شركة AL-AYUNI Investment and Contracting Company تعلن عن وظيفة أخصائي أول في الأمن السيبراني في الرياض
تفاصيل الوظيفة
شركة العيوني للاستثمار والمقاولات تعلن عن وظيفة أخصائي أول للأمن السيبراني (Specialist I, Cybersecurity) في الرياض، السعودية.
المهام والمسؤوليات
- قيادة تصميم وتنفيذ وتشغيل وتحسين حلول الأمن السيبراني المتقدمة لحماية البنية التحتية لتقنية المعلومات والتطبيقات والبيئات السحابية وأصول المعلومات.
- تقديم خبرة فنية عليا في هندسة الأمن السيبراني، اكتشاف التهديدات، إدارة الثغرات، أمن البنية التحتية، والاستجابة للحوادث مع ضمان الامتثال للمتطلبات التنظيمية وأفضل الممارسات (بما في ذلك ضوابط الأمن السيبراني الوطنية NCA وقانون حماية البيانات الشخصية PDPL).
- قيادة تصميم وتنفيذ وتكوين وصيانة حلول الأمن السيبراني (Firewalls, IDS/IPS, SIEM, EDR/XDR, DLP, IAM, PAM ومنصات مراقبة الأمن).
- تطوير وتعزيز بنية الأمن لحماية الشبكات والأنظمة والتطبيقات والبيئات السحابية.
- إدارة وتحسين أدوات الأمن والسياسات والقواعد والتكوينات لرفع قدرات اكتشاف التهديدات ومنعها.
- إجراء تقييمات أمنية متقدمة، وإدارة الثغرات، واختبارات الاختراق.
- تحليل التنبيهات الأمنية، والتحقيق في الحوادث، وإجراء تحليل الأسباب الجذرية، وتنسيق أنشطة المعالجة.
- تطوير معايير تعزيز الأمن وضمان التكوين الآمن للأنظمة والبنية التحتية.
- قيادة المراجعات الأمنية للتقنيات الجديدة والتطبيقات والبائعين والتكاملات الخارجية.
- دعم تنفيذ الضوابط الأمنية في البيئات المحلية والسحابية.
- مراقبة التهديدات الأمنية الناشئة والثغرات وتقنيات الهجوم.
- قيادة أنشطة الاستجابة للحوادث (التحقيق، الاحتواء، الاستئصال، استخلاص الدروس).
- إجراء تحليل التهديدات والتوصية بتحسينات للوضع الأمني للمنظمة.
- صيانة وتطوير قواعد كشف SIEM ومنطق الربط وحالات الاستخدام الأمني.
- ضمان توافق الضوابط الأمنية مع ضوابط الأمن السيبراني الوطنية الأساسية (ECC) وقانون حماية البيانات الشخصية (PDPL) والمتطلبات التنظيمية الأخرى.
- دعم عمليات التدقيق الأمني الداخلية والخارجية بتقديم الأدلة الفنية والوثائق.
- إجراء تقييمات المخاطر والتوصية بتحسينات أمنية.
- صيانة سياسات وإجراءات ومعايير الأمن السيبراني والوثائق الفنية.
- دعم تقارير الامتثال ومبادرات تحسين النضج الأمني.
- تقديم التوجيه الفني والإرشاد لأعضاء فريق الأمن السيبراني المبتدئين.
- قيادة مشاريع الأمن السيبراني وضمان التنفيذ الناجح لحلول الأمن.
- تقييم التقنيات الأمنية الجديدة والتوصية بالحلول المناسبة.
- التعاون مع فرق البنية التحتية لتقنية المعلومات وتطوير التطبيقات والأعمال لضمان تسليم تقني آمن.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني، أمن المعلومات، علوم الحاسب، تقنية المعلومات أو مجال ذي صلة.
- خبرة من 5 إلى 8 سنوات في مجال الأمن السيبراني أو أمن المعلومات أو هندسة الأمن أو العمليات السيبرانية.
- الشهادات المهنية المفضلة: CISSP، CISM، CompTIA Security+، CCNP Security، CEH، CySA+، Microsoft AZ-500، Microsoft SC-200 / SC-300، Fortinet NSE / Palo Alto PCNSE.
عرض النص الأصلي للإعلان
The Senior Specialist, Cybersecurity is responsible for leading the design, implementation, operation, and continuous improvement of advanced cybersecurity solutions to protect the organization's IT infrastructure, applications, cloud environments, and information assets. The role provides senior technical expertise in cybersecurity engineering, threat detection, vulnerability management, security architecture, and incident response while ensuring compliance with regulatory requirements and industry best practices, including NCA Cybersecurity Controls and PDPL.
Key Responsibilities
Cybersecurity Engineering & Operations
- Lead the design, implementation, configuration, and maintenance of cybersecurity solutions, including Firewalls, IDS/IPS, SIEM, EDR/XDR, DLP, IAM, PAM, and security monitoring platforms.
- Develop and enhance security architecture to protect enterprise networks, systems, applications, and cloud environments.
- Manage and optimize security tools, policies, rules, and configurations to improve threat detection and prevention capabilities.
- Perform advanced security assessments, vulnerability management, and penetration testing activities.
- Analyze security alerts, investigate incidents, perform root cause analysis, and coordinate remediation activities.
- Develop security hardening standards and ensure secure configuration of systems and infrastructure.
- Lead security reviews for new technologies, applications, vendors, and third-party integrations.
- Support implementation of security controls across on-premises and cloud environments.
Threat Management & Incident Response
- Monitor emerging cybersecurity threats, vulnerabilities, and attack techniques.
- Lead incident response activities, including investigation, containment, eradication, and lessons learned.
- Perform threat analysis and recommend improvements to the organization's security posture.
- Maintain and improve SIEM detection rules, correlation logic, and security use cases.
Governance, Risk & Compliance
- Ensure cybersecurity controls align with NCA Essential Cybersecurity Controls (ECC), PDPL, and applicable regulatory requirements.
- Support internal and external cybersecurity audits by providing technical evidence and documentation.
- Conduct risk assessments and recommend security improvements.
- Maintain cybersecurity policies, procedures, standards, and technical documentation.
- Support compliance reporting and security maturity improvement initiatives.
Technical Leadership
- Provide technical guidance and mentorship to junior cybersecurity team members.
- Lead cybersecurity projects and ensure successful implementation of security solutions.
- Evaluate new cybersecurity technologies and recommend suitable solutions.
- Collaborate with IT infrastructure, application development, and business teams to ensure secure technology delivery.
Qualifications
Education:
- Bachelor's Degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field.
Experience
- 5-8 years of relevant experience in cybersecurity, information security, security engineering, or cyber operations.
Preferred Certifications
- CISSP (Preferred)
- CISM (Preferred)
- CompTIA Security+
- CCNP Security
- CEH
- CySA+
- Microsoft AZ-500
- Microsoft SC-200 / SC-300
- Fortinet NSE / Palo Alto PCNSE
رقم الإعلان لدى المصدر: 4468707370