📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

وظيفة أخصائي أمن معلومات أول شاغرة لدى Lifera في الرياض

Information Security Sr. Specialist
🏢 Lifera
🕒 نُشرت: (منذ 5 أيام) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة Lifera عن توفر وظيفة أخصائي أول أمن معلومات في مدينة الرياض.

نبذة عن الوظيفة

الأخصائي الأول لأمن المعلومات مسؤول عن حماية أصول المعلومات في المؤسسة من خلال تنفيذ ومراقبة وتحسين ضوابط الأمن السيبراني باستمرار. يتضمن الدور إدارة المخاطر بفاعلية، والاستجابة للحوادث، وحوكمة الأمن، والتعاون مع فرق تقنية المعلومات للحفاظ على بيئة تقنية آمنة ومرنة.

المهام والمسؤوليات

  • تطوير ومراجعة وتنفيذ ضوابط وسياسات وإجراءات ومعايير أمن المعلومات لضمان ممارسات أمنية قوية ومتسقة في جميع أنحاء المؤسسة.
  • المشاركة في التدقيقات الداخلية والخارجية من خلال إعداد الوثائق والأدلة ومتابعة الإجراءات.
  • ضمان توافق ممارسات الأمن مع المعايير العالمية للأمن السيبراني وأطر تقنية المعلومات التنظيمية.
  • مراقبة التنبيهات والسجلات والأحداث الأمنية باستخدام أدوات المراقبة (مثل MS Defender و SIEM والحماية الطرفية وأدوات أمن الشبكات).
  • التحقيق في الحوادث الأمنية وتنسيق إجراءات الاحتواء والاسترداد وإجراء تحليل ما بعد الحادث.
  • تحديد الثغرات الأمنية في الأنظمة والتطبيقات وضمان معالجتها في الوقت المناسب بالتعاون مع فرق البنية التحتية والتطبيقات.
  • تصميم وتنفيذ وصيانة حلول أمنية تشمل الجدران النارية و IAM و PAM والتشفير وأمن الشبكات/السحابة والحماية الطرفية وأدوات إدارة الهوية والوصول وبوابات البريد الإلكتروني وحلول حماية البيانات.
  • ضمان تكوين الأنظمة وتحديثها ومواءمتها مع أفضل ممارسات الأمن.
  • تأمين أعباء العمل السحابية في مايكروسوفت وجوجل و AWS والبيئات الهجينة وفقًا لأفضل الممارسات وإرشادات NCA السحابية.
  • إجراء تقييمات منتظمة للمخاطر وتحديد الفجوات والتوصية باستراتيجيات التخفيف المناسبة.
  • مراجعة الأنظمة والحلول والخدمات الخارجية لضمان التصميم والتكوين الآمن.
  • الحفاظ على توثيق المخاطر والضوابط وإجراءات التخفيف.
  • دعم تنفيذ حملات التوعية الأمنية وجلسات التدريب المستهدفة للموظفين.
  • تقديم إرشادات حول السلوك الآمن والتهديدات الناشئة والممارسات الوقائية.
  • العمل كنقطة اتصال لجميع الأمور المتعلقة بالأمن ضمن مشاريع ومبادرات تقنية المعلومات.
  • التعاون مع الفرق الداخلية والموردين الخارجيين لضمان تنفيذ المشاريع بشكل متماسك وآمن.
  • تقديم دعم استشاري للحفاظ على التكوينات الآمنة وحماية المعلومات الحساسة.

الشروط والمتطلبات

  • درجة البكالوريوس في أمن المعلومات أو الأمن السيبراني أو علوم الحاسب أو تقنية المعلومات أو مجال معادل.
  • الشهادات المفضلة: CISSP, CCSP, CISM, ISO/IEC 27001 Lead Implementer, CRISC, NCA ECC, PDPL, CEH, Security+ أو شهادات معترف بها مماثلة.
  • خبرة لا تقل عن 5-6 سنوات في أمن المعلومات أو عمليات الأمن السيبراني أو إدارة المخاطر أو المجالات ذات الصلة.
  • خبرة عملية في الاستجابة للحوادث وإدارة الثغرات والحماية الطرفية وأدوات مراقبة الأمن.
  • خبرة في دعم وظيفة 'أخصائي أمن' ضمن مؤسسة تقنية المعلومات كما هو مشار إليه في وثائق استراتيجية تقنية المعلومات الداخلية.
  • خبرة في SOC و MDR والاستجابة للحوادث وأمن السحابة وإدارة الثغرات وهندسة الأمن.

