📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

وظيفة أخصائي أول أمن تقنية المعلومات لدى ArcelorMittal Tubular Products Al-Jubail في الجبيل

Sr. Specialist, IT Security
🕒 نُشرت: (منذ 4 أيام) 📍 الجبيل وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة ArcelorMittal Tubular Products Al-Jubail عن توفر وظيفة أخصائي أول في أمن تقنية المعلومات (Sr. Specialist, IT Security) في المنطقة الشرقية - الجبيل، السعودية.

نبذة عن الوظيفة

يقوم الأخصائي الأول في أمن تقنية المعلومات بتنفيذ وإدارة وصيانة تقنيات الأمن المؤسسي لحماية سرية وسلامة وتوافر نظم وبيانات المعلومات. يقدم هذا الدور خبرة فنية متقدمة عبر عمليات الأمن، ومراقبة التهديدات، والاستجابة للحوادث، وإدارة الثغرات، وحوكمة الوصول، والامتثال. يطبق المعايير الأمنية المؤسسية المتماشية مع الأطر الدولية (ISO/IEC 27001, NIST) والأنظمة الوطنية السعودية (NCA ECC و OTCC)، ويعمل بشكل وثيق مع فرق البنية التحتية والشبكات والسحابة والتطبيقات ومكتب الخدمة والأمن السيبراني والتدقيق لتعزيز المرونة السيبرانية للمنظمة.

المهام والمسؤوليات

  • تطوير وصيانة البنى المرجعية لأمن تقنية المعلومات المتماشية مع ISO/IEC 27001 و NIST SP 800-53 و COBIT 2019 والأنظمة السعودية (NCA ECC و OTCC).
  • تنفيذ وإدارة وصيانة تقنيات الأمن المؤسسي بما في ذلك حماية نقاط النهاية (EDR)، وجدران الحماية من الجيل التالي، وأنظمة كشف/منع التسلل (IDS/IPS)، ومكافحة البرمجيات الخبيثة، وبوابات أمن البريد الإلكتروني والويب، ومنع تسرب البيانات (DLP)، وأدوات فحص الثغرات، وحلول SIEM.
  • مراقبة التنبيهات والسجلات والأحداث الأمنية باستمرار؛ وإجراء الفرز والتحقيق والتصعيد والمعالجة للتهديدات والحوادث.
  • قيادة ودعم الاستجابة للحوادث الأمنية والتحقيقات الجنائية الرقمية، بما في ذلك الاحتواء والاستئصال والتعافي وتحليل السبب الجذري.
  • إجراء تقييمات المخاطر وفحص الثغرات ومراجعات التكوين عبر الأنظمة ونقاط النهاية والشبكات وأعباء العمل السحابية؛ ومتابعة النتائج حتى إغلاقها.
  • التعاون مع فرق البنية التحتية لتقنية المعلومات والشبكات والتطبيقات والسحابة ومكتب الخدمة لتطبيق مبادئ الأمن بالتصميم (security by design) في مشاريع النظم وعمليات إدارة التصحيحات.
  • تطبيق خطوط الأساس الأمنية وتشديد التكوين وسياسات إدارة التصحيحات عبر الخوادم ونقاط النهاية والبيئات السحابية (مثل CIS Benchmarks).
  • إدارة حوكمة الهوية والوصول، بما في ذلك توفير الوصول وإدارة الوصول المميز (PAM) ومراجعات وصول المستخدم الدورية.
  • ضمان النشر والتكوين الآمن لجدران الحماية وطبقات أمان الشبكة والوكلاء والأجهزة الأمنية.
  • تطوير وإنفاذ وصيانة السياسات والمعايير والإجراءات الأمنية المتماشية مع حوكمة المؤسسة.
  • دعم عمليات التدقيق الداخلي والخارجي (مثل ISO 27001 و SOC 2 والامتثال لـ NCA) من خلال جمع الأدلة ومراجعات الوصول ومتابعة المعالجة مع فرق التدقيق والامتثال.
  • صيانة واختبار خطط التعافي من الكوارث واستمرارية الأعمال لأنظمة الأمن بشكل دوري.
  • تقديم المشورة للإدارة العليا لتقنية المعلومات حول استراتيجيات تخفيف المخاطر والتهديدات الناشئة وتحسينات التحكم.
  • المشاركة في المشاريع متعددة الوظائف لتطبيق مبادئ الأمن بالتصميم في نظم وعمليات الأعمال.
  • الحفاظ على توثيق دقيق وأدلة التشغيل (runbooks) ومقالات قاعدة المعرفة، والدفع نحو التحسين المستمر لعمليات الأمن.

