سلة تعلن عن وظيفة رئيس الأمن السيبراني - PayLink في جدة
تفاصيل الوظيفة
تعلن شركة سلة (PayLink) عن توفر فرصة وظيفية شاغرة بمسمى رئيس الأمن السيبراني (Head of Cyber Security - PayLink) في مدينة جدة، المملكة العربية السعودية.
المهام والمسؤوليات
- تطوير وتنفيذ وصيانة سياسات وإجراءات ومعايير وضوابط الأمن السيبراني بما يتوافق مع إطار الأمن السيبراني لدى البنك المركزي السعودي (SAMA CSF) والمتطلبات التنظيمية ذات الصلة.
- قيادة تقييمات مخاطر الأمن السيبراني ومراجعات الامتثال والتدقيق الداخلي وأنشطة المعالجة.
- الحفاظ على وثائق حوكمة الأمن السيبراني وسجلات المخاطر وتقارير الامتثال.
- تحديد فجوات الامتثال التنظيمي ووضع خطط العمل التصحيحية.
- الإشراف على العمليات اليومية للأمن السيبراني ومراقبة التهديدات واكتشافها وأنشطة الاستجابة للحوادث.
- إدارة حلول مراقبة الأمن بما في ذلك SIEM وEDR/XDR وجدران الحماية وأنظمة كشف/منع الاختراق (IDS/IPS).
- قيادة تحقيقات حوادث الأمن السيبراني وتحليل الأسباب الجذرية والإجراءات التصحيحية.
- تطوير وصيانة واختبار إجراءات الاستجابة للحوادث وعمليات التصعيد.
- الإشراف على ضوابط أمن الشبكات وتكوينات جدران الحماية وإدارة الوصول وحماية البنية التحتية.
- التعاون مع فرق التطوير لدمج الأمن في دورة حياة تطوير البرمجيات (SDLC).
- ضمان تنفيذ ضوابط أمنية مناسبة عبر تطبيقات الويب وواجهات برمجة التطبيقات (APIs) والتطبيقات المحمولة ومنصات الدفع.
- دعم مراجعات الهندسة الأمنية وتقييمات أمن التطبيقات وأنشطة اختبار الاختراق.
- قيادة تقييمات الثغرات الأمنية والاختبارات الأمنية وتتبع المعالجة.
- تقييم مخاطر الأمن السيبراني عبر التطبيقات والشبكات والبيئات السحابية والتكاملات مع الجهات الخارجية.
- التنسيق مع فرق تقنية المعلومات والهندسة لمعالجة الثغرات الحرجة ضمن الجداول الزمنية المحددة.
- مراقبة التهديدات السيبرانية الناشئة والتوصية بتدابير أمنية وقائية.
- قيادة مبادرات الأمن السيبراني وإدارة مشاريع الأمن وتوجيه أعضاء فريق الأمن السيبراني.
- التنسيق مع أصحاب المصلحة في تقنية المعلومات والهندسة والمخاطر والامتثال والأعمال.
- تطوير وتقديم برامج التوعية والتدريب في مجال الأمن السيبراني.
- إعداد مؤشرات الأداء الرئيسية للأمن السيبراني وتقارير المخاطر وتحديثات الوضع الأمني للإدارة العليا.
الشروط والمتطلبات
- الجنسية السعودية شرط أساسي.
- درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو علوم الحاسب أو تقنية المعلومات أو مجال ذي صلة.
- يفضل الحصول على شهادات مهنية في الأمن السيبراني مثل CISSP أو CISM أو CRISC أو CEH أو ما يعادلها.
- خبرة لا تقل عن 5 سنوات في مجال الأمن السيبراني أو أمن المعلومات داخل مؤسسات مالية مرخصة من البنك المركزي السعودي (ساما) أو بنوك أو مزودي خدمات دفع أو شركات تقنية مالية (FinTech) في المملكة العربية السعودية.
- خبرة عملية مثبتة في تنفيذ وصيانة الضوابط المتوافقة مع إطار الأمن السيبراني للبنك المركزي السعودي (SAMA CSF).
- خبرة مثبتة في حوكمة الأمن السيبراني وإدارة المخاطر والامتثال (GRC) بما في ذلك تقييمات المخاطر والتدقيق التنظيمي وخطط المعالجة.
- خبرة مثبتة في إدارة عمليات الأمن (SOC) ومراقبة الأمن والاستجابة لحوادث الأمن السيبراني.
