انضم إلى Accenture Middle East كمستشار أمني (Security Delivery Consultant) في جازان، السعودية، حيث ستكون مسؤولاً عن تصميم ونشر وصيانة حلول الأمن السيبراني المتقدمة ضمن فريق Accenture Security.
المهام والمسؤوليات
- تصميم ونشر وصيانة بيئة Tenable.sc بما في ذلك ماسحات Nessus والعوامل والموصلات عبر قطاعي IT وOT/ICS.
- إدارة سياسات الفحص والجداول وبيانات الاعتماد ومناطق الماسح لتعظيم التغطية.
- دمج Tenable مع CMDB وأنظمة التذاكر (ServiceNow / Jira) ومنصات SIEM.
- الحفاظ على صحة الماسح وتحديثات الإضافات والامتثال للتراخيص وتخطيط السعة؛ وإدارة دورات الترقية والتصحيح.
- تحديد وفرض عملية إدارة الثغرات الأمنية الشاملة: الاكتشاف، التحديد، تقييم المخاطر، تعيين اتفاقيات مستوى الخدمة، المعالجة، التحقق، ومعالجة الاستثناءات.
- تطبيق تحديد الأولويات القائم على المخاطر باستخدام CVSS وEPSS وVPR (تصنيف أولوية الثغرات من Tenable) وأهمية الأصول ومصادر استخبارات التهديدات.
- قيادة جهود المعالجة بالتعاون مع مالكي الأنظمة، ونشر إرشادات معالجة واضحة، وتتبع الالتزام باتفاقيات مستوى الخدمة في لوحات البيانات.
- تطوير وصيانة ومراجعة وثائق سياسة إدارة الثغرات الأمنية ومعاييرها وإجراءاتها.
- إدارة منصة Darktrace للكشف والاستجابة للشبكة (NDR).
- تطوير وإدارة سياسات NDR.
- دمج NDR مع SIEM وأدوات الأمان الأخرى.
- ضبط نماذج الكشف في NDR وضبط الحساسية وتقليل النتائج الإيجابية الخاطئة.
- مراقبة صحة أجهزة NDR واتصال المستشعرات وضمان الرؤية المستمرة عبر الشبكة.
- تطبيق تحديثات NDR وإدارة تغييرات التكوين وضمان التوافق مع سياسات الأمان.
- إدارة العمليات اليومية لمنصة ThreatQ لاستخبارات التهديدات (TIP)، بما في ذلك استيعاب البيانات وإثرائها وتكوين سير العمل.
- تكوين وصيانة التكامل مع خلاصات استخبارات التهديدات.
- تطبيق نماذج التسجيل وقواعد الإثراء ومنطق تحديد الأولويات لضمان ظهور الاستخبارات عالية القيمة.
- بناء وتحسين سير العمل الآلي.
- الحفاظ على تكامل TIP مع SIEM وضوابط الأمان أو المنصات الأخرى.
المتطلبات
- خبرة عملية من 5 إلى 8 سنوات في مجال أمن المعلومات مع تركيز لا يقل عن 3 سنوات على إدارة الثغرات الأمنية.
- خبرة عملية لا تقل عن سنتين في إدارة Tenable SC (إلزامي).
- فهم قوي لفئات الثغرات الشائعة (OWASP Top 10, CWE Top 25, CVE ecosystem) وسير عمل إدارة التصحيحات.
- خبرة عملية في إدارة NDR Darktrace (موصى به).
- خبرة عملية في إدارة TIP ThreatQ (موصى به).
- موقع العمل: جازان، المملكة العربية السعودية.
عرض النص الأصلي للإعلان
About Accenture
Accenture helps the world’s leading enterprises reinvent by building their digital core and unleashing the power of AI to create value at speed for organizations across industries. Our strategy is to be the reinvention partner of choice for our clients and lead in the safe, widespread adoption of AI, and to be the most client-focused, AI-enabled, great place to work in the world. We bring together the talent of our approximately 786,000 people with proprietary assets and platforms, deep process and industry expertise, and leading ecosystem relationships to deliver end-to-end solutions and measurable outcomes at scale. Through our Reinvention Services, we offer broad expertise across Cybersecurity, Digital Core, Finance, Industry and Enterprise, Song, Supply Chain and Engineering, and Talent, with advanced capabilities in AI and Data, Industry and Process, and Technology. We serve approximately 9,000 clients and generated approximately $70 billion in FY25 revenue. Visit us at accenture.com.
Accenture Security
Join Accenture Security to pioneer security solutions that blend risk strategy, digital identity, cyber defense, application security and managed services. Using the coolest next-gen tech, you’ll have every chance to stay one step ahead of cybercrime and out-hack the hackers.
Accenture Security provides comprehensive security services - from security strategy development to business transformation, to managed security services - on demand and at a global scale to help mitigate risks and take full advantage of advanced technologies and proven risk management models. Our experienced team of global security professionals helps businesses understand their risks and build resilience from the inside out, giving them the confidence to focus on what matters most: innovation and business growth.
Job Description :
Architect, deploy, and maintain Tenable.sc environment including Nessus scanners, agents, and connectors across IT and OT/ICS segments.
Manage scan policies, schedules, credentials, and scanner zones to maximize coverage
Integrate Tenable with CMDB, ticketing (ServiceNow / Jira), and SIEM platforms
Maintain scanner health, plugin updates, license compliance, and capacity planning; own upgrade and patch cycles.
Define and enforce the end-to-end vulnerability management process: discovery, identification, risk scoring, SLA assignment, remediation, verification, and exception handling.
Apply risk-based prioritization using CVSS, EPSS, VPR (Tenable Vulnerability Priority Rating), asset criticality, and threat intelligence feeds.
Drive remediation efforts by collaborating with system owners, publishing clear remediation guidance, and tracking SLA adherence in dashboards.
Develop, maintain, and review vulnerability management policy, standards, and procedures documentation.
Administration of NDR (Endpoint Detection and Response) Darktrace platform
Develop and manage NDR policies
Integration of NDR with SIEM and other Security tools
Fine tune NDR detection models, adjust sensitivity, and reduce false positives.
Monitor NDR appliance health, sensor connectivity and ensure continuous visibility across the network.
Apply NDR updates, manage configuration changes, and ensure alignment with security policies.
Manage day to day operations of the ThreatQ Threat Intelligence Platform (TIP), including data ingestion, enrichment, and workflow configuration
Configure and maintain integrations with threat intel feeds
Apply scoring models, enrichment rules, and prioritization logic to ensure high value intelligence is surfaced
Build and optimize automated workflows
Maintain integrations of TIP with SIEM, Security controls or other platforms.
Skills and Qualifications :
5-8 years of hands-on experience in information security with at least 3 years focused on vulnerability management
2+ years of hands-on experience in administering Tenable SC is a must
Solid understanding of common vulnerability classes (OWASP Top 10, CWE Top 25, CVE ecosystem) and patch management workflows
Hands on experience in administration of NDR Darktrace is recommended
Hands on experience in administration of TIP Threatq is recommended
Work location: Jazan, KSA