وظيفة أخصائي إدارة حوادث الأمن السيبراني شاغرة لدى طيران ناس في الرياض
تفاصيل الوظيفة
يسعى طيران ناس عبر إدارة أمن المعلومات إلى تعيين أخصائي إدارة حوادث الأمن السيبراني (Cybersecurity Incident Management Specialist) في الرياض، السعودية.
نبذة عن الوظيفة
يتولى هذا الدور مسؤولية تنسيق وإدارة دورة حياة الاستجابة لحوادث الأمن السيبراني من البداية إلى النهاية، بما في ذلك تقييم الحادث وتصنيفه والتحقيق فيه والتصعيد والاحتواء والاستئصال والتعافي والإغلاق. يعمل المنسق مع أصحاب المصلحة الداخليين ومقدمي خدمات الأمن السيبراني والأطراف الثالثة ذات الصلة لضمان استجابة فعّالة وفي الوقت المناسب للحوادث، مع الحفاظ على سجلات دقيقة للحوادث، ودعم متطلبات الإبلاغ التنظيمية المطبقة، وتتبع الإجراءات التصحيحية، والمساهمة في الدروس المستفادة والتحسين المستمر لقدرات الاستجابة للحوادث.
المهام والمسؤوليات
- استلام وتقييم حوادث الأمن السيبراني المحتملة التي يتم التصعيد إليها عبر قدرات المراقبة الأمنية أو مركز عمليات الأمن (SOC/MSSP) أو الموظفين أو الأطراف الثالثة أو أي قنوات إبلاغ معتمدة أخرى.
- التحقق من صحة حوادث الأمن السيبراني وتصنيفها وتحديد أولوياتها وإدارتها وفقًا لمعايير التصنيف المعتمدة ومستويات الخطورة وتأثير الأعمال ومتطلبات التصعيد.
- تنسيق أنشطة الاستجابة لحوادث الأمن السيبراني من البداية إلى النهاية، بما في ذلك التحقيق والاحتواء والاستئصال والتعافي والإغلاق، مع الفرق الداخلية ذات الصلة ومقدمي الخدمات والأطراف الثالثة.
- التنسيق مع مركز عمليات الأمن (SOC/MSSP) وفرق الأمن السيبراني ذات الصلة للحصول على التحليل الفني المطلوب ومؤشرات الاختراق (IOCs) ومعلومات التهديدات والسجلات والمعلومات الأخرى الضرورية للتحقيق في الحوادث والاستجابة لها.
- تصعيد حوادث الأمن السيبراني الحرجة وذات الخطورة العالية وفقًا لمصفوفة التصعيد المعتمدة وضمان التواصل في الوقت المناسب مع الإدارة وأصحاب المصلحة المعنيين.
- التنسيق مع تقنية المعلومات وأصحاب الأنظمة ووحدات الأعمال والشؤون القانونية وحماية البيانات واستمرارية الأعمال والاتصالات والموارد البشرية والوظائف الأخرى ذات الصلة بناءً على طبيعة الحادث وتأثيره.
- الحفاظ على سجلات كاملة ودقيقة للحوادث، بما في ذلك التصنيف والتأثير وأنشطة التحقيق والقرارات والإجراءات المتخذة والأدلة والاتصالات والجداول الزمنية وتفاصيل الحل.
- ضمان الحفظ المناسب والتعامل مع الأدلة المتعلقة بالحادث ودعم أنشطة الطب الشرعي الرقمي عند الحاجة.
- دعم تقييم حوادث الأمن السيبراني مقابل متطلبات الإبلاغ والإخطار التنظيمية للهيئة الوطنية للأمن السيبراني (NCA) وغيرها، والتنسيق لإعداد معلومات الحادث المطلوبة والتقديمات التنظيمية.
- إجراء وتنسيق مراجعات ما بعد الحادث وتحليل السبب الجذري (RCA) لحوادث الأمن السيبراني ذات الصلة.
- تحديد الإجراءات التصحيحية والوقائية الناشئة عن الحوادث وتحليل السبب الجذري والدروس المستفادة، وتعيينها لأصحابها المعنيين، وتتبع تنفيذها حتى الإغلاق.
