادتها، والتحقيقات الجنائية الرقمية، وتحليل البرمجيات الخبيثة والقطع الأثرية، وصيد التهديدات، وإعداد تقارير ما بعد الحادث عبر بيئات الشركة السحابية والتقنية التشغيلية، مع ضمان كشف الحوادث الأمنية والتحقيق فيها وحلها ضمن مستويات الخدمة المتفق عليها، والحفاظ على الأدلة بطريقة قابلة للدفاع عنها، ومواءمة ممارسات DFIR مع استراتيجية الشركة ورغبتها في المخاطرة والمعايير الوطنية والدولية المعمول بها.
المهام والمسؤوليات
- إدارة تكوين وضبط التشغيل اليومي لأدوات DFIR بما يشمل كشف نقاط النهاية والاستجابة، ومنصات الاستحواذ والتحليل الجنائي، ومصادر السجلات والتليمترية التي يعتمد عليها في التحقيقات.
- ضمان امتثال ممارسات الاستجابة للحوادث والتحقيق الجنائي لسياسات أمن المعلومات والمتطلبات التنظيمية والمعايير الوطنية والدولية (مثل NCA ECC وPDPL وISO 27001 وNIST SP 800-61).
- إدارة تطوير وصيانة خطة الاستجابة للحوادث وسيناريوهات التشغيل وتصنيف الخطورة ومصفوفة التصعيد، وضمان اختبارها وتحديثها بما يتماشى مع المشهد التهديدي المتغير.
- ضمان فرز الحوادث الأمنية واحتوائها واستئصالها واستعادتها في الوقت المناسب، مع تحديد الأولويات حسب تأثير الأعمال وإغلاقها ضمن مستويات الخدمة المتفق عليها.
- إدارة استحواذ الأدلة الجنائية ومعالجتها، وضمان سلسلة الحيازة والتحقق من السلامة والحفظ القابل للدفاع عنه للإجراءات القانونية أو التنظيمية أو التأديبية.
- إدارة تطوير حالات استخدام الكشف وفرضيات الصيد المستنبطة من التحقيقات، وضمان تغذية النتائج والمؤشرات في قدرات المراقبة والتنبيه والاستجابة.
- الإشراف على التحقيق الفني في حالات البرمجيات الخبيثة والاختراق والتهديدات الداخلية وتسريب البيانات، بما يشمل تحليل القطع الأثرية للمضيف والذاكرة والشبكة والهوية والسحابة حتى السبب الجذري الموثق.
- إدارة جودة وتوقيت تقارير الحوادث والملخصات التنفيذية ومراجعات ما بعد الحادث، وضمان تتبع النتائج القابلة للتنفيذ والدروس المستفادة والإجراءات التصحيحية حتى الإغلاق.
- الإشراف على صيد التهديدات الاستباقي عبر تليمترية نقاط النهاية والشبكة والسحابة والهوية، باستخدام استخبارات التهديدات وتقنيات الخصم المرفوعة إلى أطر معترف بها مثل MITRE ATT&CK.
- ضمان التحقق من جاهزية DFIR من خلال تمارين الطاولة ومحاكاة الهجمات واختبار الفريق الأرجواني، والتحقق الرسمي من إمكانية تحقيق أهداف الاستجابة والاستعادة الموثقة.
- إدارة أتمتة إجراءات التحقيق والاستجابة من خلال سيناريوهات التشغيل والبرمجة النصية، مما يقلل الجهد اليدوي ويحسن متوسط وقت الكشف والاحتواء والاستعادة.
- ضمان توثيق جميع عمليات DFIR والتكوينات الفنية وإجراءات التشغيل القياسية وصيانتها وإبلاغها لأصحاب المصلحة المعنيين.
- الإشراف على دمج استخبارات التهديدات السيبرانية في سير عمل الكشف والصيد والاستجابة، بما يشمل استيعاب المؤشرات وإثراءها والمسح الاستعادي عبر البنية التحتية.
- الإشراف على علاقات الموردين ومقدمي الخدمات لتقنيات DFIR وخدمات الاستجابة للحوادث المحتجزة، وضمان الالتزام بمستويات الخدمة وأفضل الممارسات الموصى بها.
