علم تعلن عن وظيفة مدير - Cybersecurity, Application Security في الرياض
تفاصيل الوظيفة
تعلن شركة علم عن توفر وظيفة شاغرة في مدينة الرياض بمسمى (مدير - أمن المعلومات، أمن التطبيقات)، حيث يتولى قيادة أنشطة حوكمة وإدارة مخاطر أمن المعلومات والامتثال والحماية، وضمان توافق الممارسات مع السياسات واللوائح التنظيمية لتعزيز نضج أمن المعلومات في الشركة.
المهام والمسؤوليات
- قيادة تطوير وتنفيذ خطط ومبادرات وحوكمة أمن المعلومات ضمن النطاق المحدد، وضمان توافق أهداف أمن المعلومات مع الأولويات الإستراتيجية للشركة والمتطلبات التنظيمية.
- تقديم التوجيه والإرشاد بشأن سياسات ومعايير وإجراءات أمن المعلومات ومتطلبات الضوابط.
- الإشراف على تقييمات مخاطر أمن المعلومات للأنظمة والخدمات والعمليات، والتحقق من المخاطر الرئيسية وثغرات الضوابط والتهديدات ونقاط الضعف المؤثرة على السرية أو التكامل أو التوفر.
- إدارة خطط معالجة المخاطر ومتابعة الجهات المعنية لضمان التخفيف الفوري والتقليل الفعال للمخاطر.
- الإشراف على تصميم وتنفيذ وفعالية ضوابط أمن المعلومات، وضمان الامتثال للوائح والسياسات الداخلية والمعايير ذات الصلة، وتحليل فجوات الامتثال وخطط المعالجة لدعم الجاهزية للتدقيق والتقارير الإدارية.
- تقديم الاستشارات الأمنية للمعنيين في الأعمال والتقنية حول المبادرات والمشاريع والخدمات، ودمج متطلبات أمن المعلومات في الحلول والعمليات وقرارات العمل من المراحل المبكرة.
- الإشراف على أنشطة المراقبة الأمنية والتأكد من مراجعة الأحداث الأمنية ورفعها ومعالجتها بشكل مناسب، والتنسيق مع الفرق المعنية خلال الحوادث لدعم التحقيق والاحتواء والمعالجة وإعداد التقارير.
- الإشراف على أنشطة إدارة الثغرات بما يشمل تحديد الأولويات ومتابعة المعالجة بناءً على المخاطر، ومراقبة التهديدات الأمنية الناشئة وتقييم أثرها المحتمل، والتنسيق مع مالكي الأنظمة والفرق التقنية لإغلاق الثغرات الحرجة.
- بناء علاقات فعالة مع الجهات الداخلية وتعزيز الوعي بأمن المعلومات، ودعم تبني الممارسات الآمنة، وتسهيل التوفيق بين متطلبات أمن المعلومات وأولويات الأعمال واحتياجات التسليم التشغيلي.
- إعداد ومراجعة لوحات معلومات أمن المعلومات وتقارير الإدارة حول المخاطر والضوابط والامتثال والحوادث وخطط التحسين، وتحليل مؤشرات الأداء لتحديد الاتجاهات والثغرات وفرص تطوير النضج، وقيادة مبادرات التحسين المستمر لتعزيز المرونة والحوكمة والجاهزية التشغيلية.
الشروط والمتطلبات
- درجة البكالوريوس في أمن المعلومات، أو أمن الحاسب، أو علوم الحاسب، أو تقنية المعلومات، أو هندسة الحاسب، أو مجال ذي صلة.
- يفضل حصول المرشح على درجة الماجستير في مجال ذي صلة.
- يفضل الحصول على شهادات مهنية في أمن المعلومات، أو إدارة المخاطر، أو الحوكمة، أو المجالات ذات الصلة.
- خبرة لا تقل عن 8 سنوات في مجال أمن المعلومات، أو أمن الحاسب، أو الحوكمة والمخاطر والامتثال، أو عمليات الأمن، أو إدارة الثغرات، أو مجال ذي صلة.
- خبرة في قيادة أنشطة أمن المعلومات، والإشراف على ضوابط الأمن، وإدارة مخاطر أمن المعلومات، ودعم الامتثال التنظيمي، وتنسيق الجهات المعنية، وتحسين نضج أمن المعلومات.
