وظيفة مستشار الأمن السيبراني شاغرة لدى Artificial Intelligence Global Company في الخبر
تفاصيل الوظيفة
شركة عالمية في مجال الذكاء الاصطناعي تبحث عن مستشار أمن سيبراني للعمل في المنطقة الشرقية (الخبر)، السعودية. سيكون المستشار مسؤولاً عن تصميم وإعداد المقترحات التي تلبي متطلبات ومعايير الأمن السيبراني لعملاء القطاعين العام والصناعي، مع تركيز أساسي على تنفيذ أمن تقنيات التشغيل (OT) لعملاء القطاع الصناعي (النفط والغاز والطاقة والمرافق).
المهام والمسؤوليات
- تصميم وإعداد مقترحات أمنية تلبي متطلبات ومعايير الأمن السيبراني للعملاء.
- تنفيذ حلول أمن تقنيات التشغيل (OT) مع التركيز على عملاء القطاع الصناعي.
- إعداد قوائم الامتثال في حال وجود أي انحراف عن الممارسات القياسية المتبعة.
- قيادة تصميم العمارة الشاملة وتنفيذ بنى شبكات OT آمنة، مع ضمان الفصل بين شبكات IT وOT.
- إعداد عمارة النظام، والعمارة المنطقية، وقائمة المواد (Bill of Material) بأحدث الأجهزة والبرمجيات، ومواصفات التصميم الوظيفي، وتفاصيل التصميم، وإجراءات اختبار القبول في المصنع والموقع، وبيان طريقة التكامل والتعديل.
- تنفيذ وإدارة ضوابط OT IDS/IPS وجدران الحماية المتينة من Fortinet وPalo Alto وDragos وNozomi.
- تكوين وإدارة مفاتيح الشبكة L2 وL3 وتقويتها، واستكشاف الأخطاء وإصلاحها عبر حلول أمنية متعددة، مع معرفة متعمقة بقوائم التحكم بالوصول (ACLs).
- تنفيذ وإدارة ضوابط وصول صارمة لبيئة DCS تشمل المصادقة والتحكم بالوصول المبني على الأدوار والوصول عن بُعد الآمن.
- تصميم وتنفيذ الشبكات مع مفاهيم الطبقات، وتكوين مفاتيح التوجيه، وتصميم الشبكة وتحديد مواقع المكونات بناءً على الوظيفة.
- إدارة نظام تحديث أمان Windows (WSUS) وتكوين برنامج What's Up Gold وإنشاء مخططات العمارة.
- تكوين نظام إدارة الشبكات (NMS) من التركيب حتى التشغيل وإنشاء لوحات المعلومات.
- إدارة الحماية من الفيروسات (McAfee AV Epo) مع القائمة البيضاء، وتقوية سطح المكتب، ومنع تثبيت الملفات التنفيذية الجديدة، والتحكم بالتكامل والتغيير، ومنع فقدان البيانات.
- تصميم مجموعات VM HA، وتصميم عمارة VM، وإنشاء السياسات والحفاظ عليها، وتصميم نظام النسخ الاحتياطي باستخدام منتجات Veritas NetBackup وAcronis وVeeam Backup & Replication.
- إجراء والإشراف على تقييمات المخاطر المنتظمة لبيئة OT، وتحديد الثغرات والتهديدات المحتملة.
- ضمان فصل شبكة DCS بشكل كافٍ عن الشبكات الأخرى لتقليل مخاطر الاختراق.
- التعاون الوثيق مع فرق الأمن السيبراني OT لدى العملاء لضمان ممارسات أمنية متسقة عبر بيئتي IT وOT.
- التوصية بتحسينات أمنية ومشتريات تدعم الدفاع عن بيئات OT لصالح العميل.
- تقديم التدريب والتوجيه لمهندسي OT حول أفضل ممارسات الأمن.
- إدارة التصحيحات (Patch Management).
الشروط والمتطلبات
- خبرة عملية لا تقل عن 8-10 سنوات في عمليات الأمن السيبراني.
