📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

وظيفة أخصائي دفاع أمن سيبراني أول شاغرة لدى شركة الفلك للمعدات والتجهيزات الإلكترونية في جدة

Cyber Security Defense Senior Specialist
🕒 نُشرت: (منذ 19 يوماً) 📍 جدة وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة الفلك للمعدات والتجهيزات الإلكترونية عن توفر وظيفة أخصائي أول دفاع الأمن السيبراني (Cyber Security Defense Senior Specialist) في مكة جدة السعودية.

المهام والمسؤوليات

  • إدارة الثغرات واختبار الاختراق: تطوير ومراجعة وتحديث منهجيات اختبار الاختراق لضمان التغطية الشاملة والالتزام بأفضل الممارسات.
  • إجراء نمذجة التهديدات وتقييم الثغرات لتحديد نقاط الضعف في البنية التحتية والتطبيقات والأنظمة وتقديم توصيات للمعالجة.
  • التنسيق لأنشطة اختبار الاختراق ومراجعة الكود المصدري واختبار أمان التطبيقات وعمليات الفرق الحمراء.
  • المسؤولية عن أنشطة فحص الثغرات على الأنظمة والأصول، وصحة ماسحات الثغرات ونشرها عبر قطاعات الشبكة المختلفة، ومراجعة التكوين، وجميع الأنشطة المرتبطة بإدارة الثغرات، وإعداد تقارير الثغرات لتقنية المعلومات.
  • متابعة حالة معالجة الثغرات والإجراءات المتخذة بالتنسيق مع إدارة تقنية المعلومات.
  • الحفاظ على مؤشرات أداء إدارة الثغرات ومتابعة المعالجة مع أمن تقنية المعلومات للثغرات المحددة.
  • صيد التهديدات وإدارتها: المسؤولية عن أنشطة استخبارات التهديدات والتنسيق لأنشطة صيد التهديدات.
  • إدارة تقييم الاختراق وفحص Yara وSigma لتحديد ومعالجة الاختراقات المحتملة، وإعداد التقارير لتقنية المعلومات.
  • فرز وحل هجمات النواقل المتقدمة مثل شبكات البوت والتهديدات المستمرة المتقدمة (APTs).
  • جمع وتحليل استخبارات التهديدات من مصادر داخلية وخارجية.
  • متابعة التحديثات على التهديدات الواردة من الجهات المختصة وضمان انعكاسها على أنظمة تقنية المعلومات.
  • مراقبة مصادر البيانات الخارجية لفهم التهديدات الناشئة وتحديد ما قد يؤثر على المنظمة.
  • مراقبة مركز العمليات الأمنية (SOC) وإدارة الحوادث السيبرانية: المسؤولية عن مراقبة والتحقيق في أحداث وحوادث الأمن السيبراني، والعمل كمستجيب أول لتحليل الطب الشرعي والتحقيق.
  • الحفاظ على مستودع للحوادث تصنيفات مختلفة للحوادث.
  • ربط بيانات الحوادث لتحديد الثغرات والمساعدة في تنسيق التخفيف منها.
  • استخدام المعرفة بجهات التهديد لإعداد استجابة المنظمة للحوادث السيبرانية.
  • تنفيذ استراتيجية الاحتواء أثناء فقدان البيانات أو أحداث الاختراق.
  • تحليل النشاط الضار لتحديد الثغرات التي تم استغلالها وطرق الاستغلال وتأثيرها على النظام والمعلومات.
  • العمل مع مركز العمليات الأمنية (SOC) على جميع الحوادث السيبرانية المرفوعة.
  • تنفيذ عمليات إدارة الأحداث.
  • المسؤولية عن إدخال الأصول الجديدة لتوسيع نطاق مراقبة SOC.
  • المسؤولية عن الحالة الصحية لـ SIEM والتنسيق مع البائع الخارجي لأي نشاط متعلق بـ SIEM.
  • تقديم توصيات لإنشاء وضبط حالات الاستخدام للمسؤولين بناءً على نتائج التحقيقات أو مراجعات التهديدات.
  • مراقبة أداء جميع الوظائف الخارجية لـ SOC لضمان امتثال البائع لمستويات الخدمة المتفق عليها ومؤشرات الأداء.