المهارات المطلوبة

  • معرفة قوية بأطر الأمن السيبراني وأفضل الممارسات العالمية ومنهجيات إدارة المخاطر.
  • مهارة في مراقبة الأمن وتحليل التهديدات والحماية الطرفية وأمن الشبكات وإدارة الهوية.
  • القدرة على تحليل الثغرات وتقييم المخاطر والتوصية بإجراءات تصحيحية عملية.
  • مهارات تواصل وتوثيق قوية مع القدرة على التعاون عبر فرق تقنية المعلومات.
  • القدرة على العمل بشكل مستقل وإدارة أولويات متعددة والحفاظ على درجة عالية من الاهتمام بالتفاصيل.
  • معرفة قوية بـ NCA ECC و SAMA CSF و PDPL و ISO/IEC 27001.
عرض النص الأصلي للإعلان

Main Purpose:

The Information Security Senior Specialist is responsible for protecting the organization’s information assets by implementing, monitoring, and continuously improving cybersecurity controls. The role ensures effective risk management, incident response, security governance, and collaboration with IT teams to maintain a secure and resilient technology environment.


Area of Responsibility:


Information Security Governance

  • Develop, review, and implement information security controls, policies, procedures, and standards to ensure strong and consistent security practices across the organization.
  • Participate in internal and external audits by preparing documentation, evidence, and follow up actions.
  • Ensure alignment of security practices with global cybersecurity standards and organizational IT frameworks.

Security Operations & Incident Response

  • Monitor security alerts, logs, and events using security monitoring tools (e.g., MS Defender, SIEM, endpoint protection, network security tools).
  • Investigate security incidents, coordinate containment and recovery actions, and conduct post incident analysis.
  • Identify system and application vulnerabilities and ensure timely remediation in collaboration with infrastructure and application teams.

Security Tools Administration

  • Design, implement, and maintain security solutions including firewalls, IAM, PAM, encryption, network/cloud security, endpoint protection, identity and access management tools, email security gateways, and data protection solutions.
  • Ensure systems are properly configured, updated, and aligned with security best practices.
  • Secure cloud workloads in Microsoft, Google, AWS, and hybrid environments in line with best practice and NCA cloud guidelines.

Risk Assessment & Compliance

  • Conduct regular risk assessments, identify gaps, and recommend appropriate mitigation strategies.
  • Review systems, solutions, and third party services to ensure secure design and configuration.
  • Maintain documentation of risks, controls, and mitigation actions.

Security Awareness & Training

  • Support the delivery of security awareness campaigns and targeted training sessions for employees.
  • Provide guidance on secure behavior, emerging threats, and preventive practices.

Collaboration & Support

  • Act as the point of contact for all security related matters within IT projects and initiatives.
  • Collaborate with internal teams and external vendors to ensure cohesive and secure project execution.
  • Provide advisory support to maintain secure configurations and protect sensitive information.


Educational Qualification:

  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, or an equivalent field.
  • Preferred certifications: CISSP,CCSP, CISM, ISO/IEC 27001 Lead Implementer, CRISC, NCA ECC, PDPL, CEH, Security+, or equivalent industry recognized credentials.


Work Experience:

  • Minimum 5-6 years of experience in information security, cybersecurity operations, risk management, or related fields.
  • Hands on experience with incident response, vulnerability management, end point security, and security monitoring tools.
  • Experience supporting the “Security Specialist” function within an IT organization as referenced in internal IT strategy documentation.
  • Experience in SOC, MDR incident response, cloud security, vulnerability management, and security engineering.


Required Skills:

  • Strong knowledge of cybersecurity frameworks, global best practices, and risk management methodologies.
  • Skilled in security monitoring, threat analysis, endpoint protection, network security, and identity management.
  • Ability to analyze vulnerabilities, assess risks, and recommend practical remediation actions.
  • Strong communication and documentation skills with the ability to collaborate across IT teams.
  • Ability to work independently, manage multiple priorities, and maintain high attention to detail.
  • Strong knowledge of NCA ECC, SAMA CSF, PDPL, and ISO/IEC 27001.
المصدر: LinkedIn - أُضيفت للموقع في 5 أكتوبر 2026
رقم الإعلان لدى المصدر: 4474214233