📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

هيئة الزكاة والضريبة والجمارك تعلن عن وظيفة أخصائي أول أمن المعلومات - GRC في الرياض

Information Security GRC Lead Specialist
🏢 هيئة الزكاة والضريبة والجمارك
🕒 نُشرت: (اليوم) 📍 الرياض وظيفة حكومية وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

هيئة الزكاة والضريبة والجمارك تعلن عن وظيفة أخصائي أول في حوكمة أمن المعلومات والمخاطر والامتثال (GRC) في الرياض.

نبذة عن الوظيفة

شاغلو هذا المستوى هم محترفون ذوو خبرة قادرون على تنفيذ العمل بتوجيهات عامة. يركزون بشكل أساسي على تطوير حلول للتحديات التي تتطلب بعض التحليل لفهمها وحلها، ومعالجة المشكلات التي يتم رفعها من المستويات المبتدئة. يقومون بأنشطة تشغيلية معقدة تشمل المساعدة في وضع سياسات ومعايير أمن المعلومات، وتطوير العمليات ذات الصلة، وتطوير برامج حوكمة أمن المعلومات وإدارة المخاطر والامتثال، ومراجعة نتائج تقييم الأمن السيبراني ووضع خطة التخفيف اللازمة، ومراقبة سجل مخاطر الأمن السيبراني، ومتابعة التنفيذ والتوصية بإجراءات التحسين، والتعرف على أنماط وحالات عدم الامتثال لسياسات الأمن السيبراني، وتحديد الفجوات والتوصية بمجالات التحسين.

المهام والمسؤوليات

  • حوكمة أمن المعلومات: وضع سياسات ومعايير أمن المعلومات وتطوير العمليات ذات الصلة بما يضمن التوافق مع المتطلبات التنظيمية للأمن السيبراني.
  • تصميم إجراءات وأطر أمن المعلومات لضمان الاتساق في تنفيذ الضوابط الأمنية.
  • تطوير برامج حوكمة أمن المعلومات وإدارة المخاطر والامتثال للإدارة الفعالة لمخاطر تقنية المعلومات والامتثال للمتطلبات.
  • إعداد برامج التوعية بالأمن السيبراني ووضع خطة تعليمية تشمل ورش العمل والندوات وغيرها حول المعايير والسياسات وعمليات الحوكمة لتعزيز الوعي والمعرفة بموضوعات الأمن السيبراني لدى موظفي الهيئة.
  • إدارة مخاطر أمن المعلومات: إجراء تقييم مخاطر الأمن السيبراني لتحديد المخاطر المحتملة والتغيرات اليومية ذات الصلة، وبدء تطوير خطة التخفيف اللازمة.
  • تطوير خطة تخفيف المخاطر وخطة المعالجة لإدارة المخاطر بفعالية وفقًا لرغبة الهيئة في المخاطرة.
  • إدارة مخاطر الأمن السيبراني وسجل المخاطر لتحديد وتسجيل وتتبع المخاطر المحتملة وضمان الامتثال لمعايير الأمن السيبراني وسياسات وإجراءات الحوكمة.
  • متابعة تنفيذ الضوابط المخففة وفقًا للخطة الموضوعة وضمان تحديث سجل المخاطر.
  • إجراء تقييم المخاطر لعدم المطابقات المحددة أثناء عمليات تدقيق الأمن والتوصية بإجراءات التحسين اللازمة لقدرات الحماية والكشف.
  • الامتثال لأمن المعلومات: إجراء تدقيق أمن المعلومات وتقييم نصف سنوي ضد NCA وتقييم سنوي ضد ISO 27001 للتعرف على أنماط وحالات عدم الامتثال لسياسات الأمن السيبراني والتوصية بمجالات التحسين.
  • إدارة حالات عدم الامتثال وتحسين العمليات والعمليات التجارية من خلال دعم التقييمات الخارجية ضد إطار NCA.
  • إعداد تقرير دوري يجمع حالة الامتثال لأمن المعلومات وإبلاغه للجهات التنظيمية (ISO 27001 و NCA).
  • التنظيم والعمليات: اتباع جميع السياسات والعمليات ذات الصلة وإجراءات التشغيل القياسية لضمان تنفيذ العمل بطريقة محكومة ومتسقة.
  • المساعدة في حل المشكلات المرفوعة وتقديم الدعم اللازم للفريق المبتدئ لضمان تنفيذ العمل بكفاءة.
  • رفع المشكلات المعقدة إلى الشخص المعني لضمان إغلاق الحالات/المشكلات بشكل صحيح.
  • أداء مهام أخرى حسب الطلب.
  • إدارة الأفراد: تدريب الموظفين المبتدئين على الأنشطة الوظيفية المختلفة لضمان نقل المعرفة، عند الاقتضاء.
  • توفير توجيه واضح، وتحديد أولويات المهام، وتعيين المسؤوليات وتفويضها، ومراقبة سير العمل للمرؤوسين/الموظفين المبتدئين.
  • دعم الموظفين المبتدئين أو المرؤوسين المباشرين لتنفيذ مهامهم وفقًا للسياسات والعمليات الموضوعة.