- إدارة نقل المعرفة من الموارد المتعاقدة والخارجية إلى ملكية الشركة، وضمان تسليم موثق ومتحقق منه لجميع الأنشطة التشغيلية DFIR.
- العمل كنقطة تصعيد للحوادث عالية الخطورة أو الحساسة أو ذات الأهمية القانونية، والتحقق من المخاطر وضمان الموافقات التنظيمية المناسبة ودفع الإجراءات التصحيحية والوقائية.
- تقديم مدخلات لاستراتيجية الأمن السيبراني للإدارة من منظور قسم التحقيقات الرقمية والاستجابة للحوادث، بما يضمن التوافق مع رؤية الشركة ورسالتها ورغبتها في المخاطرة.
- تطوير أهداف القسم ومؤشرات الأداء الرئيسية والخطط التشغيلية السنوية للاستجابة للحوادث والتحقيق الجنائي وصيد التهديدات وإعداد التقارير، وضمان تحقيق مستويات الأداء المستهدفة.
- المساهمة في إعداد الميزانية ومراقبة الأداء المالي للمبادرات والأدوات والخدمات المتعلقة بـ DFIR، وضمان الاستخدام الفعال والفعال من حيث التكلفة.
- تنفيذ وضمان الالتزام بسياسات القسم ومعاييره وإجراءاته للاستجابة للحوادث والتحقيق الجنائي، مع الإشراف على مراقبة الأداء وإعداد تقارير مؤشرات الأداء واتخاذ الإجراءات التصحيحية عند الحاجة.
- ضمان التوظيف الفعال والتطوير ونشر فريق DFIR بما يشمل التغطية عند الطلب والمناوبات، بالتنسيق مع الإدارة العليا، وتعزيز نمو المواهب وبناء القدرات والجاهزية للخلافة.
الشروط والمتطلبات
- درجة البكالوريوس (إلزامية) في علوم الحاسب، أو أمن المعلومات، أو نظم المعلومات، أو هندسة البرمجيات أو تخصص تقني ذي صلة.
- درجة الماجستير (مفضلة) في أمن المعلومات، أو إدارة الأمن السيبراني، أو إدارة الأعمال (MBA مع تركيز على تكنولوجيا المعلومات/الأمن).
- خبرة لا تقل عن 6 سنوات في مجال الأمن السيبراني، منها 3 سنوات على الأقل في التحقيقات الرقمية والاستجابة للحوادث (DFIR) في بيئة إنتاج مؤسسية.
- الشهادات المهنية المفضلة: GCFA, GCFE, GCIH, GNFA, GREM أو CISSP.
- إجادة اللغتين العربية والإنجليزية كتابةً وتحدثاً.
- المشاركة في مناوبات التصعيد على مدار الساعة (24/7) للحوادث الأمنية، والاستعداد للسفر إلى المواقع لاستحواذ الأدلة عند الحاجة.
عرض النص الأصلي للإعلان
Be the change. Join the world’s most visionary developer.
Red Sea Global (RSG) is showing that there is a better way to positively shape the places we live, work and travel.
We are purpose-driven and committed to people and planet. Our transformative programs are a driving force to achieving Vision 2030, as well as leading the world towards regenerative tourism.
Join RSG and be part of the positive change for Saudi Arabia and the world.
Job Purpose:
Manage and oversee RSG's Digital Forensics and Incident Response (DFIR) function, including incident triage, containment and recovery, digital forensic investigations, malware and artifact analysis, threat hunting, and post-incident reporting across RSG's corporate, cloud, and operational technology environments, ensuring that security incidents are detected, investigated, and resolved within agreed service levels, that evidence is preserved in a defensible manner, and that DFIR practices align with RSG's organizational strategy, risk appetite, and applicable national and international standards.
Job Responsibilities:
- Manage the configuration, tuning, and daily operation of DFIR tooling, including endpoint detection and response, forensic acquisition and analysis platforms, and the log and telemetry sources relied upon for investigations.
