وظيفة مهندس أمن سيبراني (Staff Engineer - Cyber Security) لدى رسن بالرياض
تفاصيل الوظيفة
رسن في الرياض، المملكة العربية السعودية، تبحث عن مهندس أول - الأمن السيبراني للانضمام إلى فريقها. يقدم هذا الدور الدعم التنسيقي والحوكمة والإشراف عبر وظائف الأمن السيبراني في المؤسسة، ويعمل كحلقة وصل رئيسية بين القيادة والفرق الفنية وأصحاب المصلحة، لضمان تتبع ومراقبة وإبلاغ المبادرات الأمنية وإدارة المخاطر ومتطلبات الامتثال والضوابط التشغيلية بفعالية.
المهام والمسؤوليات
- متابعة الفرق الفنية في أنشطة العمليات الأمنية والحوادث والثغرات وتقدم الإصلاح.
- مراقبة تنفيذ خطط العمل الأمنية وتتبع الإنجاز وفق الجداول الزمنية المتفق عليها.
- دعم نشر وتشغيل ومراقبة فعالية تقنيات الأمن السيبراني مثل SIEM وEDR وIAM وPAM وDLP وWAF.
- تتبع تنفيذ الضوابط الأمنية وتحديد التأخيرات أو المخاطر أو المشكلات التشغيلية التي تتطلب انتباه الإدارة.
- رفع القضايا غير المحلولة وفجوات الضوابط وتأخيرات الإصلاح إلى قيادة الأمن السيبراني.
- دعم تطوير ومراجعة وصيانة سياسات الأمن السيبراني وإجراءاته ومعاييره ووثائقه ذات الصلة.
- المساعدة في تقييمات الامتثال للأمن السيبراني ومراجعاته وفق الأطر والمعايير المطبقة.
- دعم تنفيذ ومراقبة الضوابط الداخلية ومتطلبات الحوكمة.
- الحفاظ على سجلات مخاطر الأمن السيبراني وخطط العمل وسجلات تتبع الإصلاح وتحديثها.
- مراقبة الأنشطة المتعلقة بالامتثال وضمان تتبع الفجوات المحددة حتى الحل.
- دعم المراجعات الداخلية والخارجية للأمن السيبراني والتقييمات والمراجعات التنظيمية.
- تنسيق جمع الأدلة وإعداد الوثائق وردود أصحاب المصلحة لأنشطة المراجعة.
- تتبع نتائج المراجعة والتوصيات وخطط العمل التصحيحية لضمان الإغلاق في الوقت المناسب.
- الحفاظ على سجلات المراجعة وضمان دقة الوثائق الداعمة ويسر الوصول إليها.
- مساعدة الإدارة في مراقبة حالة مبادرات الامتثال والضمان.
- إعداد لوحات معلومات وتقارير ومؤشرات أداء رئيسية وعروض تقديمية للإدارة.
- التنسيق مع فرق تقنية المعلومات ووحدات الأعمال والموردين والاستشاريين ومقدمي الخدمات الخارجية في الأمور المتعلقة بالأمن السيبراني.
- تسهيل التواصل بين قيادة الأمن السيبراني والفرق التشغيلية لضمان التوافق على الأولويات والتسليمات.
- دعم التقارير الإدارية حول مخاطر الأمن السيبراني وحالة الامتثال والحوادث ومبادرات التحسين.
- ضمان صيانة ومراجعة دورية لوثائق الأمن السيبراني والسجلات والتحف الحوكمية.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو تقنية المعلومات أو مجال ذي صلة.
- شهادة CompTIA Security+.
- شهادة ISO 27001 Foundation أو Lead Implementer.
- شهادة CRISC (معتمدة في مخاطر وأنظمة التحكم في المعلومات) - مفضلة.
- خبرة عملية سابقة 4+ سنوات في الأمن السيبراني أو أمن المعلومات أو مجالات ذات صلة.
- خبرة في حوكمة الأمن السيبراني أو الامتثال أو إدارة المخاطر أو تنسيق المراجعة أو أدوار دعم العمليات الأمنية.
- خبرة في العمل مع أطر الأمن السيبراني والمتطلبات التنظيمية وأنشطة مراقبة الضوابط - مفضلة.
المهارات المطلوبة
- فهم جيد لمبادئ الأمن السيبراني والضوابط وإدارة المخاطر وممارسات الحوكمة.
- معرفة بأطر الأمن السيبراني ومتطلبات الامتثال والمعايير الصناعية.
- مهارات قوية في التنسيق وإعداد التقارير والتوثيق وإدارة أصحاب المصلحة.
- قدرة على فهم وإيصال الأمور الفنية للأمن السيبراني على مستوى الأعمال والإدارة.
