📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

وظيفة استشاري - مدير متخصص في إدارة الثغرات الأمنية (Cyber Operate) لدى ديلويت في الرياض

Consultant - Manager| Cyber Operate | Vulnerability Management Specialist | KSA
🕒 نُشرت: (أمس) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

شركة Deloitte، إحدى أكبر وأعرق شركات الخدمات المهنية عالمياً والحاصلة على جوائز كأفضل صاحب عمل في الشرق الأوسط وأفضل شركة استشارات، تعلن عن وظيفة Consultant - Manager (أخصائي إدارة الثغرات) ضمن فريق Cyber Operate في الرياض، السعودية.

نبذة عن الوظيفة

ستتولى خلال فترة عملك إجراء تقييمات شاملة للثغرات الأمنية عبر الشبكات، المنصات السحابية، الأنظمة، والتطبيقات، بالإضافة إلى إدارة أدوات المسح وتحديد أولويات الثغرات بناءً على المخاطر، ومتابعة الإصلاح، وإعداد التقارير ولوحات المؤشرات لإدارة البرنامج.

المهام والمسؤوليات

  • إجراء تقييمات الثغرات: تقييم الشبكات (داخلية، مركز بيانات، DMZ، لاسلكية، شريكة) مع مسح محدد ومصادق، وتقييم بيئات Azure وAWS وGCP وفق معايير CIS وNCA CCC، وتقييم أنظمة Windows وLinux والخوادم والأجهزة الطرفية وقواعد البيانات ومنصات الافتراضية وأجهزة الشبكة والأمان مع فحص التهيئة والتصلب، وتقييم تطبيقات الويب وواجهات API والخلفيات بالتزامن مع فريق أمن التطبيقات.
  • تقييم الأنظمة الجديدة قبل الإطلاق وبعد التغييرات الكبرى، وإجراء تقييمات مستهدفة عند الطلب.
  • إنتاج تقارير تقييم واضحة مع نتائج مصنفة حسب المخاطر والأدلة وخطوات الإصلاح العملية لكل مالك أصل.
  • تشغيل وضبط منصات المسح (مثل Tenable وQualys وRapid7) بما في ذلك سياسات المسح وبيانات الاعتماد والجداول والعوامل.
  • الحفاظ على تغطية المسح متوافقة مع سجل الأصول وCMDB، وسد الفجوات بما في ذلك الأصول الجديدة وغير المُدارة.
  • العمل مع فريق OT على طرق آمنة معتمدة لتقييم الأنظمة الصناعية والمباني.
  • تحديد أولويات الثغرات باستخدام CVSS وEPSS وCISA KEV وأهمية الأصول والتعرض وتهديدات الاستخبارات لمعالجة المخاطر الأكثر خطورة أولاً.
  • التحقق من النتائج الحرجة وتصفية الإيجابيات الكاذبة قبل إرسالها لفرق تقنية المعلومات.
  • تتبع التهديدات الناشئة وثغرات اليوم صفر، وإجراء فحوص سريعة للتعرض وإصدار تنبيهات واضحة.
  • الاتفاق على خطط الإصلاح والمواعيد النهائية مع مالكي الأنظمة التقنية والسحابية والتطبيقات، ومتابعتها حتى الإغلاق بعلاقات عمل جيدة.
  • التحقق من الإصلاحات بإعادة المسح، وإدارة عملية الاستثناءات وقبول المخاطر مع التبرير وتواريخ الانتهاء.
  • إدارة التصحيح وفقًا لـ NIST SP 800-40 بالتعاون مع فرق البنية التحتية.
  • تحديد سياسة إدارة الثغرات والإجراءات وجداول المسح واتفاقيات مستوى الخدمة للإصلاح وفقًا لـ NCA ECC.
  • بناء لوحات المؤشرات ومؤشرات الأداء (الامتثال لـ SLA، العمر، التغطية، اتجاه المخاطر)، وإعداد تقارير شهرية للإدارة.
  • أتمتة المسح وإنشاء التذاكر والتقارير حيثما أمكن (مثل Python وواجهات API وتكامل ServiceNow).
  • مشاركة النتائج مع فرق اختبار الاختراق ومركز العمليات الأمنية والمخاطر للحفاظ على صورة المخاطر الكلية محدثة.

الشروط والمتطلبات

  • خبرة 4-8 سنوات إجمالية مع خبرة عملية في تقييم وإدارة الثغرات.
  • درجة البكالوريوس في تقنية المعلومات أو الأمن السيبراني أو مجال ذي صلة.
  • خبرة عملية في أداة مسح مؤسسية واحدة على الأقل (Tenable أو Qualys أو Rapid7).
  • خبرة في تقييم اثنين على الأقل من: الشبكات والأنظمة المحلية، المنصات السحابية، تطبيقات الويب وواجهات API.
  • معرفة قوية بأساسيات Windows وLinux والشبكات والسحابة، وفهم أنظمة تسجيل CVSS وEPSS.
  • معرفة بمتطلبات إدارة الثغرات في NCA ECC.
  • يفضل إتقان لغة Python أو PowerShell لأتمتة وإعداد التقارير.
  • يفضل خبرة في أدوات ITSM (ServiceNow أو Jira) لسير عمل الإصلاح.
  • يفضل خبرة في أدوات أمان السحابة (CSPM) أو أدوات مسح الحاويات (مثل Wiz وPrisma Cloud وDefender for Cloud).
  • يفضل إجادة اللغة العربية.
  • شهادة واحدة على الأقل مفضلة: CompTIA Security+ أو CySA+ أو CEH. وكذلك شهادات GIAC (GSEC أو GCIH) وشهادات Tenable أو Qualys.
  • الإلمام بالأطر والمعايير: NCA ECC-2:2024، NCA CCC، NIST SP 800-40 Rev 4، NIST SP 800-115، NIST CSF 2.0، ISO/IEC 27001:2022 (A.8.8)، CIS Controls v8، CIS Benchmark.