- Ensure incident response and forensic practices comply with RSG's information security policies, regulatory requirements, and national/international standards (e.g., NCA ECC, PDPL, ISO 27001, NIST SP 800-61).
- Manage the development and maintenance of the incident response plan, playbooks, severity classification, and escalation matrix, ensuring they remain tested, current, and aligned to the evolving threat landscape.
- Ensure timely triage, containment, eradication, and recovery of security incidents, prioritized by business impact and closed within agreed service levels.
- Manage forensic evidence acquisition and handling, ensuring chain of custody, integrity verification, and defensible preservation for legal, regulatory, or disciplinary proceedings.
- Manage the development of detection use cases and hunting hypotheses derived from investigations, ensuring findings and indicators are fed back into RSG's monitoring, alerting, and response capability.
- Oversee the technical investigation of malware, intrusion, insider, and data exfiltration cases, including host, memory, network, identity, and cloud artifact analysis through documented root cause.
- Manage the quality and timeliness of incident reports, executive summaries, and post-incident reviews, ensuring actionable findings, lessons learned, and corrective actions are tracked to closure.
- Oversee proactive threat hunting across endpoint, network, cloud, and identity telemetry, using threat intelligence and adversary techniques mapped to recognized frameworks such as MITRE ATT&CK.
- Ensure DFIR readiness is verified through tabletop exercises, attack simulation and purple-team testing, and formal validation that documented response and recovery objectives are achievable.
- Manage the automation of investigation and response actions through orchestration playbooks and scripting, reducing manual effort and improving mean time to detect, contain, and recover.
- Ensure that all DFIR processes, technical configurations, and standard operating procedures are fully documented, maintained, and communicated to relevant stakeholders.
- Oversee the integration of cyber threat intelligence into detection, hunting, and response workflows, including indicator ingestion, enrichment, and retrospective sweeps across the estate.
- Oversee vendor and service-provider relationships for DFIR technologies and retained incident response services, ensuring adherence to service levels and recommended best practices.
- Manage the transfer of knowledge from contracted and external resources into RSG ownership, ensuring documented and verified handover of all DFIR operational activities.
- Act as escalation point for high-severity, sensitive, or legally significant incidents, validating risk, ensuring appropriate approvals and regulatory notifications, and driving corrective and preventive actions.
Managerial Responsibilities
- Provide input into the Department's cybersecurity strategy from the Digital Forensics & Incident Response Section perspective, ensuring alignment with RSG's vision, mission, and risk appetite.
- Develop Section objectives, KPIs, and annual operational plans for incident response, digital forensics, threat hunting, and investigation reporting, ensuring implementation meets established performance targets.
- Contribute to budget preparation and monitor financial performance of DFIR-related initiatives, tools, retainers, and services, ensuring efficient and cost-effective utilization.
- Implement and ensure adherence to Section policies, standards, and procedures for incident response and digital forensics, while overseeing performance monitoring, KPI reporting, and corrective actions where needed.
- Ensure effective staffing, development, and deployment of the DFIR team, including on-call and shift coverage, in coordination with higher management, fostering talent growth, capability building, and succession readiness.
Job Requirements:
Academic Qualification:
- Bachelor’s degree (mandatory): Computer Science, Information Security, Information Systems, Software Engineering or a related technical discipline.
- Master’s degree (preferred): Information Security, Cybersecurity Management, or Business Administration (MBA with IT/Security focus).
Qualifications & Experience:
- 6+ years in cybersecurity, of which a minimum of 3 years in hands-on digital forensics and incident response within an enterprise production environment.
- Preferred certifications: GCFA, GCFE, GCIH, GNFA, GREM, or CISSP. Fluent written and spoken Arabic and English. Participation in a defined 24/7 on-call escalation rota for security incidents, with readiness to travel to site for evidence acquisition when required.
For more information about Red Sea Global, visit:
🌐 Website: https://www.redseaglobal.com/en
🔗 LinkedIn: https://www.linkedin.com/company/red-sea-global/
▶️YouTube: https://www.youtube.com/channel/UCMo1fSbA3iOhvvC8OP0IYNA
🐦 X: @RedSeaGlobal
رقم الإعلان لدى المصدر: 4466269488