- التحقق من اكتمال أنشطة الاسترداد والمعالجة المتفق عليها قبل التوصية بإغلاق الحادث.
- الحفاظ على إجراءات الاستجابة لحوادث الأمن السيبراني وقوائم التشغيل وقوائم الاتصال ومصفوفات التصعيد والوثائق الداعمة الأخرى ومراجعتها دوريًا.
- المشاركة في تمارين ومحاكاة الاستجابة لحوادث الأمن السيبراني وتوثيق الفجوات وإجراءات التحسين المحددة.
- مراقبة أداء الاستجابة للحوادث مقابل اتفاقيات مستوى الخدمة (SLAs) ومؤشرات الأداء الرئيسية (KPIs) ومقاييس الأداء الأخرى، وإعداد تقارير ولوحات معلومات دورية لإدارة الحوادث.
- تحديد أنماط الحوادث المتكررة والأصول المتأثرة وناقلات الهجوم ونقاط الضعف في التحكم والاتجاهات الأخرى لدعم التحسين المستمر لضوابط الأمن السيبراني.
- دعم التنسيق مع مقدمي خدمات الاستجابة للحوادث الخارجية والطب الشرعي الرقمي واستخبارات التهديدات وغيرهم من مقدمي الخدمات المتخصصة عند الحاجة.
عرض النص الأصلي للإعلان
Job Purpose
Responsible for coordinating and managing the end-to-end cybersecurity incident response lifecycle, including incident assessment, classification, investigation, escalation, containment, eradication, recovery, and closure. The role coordinates with internal stakeholders, cybersecurity service providers, and relevant third parties to ensure timely and effective response to cybersecurity incidents, while maintaining accurate incident records, supporting applicable regulatory reporting requirements, tracking corrective actions, and contributing to lessons learned and continuous improvement of cybersecurity incident response capabilities.
Operational Responsibilities
• Receive and assess potential cybersecurity incidents escalated through cybersecurity monitoring capabilities, the SOC/MSSP, employees, third parties, or other authorized reporting channels.
• Validate, classify, prioritize, and manage cybersecurity incidents according to approved incident classification criteria, severity levels, business impact, and escalation requirements.
• Coordinate end-to-end cybersecurity incident response activities, including investigation, containment, eradication, recovery, and closure, with relevant internal teams, service providers, and third parties.
• Coordinate with the SOC/MSSP and relevant cybersecurity teams to obtain required technical analysis, indicators of compromise (IOCs), threat intelligence, logs, and other information necessary for incident investigation and response.
• Escalate critical and high-severity cybersecurity incidents according to the approved escalation matrix and ensure timely communication with relevant management and stakeholders.
• Coordinate with IT, system owners, business units, Legal, Data Protection, Business Continuity, Communications, Human Resources, and other relevant functions based on the nature and impact of the incident.
• Maintain complete and accurate incident records, including classification, impact, investigation activities, decisions, actions taken, evidence, communications, timelines, and resolution details.
• Ensure appropriate preservation and handling of incident-related evidence and support digital forensic activities when required.
• Support assessment of cybersecurity incidents against applicable NCA and other regulatory reporting and notification requirements, and coordinate the preparation of required incident information and regulatory submissions.
• Conduct and coordinate post-incident reviews and Root Cause Analysis (RCA) for applicable cybersecurity incidents.
• Identify corrective and preventive actions arising from incidents, root cause analyses, and lessons learned, assign them to relevant owners, and track their implementation through closure.
• Validate that agreed recovery and remediation activities have been completed before recommending incident closure.
• Maintain and periodically review cybersecurity incident response procedures, playbooks, contact lists, escalation matrices, and supporting documentation.
• Participate in cybersecurity incident response exercises and simulations and document identified gaps and improvement actions.
• Monitor incident response performance against defined SLAs, KPIs, and other performance measures and prepare periodic incident management reports and dashboards.
• Identify recurring incident patterns, affected assets, attack vectors, control weaknesses, and other trends to support continuous improvement of cybersecurity controls.
• Support coordination with external incident response, digital forensics, threat intelligence, and other specialized service providers when required.
رقم الإعلان لدى المصدر: 4470841532