📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

البحر الأحمر الدولية تعلن عن وظيفة مساعد مدير إدارة الثغرات في الرياض

Assistant Manager - Vulnerability Management
🏢 البحر الأحمر الدولية (Red Sea Global)
🕒 نُشرت: (منذ 12 يوماً) 📍 الرياض وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

تعلن شركة البحر الأحمر الدولية (RSG) عن وظيفة مساعد مدير - إدارة الثغرات (Assistant Manager - Vulnerability Management) في الرياض، السعودية.

نبذة عن الوظيفة

  • الإشراف على دورة حياة إدارة الثغرات بالكامل عبر أنظمة RSG وشبكاتها وتطبيقاتها وأصولها السحابية، مع ضمان رؤية مستمرة للتعرضات وتنفيذ المعالجة في الوقت المناسب.

المهام والمسؤوليات

  • الحفاظ على جرد أصول محدث باستمرار يشمل البيئات المحلية والسحابية والمحمولة والبيئات التشغيلية (OT)، مع ربط التعرضات بأهمية الأصول وسياق المخاطر التجارية.
  • تخطيط وتنفيذ المسح المستمر للثغرات وتقييمات التهيئة وكشف سوء التهيئة عبر البنية التحتية الرقمية لـ RSG لضمان التغطية الشاملة.
  • ترتيب أولويات الثغرات المحددة باستخدام أطر قائمة على المخاطر تدمج تقييمات أهمية الأصول ومصادر معلومات التهديدات واحتمالية الاستغلال.
  • التنسيق مع فرق المعالجة (بما في ذلك مالكي البنية التحتية والتطبيقات والسحابة) لتوجيه أنشطة التصحيح وتغييرات التهيئة وتنفيذ الضوابط التعويضية.
  • تتبع والتحقق من تقدم المعالجة من خلال دورات إعادة اختبار منظمة، والتحقق من الإصلاحات وتأكيد إغلاق النتائج المفتوحة وفقاً لمستويات الخدمة المحددة (SLAs).
  • إنتاج تقارير حالة الثغرات ولوحات البيانات التي تغطي النتائج المفتوحة وتقدم المعالجة ومقاييس العمر واتجاهات تقليل التعرض العامة لمراجعة أصحاب المصلحة.
  • الحفاظ على سياسة إدارة الثغرات وسير العمل التشغيلي وتكوين مجموعة الأدوات ووثائق الحوكمة وتحسينها باستمرار بما يتماشى مع معايير الأمن السيبراني.
  • دعم دمج ضوابط إدارة الثغرات في خطوط DevOps وCI/CD، والمساهمة في ممارسات التطوير الآمن عبر دورة حياة تسليم التقنية في RSG.
  • المساهمة في أتمتة سير عمل إدارة الثغرات من خلال أدوات البرمجة النصية والتنسيق لتعزيز كفاءة المسح وتقليل الجهد اليدوي.

الشروط والمتطلبات

  • درجة البكالوريوس في الأمن السيبراني أو تقنية المعلومات أو علوم الحاسب أو مجال ذي صلة.
  • شهادات مهنية (يفضل): Certified Ethical Hacker (CEH)، CompTIA Security+، GIAC Vulnerability Assessment Analyst (GEVA).
  • خبرة لا تقل عن 6 سنوات في الأمن السيبراني، وإدارة الثغرات، وتقييم الثغرات، وتنسيق المعالجة، وإدارة مخاطر الأمن في بيئات المؤسسات. يفضل الخبرة في أمن السحابة، وإدارة التعرضات، والتعاون متعدد الوظائف مع فرق البنية التحتية والتطبيقات والأمن.

المهارات المطلوبة

  • اكتشاف الأصول وإدارة المخزون
  • مسح الثغرات وتشغيل الأدوات
  • ترتيب أولويات الثغرات القائم على المخاطر
  • تنسيق إدارة التصحيح وتتبع المعالجة
  • أتمتة سير عمل إدارة الثغرات
  • إعداد تقارير مقاييس الثغرات ولوحات البيانات
  • إدارة الثغرات في البيئات السحابية
  • دمج الثغرات في DevOps وCI/CD الآمن
  • أمن الأنظمة التشغيلية (OT) والأنظمة الصناعية
عرض النص الأصلي للإعلان

Be the change. Join the world’s most visionary developer.


Red Sea Global (RSG) is showing that there is a better way to positively shape the places we live, work and travel.


We are purpose-driven and committed to people and planet. Our transformative programs are a driving force to achieving Vision 2030, as well as leading the world towards regenerative tourism.


Join RSG and be part of the positive change for Saudi Arabia and the world.


Job Purpose

Supervise the end-to-end vulnerability management lifecycle across RSG's systems, networks, applications, and cloud assets, ensuring continuous exposure visibility and timely remediation execution.


KEY RESPONSIBILITIES/ ACCOUNTABILITIES

/ Include not limited too


  • Maintain a continuously updated asset inventory spanning on-premises, cloud, mobile, and OT environments, mapping exposures against asset criticality and business risk context.


  • Plan and execute continuous vulnerability scanning, configuration assessments, and misconfiguration detection across RSG's digital infrastructure to ensure comprehensive coverage.


  • Prioritize identified vulnerabilities using risk-based frameworks that integrate asset criticality ratings, threat intelligence feeds, and exploit likelihood scoring.


  • Coordinate with remediation teams, including infrastructure, application, and cloud owners. to guide patching activities, configuration changes, and compensating control implementation.


  • Track and verify remediation progress through structured retesting cycles, validating fixes and confirming closure of open findings in line with defined SLAs.


  • Produce vulnerability status reports and dashboards covering open findings, remediation progress, aging metrics, and overall exposure reduction trends for senior stakeholder review.


  • Maintain and continuously improve the vulnerability management policy, process workflows, toolchain configuration, and governance documentation in alignment with cybersecurity standards.


  • Support the integration of vulnerability management controls into DevOps and CI/CD pipelines, contributing to secure development practices across RSG's technology delivery lifecycle.


  • Contribute to the automation of vulnerability management workflows through scripting and orchestration tools to enhance scanning efficiency and reduce manual effort.


KNOWLEDGE AND EXPERIENCE


Academic Qualifications

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.


Professional Certifications


  • Certified Ethical Hacker (CEH) - Preferred
  • CompTIA Security+ - Preferred
  • GIAC Vulnerability Assessment Analyst (GEVA) - Preferred


Skills

  • Asset Discovery and Inventory Management
  • Vulnerability Scanning and Tool Operation
  • Risk-Based Vulnerability Prioritization
  • Patch Management Coordination and Remediation Tracking
  • Automation of Vulnerability Management Workflows
  • Vulnerability Metrics Reporting and Dashboard Creation
  • Cloud Vulnerability Management
  • Secure DevOps / CI/CD Vulnerability Integration
  • OT and Industrial Control Systems Security


Experience

Years & Nature of Experience


Minimum 6 years of experience in cybersecurity, vulnerability management, vulnerability assessment, remediation coordination, and security risk management within enterprise environments. Experience in cloud security, exposure management, and cross-functional collaboration with infrastructure, application, and security teams is preferred.

المصدر: LinkedIn - أُضيفت للموقع في 1 أغسطس 2026

وظائف أخرى لدى البحر الأحمر الدولية