📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

ديلويت تعلن عن وظيفة مستشار أول في أمن الأنظمة التشغيلية OT بالرياض

Senior Consultant - Senior Manager| Cyber Operate | OT Security Specialist| KSA
🕒 نُشرت: (أمس) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة Deloitte، إحدى أكبر شركات الخدمات المهنية وأكثرها سمعة في العالم، عن فرصة وظيفية لمستشار أول - مدير أول متخصص في أمن تقنية العمليات (OT Security) للعمل في الرياض، المملكة العربية السعودية.

المهام والمسؤوليات

  • تصميم أمن OT: تحديد بنية OT الأمنية والتصاميم المرجعية (Purdue-zoning, IEC 62443 zones and conduits, OT DMZs, secure remote access, backup and recovery).
  • تعيين متطلبات الأمن السيبراني للمصنّعين ومتكاملي الأنظمة والمقاولين (IEC 62443-2-4, 3-3, 4-2) ومراجعة تصاميمهم قبل التركيب.
  • تأمين المشاريع الجديدة حتى التسليم: التحقق من أن الأنظمة مسلّمة بحالة محصّنة وموثقة مع إزالة بيانات الاعتماد الافتراضية والخدمات غير المستخدمة.
  • تحديد أنماط تكامل آمنة بين IT وOT للأنظمة التي تشارك البيانات مع منصات الأعمال والمدن الذكية.
  • تقييم بيئات OT: بناء وصيانة جرد أصول OT (وحدات تحكم، شاشات HMI، خوادم، أجهزة شبكة ومسارات الاتصال).
  • إجراء تقييمات المخاطر وفقاً لـ IEC 62443: تحديد المناطق، تعيين مستويات الأمان المستهدفة، تقييم الفجوات والتوصية بالضوابط.
  • تقييم الامتثال لـ NCA OTCC وNCA ECC لأنظمة OT وتتبع المعالجة.
  • اختبار بيئات OT وIT المتصلة: مراجعة التكوين الأمني لوحدات التحكم (PLC)، شاشات HMI، محطات العمل الهندسية، خوادم SCADA والمؤرخ، والمفاتيح الكهربائية الصناعية وجدران الحماية استناداً إلى أدلة التحصين المعتمدة.
  • اختبار جدران الحماية والتقسيم: مراجعة قواعد جدران الحماية عند حدود IT/OT والمناطق، واختبار أن التقسيم يمنع فعلياً المسارات غير المصرح بها بين IT المؤسسية و DMZ OT وشبكات التحكم.
  • تحليل حركة الشبكة: التقاط وتحليل حركة شبكة OT (مثل Wireshark, Zeek, منصات مراقبة OT) لوضع خط أساس للاتصالات الطبيعية، والعثور على الأصول غير المعروفة، والبروتوكولات غير الآمنة، وبيانات الاعتماد النصية، والاتصالات الخارجية غير المتوقعة.
  • أنظمة IT المتصلة: اختبار خوادم Windows وLinux، وحدات تحكم المجال، مضيفي القفز، وبوابات الوصول عن بُعد التي تدعم OT، مع تغطية التصحيح والتحصين والحسابات والصلاحيات.
  • الوصول عن بُعد واللاسلكي: اختبار مسارات الوصول عن بُعد للبائعين، شبكات VPN، والشبكات اللاسلكية الصناعية للكشف عن ضعف المصادقة والتعرض.
  • تنفيذ اختبارات آمنة (سلبية أو نشطة معتمدة) فقط، مع موافقة التغيير وتوقيع العمليات لضمان عدم تعطيل العمليات الحية.
  • إنتاج تقارير اختبار واضحة مع نتائج مصنفة حسب المخاطر وأدلة وإصلاحات عملية تناسب البيئة التشغيلية.
  • إدارة عمليات أمن OT: نشر وإدارة مراقبة شبكة OT (مثل Nozomi, Claroty, Dragos) وضبط الكشف للبروتوكولات الصناعية (Modbus, BACnet, DNP3, OPC UA, IEC 61850).
  • بناء دليل استجابة للحوادث OT بالتعاون مع SOC وفرق العمليات، وتنفيذ تمارين مشتركة.
  • إدارة ثغرات OT وتصحيحها بما يتوافق مع دعم البائع ومتطلبات سلامة المصنع.
  • التحكم ومراقبة الوصول عن بُعد لأطراف ثالثة وبائعين لأنظمة OT.
  • الحوكمة والتقارير: كتابة سياسات ومعايير وإجراءات أمن OT متوافقة مع NCA OTCC وIEC 62443.
  • العمل عن كثب مع فرق العمليات والهندسة في المواقع الحية، وشرح الأمن بمصطلحات تشغيلية مع احترام السلامة ووقت التشغيل.
  • تقديم تقارير حول وضع المخاطر OT وحالة الامتثال للإدارة.

