وظيفة أخصائي أمن سيبراني شاغرة لدى El Seif Operation and Maintenance في الرياض
تفاصيل الوظيفة
تعلن شركة El Seif Operation and Maintenance (ESOM Holding) عن توفر وظيفة أخصائي أمن معلومات (IT Security Specialist) في الرياض، السعودية، وذلك لحماية الأصول الرقمية والبنية التحتية التقنية والتطبيقات وأنظمة المعلومات، مع الالتزام بمتطلبات الأمن السيبراني السعودية.
نبذة عن الوظيفة
يبحث ESOM Holding عن أخصائي أمن معلومات ذي خبرة لحماية الأصول الرقمية والبنية التحتية التقنية والتطبيقات وأنظمة المعلومات. يجمع الدور بين التقييمات الأمنية العملية، واختبار الاختراق، والحوكمة، وإدارة المخاطر، والامتثال، وإدارة خدمات أمن تكنولوجيا المعلومات. سيدعم المرشح الناجح التوافق مع متطلبات الأمن السيبراني السعودية، بما في ذلك NCA ECC وCSCC وSAMA CSF (حيثما ينطبق)، وذلك في بيئة متوافقة مع ITIL.
المهام والمسؤوليات
- إجراء تقييمات الثغرات واختبار الاختراق عبر الشبكات والبنية التحتية والأنظمة اللاسلكية والتطبيقات والبيئات السحابية.
- إجراء اختبار أمن التطبيقات الثابت والديناميكي (SAST وDAST) وتقديم توصيات عملية للعلاج.
- تطوير وصيانة سياسات وإجراءات أمن المعلومات وسجلات المخاطر والمعايير ووثائق الامتثال للأمن السيبراني.
- دعم التوافق مع أطر الأمن السيبراني السعودية، بما في ذلك NCA ECC وCSCC، والتنسيق لعمليات تدقيق الأمن السيبراني الداخلية والخارجية.
- مراجعة بنية النظام والشبكة، ومراقبة التهديدات الناشئة، وتقييم مخاطر الأمن من الأطراف الثالثة، وضمان ممارسات التصميم الآمن.
- إدارة الحوادث الأمنية، والتحقيقات في السبب الجذري، وضوابط استمرارية الخدمة، وسجلات الأمن، ومؤشرات الأداء الرئيسية، وتحديثات CMDB ضمن بيئة متوافقة مع ITIL.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو علوم الحاسب أو تقنية المعلومات أو مجال ذي صلة.
- خبرة لا تقل عن 5 سنوات مخصصة في أمن البنية التحتية أو اختبار أمن التطبيقات أو اختبار الاختراق أو حوكمة الأمن السيبراني.
- خبرة عملية مع أدوات مثل Nessus وBurp Suite وMetasploit وWireshark أو Acunetix.
- فهم قوي لبروتوكولات الشبكات وجدران الحماية وإدارة الهوية والوصول ومعايير التشفير وممارسات البرمجة الآمنة.
- معرفة قوية بأطر الامتثال للأمن السيبراني السعودية، خاصة NCA ECC وCSCC.
- معرفة عملية بإدارة خدمات ITIL وإدارة الحوادث وإدارة المشكلات واستمرارية الخدمة.
- إجادة مهنية لكل من اللغتين العربية والإنجليزية.
- الجنسية سعودية (إلزامي) - وفقًا للمتطلبات التنظيمية السعودية.
- يفضل: شهادة في الأمن السيبراني مثل CEH أو OSCP أو CISSP أو CISM أو CompTIA Security+.
- يفضل: شهادة ITIL Foundation.
- يفضل: خبرة مع SAMA CSF أو أمن السحابة أو تقييم مخاطر الطرف الثالث أو تدقيق الأمن السيبراني المؤسسي.
عرض النص الأصلي للإعلان
Job Title: IT Security Specialist
Department: Group Information Technology
Location: Riyadh, Saudi Arabia
Employment Type: Full-time
Nationality Requirement: Saudi (Mandatory)
Note: This position is restricted to Saudi Nationals only in accordance with applicable Saudi Arabian regulatory and compliance requirements. Applications from non-Saudi candidates will be automatically disqualified and will not proceed to profile review.
Experience: Minimum 5 years
Reporting To: Head of Information Security / Group Director of IT
About the Role
ESOM Holding is seeking an experienced IT Security Specialist to protect the organization’s digital assets, technology infrastructure, applications, and information systems.
The role combines hands-on cybersecurity assessments, penetration testing, governance, risk management, compliance, and IT security service management. The successful candidate will support alignment with Saudi cybersecurity requirements, including NCA ECC, CSCC, and SAMA CSF where applicable, within an ITIL-aligned environment.
Key Responsibilities
- Conduct vulnerability assessments and penetration testing across networks, infrastructure, wireless systems, applications, and cloud environments.
- Perform static and dynamic application security testing, including SAST and DAST, and provide practical remediation recommendations.
- Develop and maintain information security policies, procedures, risk registers, standards, and cybersecurity compliance documentation.
- Support alignment with Saudi cybersecurity frameworks, including NCA ECC and CSCC, and coordinate internal and external cybersecurity audits.
- Review system and network architectures, monitor emerging threats, assess third-party security risks, and ensure secure-by-design practices.
- Manage security incidents, root-cause investigations, service continuity controls, security records, KPIs, and CMDB updates within an ITIL-aligned environment.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related discipline.
- Minimum 5 years of dedicated experience in infrastructure security, application security testing, penetration testing, or cyber governance.
- Hands-on experience with tools such as Nessus, Burp Suite, Metasploit, Wireshark, or Acunetix.
- Strong understanding of network protocols, firewalls, identity and access management, encryption standards, and secure coding practices.
- Strong knowledge of Saudi cybersecurity compliance frameworks, particularly NCA ECC and CSCC.
- Working knowledge of ITIL service management, incident management, problem management, and service continuity.
- Professional proficiency in both Arabic and English.
Preferred Qualifications
- Cybersecurity certification such as CEH, OSCP, CISSP, CISM, or CompTIA Security+.
- ITIL Foundation certification.
- Experience with SAMA CSF, cloud security, third-party risk assessments, or enterprise cybersecurity audits.
وظائف أخرى لدى El Seif Operation and Maintenance