وظيفة رئيس البنية التحتية لتقنية المعلومات لدى علم بمدينة الرياض
تفاصيل الوظيفة
شركة علم (Elm) تعلن عن وظيفة رئيس - البنية التحتية لتقنية المعلومات (Principal - IT Infrastructure) في الرياض.
نبذة عن الوظيفة
يهدف هذا الدور إلى العمل كسلطة تقنية رئيسية في مجال أمن الشبكات (Network Security)، حيث يتولى تصميم وتنفيذ وتحسين وإدارة بيئات الشبكات الآمنة عبر المشهد التقني للمؤسسة. يقدم الرئيس إرشادات خبيرة في بنى الأمان المتقدمة، وتخفيف التهديدات، والاستجابة للحوادث، وحلول البائعين، والضوابط التشغيلية لتعزيز المرونة، وحماية أنظمة المؤسسة، وضمان التوافق مع أهداف علم الاستراتيجية والسياسات والإجراءات ومعايير أمن المعلومات ومتطلبات الامتثال.
المهام والمسؤوليات
- الإشراف على عمليات أمن الشبكات المعقدة وضمان التوافق مع مستويات الخدمة المتفق عليها، وتحليل وحل الحوادث الأمنية المتقدمة بما في ذلك تحليل الأسباب الجذرية، وتقديم تحسينات للوضع الأمني والكفاءة التشغيلية، وإجراء عمليات تدقيق أمنية ودعم الامتثال.
- تقييم وتوصية تقنيات أمن الشبكات المتقدمة وتصميماتها، وتصميم والتحقق من بنى الشبكات الآمنة المتوافقة مع نماذج التهديد ومتطلبات العمل، وإجراء تحليل الفجوات، وتقديم إرشادات خبيرة في التكوينات المعقدة وورش العمل التصميمية ومراجعات البنية.
- دعم عمليات الاستجابة للحوادث والتحقيقات الجنائية وتوثيق الأحداث الأمنية، وتطبيق الضوابط الأمنية التشغيلية لتقليل التعرض للتهديدات، والمساهمة في تقييم الاختراق والصيد عن التهديدات والاستجابة للثغرات، وتنفيذ توصيات تقييم المخاطر وخطط المعالجة.
- إدارة متطلبات نقل البيانات الآمنة باستخدام التشفير المناسب وضوابط الاتصال الآمن، والتحقق من تكوينات الشبكات الآمنة لحماية الأنظمة والخدمات، ودعم تصميم وتنفيذ حلول الاتصال الآمن للبيئات الداخلية والخارجية، وتحديد المخاطر المرتبطة بالوصول والاتصال والتشفير والتوصية بإجراءات التخفيف.
- صياغة المتطلبات الفنية والمساهمة في طلبات العروض (RFP) لحلول أمن الشبكات، وتقديم خبرة موضوعية في تقييم العروض وحلول البائعين، وقيادة المسارات الفنية المعينة في مشاريع أمن الشبكات من التخطيط إلى التنفيذ والاستقرار، وضمان تلبية مخرجات المشروع للمتطلبات الفنية والأمنية والأداء والتشغيل.
- العمل كنقطة اتصال فنية مع البائعين لتقنيات أمن الشبكات، وإدارة تصعيد المشكلات التقنية الحرجة وضمان الحل في الوقت المناسب، ومراجعة مخرجات البائعين لضمان الامتثال لتوقعات الأمان والأداء والبنية والخدمة، والتنسيق مع أصحاب المصلحة الداخليين والبائعين لدعم التنفيذ الفعال والصيانة والتحسين.
- التعاون مع فرق الأمن السيبراني والبنية التحتية والعمليات والبنية والتطبيقات لمعالجة الثغرات وتعزيز استراتيجيات الحماية، وتقديم استشارات خبيرة حول متطلبات أمن الشبكات للمبادرات التقنية، والمواءمة مع أصحاب المصلحة حول تنفيذ الضوابط وإجراءات تخفيف المخاطر، ودعم التخطيط للتعافي من الكوارث والاختبار والتوثيق من منظور أمن الشبكات والاتصال.
- إعداد وصيانة الوثائق الفنية والإجراءات التشغيلية وسجلات البنية وتحليل الحوادث ومراجع تكوينات الأمان، وتقديم تقارير واضحة عن العمليات الأمنية والمخاطر والحوادث وحالة المشروع وتوصيات التحسين، ومشاركة المعرفة وتقديم التوجيه الفني لتعزيز قدرات الفريق، وتعزيز التحسين المستمر لممارسات أمن الشبكات والعمليات والمراقبة والحوكمة التشغيلية.
- اتباع جميع سياسات القسم ذات الصلة وعمليات وإجراءات التشغيل القياسية والتعليمات لضمان سير العمل بشكل متحكم ومتسق، والامتثال لسياسات وإجراءات وضوابط إدارة السلامة والجودة والبيئة لضمان بيئة عمل صحية وآمنة.
- الامتثال لجميع ممارسات ومعايير أمن المعلومات ذات الصلة لضمان سلامة البيانات وسريتها.
الشروط والمتطلبات
- درجة البكالوريوس في علوم الحاسب، تقنية المعلومات، الأمن السيبراني، هندسة الشبكات، هندسة الحاسب، أو مجال ذي صلة.
- يفضل درجة الماجستير أو شهادات مهنية ذات صلة في أمن الشبكات، الأمن السيبراني، أمن البنية التحتية، أو أمن المعلومات.
- خبرة لا تقل عن 8 سنوات في مجال أمن الشبكات، أمن البنية التحتية، عمليات الأمن السيبراني، بنية الأمان، تصميم الشبكات الآمنة، أو المجالات التقنية ذات الصلة.
