📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

Novelus تعلن عن وظيفة مهندس عمليات أمن سيبراني في مكة جدة السعودية

Cybersecurity Operations Engineer
🏢 Novelus
🕒 نُشرت: (منذ 8 أيام) 📍 جدة وظائف الهندسة والتقنية

تفاصيل الوظيفة

شركة Novelus، فريق مبتكر يركز على تسريع نشر التكنولوجيا، تبحث عن مهندس عمليات أمن سيبراني للعمل في مكة وجدة، السعودية.

نبذة عن الوظيفة

فريق Novelus هو مجموعة من المبتكرين الذين يركزون بشكل كبير على تسريع نشر التكنولوجيا. نقدم بيئة عمل ودية وتعاونية وفرصًا للنمو الشخصي والمهني والتعرض لمشاريع ديناميكية وأحدث التقنيات. نحن نبحث عن شخص يقوم بتشغيل ضوابط الأمان المعتمدة، وتحديد أحداث الأمان وفرزها، وتنسيق الاستجابة والمعالجة، والحفاظ على أدلة الامتثال لمتطلبات الأمان المعتمدة من الشركة.

المهام والمسؤوليات

  • مراجعة تنبيهات EDR ومراقبة الأمان المعينة، والتحقق من النشاط المشبوه، والتحقيق في المستخدمين أو الأجهزة المتأثرة، وتصعيد الحوادث وفقًا لعملية الخطورة والاستجابة المتفق عليها.
  • إدارة سياسات وضوابط نقاط النهاية المعتمدة. تنفيذ إجراءات الاحتواء ضمن السلطة المفوضة والحصول على الموافقة المطلوبة للتغييرات التخريبية أو غير القابلة للعكس.
  • مراجعة تكوينات أمان المحيط والتغييرات المقترحة مع فريق البنية التحتية. تحديد القواعد الضعيفة، وثغرات الوصول، وفجوات التكوين للمعالجة المصرح بها.
  • تشغيل تقييمات الثغرات المعتمدة ضمن الأصول والنوافذ المتفق عليها. التحقق من النتائج، وترتيب أولوياتها حسب التعرض والتأثير التجاري، وتعيين المالكين، والتحقق من المعالجة.
  • دعم مراجعات الوصول المميز، وفحوصات خط الأساس الأمني، وأدلة الامتثال. الحفاظ على سجل الاستثناءات والإبلاغ عن المخاطر غير المعالجة إلى المالك المعين.
  • المساعدة في تقييمات فجوات الأمان، وتقييمات المخاطر، وتنفيذ الضوابط، وتحديث السياسات ضمن نطاق تكنولوجيا المعلومات المتفق عليه.
  • الحفاظ على أدلة التدقيق، ودعم عمليات التدقيق الداخلية والخارجية، وتتبع الإجراءات التصحيحية حتى الإغلاق.

الشروط والمتطلبات

  • خبرة 3-5 سنوات في عمليات الأمان، تتضمن خبرة عملية في أمان نقاط النهاية، ومعالجة الحوادث، وتقييم الثغرات، وتنسيق المعالجة. يفضل خبرة في حماية المستخدمين المؤسسيين والخوادم والشبكات.
  • شهادة Microsoft Certified Security Operations Analyst Associate (SC-200) ذات صلة عند استخدام أدوات أمان Microsoft.
  • تدريب عملي على EDR، SIEM، وجدار الحماية الخاص بالبائع، وتحليل الثغرات، وتمارين الاستجابة للحوادث.
  • إضافة تعلم حوكمة الأمان مع توسع المسؤوليات.

المهارات المطلوبة

  • معرفة عملية بـ EDR، SIEM، وجدار الحماية؛ أساسيات أمان Windows وLinux؛ التحقيق في الحوادث؛ تفسير الثغرات؛ والمعالجة القائمة على المخاطر.
  • معرفة عملية بـ ISO/IEC 27001، نظم إدارة أمن المعلومات (ISMS)، وممارسات الحوكمة والمخاطر والامتثال (GRC) بما في ذلك تقييمات المخاطر، ضوابط الأمان، مراجعات الامتثال، إعداد أدلة التدقيق، إدارة السياسات والإجراءات، تحديد فجوات الضوابط، تتبع الإجراءات التصحيحية، ودعم شهادات ISO 27001 وعمليات تدقيق المراقبة.
  • تقارير فنية واضحة، التعامل مع الأدلة، الحفاظ على سجل المخاطر، والتعاون مع فرق البنية التحتية والتطبيقات والامتثال والتدقيق.

المزايا

  • بيئة عمل ودية وتعاونية.
  • فرص نمو شخصي ومهني.
  • التعرض لمشاريع ديناميكية وأحدث التقنيات.
عرض النص الأصلي للإعلان

Who We Are:

Novelus Team is a group of innovative people, excessively focused on accelerating technology deployment. Our most important asset is our employees, which is why we focus on providing a progressive, vibrant and empowering culture.


Why Novelus:

This is a great opportunity to be part of a company with record growth. Novelus employees enjoy a comprehensive set of benefits, including but not limited to:

  • Friendly and collaborative work environment
  • Personal and professional growth opportunities
  • Exposure to dynamic projects and the latest technologies


Who We're Looking For:

  • Operate the accepted security controls, identify and triage security events, coordinate response and remediation, and maintain evidence of compliance with Company-approved security requirements.


What You’ll Do:

  • Review assigned EDR and security-monitoring alerts, validate suspicious activity, investigate affected users or devices, and escalate incidents under the agreed severity and response process.
  • Administer approved endpoint policies and controls. Perform containment actions within delegated authority and obtain required approval for disruptive or irreversible changes.
  • Review perimeter security configurations and proposed changes with the infrastructure team. Identify weak rules, access exposures and configuration gaps for authorised remediation.
  • Run approved vulnerability assessments within agreed assets and windows. Validate findings, prioritise them by exposure and business impact, assign owners and verify remediation.
  • Support privileged-access reviews, security baseline checks and compliance evidence. Maintain an exception register and report unresolved risks to the designated owner.
  • Assist with security gap assessments, risk assessments, control implementation and policy updates within the agreed IT scope.
  • Maintain audit evidence, support internal and external audits, and track corrective actions to closure


What You’ll Need:

  • 3-5 years in security operations, including hands-on endpoint security, incident handling, vulnerability assessment and remediation coordination. Experience protecting enterprise users, servers and networks is preferred. Prioritise deployed EDR, SIEM and firewall vendor training, vulnerability analysis and incident-response exercises. Microsoft Certified Security Operations Analyst Associate, associated with SC-200 [4], is relevant when Microsoft security tools are used. Add security governance learning as responsibilities expand.
  • Practical EDR, SIEM and firewall knowledge; Windows and Linux security fundamentals; incident investigation; vulnerability interpretation; and risk-based remediation. Working knowledge of ISO/IEC 27001, Information Security Management Systems (ISMS), and Governance, Risk and Compliance (GRC) practices, including risk assessments, security controls, compliance reviews, audit evidence preparation, policy and procedure management, control-gap identification, corrective-action tracking, and support for ISO 27001 certification and surveillance audits. Clear technical reporting, evidence handling, risk-register maintenance, and collaboration with infrastructure, application, compliance and audit teams are essential.
المصدر: LinkedIn - أُضيفت للموقع في 1 أكتوبر 2026
رقم الإعلان لدى المصدر: 4474332286