تفاصيل الوظيفة
بنك D360 يعلن عن وظيفة مهندس تشفير (Cryptography Engineer) في الرياض، المملكة العربية السعودية. يتولى هذا الدور دعم تصميم وتنفيذ وإدارة العمليات اليومية لإدارة المفاتيح التشفيرية، وضمان أمن الأنظمة التشفيرية وفقًا للمعايير ومتطلبات الأمان التنظيمية.
المهام والمسؤوليات
- إدارة وصيانة أنظمة إدارة المفاتيح (مثل HSMs، خزائن المفاتيح، cloud KMS).
- دعم تنفيذ استراتيجية إدارة المفاتيح على مستوى المؤسسة.
- اتباع السياسات والإجراءات الخاصة بدورة حياة المفتاح التشفيري (التوليد، التخزين، التدوير، الإلغاء).
- ضمان دمج خدمات التشفير والتوقيع بشكل صحيح مع التطبيقات والبنية التحتية.
- ضمان الامتثال من خلال إعداد التوثيق والمساعدة في عمليات التدقيق والمراجعة.
- حفظ سجلات التهيئات والعمليات وأنشطة إدارة المفاتيح.
- مراقبة أنظمة إدارة المفاتيح والإبلاغ عن أي حالات شاذة أو مشكلات.
- المساعدة في التحقيق في الحوادث المتعلقة بالمفاتيح وحلها.
- المشاركة في المراجعات الدورية لاستخدام المفاتيح وتقييمات المخاطر.
- العمل مع فرق الهندسة و DevOps والبنية التحتية لدعم تنفيذ الضوابط التشفيرية.
- اتباع الإرشادات المتعلقة بالخوارزميات الآمنة وأفضل الممارسات عند تنفيذ الحلول التشفيرية.
- المساعدة في تعزيز الوعي بممارسات إدارة المفاتيح والتشفير داخل الفريق.
- تنفيذ المهام المسندة المتعلقة بالعمليات التشفيرية والضوابط الأمنية.
- أداء أي مهام أخرى يكلف بها المشرف المباشر ضمن طبيعة العمل.
- فرض ودمج والامتثال لجميع الضوابط الضرورية وسياسات وإجراءات وممارسات أمن المعلومات ذات الصلة، بالإضافة إلى التدريب والإبلاغ والعناية الواجبة واليقظة الشخصية ضمن أنشطة وعمليات القسم/الوحدة.
الشروط والمتطلبات
- مؤهل جامعي من مؤسسة معترف بها دوليًا.
- شهادات مهنية معترف بها في المجال مثل CISSP، CISM، CKA، CCSP أو ما يعادلها.
- خبرة من 3 إلى 5 سنوات في علوم الحاسب، أمن المعلومات، الهندسة، أو مجال ذي صلة.
- خبرة مثبتة كقائد لإدارة المفاتيح التشفيرية أو مدير أمن أو مهندس أمن مع تركيز على التشفير/دورة حياة المفاتيح.
- معرفة قوية بمبادئ التشفير والخوارزميات مثل AES، RSA، ECC وغيرها، والتخزين الآمن للمفاتيح.
- خبرة عملية مع HSMs، PKI، خزائن المفاتيح، خدمات إدارة المفاتيح السحابية، وأدوات التشفير.
- الإلمام بمعايير الأمان ومتطلبات الامتثال مثل NIST، ISO، PCI-DSS، FIPS.
- خبرة في قيادة الفرق التقنية وتقديم حلول آمنة على نطاق واسع.
- مهارات ممتازة في التواصل وإدارة أصحاب المصلحة.
المهارات المطلوبة
- التشفير وإدارة المفاتيح (Cryptography & Key Management)
- هندسة الأمن (Security Architecture)
- الاستجابة للحوادث (Incident Response)
- إدارة المخاطر (Risk Management)
- التفكير التحليلي (Analytical Thinking)
- الاستدلال المعقد (Complex Reasoning)
- التواصل (Communication)
- الثقة والشفافية (Trust & Transparency)
عرض النص الأصلي للإعلان
The role is responsible to Support the design, implementation, and daily operations of cryptographic key management processes. Assist in ensuring keys and cryptographic systems are securely maintained, compliant with standards, and aligned with organizational security requirements
- Manage and maintain key management systems (e.g., HSMs, key vaults, cloud KMS).
- Support the implementation of the enterprise key management strategy.
- Follow policies and procedures for the cryptographic key lifecycle (generation, storage, rotation, and revocation).
- Ensure encryption and signing services are properly integrated with applications and infrastructure.
- Ensure activities are compliance by preparing documentation and assisting in audits and reviews.
- Maintain records of configurations, processes, and key management activities.
- Monitor key management systems and report any anomalies or issues.
- Assist in investigating and resolving key-related incidents.
- Participate in periodic key usage reviews and risk assessments.
- Work with engineering, DevOps, and infrastructure teams to support implementation of cryptographic controls.
- Follow guidance on secure algorithms and best practices when implementing cryptographic solutions.
- Help promote awareness of key management and cryptography practices within the team.
- Carry out assigned tasks related to cryptographic operations and security controls.
- Perform any other duties assigned to by line manager related to the nature of the work.
- Enforce, incorporate, and comply with all necessary controls and related information security policies, procedures, practices, training, reporting, personal due diligence, and vigilance, within departmental/unit activities and operations.
Preferred Qualifications
- A tertiary-level qualification from an internationally recognized institution
- Industry-recognized certifications such as CISSP, CISM, CKA, CCSP, or equivalent.
Years & Nature of Experience
- Recommended 3 to 5 years of equivalent experience in Computer Science, Information Security, Engineering, or a related field.
- Proven experience as a Cryptographic Key Management lead, Security Manager, or Security Architect with a focus on encryption/key lifecycle.
- Strong knowledge of cryptographic principles, algorithms (AES, RSA, ECC, etc.), and secure key storage.
- Hands‑on experience with HSMs, PKI, key vaults, cloud key management services, and encryption tooling.
- Familiarity with security standards and compliance requirements (e.g., NIST, ISO, PCI‑DSS, FIPS).
- Experience leading technical teams and delivering secure solutions at scale.
- Excellent communication and stakeholder management skills.
Technical Competencies
- Cryptography & Key Management
- Security Architecture
- Incident Response
- Risk Management
Behavioural Competencies
- Analytical Thinking
- Complex Reasoning
- Communication
- Trust & Transparency
رقم الإعلان لدى المصدر: 90544