الشروط والمتطلبات

  • خبرة إجمالية من 5 إلى 10 سنوات.
  • درجة البكالوريوس في الهندسة الكهربائية أو هندسة التحكم أو هندسة الحاسب أو مجال ذي صلة.
  • خبرة عملية في بيئات OT/ICS: PLC, DCS, SCADA, BMS, HMI والشبكات الصناعية.
  • معرفة عملية بالبروتوكولات الصناعية (مثل Modbus, BACnet, DNP3, OPC UA, IEC 61850).
  • خبرة عملية في تطبيق IEC 62443 وNCA OTCC.
  • خبرة عملية في الاختبارات التقنية في بيئات OT أو البيئات المدمجة IT/OT: مراجعات التكوين، مراجعات قواعد جدران الحماية واختبار التقسيم.
  • مهارات التقاط وتحليل حركة الشبكة (مثل Wireshark, Zeek) بما في ذلك البروتوكولات الصناعية.
  • خبرة في منصة مراقبة OT واحدة على الأقل (Nozomi, Claroty, Dragos أو ما يشابهها).
  • القدرة على العمل في مواقع تشغيلية حية مع اتباع قواعد السلامة.
  • يفضل خبرة في أنظمة إدارة المباني، التبريد المناطقي، المرافق، أنظمة التحكم في الرحلات أو العروض، أو إنترنت الأشياء للمدن الذكية.
  • يفضل خبرة في تأمين مشاريع البناء الجديدة خلال مرحلة الإنشاء والتسليم.
  • يفضل خبرة في تحصين واختبار Windows/Active Directory في بيئات OT.
  • يفضل مهارات هندسة الشبكات (جدران حماية صناعية، تقسيم، ثنائيات البيانات).
  • يفضل إتقان اللغة العربية.
  • شهادة واحدة مفضلة على الأقل: GICSP, GRID, ISA/IEC 62443 Cybersecurity Expert/Specialist. كما تُقدّر: CISSP, GCIP, GPEN, شهادات البائعين (Nozomi, Claroty, Dragos).
  • الإلمام بالأطر والمعايير التالية: NCA OTCC-1:2022، NCA ECC-2:2024، IEC 62443 (2-1, 2-4, 3-2, 3-3, 4-2)، NIST SP 800-82 Rev 3، NIST SP 800-115، NIST CSF 2.0، MITRE ATT&CK for ICS.

المهارات المطلوبة

  • بناء فهم شخصي لغرض الشركة وقيمها، واستكشاف فرص التأثير.
  • إظهار التزام قوي بالتعلم والتطوير الشخصي؛ والعمل كسفير للعلامة التجارية للمساعدة في جذب أفضل المواهب.
  • فهم التوقعات وإظهار المساءلة الشخصية للحفاظ على الأداء في المسار الصحيح.
  • التركيز بنشاط على تطوير مهارات التواصل الفعال وبناء العلاقات.
  • فهم كيف يساهم العمل اليومي في أولويات الفريق والأعمال.
عرض النص الأصلي للإعلان
About Deloitte: When you work for us, you commit to a career at one of the largest and most prestigious professional services firms in the world. We have received numerous awards over the last few years, including Best Employer in the Middle East, and Best Consulting Firm, and the Middle East Training & Development Excellence Award.

Our Purpose

Deloitte makes an impact that matters. Every day we challenge ourselves to do what matters most-for clients, for our people, and for society. We serve clients distinctively, bringing innovative insights, solving complex challenges and unlocking sustainable growth. We inspire our talented professionals to deliver outstanding value to clients, providing an exceptional career experience and an inclusive and collaborative culture. We contribute to society, building confidence and trust in the markets, upholding the integrity of organizations and supporting our communities.

Our shared values guide the way we behave to make a positive, enduring impact:

During your tenure as a Senior Consultant - Senior Manager, you will demonstrate and develop your capabilities in the following areas.