عرض النص الأصلي للإعلان
|
Job Description |
|||||
|
OVERVIEW |
|||||
|
Job Title |
Manager |
Job Code |
701431 |
Grade |
T1 |
|
Group |
- |
Division |
Legal, Risk & Governance |
||
|
Department |
Cybersecurity |
Unit |
- |
|
ROLE PURPOSE The aim is to state the overall significance of the job from the organization's perspective. |
|
The role exists to lead cybersecurity governance, risk, compliance, and protection activities across the assigned scope by setting direction, overseeing security controls, enabling regulatory alignment, and driving cybersecurity maturity. The role contributes to protecting Elm's information assets, digital services, and business operations by ensuring cybersecurity practices are implemented, monitored, and continuously improved in alignment with Elm's approved policies, procedures, strategic objectives, and applicable regulatory requirements.
|
|
KEY ACCOUNTABILITIES & ACTIVITIES This section describes the principal outputs required from the job. |
|
|
Key Accountabilities |
Key Activities |
|
1. Cybersecurity Strategy and Governance |
• Lead the development and execution of cybersecurity plans, initiatives, and governance activities within the assigned scope. • Ensure cybersecurity objectives are aligned with Elm's strategic priorities, business requirements, and regulatory expectations. • Provide direction and guidance on cybersecurity policies, standards, procedures, and control requirements. |
|
2. Cybersecurity Risk Management |
• Oversee cybersecurity risk assessments for systems, services, processes, and business initiatives. • Validate key cybersecurity risks, control gaps, threats, and vulnerabilities that may impact confidentiality, integrity, or availability. • Drive risk treatment plans and follow up with stakeholders to ensure timely mitigation and effective risk reduction. |
|
3. Security Controls and Compliance Oversight |
• Oversee the design, implementation, and effectiveness of cybersecurity controls across the assigned environment. • Ensure compliance with applicable cybersecurity regulations, internal policies, and relevant standards. • Review compliance gaps, remediation plans, and evidence to support audit readiness and management reporting. |
|
4. Cybersecurity Advisory and Business Enablement |
• Provide cybersecurity advisory support to business and technical stakeholders on initiatives, projects, and services. • Ensure cybersecurity requirements are embedded into solutions, processes, and business decisions from early stages. • Balance business enablement with risk-based cybersecurity controls and practical implementation guidance. |
|
5. Security Monitoring and Incident Response Oversight |
• Oversee cybersecurity monitoring activities and ensure security events are reviewed, escalated, and handled appropriately. • Coordinate with relevant teams during cybersecurity incidents to support investigation, containment, remediation, and reporting. • Review incident outcomes and ensure lessons learned are translated into improvement actions. |
|
6. Vulnerability and Threat Management |
• Oversee vulnerability management activities, including prioritization, remediation follow-up, and risk-based treatment. • Monitor emerging cybersecurity threats and assess their potential impact on Elm's systems, services, and operations. • Coordinate with system owners and technical teams to ensure timely closure of critical vulnerabilities and exposure areas. |
|
7. Stakeholder Management and Cybersecurity Awareness |
• Build and maintain effective relationships with internal stakeholders, business owners, technology teams, and governance functions. • Promote cybersecurity awareness and support the adoption of secure practices across the assigned scope. • Facilitate alignment between cybersecurity requirements, business priorities, and operational delivery needs. |
|
8. Performance Reporting and Continuous Improvement |
• Prepare and review cybersecurity dashboards and management updates covering risks, controls, compliance, incidents, and improvement plans. • Analyze cybersecurity performance indicators to identify trends, gaps, and maturity improvement opportunities. • Lead continuous improvement initiatives that enhance cybersecurity resilience, governance effectiveness, and operational readiness. |
|
9. Policies, Processes & Procedures |
• Follow all relevant departmental policies, processes, standard operating procedures, and instructions so that work is carried out in a controlled and consistent manner. • Comply with all relevant safety, quality, and environmental management policies, procedures, and controls to ensure a healthy and safe work environment. |
|
10. Information Security |
• Comply with all relevant information security practices and standards to ensure data integrity and confidentiality. |
|
JOB SPECIFICATIONS |
|
|
Academic and professional qualifications |
• Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Computer Engineering, or a related field.
• Master's degree in a relevant field is preferred. • Professional certifications in cybersecurity, information security, risk management, governance, or related fields are preferred. |
|
Years and Nature of Experience |
• 8+ years of relevant experience in cybersecurity, information security, governance, risk and compliance, security operations, vulnerability management, or a related field.
• Experience in leading cybersecurity activities, overseeing security controls, managing cybersecurity risks, supporting regulatory compliance, coordinating stakeholders, and driving cybersecurity maturity improvement initiatives. |
رقم الإعلان لدى المصدر: 1374236157