📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

Help AG تعلن عن وظيفة محلل استخبارات التهديدات السيبرانية في الرياض

Cyber Threat Intelligence Analyst
🏢 Help AG
🕒 نُشرت: (منذ 9 أيام) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

Help AG، إحدى شركات e&، تبحث عن محلل استخبارات التهديدات السيبرانية (TIA) للعمل في الرياض. سيكون المحلل جزءاً من فريق الدفاع السيبراني، مسؤولاً عن جمع وتحليل ونشر الاستخبارات السيبرانية المؤثرة على الشركة أو عملائها. يتطلب الدور العمل خلال الأزمات والطوارئ والتي قد تستدعي ساعات عمل إضافية.

المهام والمسؤوليات

  • تحديد وجمع وتحليل البيانات الأولية والثانوية من مصادر متنوعة.
  • إنشاء وتحديث متطلبات الاستخبارات العامة (GIRs) ومتطلبات الاستخبارات ذات الأولوية (PIRs) ومتطلبات الاستخبارات الخاصة بالمؤسسة (OSIRs) للعملاء.
  • إنشاء ملفات تهديد ومشهد تهديدات للشركات أو العملاء.
  • إنشاء نماذج ماس (Diamond Models) حول العملاء والجهات الخصمة.
  • تحسين إنشاء وتوصيل المعلومات الاستخبارية للعملاء والشركاء عبر تقارير وأدوات متنوعة، وربط النقاط وإضافة قيمة للخدمة المقدمة.
  • إجراء تحقيقات على الإنترنت والويب المظلم في مواضيع مختلفة، من تحقيقات عامة إلى عمليات بحث محددة.
  • تحديد وتقييم وتتبع تكتيكات وتقنيات وإجراءات الجهات الفاعلة في التهديدات السيبرانية.
  • تقديم مراجعة وتحقق للتهديدات للعملاء حول تعرضهم لمخاطر وتهديدات الأمن السيبراني والتأثير المحتمل.
  • تقديم استخبارات سيبرانية استراتيجية وفنية وتكتيكية قابلة للتنفيذ للشركة وفروعها عبر تقارير أسبوعية وشهرية ومخصصة، بالإضافة إلى إحاطات وعروض تقديمية.
  • إجراء عمليات بحث على الإنترنت باللغتين الإنجليزية والعربية لتحليل التواجد الرقمي للعملاء وتحسين تغذية البيانات في أدوات تحليل وحصاد التهديدات.
  • تطبيق تقنيات بحث متقدمة (مثل العوامل المنطقية) في محركات البحث ومواقع التواصل وقواعد البيانات والويب المظلم لتقليل النتائج الإيجابية الكاذبة.
  • دعم العملاء في جهود إزالة المحتوى الاحتيالي أو المسيء أو المشبوه عبر الإنترنت.
  • الاطلاع المستمر على أدوات وتقنيات المهاجمين والتهديدات السيبرانية الإقليمية والدولية وسياقات الأعمال والسياسة لعكسها على التهديدات المكتشفة/المنشأة وتحسين التقارير.
  • تقديم تغذية راجعة وتوصيات لفرق الدفاع السيبراني الخلفية (مثل فريق MDR) لتعزيز قدرات الكشف وتحسين أداء البوابة وتجربة المستخدم.
  • فهم صناعات العملاء لتوليد كلمات مفتاحية بالعربية لدعم البحث عن المحتوى العربي عبر الإنترنت.
  • تحديد مصادر معلومات جديدة (بالإنجليزية والعربية) وكلمات بحث وممارسات أفضل لتحقيق كشف تهديد دقيق ومرتبط بالعميل.
  • عند طلب تحقيقات مخصصة من العملاء، المساعدة في تحديد نطاق التحقيق وموعد التسليم وعرض النتائج على العميل (تقرير).
  • فهم وإجراء تحليل الفرضيات المتنافسة (ACH) لاستخدامها في صيد التهديدات وإنتاج الاستشارات.
  • إدارة دورة حياة استخبارات التهديدات.
  • الحفاظ على مستوى عالٍ من الوعي بمشهد التهديدات الحالي.
  • المساعدة في تقديم تحليل التهديدات والثغرات وخدمات الاستشارات الأمنية.
  • المشاركة في تبادل المعرفة مع المحللين الآخرين وكتابة مقالات فنية لقواعد المعرفة الداخلية.
  • تنفيذ المهام بشكل مستقل مع بعض الإشراف.
  • تقديم خدمات استخبارات سيبرانية.
  • البحث وصياغة أوراق تحليلية وتقديم إحاطات استخبارية ضمن مواعيد قصيرة حول مواضيع جغرافية ووظيفية متنوعة.
  • استخدام المعرفة والإبداع وأفضل ممارسات الحرفة التحليلية لإيجاد حلول للمشكلات المعقدة.