Design OT security

  • Define the OT security architecture and reference designs: Purdue-model zoning, IEC 62443 zones and conduits, OT DMZs, secure remote access, and backup and recovery
  • Set cybersecurity requirements for OEMs, system integrators and contractors (IEC 62443-2-4, 3-3, 4-2), and review their designs before installation
  • Secure new builds through to handover: check that systems are delivered hardened, documented, and with default credentials and unused services removed
  • Define secure IT/OT integration patterns for systems that share data with business and smart-city platforms

Assess OT environments

  • Build and maintain the OT asset inventory: controllers, HMIs, servers, network devices and their communication paths
  • Run IEC 62443 risk assessments: identify zones, set target security levels, assess gaps and recommend controls
  • Assess compliance with NCA OTCC and NCA ECC for OT systems, and track remediation

Test OT and connected IT environments

  • Configuration reviews: review the security configuration of PLCs, HMIs, engineering workstations, SCADA and historian servers, industrial switches and firewalls against vendor hardening guides and approved baselines
  • Firewall and segmentation testing: review firewall rule sets at IT/OT and zone boundaries, and test that segmentation actually blocks unauthorized paths between corporate IT, the OT DMZ and control networks
  • Network traffic analysis: capture and analyze OT network traffic (e.g. Wireshark, Zeek, OT monitoring platforms) to baseline normal communications, find unknown assets, insecure protocols, cleartext credentials and unexpected external connections
  • Connected IT systems: test the Windows and Linux servers, domain controllers, jump hosts and remote access gateways that support OT, covering patching, hardening, accounts and privileges
  • Remote and wireless access: test vendor remote access paths, VPNs and industrial wireless for weak authentication and exposure
  • Run safe, passive or approved active testing only, with change approval and operations sign-off, so live processes are never disrupted
  • Produce clear test reports with risk-rated findings, evidence and practical fixes that suit the operational environment

Manage OT security operations

  • Deploy and manage OT network monitoring (e.g. Nozomi, Claroty, Dragos), and tune detections for industrial protocols (Modbus, BACnet, DNP3, OPC UA, IEC 61850)
  • Build OT incident response playbooks with the SOC and operations teams, and run joint exercises
  • Manage OT vulnerabilities and patching in line with vendor support and plant safety requirements
  • Control and monitor third-party and vendor remote access to OT systems

Govern and report

  • Write OT security policies, standards and procedures aligned with NCA OTCC and IEC 62443
  • Work closely with operations and engineering teams on live sites, explaining security in operational terms and respecting safety and uptime
  • Report OT risk posture and compliance status to management

Leadership Capabilities

  • Builds own understanding of our purpose and values; explores opportunities for impact.
  • Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent.
  • Understands expectations and demonstrates personal accountability for keeping performance on track.
  • Actively focuses on developing effective communication and relationship-building skills.
  • Understands how their daily work contributes to the priorities of the team and the business. 

Qualifications

  • Years of experience: 5-10 total years
  • Bachelor's in electrical, control, computer engineering or a related field
  • Hands-on experience with OT/ICS environments: PLCs, DCS, SCADA, BMS, HMIs and industrial networks
  • Working knowledge of industrial protocols (e.g. Modbus, BACnet, DNP3, OPC UA, IEC 61850)
  • Practical experience applying IEC 62443 and NCA OTCC
  • Hands-on technical testing in OT or converged IT/OT environments: configuration reviews, firewall rule reviews and segmentation testing
  • Network traffic capture and analysis skills (e.g. Wireshark, Zeek), including industrial protocols
  • Experience with at least one OT monitoring platform (Nozomi, Claroty, Dragos or similar)
  • Comfortable working on live operational sites under safety rules
  • Experience with building management, district cooling, utilities, ride or show control, or smart-city IoT is preferred.
  • Experience securing new-build projects through construction and handover is preferred.
  • Windows/Active Directory hardening and testing in OT environments is preferred.
  • Network engineering skills (industrial firewalls, segmentation, data diodes) is preferred.
  • Arabic Language is preferred.
  • At least one preferred: GICSP, GRID, ISA/IEC 62443 Cybersecurity Expert/Specialist. Also valued: CISSP, GCIP, GPEN, vendor certifications (Nozomi, Claroty, Dragos).
  • Frameworks & Standards: NCA OTCC-1:2022
  • NCA ECC-2:2024
  • IEC 62443 (2-1, 2-4, 3-2, 3-3, 4-2)
  • NIST SP 800-82 Rev 3
  • NIST SP 800-115
  • NIST CSF 2.0
  • MITRE ATT&CK for ICS
المصدر: LinkedIn - أُضيفت للموقع في 8 أكتوبر 2026
رقم الإعلان لدى المصدر: 4477415262