الشروط والمتطلبات

  • درجة البكالوريوس في علوم الحاسب أو تقنية المعلومات.
  • خبرة مع أدوات تقييم الأمن.
  • خبرة في إدارة الثغرات واختبار الاختراق.
  • معرفة بحلول SIEM.
  • معرفة بتنسيقات السجلات والقدرة على تجميع وتحليل بيانات السجلات لأغراض التحقيق (سجلات syslog و HTTP و DB).
  • خبرة متعمقة مع أدوات البحث في السجلات.
  • شهادات مهنية ذات صلة مثل (GCIH) و (CTIA) و (CDFE) و (OSCP) و (CEH) و (OSWA) مرغوب فيها بشدة.
عرض النص الأصلي للإعلان

Key Responsibilities:

Vulnerability management and Penetration testing

  • Develop, review and update penetration testing methodologies, ensuring comprehensive coverage and adherence to industry best practices.
  • Conduct threat modelling and vulnerability assessments to identify potential weaknesses in infrastructure, applications, and systems and provide recommendations for remediation.
  • Coordinate penetration testing, source code review, application security testing, and red teaming activities.
  • Responsible for vulnerability scanning activities on systems and assets, Vulnerability scanners health and deployment across the different segments of network, configuration review, and all associated activities related to vulnerability management preparation of vulnerability reports to IT.
  • Follow-up on vulnerability remediation status and actions taken in coordination with IT department.
  • Maintain vulnerability management KPI and follow up remediation with IT security for identified vulnerabilities.

Threat Hunting and Threat Management

  • Responsible for threat intelligence activities, and coordination of threat hunting activities.
  • Manage compromise assessment, Yara scanning, and sigma scanning activities to identify and address potential breaches and preparation of reports for IT actions accordingly.
  • Triage and resolve advanced vector attacks such as botnets and advanced persistent threats (APTs).
  • Gather and analyze threat intelligence from internal and external sources.
  • Follow updates on threats posted or received from relevant authorities and ensure these updates are reflected on IT systems as applicable.
  • Monitor external data sources to keep understanding of emerging cybersecurity threats and determine which security issues may have an impact on the organization.

SOC monitoring & Cyber incident management

  • Responsible for the monitoring and investigation of Cybersecurity events and incidents and act as first responder forensics analysis and investigation.
  • Maintain an incident repository for organization incidents with different incident classifications.
  • Correlate incident data to identify vulnerabilities and help in coordinating a mitigation for these vulnerabilities that might impact the company.
  • Use knowledge of threat actors and activities to prepare organization's response to a cyber incident.
  • Implement the containment strategy during data loss or breach events.
  • Analyse malicious activity to determine vulnerabilities exploited, exploitation methods and effects on system and information.
  • Responsible to work with the SOC all raised cyber security incidents.
  • Implement the event management processes.
  • Responsible for onboarding the new assets to extend SOC monitoring over them.
  • Responsible for the SIEM health status and coordinating any required activity related to the SIEM with the outsourced vendor.
  • Provide use case creation/tuning recommendations to administrators based on findings during investigations or threat reviews.
  • Monitor the performance on all outsourced functions to SOC to ensure vendor conformance to agreed SLAs and KPIs.



QUALIFICATIONS:

  • Bachelor’s degree in computer science, Information Technology
  • Experience with Security Assessment tools
  • Experience in Vulnerability management and Penetration testing
  • Knowledge of SIEM solutions
  • Knowledge of log formats and ability to aggregate and parse log data for syslog, http logs, DB logs for investigation purposes.
  • In-depth experience with log search tools
  • Relevant professional certificates in Certified Incident Handler (GCIH), Certified Threat Intelligence Analyst (CTIA), Certified Digital Forensics Examiner (CDFE), Offensive
  • Security Certified Professional, Certified Ethical Hacker (CEH), and Certified Web Assessor (OSWA) certification are highly desirable.
المصدر: LinkedIn - أُضيفت للموقع في 20 سبتمبر 2026
رقم الإعلان لدى المصدر: 4467323699