- معرفة تقنية قوية في أمن الشبكات وأمن التطبيقات وإدارة الثغرات الأمنية والهندسة الأمنية.
- خبرة عملية مع تقنيات الأمن السيبراني مثل SIEM وEDR/XDR وجدران الحماية وIDS/IPS وأدوات فحص الثغرات.
- خبرة في إجراء أو الإشراف على تقييمات الثغرات واختبار الاختراق وأنشطة معالجة الثغرات.
- خبرة مثبتة في قيادة مشاريع الأمن السيبراني وتنسيق الفرق الفنية أو إدارة متخصصي الأمن السيبراني.
- مهارات تواصل وتحليل وإدارة أصحاب المصلحة وحل المشكلات قوية.
عرض النص الأصلي للإعلان
Job Summary
We are seeking an experienced Cyber Security Manager to lead cybersecurity operations, governance, risk management, and regulatory compliance across PayLink's payment platforms and technology infrastructure.
The ideal candidate will have 5+ years of cybersecurity experience within SAMA-licensed financial institutions or FinTech companies, with demonstrated hands-on experience implementing SAMA cybersecurity requirements, managing security operations, responding to security incidents, and leading cybersecurity initiatives.
Key Responsibilities
Cybersecurity Governance & SAMA Compliance
- Develop, implement, and maintain cybersecurity policies, procedures, standards, and controls aligned with the SAMA Cyber Security Framework (CSF) and applicable regulatory requirements.
- Lead cybersecurity risk assessments, compliance reviews, internal audits, and remediation activities.
- Maintain cybersecurity governance documentation, risk registers, and compliance reporting.
- Identify regulatory compliance gaps and develop corrective action plans.
Security Operations & Incident Response
- Oversee daily security operations, threat monitoring, detection, and incident response activities.
- Manage security monitoring solutions, including SIEM, EDR/XDR, firewalls, and intrusion detection/prevention systems (IDS/IPS).
- Lead cybersecurity incident investigations, root cause analysis, and corrective actions.
- Develop, maintain, and test incident response procedures and escalation processes.
Network, Application & Infrastructure Security
- Oversee network security controls, firewall configurations, access management, and infrastructure protection.
- Collaborate with development teams to integrate security into the Software Development Life Cycle (SDLC).
- Ensure appropriate security controls are implemented across web applications, APIs, mobile applications, and payment platforms.
- Support secure architecture reviews, application security assessments, and penetration testing activities.
Vulnerability & Risk Management
- Lead vulnerability assessments, security testing, and remediation tracking.
- Evaluate cybersecurity risks across applications, networks, cloud environments, and third-party integrations.
- Coordinate with IT and engineering teams to remediate critical vulnerabilities within defined timelines.
- Monitor emerging cyber threats and recommend preventive security measures.
Leadership & Security Awareness
- Lead cybersecurity initiatives, manage security projects, and mentor cybersecurity team members.
- Coordinate with IT, Engineering, Risk, Compliance, and business stakeholders.
- Develop and deliver cybersecurity awareness and training programs.
- Prepare cybersecurity KPIs, risk reports, and security posture updates for senior management.
Requirements
- Saudi nationality is mandatory.
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.
- Professional cybersecurity certifications such as CISSP, CISM, CRISC, CEH, or equivalent are preferred. .
- Minimum 5 years of relevant cybersecurity or information security experience within SAMA-licensed financial institutions, banks, payment service providers, or FinTech companies in Saudi Arabia.
- Proven hands-on experience implementing and maintaining controls aligned with the SAMA Cyber Security Framework (SAMA CSF).
- Demonstrated experience in Cybersecurity Governance, Risk Management, and Compliance (GRC), including risk assessments, regulatory audits, and remediation plans.
- Proven experience managing Security Operations (SOC), security monitoring, and cybersecurity incident response.
- Strong technical knowledge of Network Security, Application Security, Vulnerability Management, and Security Architecture.
- Hands-on experience with cybersecurity technologies such as SIEM, EDR/XDR, firewalls, IDS/IPS, and vulnerability scanning tools.
- Experience conducting or overseeing vulnerability assessments, penetration testing, and security remediation activities.
- Demonstrated experience leading cybersecurity projects, coordinating technical teams, or managing cybersecurity professionals.
- Strong communication, analytical, stakeholder management, and problem-solving skills.
رقم الإعلان لدى المصدر: D8C636C37E