تفاصيل الوظيفة
تعلن شركة Sahm Capital في الرياض، المملكة العربية السعودية، عن توفر وظيفة أخصائي الأمن السيبراني (Cyber Security Specialist) للانضمام إلى فريق العمل.
نبذة عن الوظيفة
- أخصائي الأمن السيبراني مسؤول عن تصميم وتنفيذ وتشغيل ضوابط الأمن السيبراني التقنية في جميع أنحاء المؤسسة.
- يركز الدور على تأمين البنية التحتية ومراجعة أنظمة السحابة والهندسة المعمارية وإدارة الثغرات ودعم أنشطة اختبار الاختراق، مع ضمان التوافق مع معايير الأمن الداخلية ومتطلبات الأمن السيبراني السعودية.
المهام والمسؤوليات
- نشر وإدارة وتكوين أدوات الأمن السيبراني مثل DLP وEDR وجدران الحماية وحلول IAM وغيرها.
- دعم التكوين الآمن للأنظمة والخوادم ونقاط النهاية والبيئات السحابية.
- مراقبة الأحداث الأمنية ودعم عمليات مركز عمليات الأمن (SOC) للكشف عن التهديدات والاستجابة لها.
- مراجعة الأنظمة والتطبيقات والهندسة المعمارية السحابية من منظور أمني، وتحديد نقاط الضعف في التصميم والتوصية بالتحسينات.
- دعم ممارسات التصميم الآمن للأنظمة الجديدة وعمليات التكامل.
- إجراء تقييمات منتظمة للثغرات عبر البنية التحتية والتطبيقات، وتتبع الثغرات وتحديد أولوياتها ودعم معالجتها.
- التنسيق ودعم أنشطة اختبار الاختراق من طرف ثالث والتحقق من النتائج.
- دعم أنشطة الكشف عن الحوادث والتحقيق والاستجابة لها، والمشاركة في تحقيقات الأمن وتحليل السبب الجذري.
- المساعدة في صيانة وتحسين إجراءات الاستجابة للحوادث.
- دعم أنشطة تعزيز أمان الخوادم ونقاط النهاية وأجهزة الشبكة، وضمان تطبيق خطوط الأساس الأمنية والتكوينات الصحيحة.
- المساعدة في تحسين الوضع الأمني العام عبر بيئات تكنولوجيا المعلومات.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو علوم الحاسب أو ما يعادلها.
- خبرة من 3 إلى 6 سنوات في عمليات الأمن السيبراني أو مركز عمليات الأمن (SOC) أو أدوار هندسة الأمن.
- الشهادات المطلوبة: Security+، Certified Ethical Hacker (CEH)، CompTIA CySA+، OffSec Certified Professional (OSCP).
- اللغة العربية كلغة أم، وإجادة اللغة الإنجليزية كتابةً وتحدثًا (سعودي الجنسية).
- يفضل خبرة مثبتة في تطبيق إطار عمل NCA ECC، إرشادات الأمن السيبراني لهيئة السوق المالية (CMA)، قواعد حماية البيانات الشخصية (SDAIA PDPL)، وإطار عمل أمن تداول.
- التسجيل في سجل الهيئة (CMA Register) - قدرة على العمل.
- معرفة بأدوات حماية العلامة التجارية / حماية المخاطر الرقمية (DRP) مثل BrandShield، PhishLabs، Recorded Future وآليات إزالة النطاقات.
- معرفة بأدوات الأمن السيبراني (SIEM، EDR، جدران الحماية، IAM وغيرها).
- فهم إدارة الثغرات والاستجابة للحوادث وإدارة المخاطر.
- فهم أساسي لأمن البريد الإلكتروني (DMARC، DKIM، SPF) والدفاع ضد التصيد.
- مهارات قوية في التوثيق والتنسيق، والقدرة على إدارة مهام متعددة في بيئة منظمة.
- روح العمل الجماعي لمساعدة الزملاء والفرق الأخرى في المشكلات التقنية.
- مهارات تواصل وشخصية قوية لبناء العلاقات.
- القدرة على إدارة الوقت وتحديد أولويات مشاريع متعددة في وقت واحد، مع الانتباه للتفاصيل والمرونة في التعامل مع الأولويات المتغيرة والتواصل بلباقة واحترافية.
عرض النص الأصلي للإعلان
Job Objective
The Cybersecurity Specialist is responsible for designing implementing and operating technical cybersecurity controls across the organization. The role focuses on securing infrastructure reviewing system and cloud architectures managing vulnerabilities and supporting penetration testing activities while ensuring alignment with internal security standards and Saudi cybersecurity requirements
Duties and Responsibilities
Security Engineering and Infrastructure Protection
- Deploy configure and manage cybersecurity tools including DLP EDR firewalls and IAM solutions …etc.
- Support secure configuration of systems servers endpoints and cloud environments
- Monitor security events and support SOC operations for threat detection and response
Architecture Security Review
- Review system applications and cloud architectures from a security perspective
- Identify design weaknesses and recommend security improvements
- Support secure design practices for new systems and integrations
Vulnerability Management and Penetration Testing
- Conduct regular vulnerability assessments across infrastructure and applications
- Track prioritize and support remediation of security vulnerabilities
- Coordinate and support third party penetration testing activities and validate findings
Incident Response and Security Operations
- Support incident detection investigation and response activities
- Assist in maintaining and improving incident response procedures
- Participate in security investigations and root cause analysis
Systems and Security Hardening
- Support system hardening activities across servers endpoints and network devices
- Ensure security baselines and configurations are properly implemented
- Assist in improving overall security posture across IT environments
Education
Bachelor’s degree in Cybersecurity, Information Security, Computer Science or equivalent degree
Qualifications and Experience:
3-6 years of experience in cybersecurity operations, SOC or security engineering roles
- Certifications (Must have):
Security+
- Certified Ethical Hacker (CEH)
- CompTIA CySA+
- OffSec Certified Professional (OSCP)
- Native Arabic fluent in write and speak English (Saudi National)
- Proven experience implementing NCA ECC, CMA Cybersecurity Guidelines, SDAIA PDPL rules, and Tadawul security framework is preferable.
- Knowledge of Brand Protection / Digital Risk Protection (DRP) tools (e.g., BrandShield, PhishLabs, Recorded Future) and domain takedown mechanisms.
- Knowledge of cybersecurity tools (SIEM, EDR, firewalls, IAM …).
- Understanding of vulnerability management, incident response and risk management.
- Basic understanding of email security (DMARC, DKIM, SPF) and phishing defense.
- Strong documentation and coordination skills.
- Ability to manage multiple tasks in a structured environment.
- Team-oriented attitude to help other colleagues and teams with technical problems
- Strong interpersonal communication and relationship-building skills
- Ability to manage time and effectively prioritize numerous projects at one time
- Organized and attentive to detail, flexible with changing priorities and able to communicate in a polite and professional manners
CMA Register - able Function
Yes
رقم الإعلان لدى المصدر: 4469887878