الشروط والمتطلبات

  • درجة البكالوريوس في علوم الأمن السيبراني أو ما يعادلها.
  • خبرة لا تقل عن 4 سنوات في مجال ذي صلة.

المهارات المطلوبة

  • التعاون والتواصل - مستوى متطور
  • إدارة عمليات تقنية المعلومات - مستوى proficient
  • الاحترافية - مستوى proficient
  • إدارة المشاريع - مستوى proficient
  • التوجه نحو النتائج - مستوى proficient
  • الامتثال لتقنية المعلومات - مستوى متقدم
  • أمن المعلومات - مستوى proficient
  • التركيز على العملاء - مستوى proficient
  • تمكين التغيير والابتكار - مستوى متطور
  • إدارة الموردين - مستوى proficient
  • حوادث الأمن السيبراني والتحقيق - مستوى proficient
عرض النص الأصلي للإعلان
Purpose of Job

Jobholders at this level are experienced professionals capable of conducting work with general directions. They are primarily concerned with developing solutions to challenges which require some analysis to understand and resolve, and addressing issues escalated from junior levels. They undertake complex operational activities including assisting in setting information security policies and standards, developing related processes, developing information security, governance, risk and compliance programs, reviewing cybersecurity assessment results and develop accordingly needed mitigation plan, monitoring cybersecurity risk register, following-up on the implementation and recommending improvement actions, recognizing patterns and cases of noncompliance with cybersecurity policies, and identifying gaps and recommend areas of improvement.

Job Resposiblites

Job Details

Information Security Governance

  • Set information security policies, standards and develop accordingly related processes ensuring alignment with cybersecurity regulatory requirements
  • Design information security procedures and frameworks to ensure consistency in the implementation of security control
  • Develop information security, governance, risk and compliance programs for effective management of IT and security risks meeting compliance requirements
  • Prepare cybersecurity awareness programs and develop education plan including workshops, seminars, etc. regarding standards, policies and governance processes foster attentiveness and knowledge in cybersecurity topics across ZATCA’s employees

Information Security Risk Management

  • Conduct cybersecurity risk assessment to identify potential risks and related daily changes initiating the development of needed mitigation plan
  • Develop risk mitigation plan and remediation plan to effectively manage risk in accordance with ZATCA’s risk appetite
  • Manage cybersecurity risks and risks register to identify, log and track potential risks ensuring compliance with cybersecurity standards and governance policies and procedures
  • Follow-up on the implementation of corresponding mitigating controls as per set plan ensuring update of risk register
  • Conduct risk assessment for the identified non-conformities during security audits and recommend accordingly needed improvement action for protection and detection capabilities

Information Security Compliance

  • Perform information security audit, semiannually assessment against NCA and annually assessment against ISO 27001 to recognize patterns and cases of non-compliance with cybersecurity policies and recommend accordingly areas of improvement
  • Manage non-compliance cases improving business process and operations by supporting external assessments against NCA framework
  • Develop periodic report consolidating the status of information security compliance and report it with regulates (ISO 27001 & NCA)

Organization and Operations

  • Follow all relevant policies, processes and standard operating procedures so that work is carried out in a controlled and consistent manner
  • Help in solving escalated problems and provide needed support for junior team to ensure work is carried out in an efficient manner
  • Escalate complex problems to the relevant person to ensure cases/issues are closed properly
  • Perform other duties as requested

People Management

  • Train junior staff on the different job activities to ensure transfer of know-how, when applicable
  • Provide clear direction, prioritize tasks, assign and delegate responsibility, and monitor the workflow of subordinates/ junior staff
  • Support junior staff or direct reports in order to execute their duties according to set policies and processes

Communication and Contacs

Education

Bachelor’s degree in Science in Cybersecurity or equivalent is required

Experience

A minimum of 4 years of relevant experience

Competencies

Collaboration and Communication - Developing

IT Operations Management - Proficient

Professionalism - Proficient

Project Management - Proficient

Results Oriented - Proficient

IT Compliance - Advanced

Information Security - Proficient

Customer Focus - Proficient

Enablement of Change and Innovation - Developing

Vendor Management - Proficient

Cybersecurity Incident and Investigation - Proficient
المصدر: LinkedIn - أُضيفت للموقع في 30 يوليو 2026
📚 دليل ذو صلةالتقديم على الوظائف الحكومية عبر جدارة (جدارات): دليل كامل خطوة بخطوة

وظائف أخرى لدى هيئة الزكاة والضريبة والجمارك