- درجة البكالوريوس مع شهادات مهنية متعددة ذات صلة مثل ISA/IEC 62443 وCISM وCCSP.
- شهادات تقنية مطلوبة في Dragos وNozomi وFortinet NSE4 فأعلى أو Palo Alto PNSE أو ما يعادلها.
- شهادة IEC 62443 Expert.
- معرفة متقدمة بأطر تقييم المخاطر وتنفيذها وتسليمها.
- فهم عميق لأطر الأمن الصناعي في ضوابط ICS لتقنيات OT.
- فهم قوي لأنظمة التحكم الصناعية (ICS) وبيئات تقنيات التشغيل (OT)، بما في ذلك معرفة البروتوكولات والبنى والمكونات المستخدمة في قطاعات البنية التحتية الحيوية.
- معرفة المعايير والأطر الصناعية ذات الصلة مثل NCA وإطار NIST للأمن السيبراني وIEC 62443 وISA/IEC 62451، والقدرة على مواءمة المبادرات الأمنية مع هذه الأطر.
- خبرة قوية في تنفيذ خدمات ضوابط أمن OT.
- مهارات قوية في إدارة علاقات العملاء.
- السفر مطلوب.
- إتقان اللغة الإنجليزية (العربية إضافة مرغوبة).
المهارات المطلوبة
- خبرة واسعة في مجال الأمن السيبراني مع تركيز خاص على أمن OT أو أمن أنظمة التحكم الصناعية (ICS).
- إتقان ممارسات ومنهجيات إدارة المشاريع لضمان تنفيذ المشاريع وتسليمها بكفاءة.
- معرفة شاملة وفهم لأنظمة OT/ICS بما في ذلك SCADA وPLCs وDCS وHMIs والأجهزة الصناعية الأخرى.
- ألفة قوية بالمعايير والأطر الأساسية للأمن السيبراني مثل ISA/IEC 62443 وNIST SP 800-82 وNERC CIP وIEC 61511.
- مهارات اتصال استثنائية وقدرات تعامل مع الآخرين لتمكين التعاون السلس مع فرق متعددة الوظائف وأصحاب المصلحة.
- فهم سليم لتقنيات البرمجيات والأجهزة المستخدمة في ICS، مثل أنظمة التشغيل وقواعد البيانات ولغات البرمجة.
- معرفة متينة بأدوات وتقنيات الأمن المتطورة المستخدمة في بيئتي OT وIT، بما في ذلك أنظمة كشف التسلل الشبكي (IDS) مثل Nozomi وDragos وTenable.
- معرفة المنتجات وشهادات معتمدة في مفاتيح Hirshman وCISCO والمفاتيح الصناعية الأخرى.
- إتقان تصميم وتنفيذ الشبكات باستخدام مفاهيم الطبقات، وتكوين مفاتيح التوجيه، وتصميم الشبكة وتحديد مواقع المكونات.
- خبرة عملية في تصميم مجموعات VM HA وتصميم عمارة VM، ومعرفة منتجات على مستوى الخبراء مثل Veritas NetBackup وAcronis وVeeam Backup & Replication.
عرض النص الأصلي للإعلان
Overall Purpose of the Role
The Consultant will be responsible for designing and preparing proposals that meet cybersecurity requirements and standards for clients at Public and Industrial sectors. Yet, the majority of the work will be on Operational Technology (OT) Security Implementation for Industrial clients. This position requires a strong understanding of both IT and OT systems, as well as expertise in cybersecurity practices specific to operational technology to deal with Oil/Gas & Energy/Utilities Sectors client.
Key Skills
- Extensive expertise in the field of cybersecurity, specifically focused on OT security or industrial control systems (ICS) security.
- Proficient in project management practices and methodologies, ensuring efficient project execution and delivery.
- Comprehensive knowledge and understanding of OT/ICS systems, encompassing SCADA, PLCs, DCS, HMIs, and various other industrial control devices.