المهارات المطلوبة

  • بناء فهم شخصي لهدف الشركة وقيمها واستكشاف فرص التأثير.
  • إظهار التزام قوي بالتعلم والتطوير الشخصي؛ والعمل كسفير للعلامة التجارية لجذب المواهب المتميزة.
  • فهم التوقعات وإظهار المساءلة الشخصية للحفاظ على الأداء في المسار الصحيح.
  • التركيز بنشاط على تطوير مهارات التواصل وبناء العلاقات بفعالية.
  • فهم كيف يساهم العمل اليومي في أولويات الفريق والأعمال.
  • مهارات في البرمجة النصية (Python أو PowerShell) للأتمتة وإعداد التقارير (مفضلة).
  • خبرة في أدوات ITSM (ServiceNow أو Jira) لسير عمل الإصلاح (مفضلة).
  • خبرة في أدوات أمان السحابة (CSPM) أو مسح الحاويات (مفضلة).
عرض النص الأصلي للإعلان
About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.

Our Purpose

  • Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most-for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.
  • Our shared values guide the way we behave to make a positive, enduring impact:

During your tenure as a Consultant - Manager, you will demonstrate and develop your capabilities in the following areas.

Conduct vulnerability assessments

  • Networks: plan and run authenticated and unauthenticated assessments across corporate, data-Center, DMZ, wireless, guest-facing and partner-connected networks, including internal and internet-facing perimeter assessments
  • Cloud platforms: assess Azure, AWS and GCP environments, covering workloads, configuration and identity settings against CIS benchmarks and NCA CCC, and scan container images and Kubernetes clusters
  • Systems: assess Windows and Linux servers, endpoints, databases, virtualisation platforms, and network and security devices, including configuration and hardening checks against approved baselines
  • Applications: assess web applications, APIs and mobile app back-ends with authenticated DAST scanning, working with the Application Security team on in-depth testing
  • Assess new systems before go-live and after major changes, and run targeted assessments on request
  • Produce clear assessment reports with risk-rated findings, evidence and practical remediation steps for each asset owner

Run tooling and coverage

  • Operate and tune scanning platforms (e.g. Tenable, Qualys, Rapid7), including scan policies, credentials, schedules and agents
  • Keep scan coverage aligned with the asset inventory and CMDB, and find and close blind spots, including new and unmanaged assets
  • Work with the OT team on safe, approved methods for assessing industrial and building systems
  • Prioritize what matters
  • Prioritize vulnerabilities using CVSS, EPSS, CISA KEV, asset criticality, exposure and threat intelligence, so teams fix the riskiest issues first rather than chasing volume
  • Validate critical findings and filter out false positives before they reach IT teams
  • Track emerging threats and zero-days; run rapid exposure checks and issue clear advisories

Drive remediation

  • Agree remediation plans and deadlines with IT, cloud and application owners, and follow them through to closure with persistence and good working relationships
  • Verify fixes by rescanning, and manage the exception and risk-acceptance process with proper justification and expiry dates
  • Govern patch management in line with NIST SP 800-40, working with the infrastructure teams

Set up the programme and report on it

  • Define the vulnerability management policy, procedure, scan schedules and remediation SLAs in line with NCA ECC
  • Build dashboards and KPIs (SLA compliance, ageing, coverage, risk trend), and produce monthly reports for management
  • Automate scanning, ticketing and reporting where possible (e.g. Python, APIs, ServiceNow integration)
  • Share findings with the Penetration Testing, SOC and Risk teams so the overall risk picture stays current

Leadership Capabilities:

  • Builds own understanding of our purpose and values; explores opportunities for impact.
  • Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
  • Understands expectations and demonstrates personal accountability for keeping performance on track.
  • Actively focuses on developing effective communication and relationship-building skills.
  • Understands how their daily work contributes to the priorities of the team and the business. 

Qualifications:

  • Years of experience: 4-8 years in total with hands-on vulnerability assessment and management experience
  • Bachelor's in IT, cybersecurity or a related field
  • Practical experience with at least one enterprise scanner (Tenable, Qualys or Rapid7)
  • Has assessed at least two of: on-premise networks and systems, cloud platforms, web applications and APIs
  • Solid Windows, Linux, network and cloud fundamentals; understands CVSS and EPSS scoring
  • Knowledge of NCA ECC vulnerability management requirements
  • Scripting in Python or PowerShell for automation and reporting is preferred.
  • Experience with ITSM tools (ServiceNow, Jira) for remediation workflows is preferred.
  • Experience with cloud security posture (CSPM) or container scanning tools (e.g. Wiz, Prisma Cloud, Defender for Cloud) is preferred.
  • Arabic Language is preferred.
  • At least one preferred: CompTIA Security+, CySA+, CEH. Also valued: GIAC (GSEC, GCIH), and Tenable or Qualys vendor certifications.
  • Frameworks and Standards: NCA ECC-2:2024
  • NCA CCC
  • NIST SP 800-40 Rev 4
  • NIST SP 800-115
  • NIST CSF 2.0
  • ISO/IEC 27001:2022 (A.8.8)
  • CIS Controls v8
  • CIS Benchmark
المصدر: LinkedIn - أُضيفت للموقع في 8 أكتوبر 2026
رقم الإعلان لدى المصدر: 4477406590