طيران ناس تعلن عن وظيفة أخصائي مخاطر الأمن السيبراني في الرياض
تفاصيل الوظيفة
طيران ناس تعلن عن وظيفة متخصص مخاطر الأمن السيبراني في الرياض، حيث يتولى شاغلها مسؤولية إجراء ودعم تحديد وتقييم وتحليل ومعالجة ومراقبة والإبلاغ عن مخاطر الأمن السيبراني عبر بيئة التقنية والأنظمة والمشاريع والأطراف الثالثة والعمليات التشغيلية، بما يتوافق مع متطلبات الهيئة الوطنية للأمن السيبراني (NCA) وأطر إدارة المخاطر المعتمدة.
المهام والمسؤوليات
- تحديد وتقييم وتحليل وتقييم ومراقبة مخاطر الأمن السيبراني عبر أنظمة المنظمة وتطبيقاتها وبنيتها التحتية ومشاريعها وأطرافها الثالثة وعملياتها التجارية.
- تقديم التوجيه بشأن مخاطر الأمن السيبراني لأصحاب المصلحة الداخليين ودعم اتخاذ القرارات المستندة إلى المخاطر فيما يتعلق بالأنظمة والمشاريع والتغييرات التقنية والتعاقدات مع الأطراف الثالثة.
- مراقبة ملف مخاطر الأمن السيبراني والتعرض للمخاطر الناشئة، ودعم التصعيد والإبلاغ الفوري عن المخاطر الكبيرة إلى الإدارة ومنتديات الحوكمة المعنية.
- دعم مواءمة أنشطة إدارة مخاطر الأمن السيبراني مع متطلبات الهيئة الوطنية للأمن السيبراني (NCA) وعمليات إدارة المخاطر المؤسسية (ERM) وأطر إدارة المخاطر السيبرانية المعترف بها.
- تحديد التهديدات السيبرانية ونقاط الضعف وسيناريوهات التهديد المحتملة والأصول المتأثرة والضوابط الحالية والآثار التجارية المحتملة كجزء من تقييمات مخاطر الأمن السيبراني.
- مراجعة الأدلة المقدمة لأنشطة معالجة المخاطر المنفذة وإعادة تقييم المخاطر المتبقية عند الاقتضاء.
- الصيانة المستمرة لسجل مخاطر الأمن السيبراني بما في ذلك تصنيفات المخاطر وملكيتها وقرارات المعالجة وخطط العمل والتواريخ المستهدفة وتواريخ المراجعة والحالة الحالية.
- دعم تقييمات مخاطر الأمن السيبراني للأطراف الثالثة وتقييم المخاطر المرتبطة بالموردين ومقدمي الخدمات ومزودي الخدمات السحابية وغيرهم من الأطراف الخارجية.
- دعم تقييمات مخاطر الأمن السيبراني أثناء بدء المشاريع وتصميم الحلول والمشتريات والتنفيذ والتغييرات التقنية الكبرى لتحديد المخاطر قبل النشر في الإنتاج.
- التنسيق مع إدارات إدارة الثغرات والاستخبارات الأمنية وإدارة الحوادث والامتثال وغيرها من وظائف الأمن السيبراني لدمج النتائج والمعلومات ذات الصلة في تقييمات المخاطر.
- دعم تطوير وتحسين منهجية إدارة مخاطر الأمن السيبراني ومعايير المخاطر وقوالب التقييم وتصنيف المخاطر والعمليات المساندة.
- تطوير وصيانة مؤشرات المخاطر الرئيسية (KRIs) للأمن السيبراني ومراقبة الاتجاهات التي قد تشير إلى تغيرات في تعرض المنظمة لمخاطر الأمن السيبراني.
- تقديم تقرير سلامة عند التعرض لأي خطر أو مشكلة تتعلق بالسلامة.
- فهم والامتثال لتدابير السلامة الواردة في هذا الدليل أو منشورات السلامة.
- الإبلاغ الفوري للمشرف المختص عن جميع مخاطر السلامة والحوادث والإصابات والأضرار.
عرض النص الأصلي للإعلان
Job Purpose
Responsible for conducting and supporting the identification, assessment, analysis, treatment, monitoring, and reporting of cybersecurity risks across the organization’s technology environment, systems, projects, third parties, and business operations. The role maintains cybersecurity risk records, coordinates risk treatment activities with relevant risk and control owners, monitors residual and accepted risks, and supports informed risk-based decision making in alignment with applicable National Cybersecurity Authority (NCA) requirements, organizational policies, and recognized cybersecurity risk management frameworks.
Key Accountabilities
• Identify, assess, analyze, evaluate, and monitor cybersecurity risks across the organization’s systems, applications, infrastructure, projects, third parties, and business processes.
• Provide cybersecurity risk guidance to internal stakeholders and support risk based decision-making for systems, projects, technology changes, and third party engagements.
• Monitor the cybersecurity risk profile and emerging risk exposure and support timely escalation and reporting of significant cybersecurity risks to relevant management and governance forums.
• Support alignment of cybersecurity risk management activities with applicable National Cybersecurity Authority (NCA) requirements, organizational Enterprise Risk Management (ERM) processes, and recognized cybersecurity risk management frameworks.
Operational Responsibilities
• Identify relevant cyber threats, vulnerabilities, potential threat scenarios, affected assets, existing controls, and potential business impacts as part of cybersecurity risk assessments.
• Review supporting evidence submitted for completed risk treatment activities and reassess residual risk where applicable.
• Maintain the cybersecurity risk register, including risk ratings, ownership, treatment decisions, action plans, target dates, review dates, and current status.
• Support cybersecurity third-party risk assessments and evaluate cybersecurity risks associated with vendors, service providers, cloud providers, and other external parties.
• Support cybersecurity risk assessments during project initiation, solution design, procurement, implementation, and significant technology changes to identify risks before production deployment.
• Coordinate with vulnerability management, threat intelligence, incident management, compliance, and other cybersecurity functions to incorporate relevant findings and threat information into cybersecurity risk assessments.
• Support the development and continuous improvement of the cybersecurity risk management methodology, risk criteria, assessment templates, risk taxonomy, and supporting processes.
• Develop and maintain cybersecurity Key Risk Indicators (KRIs) and monitor trends that may indicate changes in the organization’s cybersecurity risk exposure.
Safety & Security
• Responsible to submit a safety report if exposed to any safety hazard or issue.
• Understanding and complying with safety precautions contained in this manual and/or safety publications.
• Immediately reporting to the concerned supervisor all safety hazards, accidents/incidents, injuries and damage.
رقم الإعلان لدى المصدر: 4470843476