- Preparation of a compliance list in case of any deviation required from the standard practices followed.
- Leading the design of Overall Architecture and implementation of secure OT network architectures. Ensure segmentation between IT and OT networks.
- Preparation of System Architecture, Logical Architecture, Preparation of Bill of Material with the latest available Hardware, software Functional Design Specification, Detail design specification, Factory Acceptance test Procedure, Site Acceptance test Procedure, Method Statement for Integration and Modification
- Profound familiarity with essential cybersecurity standards and frameworks, including ISA/IEC 62443, NIST SP 800-82, NERC CIP, and IEC 61511.
- Proven track record of implementing OT IDS/IPS controls & Rugged OT Firewall of Fortinet, Palo Alto, Dragos & Nozomi
- Exceptional communication and interpersonal abilities, enabling seamless collaboration with diverse cross-functional teams and stakeholders.
- Sound understanding of software and hardware technologies commonly employed in ICS, such as operating systems, databases, and programming languages.
- Solid knowledge of cutting-edge security tools and techniques utilized in both OT and IT environments, including and Network Intrusion Detection Systems (IDS) like Nozomi, Dragos, Tenable, etc.
- Configuration Knowledge on L2 and L3 Switches Hardening of Switches Troubleshooting capacity on multiple security solutions. Deep level Knowledge of ACL’s
- Implement and manage strict access controls for the DCS environment. This includes user authentication, role-based access, and secure remote access methodologies. Product Knowledge and Certification added advantage Hirshman
- CISCO
- Other Industrial Switches Designing and Implementation of the network with the layer concepts
- Network switch configuration Designing the network and positioning the components based on the functionality.
- Routing Switch
- Windows Security Update system (WSUS)
- Configuration of What's Up Gold Creating an Architecture diagram
- Configuring NMS system installation to commissioning
- Creating Dashboard
- Antivirus
- MacAfee AV Epo Whitelisting
- Desktop-Hardening System
- Antivirus Protection Whitelisting Denial of Installing new Exe and Related files Integrity control Change Control Application Control Data loss prevention.
- Hands-on experience in Design the VM HA cluster Hands-on experience in Design VM Architecture Product Knowledge
- Creating the policies and Maintaining Designing the Backup system Expert-level Product knowledge on :
- Veritas Net Backup
- Acronis
- Veeam Backup & Replication
- Risk Assessment: Conduct and oversee regular risk assessments of the OT environment, identifying vulnerabilities and potential threats.
- Network Segmentation: Ensure that the DCS is adequately segmented from other networks, minimizing the risk of potential intrusions from external and internal sources.
- Work closely with customer OT cybersecurity teams to ensure consistent security practices across IT and OT landscapes.
- Recommend security enhancements and purchases that will support the defense of the OT environments for the benefit of the client.
- Provide training and guidance to OT engineers on security best practices.
Patch Management
Education and Qualifications
- At least 8-10 years of hands-on experience in Cybersecurity operations.
- Advanced knowledge of risk assessment frameworks implementation and delivery.
- A bachelor’s degree with multiple related Professional Certifications (ISA/IEC 62443, CISM, CCSP etc.,)
- Required Technical Certifications in Dragos, Nozomi, Fortinet NSE4 & above/ Palo Alto PNSE or multiple relevant.
- In-depth understanding of industry security frameworks in ICS controls of OT Technologies.
- Strong understanding of industrial control systems (ICS) and operational technology (OT) environments, including knowledge of various protocols, architectures, and components used in critical infrastructure sectors.
- Knowledge of relevant industry standards and frameworks, such as NCA, NIST Cybersecurity Framework, IEC 62443, and ISA/IEC 62451, and the ability to align security initiatives with these frameworks.
- Strong experience of implementing OT security control services.
- Strong customer relationship management skills.
Certification
- IEC 62443 Expert
Job Scope
• Eastern Region
Customers
Internal/External customers
Travel
Yes
Languages
• English, Arabic is plus.
رقم الإعلان لدى المصدر: 4472436284