- مهارات تحليلية وتنظيمية ومتابعة قوية مع الاهتمام بالتفاصيل.
- إتقان إعداد التقارير ولوحات المعلومات والعروض التقديمية وآليات التتبع.
عرض النص الأصلي للإعلان
About Rasan
Our journey began in 2016 when we realized the burning needs of KSA’s insurance sector. To fulfil the unmet needs in the market, we had to disrupt legacy approaches with technology needed for a digital age. Today, we are market leaders, committed to improving digital experiences for thousands of people and businesses every single day.
Job Summary
The Staff Engineer - Cyber Security provides operational coordination, governance support, and oversight across the organization's cybersecurity functions. The role serves as a key link between cybersecurity leadership, technical teams, and business stakeholders, ensuring that security initiatives, risk management activities, compliance requirements, and operational controls are effectively tracked, monitored, and reported. The position contributes to strengthening the organization's cybersecurity posture by supporting governance processes, driving accountability, and facilitating the successful execution of cybersecurity programs.
Job Objectives
Ensure effective tracking and follow-up of cybersecurity operations, incidents, vulnerabilities, and remediation activities to support timely risk mitigation.
Support the implementation and monitoring of cybersecurity controls and improvement initiatives across technology environments.
Maintain compliance with applicable cybersecurity frameworks, regulatory requirements, and internal policies through effective governance and reporting.
Provide accurate and timely cybersecurity reporting, dashboards, and performance metrics to support management decision-making.
Facilitate coordination among technical teams, business stakeholders, vendors, and third parties to ensure successful execution of cybersecurity initiatives.
Support audit, assessment, and assurance activities by maintaining evidence, documentation, and remediation tracking.
Job Responsibilities
Cybersecurity Operations Coordination & Oversight
Follow up with technical teams on security operations activities, incidents, vulnerabilities, and remediation progress.
Monitor implementation of cybersecurity action plans and track completion against agreed timelines.
Support the deployment, operation, and effectiveness monitoring of cybersecurity technologies including SIEM, EDR, IAM, PAM, DLP, and WAF solutions.
Track security control implementation and identifying delays, risks, or operational issues requiring management attention.
Escalate unresolved issues, control gaps, and remediation delays to cybersecurity leadership
Governance, Risk & Compliance Support
Support the development, maintenance, and periodic review of cybersecurity policies, procedures, standards, and related documentation.
Assist in cybersecurity compliance assessments and reviews against applicable frameworks and standards.
Support implementation and monitoring of internal controls and governance requirements.
Maintain and update cybersecurity risk registers, action plans, and remediation tracking records.
Monitor compliance-related activities and ensure identified gaps are tracked through resolution.
Audit & Assurance Management
Support internal and external cybersecurity audits, assessments, and regulatory reviews.
Coordinate evidence collection, documentation preparation, and stakeholder responses for audit activities.
Track audit findings, recommendations, and corrective action plans to ensure timely closure.
Maintain audit records and ensure supporting documentation remains accurate and readily available.
Assist management in monitoring the status of compliance and assurance initiatives.
Reporting, Stakeholder & Vendor Coordination
Prepare cybersecurity dashboards, reports, metrics, KPIs, and management presentations.
Coordinate with IT teams, business units, vendors, consultants, and third-party service providers on cybersecurity-related matters.
Facilitate communication between cybersecurity leadership and operational teams to ensure alignment on priorities and deliverables.
Support management reporting on cybersecurity risks, compliance status, incidents, and improvement initiatives.
Ensure cybersecurity documentation, records, and governance artifacts are maintained and periodically reviewed.
Job Requirements
Educational Qualification
Bachelor's degree in Cyber Security , Information Technology or related filed.
Licenses & Certifications
CompTIA Security+
ISO 27001 Foundation or Lead Implementer
CRISC (Certified in Risk and Information Systems Control) - Preferred
Previous Work Experience
4+ years of experience in cybersecurity, information security, or related fields.
Experience in cybersecurity governance, compliance, risk management, audit coordination, or security operations support roles.
Experience working with cybersecurity frameworks, regulatory requirements, and control monitoring activities is preferred.
Skills and Abilities
Good understanding of cybersecurity principles, controls, risk management, and governance practices.
Knowledge of cybersecurity frameworks, compliance requirements, and industry standards.
Strong coordination, reporting, documentation, and stakeholder management skills.
Ability to understand and communicate technical cybersecurity matters at a business and management level.
Strong analytical, organizational, and follow-up capabilities with attention to detail.
Proficiency in preparing reports, dashboards, presentations, and tracking mechanisms.
رقم الإعلان لدى المصدر: 7954999