- خبرة في تصميم وتنفيذ وتحسين ودعم بيئات الشبكات الآمنة وتقنيات أمن المؤسسات.
- خبرة في تخفيف التهديدات، دعم الاستجابة للحوادث، معالجة الثغرات، الضوابط الأمنية، متطلبات الامتثال، والتنسيق مع البائعين.
- خبرة في تقديم إرشادات تقنية على مستوى الخبرة وقيادة مسارات عمل تقنية معقدة تتعلق بحلول أمن الشبكات.
عرض النص الأصلي للإعلان
|
Job Description |
|||||
|
OVERVIEW |
|||||
|
Job Title |
Principal |
Job Code |
644319 |
Grade |
E1 |
|
Group |
Government Products |
Division |
Technology Division |
||
|
Department |
IT Infrastructure |
Unit |
- |
|
ROLE PURPOSE The aim is to state the overall significance of the job from the organization’s perspective. |
|
The role exists to serve as a principal technical authority in network security, responsible for designing, implementing, optimizing, and governing secure network environments across Elm's enterprise technology landscape. The Principal provides expert guidance on advanced security architectures, threat mitigation, incident response, vendor solutions, and operational controls to strengthen resilience, protect enterprise systems, and ensure alignment with Elm's strategic objectives, policies, procedures, information security standards, and compliance requirements. |
|
KEY ACCOUNTABILITIES & ACTIVITIES This section describes the principal outputs required from the job. |
|
|
Key Accountabilities |
Key Activities |
|
1. Network Security Operations Excellence |
• Oversee complex network security operations and ensure alignment with agreed service levels, operational standards, and business requirements. • Analyze and resolve advanced network security incidents, including root cause analysis for major or recurring issues. • Recommend and apply enhancements to improve security posture, operational efficiency, automation, and control effectiveness. • Perform security audits and support compliance with relevant standards, policies, and operational controls. |
|
2. Security Architecture & Service Design |
• Evaluate and recommend advanced network security technologies, configurations, and design patterns to enhance defense capabilities. • Design and validate secure network architectures aligned with threat models, business requirements, and enterprise technology standards. • Conduct gap analysis and assess the effectiveness of implemented network security controls and countermeasures. • Provide expert guidance on complex network security configurations, deployments, design workshops, and architecture reviews. |
|
3. Threat Mitigation & Incident Response Support |
• Support incident response processes, forensic investigations, and documentation for security events affecting network environments. • Apply and maintain operational security controls and countermeasures to reduce exposure to network-based threats. • Contribute to compromise assessment, threat hunting, and vulnerability response activities in coordination with relevant teams. • Implement recommendations from risk assessments, security reviews, and remediation plans to strengthen protection strategies. |
|
4. Secure Connectivity & Encryption Management |
• Manage secure data transmission requirements using appropriate encryption methods, secure connectivity controls, and approved security standards. • Validate secure network configurations to protect enterprise systems, services, and data flows across infrastructure environments. • Support the design and implementation of secure connectivity solutions for internal platforms, external integrations, and business services. • Identify risks related to network access, connectivity, and encryption dependencies and recommend mitigation actions. |
|
5. Project Delivery & RFP Support |
• Draft technical requirements and contribute to requests for proposals for network security solutions and related services. • Provide subject matter expertise in evaluating proposals, vendor solutions, and technical options to support procurement decisions. • Lead assigned technical workstreams in network security projects from planning through implementation and stabilization. • Ensure project deliverables meet technical, security, performance, and operational requirements. |
|
6. Vendor and Support Coordination |
• Serve as the technical point of contact for vendor engagements related to network security technologies and support services. • Manage escalations of critical technical issues with vendors and ensure timely resolution and alignment with Elm requirements. • Review vendor deliverables to ensure compliance with security, performance, architecture, and service expectations. • Coordinate with internal stakeholders and vendors to support effective implementation, maintenance, and optimization of network security solutions. |
|
7. Cross-functional Security Collaboration |
• Collaborate with cybersecurity, infrastructure, operations, architecture, and application teams to address vulnerabilities and strengthen protection strategies. • Provide expert advisory support on network security requirements for technology initiatives, platforms, and service designs. • Align with relevant stakeholders on control implementation, risk mitigation actions, and secure service delivery requirements. • Support disaster recovery planning, testing, and documentation from a network security and connectivity perspective. |
|
8. Reporting, Documentation & Knowledge Transfer |
• Prepare and maintain technical documentation, operational procedures, architecture records, incident analysis, and security configuration references. • Provide clear reports and updates on security operations, risks, incidents, project status, and improvement recommendations. • Share knowledge and provide technical guidance to strengthen team capability and reduce dependency on individual expertise. • Promote continuous improvement of network security practices, processes, monitoring, and operational governance. |
|
9. Policies, Processes & Procedures |
• Follow all relevant departmental policies, processes, standard operating procedures, and instructions so that work is carried out in a controlled and consistent manner. • Comply with all relevant safety, quality, and environmental management policies, procedures, and controls to ensure a healthy and safe work environment. |
|
10. Information Security |
• Comply with all relevant information security practices and standards to ensure data integrity and confidentiality. |
|
JOB SPECIFICATIONS |
|
|
Academic and professional qualifications |
• Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, Computer Engineering, or a related field. |
|
Years and Nature of Experience |
• 8+ years of relevant experience in network security, infrastructure security, cybersecurity operations, security architecture, secure network design, or related technology fields. |
|
VERSION TRACKING |
||
|
Prepared by: |
|
|
|
First review by: |
|
|
|
Approved by: |
Name |
|
|
Signature |
|
|
|
Date |
|