وظيفة مهندس أمن سيبراني لدى Road Cafe في الرياض
Cyber Security Engineer
🏢 Road Cafe
تفاصيل الوظيفة
تعلن شركة Road Cafe عن حاجتها إلى توظيف مهندس أمن سيبراني للعمل في الرياض، المملكة العربية السعودية.
نبذة عن الوظيفة
- يتولى مسؤولية حماية البنية التحتية الرقمية للمؤسسة وأنظمة المعلومات وأصول البيانات من التهديدات السيبرانية، مع ضمان المراقبة المستمرة للضوابط الأمنية، والاستجابة السريعة للحوادث، وإدارة المخاطر، والالتزام الصارم بأطر الأمن السيبراني السعودية (مثل الضوابط الأساسية للأمن السيبراني الصادرة عن الهيئة الوطنية للأمن السيبراني) والمعايير الدولية.
المهام والمسؤوليات
- تنفيذ ومراقبة وصيانة أطر الأمن السيبراني بما يتوافق مع متطلبات الهيئة الوطنية للأمن السيبراني (NCA) مثل ECC وCSCC، بالإضافة إلى NIST وPDPL وISO 27001.
- مراقبة سجلات الأمن والشبكات والأنظمة عبر أدوات SIEM (إدارة المعلومات والأحداث الأمنية) للكشف عن أي نشاط غير معتاد أو غير مصرح به أو ضار، وقيادة أو المساعدة في احتواء الاختراقات الأمنية والتحقيق فيها والقضاء عليها.
- إجراء تقييمات منتظمة للثغرات الأمنية وتنسيق اختبارات الاختراق (VAPT) عبر البنية التحتية والمنصات السحابية والتطبيقات، والحفاظ على سجل المخاطر الأمنية للمؤسسة وتحديثه.
- مراجعة تكوينات الأنظمة وجدران الحماية وهياكل الشبكات والنشر السحابي (الهجين/المحلي) لضمان اتباع مبادئ "الثقة المعدومة" (Zero Trust) والدفاع المتعمق.
- دعم أمن الأنظمة التشغيلية (OT) وأنظمة التحكم الصناعي (ICS/SCADA) في قطاعات الطاقة والصناعة.
- إعداد تقارير فنية وتنفيذية (أسبوعية وشهرية وربعية) حول الوضع الأمني للمؤسسة، وتسهيل عمليات التدقيق الداخلي أو الخارجي المتعلقة بالامتثال.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو مجال ذي صلة.
- خبرة من 5 إلى 8 سنوات متقدمة في عمليات الأمن السيبراني أو إدارة المخاطر أو الامتثال، مع خبرة في الشبكات وجدران الحماية.
- شهادة CCNA أو CCNP إلزامية.
المهارات المطلوبة
- فهم عميق لبروتوكولات الشبكات الأساسية، وجدران الحماية، وحماية نقاط النهاية، ومعايير التشفير.
- خبرة عملية في أدوات الأمن مثل SIEM وEDR وماسحات الثغرات (مثل Nessus/Qualys).
- معرفة شاملة بأطر العمل مثل NCA ECC وNIST CSF وISO 27001 وPDPL.
- خبرة عميقة وعملية في جدران حماية Fortinet.
- مهارات قوية في التفكير النقدي والتحليل وحل المشكلات في مجال التحقيق الرقمي.
- مهارات ممتازة في التواصل اللفظي والكتابي لعرض البيانات التقنية المعقدة بوضوح لأصحاب المصلحة غير التقنيين.
- القدرة على العمل بفعالية تحت الضغط أثناء سيناريوهات الاستجابة للحوادث.
- الشهادات المهنية المفضلة: CISSP، CISM، CompTIA Security+/CySA+، CEH أو شهادات GIAC.
عرض النص الأصلي للإعلان
Job Purpose
The Cybersecurity Specialist is responsible for safeguarding the organization’s digital infrastructure, information systems, and data assets against cyber threats. This role ensures the continuous monitoring of security controls, swift incident response, risk management, and strict alignment with Saudi national cybersecurity frameworks (such as the NCA Essential Cybersecurity Controls) and international
standards.
Key Responsibilities
- Governance & Compliance (NCA Alignment): Implement, monitor, and maintain security frameworks in strict compliance with the Saudi National Cybersecurity Authority (NCA) mandates (e.g., ECC, CSCC), NIST, PDPL & ISO 27001.
- Threat Monitoring & Incident Response: Monitor security logs, networks, and systems via SIEM (Security Information and Event Management) tools for unusual, unauthorized, or malicious activity. Lead or assist in the containment, eradication, and investigation of security breaches.
- Risk Assessments & VAPT: Conduct regular vulnerability assessments and coordinate penetration testing (VAPT) across infrastructure, cloud platforms, and applications. Maintain and update the organizational Cybersecurity Risk Register.
- Security Architecture Support: Review system configurations, firewalls, network architectures, and cloud deployments (hybrid/on-premises) to ensure they follow "Zero Trust" and defense-in-depth principles.
- OT/ICS Security (For Energy/Industrial sectors): Support the security of Operational Technology (OT) and Industrial Control Systems (ICS/SCADA).
- Reporting & Auditing: Prepare technical and executive reports (weekly, monthly, quarterly) on the organization's security posture and actively facilitate internal or third-party compliance audits.
Education & Experience
- Degree: Bachelor’s degree in Cybersecurity, Information Security, or a related field.
- Experience: 5 to 8 years of progressive experience in cybersecurity operations, risk management, or compliance, network and firewall.
Technical Skills
- Deep understanding of core networking protocols, firewalls, endpoint protection, and encryption standards.
- Hands-on experience with security tools (SIEM, EDR, Vulnerability Scanners like Nessus/Qualys).
- Thorough knowledge of frameworks like NCA ECC, NIST CSF, ISO 27001 & PDPL.
- Deep knowledge and Hands on Fortinet Firewall
- Must be CCNA/CCNP certified
Soft Skills
- Strong critical thinking, analytical, and digital forensic problem-solving skills.
- Excellent verbal and written communication skills to present complex technical data clearly to non-technical stakeholders. · Ability to work effectively under pressure during active incident response scenarios.
Preferred Professional Certifications
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- CompTIA Security+ / CySA+ (For entry to mid-level) · Certified Ethical Hacker (CEH) or GIAC certifications
المصدر: LinkedIn - أُضيفت للموقع في 2 أغسطس 2026