الشروط والمتطلبات

  • درجة البكالوريوس في علوم الحاسب أو نظم المعلومات أو الهندسة الإلكترونية أو تخصص قريب الصلة.
  • خبرة سنة واحدة أو أكثر كمحلل استخبارات تهديدات أو في منصب مشابه.
  • اهتمام نشط وقابل للإثبات بكشف التهديدات السيبرانية واستخبارات التهديدات السيبرانية.
  • فهم شامل لأنظمة تكنولوجيا المعلومات ومفاهيم أمن الشبكات وبروتوكولات الشبكات.
  • فهم شامل للتهديدات السيبرانية والحروب، مثل هجمات خدمات الإنترنت وهجمات المستخدمين والهجمات المتقدمة المستمرة (APTs) والتطبيقات الضارة والاحتيال عبر الإنترنت والويب المظلم وأدوات وتقنيات القراصنة والنشطاء.
  • معرفة بأحدث الهجمات السيبرانية العالمية وبرامج الفدية البارزة ومجموعات الهجمات المتقدمة.
  • معرفة قابلة للإثبات حول إنشاء متطلبات الاستخبارات العامة (GIRs) وملفات التهديد ومشاهد التهديد.
  • معرفة قابلة للإثبات حول استخبارات التهديدات السيبرانية والجهات الفاعلة والبرمجيات الخبيثة والتكتيكات والتقنيات والإجراءات (TTPs) وتحليل التهديدات واستخدام نماذج الماس ومنهجيات وعمليات أمنية متنوعة.
  • معرفة قابلة للإثبات حول تحليل الفرضيات المتنافسة (ACH) لتقييم فرضيات متعددة للبيانات المرصودة.
  • معرفة عميقة بأفضل ممارسات أمن تكنولوجيا المعلومات وأنواع الهجمات الشائعة وطرق الكشف/المنع.
  • معرفة قابلة للإثبات حول الأمن التشغيلي السيبراني وتحليل السجلات وتحليل تدفق الشبكة والاستجابة للحوادث وتحليل البرمجيات الخبيثة والأدلة الرقمية والجرائم الإلكترونية.
  • معرفة قابلة للإثبات حول الويب العميق والمظلم.
  • فهم جيد لسلسلة القتل السيبراني أو نواقل الهجوم.
  • مهارات تواصل شفهية وكتابية ممتازة مع القدرة على شرح الأمور السيبرانية الفنية والاستراتيجية بوضوح لجماهير متنوعة.
  • القدرة على تعدد المهام وتحديد الأولويات وإدارة الوقت بفعالية.
  • اهتمام قوي بالتفاصيل.
  • مهارات شخصية ممتازة وأسلوب مهني.
  • مهارات ممتازة في خدمة العملاء.

المهارات المطلوبة

  • إجادة تقنيات البحث المتقدم واستخدام المصادر المفتوحة (OSINT).
  • القدرة على العمل تحت الضغط ضمن مواعيد قصيرة.
  • معرفة بالشهادات المهنية في تحليل الاستخبارات مثل GCTI، GOSI، C|TIA، Security+، RCIA، CTIP، CPTIA، CRTIA، CTIS-I، CTIS-II (تفضيل).
  • التمتع بالإبداع والتفكير التحليلي لحل المشكلات المعقدة.
  • مهارات البحث والكتابة التحليلية لإنتاج أوراق عمل وتقارير استخبارية.

المزايا

  • تأمين صحي مع أحد المزودين العالميين الرائدين للتأمين الطبي.
  • فرص التقدم والمسيرة المهنية من خلال المشاريع والعمل التحدي.
  • أنشطة وحملات المشاركة والرفاهية للموظفين على مدار العام.
  • فرص ممتازة للتعلم والتطوير.
  • بيئة عمل شاملة ومتنوعة.
  • بيئة عمل مرنة/مهجنة.
  • سياسة الباب المفتوح.
عرض النص الأصلي للإعلان
The Cyber Threat Intelligence Analyst (TIA) is a part of the Cyber Defense team, responsible to help collect, analyze, and disseminate cyber intelligence impacting the company or its customers. The ideal candidate will be a professional with experience in cyber intelligence/cyber risk, delivering equivalent services to organizations, with drive and creativity. This is a fantastic opportunity for a passionate professional that wants to evolve in the Cyber Intelligence world. The position will involve essential duties and responsibilities that must continue to be performed during crisis situations and contingency operations, which may necessitate extended hours of work.

