📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

وظيفة Senior Microsoft Security Administrator لدى شركة الوطنية لأنظمة المعلومات (Wisys) في الرياض

Senior Microsoft Security Administrator
🏢 Al Watania Information Systems (Wisys)
🕒 نُشرت: (اليوم) 📍 الرياض وظائف الأمن والسلامة
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

تعلن شركة Al Watania Information Systems (Wisys) عن توفر وظيفة Senior Microsoft Security Administrator في الرياض.

المهام والمسؤوليات

  • إدارة وأمن بيئة M365 E5: تشمل إعداد وصيانة سياسات Conditional Access وMulti-Factor Authentication (MFA) وPrivileged Identity Management (PIM) وIdentity Protection في Entra ID.
  • إدارة أمن نقاط النهاية (Microsoft Defender for Endpoint & Intune): الإشراف على سياسات EDR، وقواعد الامتثال للأجهزة، وقواعد Attack Surface Reduction (ASR)، والمعالجة الآلية على أجهزة Windows والجوال.
  • إدارة البريد الإلكتروني والتعاون (Defender for Office 365): الإشراف على Safe Links وSafe Attachments وسياسات مكافحة التصيد ومكافحة البريد العشوائي وفرز الحجر الصحي.
  • حماية البيانات والحوكمة (Purview): تنفيذ ومراقبة سياسات Data Loss Prevention (DLP) وحساسية التصنيف (Sensitivity Labels) وسياسات Information Barrier عبر خدمات M365.
  • إدارة تطبيقات السحابة (Defender for Cloud Apps): مراقبة الـ Shadow IT وإدارة أذونات تطبيقات OAuth وتطبيق سياسات الجلسات.
  • تشغيل Microsoft Sentinel (SIEM/SOAR): إدارة وتحسين استيعاب السجلات من M365 وEntra ID وDefender XDR وجدران الحماية والبنية التحتية السحابية مع الحفاظ على كفاءة التكلفة.
  • التحليل والكشف: كتابة وتحديث قواعد التحليل بلغة KQL (Kusto Query Language) واستعلامات الصيد ولوحات العمل والتقارير المخصصة.
  • الأتمتة (SOAR): بناء وصيانة playbooks باستخدام Logic Apps لأتمتة سير عمل الاستجابة للحوادث واحتواء التهديدات.
  • الاستجابة للحوادث: إجراء تصنيف المستوى 2/3 والتحقيق وتحليل السبب الجذري للتنبيهات الصادرة من Defender XDR وSentinel.
  • الدعم التشغيلي والصيانة (لمستخدمين يصل عددهم إلى 300): مراجعة مستمرة لـ Microsoft Secure Score ومعالجة التوصيات ومراجعة تراخيص المستخدمين.
  • إدارة التصحيح والثغرات: مراقبة رؤى Defender Vulnerability Management والتنسيق مع فريق الدعم التقني لمعالجة ثغرات البرامج في نقاط النهاية.
  • التعامل مع الطلبات (Escalations): معالجة تذاكر الدعم المتعلقة بحظر الوصول والإيجابيات الكاذبة وإصدارات الحجر الصحي واسترداد الحسابات المخترقة.
  • التوثيق والتقارير: الحفاظ على أدلة تشغيل أمنية دقيقة ورسومات معمارية وتقارير شهرية عن التهديدات والامتثال للإدارة.

الشروط والمتطلبات

  • خبرة عملية لا تقل عن 3 سنوات في إدارة ميزات أمان Microsoft 365، خاصة في بيئة E5 / Defender XDR.
  • خبرة لا تقل عن 3 سنوات في تكوين وتشغيل Microsoft Sentinel.
  • إتقان كتابة استعلامات KQL (Kusto Query Language) للسجلات والتحقيقات وقواعد التحليل.
  • خبرة في Microsoft Intune (MDM/MAM) لإدارة نقاط النهاية بنظام Windows.
  • فهم جيد لـ PowerShell لأتمتة البرمجة النصية وإدارة M365.
  • معرفة عملية بأساسيات الشبكات (DNS، جدران الحماية، VPNs) وأساسيات الهوية السحابية (Entra ID، SAML، SSO).
  • الشهادات التالية مرغوب فيها (ويفضل الحصول على واحدة على الأقل):
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300).
  • Microsoft Certified: Information Protection and Governance Administrator Associate (SC-400).
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) (مرغوب بشدة).
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100).
عرض النص الأصلي للإعلان
  • M365 E5 Security Administration & Engineering
  • Identity & Access (Entra ID): Configure and maintain Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Identity Protection rules
  • Endpoint Security (Microsoft Defender for Endpoint & Intune): Manage EDR policies, device compliance rules, Attack Surface Reduction (ASR) rules, and automated remediation on Windows/mobile devices
  • Email & Collaboration (Defender for Office 365): Oversee Safe Links, Safe Attachments, anti-phishing, anti-spam policies, and quarantine triage
  • Data Protection & Governance (Purview): Implement and monitor Data Loss Prevention (DLP) policies, Sensitivity Labels, and Information Barrier policies across M365 services
  • Cloud Apps (Defender for Cloud Apps): Monitor shadow IT, manage OAuth app permissions, and enforce session policies.
  • 2. Microsoft Sentinel (SIEM/SOAR) Operations
    • Data Connector Management: Maintain and optimize log ingestion from M365, Entra ID, Defender XDR, firewalls, and cloud infrastructure while keeping ingestion costs efficient
    • Detection & Analytics: Write and update KQL (Kusto Query Language) analytics rules, hunting queries, and custom workbooks/dashboards
    • Automation (SOAR): Build and maintain Logic Apps playbooks to automate incident response workflows and threat containment
    • Incident Response: Perform Tier 2/3 triage, investigation, and root-cause analysis on alerts originating from Defender XDR and Sentinel
  • 3. Operational Support & Maintenance (:300 Users)
    • License & Tenant Health: Continuously review Microsoft Secure Score, address recommendations, and audit user license assignments
    • Patch & Vulnerability Management: Monitor Defender Vulnerability Management insights and coordinate with IT support to remediate endpoint software vulnerabilities
    • User Escalations: Handle escalated support tickets regarding access blocks, false positives, quarantine releases, or compromised account recovery
    • Reporting & Documentation: Maintain accurate security operational runbooks, architecture diagrams, and monthly threat/compliance reporting for management

Requirements

  • 3+ years of hands-on experience administering Microsoft 365 security features, specifically within an E5 / Defender XDR environment
  • 3+ years of experience configuring and operating Microsoft Sentinel
  • Strong proficiency in writing KQL (Kusto Query Language) queries for logs, investigations, and analytics rules
  • Experience with Microsoft Intune (MDM/MAM) for Windows endpoint management
  • Solid understanding of PowerShell for M365 scripting and security automation
  • Hands-on knowledge of networking basics (DNS, Firewalls, VPNs) and cloud identity fundamentals (Entra ID, SAML, SSO)

Desirable Certifications (At least one preferred)

  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Information Protection and Governance Administrator Associate (SC-400)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) (Highly Desirable)
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)
المصدر: LinkedIn - أُضيفت للموقع في 2 أغسطس 2026

وظائف أخرى لدى Al Watania Information Systems (Wisys)