الشروط والمتطلبات

  • درجة البكالوريوس في علوم الحاسب، أو تقنية المعلومات، أو الأمن السيبراني، أو أمن المعلومات، أو مجال ذي صلة.
  • خبرة لا تقل عن 6 سنوات في مجال أمن تقنية المعلومات / الأمن السيبراني، تشمل خبرة عملية في عمليات الأمن ومراقبة SIEM والاستجابة للحوادث وإدارة الثغرات وإدارة تقنيات الأمن المؤسسي. يفضل وجود خبرة في بيئة صناعية أو تصنيعية (OT/IT) وفي الامتثال التنظيمي (ISO 27001, NCA ECC/OTCC).
عرض النص الأصلي للإعلان

ROLE SUMMARY:
The Senior Specialist, IT Security implements, administers, and maintains the organisation's enterprise 
security technologies to protect the confidentiality, integrity, and availability of information systems and data. 
The role provides advanced technical expertise across security operations, threat monitoring, incident 
response, vulnerability management, access governance, and compliance. The incumbent enforces corporate 
security standards aligned with international frameworks (ISO/IEC 27001, NIST) and Saudi national 
regulations (NCA ECC and OTCC), working closely with Infrastructure, Network, Cloud, Application, 
Service Desk, Cybersecurity, and Audit teams to strengthen the organisation's cyber resilience. 

ROLES & RESPONSIBILITIES: 
• Develop and maintain IT security reference architectures aligned with ISO/IEC 27001, NIST SP 800-53, 
COBIT 2019, and applicable Saudi regulations (NCA ECC and OTCC). 
• Implement, administer, and maintain enterprise security technologies including endpoint protection 
(EDR), next-generation firewalls, IDS/IPS, anti-malware, email and web security gateways, DLP, 
vulnerability scanners, and SIEM solutions. 
• Continuously monitor security alerts, logs, and events; perform triage, investigation, escalation, and 
remediation of threats and incidents. 
• Lead and support security incident response and forensic investigations, including containment, 
eradication, recovery, and root-cause analysis. 
• Conduct risk assessments, vulnerability scans, and configuration reviews across systems, endpoints, 
networks, and cloud workloads; track findings through to closure. 
• Experience IT Infrastructure, Network, Applications, Cloud and Service Desk teams to embed security by 
design principles into project systems and patch management processes. 
• Apply security baselines, configuration hardening, and patch-management policies across servers, 
endpoints, and cloud environments (e.g., CIS Benchmarks). 
• Administer identity and access governance, including access provisioning, privileged access management 
(PAM), and periodic user access reviews. 
• Ensure secure deployment and configuration of firewalls, network security layers, proxies, and security 
appliances.
• Develop, enforce, and maintain security policies, standards, and procedures aligned with enterprise 
governance. 
• Support internal and external audits (e.g., ISO 27001, SOC 2, NCA compliance) through evidence 
collection, access reviews, and remediation tracking with Audit and Compliance teams. 
• Maintain and periodically test disaster recovery and business continuity plans for security systems. 
• Advise IT leadership on risk-mitigation strategies, emerging threats, and control improvements. 
• Experience in IT Infrastructure, Network, Applications, Cloud, and Service Desk teams to embed 
security-by-design principles into projects, systems, and change management processes. 
• Participate in cross-functional projects to embed security-by-design into business systems and processes. 
• Maintain accurate documentation, runbooks, and knowledge-base articles, and drive continuous 
improvement of security operations.

QUALIFICATION & EDUCATION: 
• Bachelor’s degree in computer science, Information Technology, Cybersecurity, Information Security, or 
a related field.

EXPERIENCE: 
• Minimum 6 years of progressive experience in IT security / cybersecurity, including hands-on experience 
in security operations, SIEM monitoring, incident response, vulnerability management, and 
administration of enterprise security technologies. Experience in an industrial or manufacturing (OT/IT) 
environment and with regulatory compliance (ISO 27001, NCA ECC/OTCC) is preferred. 

المصدر: LinkedIn - أُضيفت للموقع في 5 أكتوبر 2026
رقم الإعلان لدى المصدر: 4474262343