  • Responsibilities
    • Identify, collect, and perform analysis of raw, primary, and secondary data derived from various sources.
    • Create and update General Intelligence Requirements (GIR)s, Priority Intelligence Requirements (PIR)s, and Organization Specific Intelligence Requirements (OSIR)s for customers.
    • Create threat profiles and threat landscapes for companies and or customers.
    • Create diamond models around customers and threat adversaries.
    • Improve the creation and delivery of intelligence information to customers and partners, via different reports and tools, linking the dots and adding value to the service delivered.
    • Perform investigations on the internet and dark web on different topics, from broad investigations to specific searches.
    • Identify, assess, and track tactics, techniques, and procedures of cyber threat actors.
    • Provide threat review and validation to customers on their exposure to cyber security risks, threats, and potential impact.
    • Provide actionable strategic, technical, and tactical cyber intelligence to company & its subsidiaries through weekly, monthly, and ad hoc reports, briefings, and presentations.
    • Conduct Internet searches, in English and Arabic, to profile customers' online presence and optimize data feeds into back end cyber threat harvesting and analysis solutions.
    • Apply advanced search techniques (e.g., Boolean terms) in Google/Bing search engines, social sites, domain databases, darknet, etc. to recue false positives.
    • Support customers in take down efforts to remove fraudulent, offensive, and suspicious online content.
    • Be up to date on knowledge of attacker tools/techniques, country and regional cyber threats, business, and political landscapes to reflect their context into detected/created threats to reduce false positives to help improve generated reports.
    • Provide feedback and recommendations to Backend Cyber defense teams such as the MDR Team to enhance detection's (e.g., false positives, generic data, fine-tuning, updated info, etc.) and improve portal performance and/or experience.
    • Understand customer industries to generated Arabic keywords to support searches of online Arabic content.
    • Identify new information sources (English and Arabic), search keywords (English and Arabic) and best practices to achieve more accurate and customer related threat detection.
    • When customers request ad-hoc investigations, assist in defining the investigation scope, delivery date and present the findings to the customer (report).
    • Understand and perform analysis of competing hypotheses (ACH) for use in threat hunting and advisory production.
    • Manage the life cycle of threat intelligence.
    • Maintain a high degree of awareness of the current threat landscape.
    • Assist in providing threat and vulnerability analysis as well as security advisory services.
    • Participate in knowledge sharing with other Analysts and writing technical articles for Internal Knowledge Bases.
    • Perform tasks independently with some oversight.
    • Deliver Cyber Intelligence services.
    • Research and craft analytic papers and deliver intelligence briefings under short deadlines on various geographical and functional topics.
    • Use knowledge, creativity, and analytic tradecraft best practices to obtain solutions to complex problem.
  • Qualifications & Skills
    • A Degree in Computer Science, Information Systems, Electronics Engineering, or a closely related degree.
    • 1+ years' experience as a TIA or related position.
    • An active, demonstrable interest in cyber threat detection, and cyber threat intelligence.
    • A thorough understanding of IT systems and network security concepts, network protocols.
    • Thorough understanding of cyber threats and warfare such as Internet services attacks, User attacks, APTs, malicious mobile apps, online fraud, dark-net, hackers' tools/techniques, hacktivist, etc.
    • Knowledge of latest global cyber-attacks, prominent ransomware, APT groups.
    • Demonstrable knowledge around GIR creations and threat profiling/landscaping
    • Demonstrable knowledge of cyber threat intelligence, threat actors, malware, tactics, techniques, and procedures (TTPs), intelligence analysis, use of diamond models and various security methodologies and processes.
    • Demonstrable knowledge analysis of competing hypotheses (ACH) for evaluating multiple competing hypotheses for observed data.
    • Deep knowledge of IT security best practices, common attack types, and detection/prevention methods.
    • Demonstrable knowledge of cyber operational security, log analysis, netflow analysis, incident response, malware analysis, computer forensics, and/or cybercrime.
    • Demonstrable knowledge on deep and dark web.
    • Good understanding of the cyber kill chain or attack vectors.
    • Excellent verbal and written communication skills including the ability to clearly articulate technical and strategic level cyber matters to a variety of audiences.
    • Ability to multitask, prioritize, and manage time effectively.
    • Strong attention to detail.
    • Excellent interpersonal skills and professional demeaner.
    • Excellent customer service skills.
    • Formal Intelligence Analysis training & certifications like GCTI, GOSI, C|TIA , Security+, RCIA, CTIP , CPTIA, CRTIA, CTIS-I and or CTIS-II.
  • Benefits
    • Health insurance with one of the leading global providers for medical insurance.
    • Career progression and growth through challenging projects and work.
    • Employee engagement and wellness campaigns activities throughout the year.
    • Excellent learning and development opportunities.
    • Inclusive and diverse working environment.
    • Flexible/Hybrid working environment.
    • Open door policy.
    • About Us

    Help AG, an e& company, is the Middle East's trusted cybersecurity partner enabling governments,

    enterprises and critical industries to innovate with confidence. Combining strategic consulting,

    advanced managed security services and deep technology expertise, Help AG enables organisations

    to strengthen cyber resilience, secure AI adoption, and build trusted sovereign digital environments.

    With more than 20 years of regional expertise, a team of over 600 cybersecurity specialists and more

    than 500 enterprise and government customers, Help AG combines deep local knowledge with

    World-class Capabilities. The Company Operates State-of-the-art, AI-powered Sovereign Security

    Operations Centres (SOCs) in Dubai and Riyadh. To date, these centres have processed more than

    32 trillion security events.

    Recognised as a Leader in the IDC MarketScape for Managed Security Services (2026) and Managed

    Detection and Response (2025), and awarded the Dubai AI Seal certification, Help AG continues to

    help organisations strengthen cyber resilience, adopt AI with confidence, and build trusted, digital

    futures across the Middle East.
    المصدر: LinkedIn - أُضيفت للموقع في 30 سبتمبر 2026
    رقم الإعلان لدى المصدر: 4473748938