وظيفة مهندس معماري للأمن السيبراني - OT/ICS لدى FNRCO في الرياض
Cyber Security Architect - OT/ICS
🏢 FNRCO
تفاصيل الوظيفة
يسر شركة FNRCO الإعلان عن توفر وظيفة مهندس أمن سيبراني للبنية التحتية (Cyber Security Architect - OT/ICS) في الرياض، المملكة العربية السعودية.
المهام والمسؤوليات
- تصميم وصيانة البنية الأمنية للمؤسسة بما يتوافق مع متطلبات الأعمال والتقنية والامتثال.
- تحديد معايير الأمان والمراجع المعمارية والنماذج والقواعد التوجيهية للسحابة والشبكات والتطبيقات والهوية والبيانات والبنية التحتية.
- مراجعة تصاميم الحلول وضمان تضمين متطلبات الأمان منذ مرحلة التصميم المبكرة.
- إجراء تقييمات معمارية أمنية للأنظمة الجديدة والمنصات وعمليات التكامل وبرامج التحول.
- تحديد المخاطر الأمنية، والتوصية بالإجراءات الرقابية، ودعم خطط معالجة المخاطر.
- العمل مع فرق البنية التحتية والسحابة والتطبيقات والشبكات والهوية (IAM) ومركز العمليات الأمنية (SOC) والحوكمة والامتثال (GRC) والتقنيات التشغيلية (OT) لضمان التطبيق الآمن منذ التصميم.
- ترجمة متطلبات الأعمال والتقنية إلى ضوابط أمنية عملية.
- دعم تطبيق نماذج الثقة الصفرية (Zero Trust) والدفاع المتعمق والتجزئة وأقل صلاحية والوصول الآمن والمراقبة الآمنة.
- تحديد متطلبات الأمان لعمليات التكامل مع الجهات الخارجية وواجهات برمجة التطبيقات (APIs) والوصول عن بُعد وأعباء العمل السحابية والأنظمة الحرجة.
- دعم حوكمة الأمان عبر مراجعة الاستثناءات والانحرافات والتنازلات المعمارية.
- تقديم التوجيه الفني لفرق المشروع خلال مراحل التصميم والبناء والاختبار والنشر.
- ضمان امتثال الحلول للسياسات الداخلية والمتطلبات التنظيمية والمعايير ذات الصلة مثل ISO 27001 وNIST وCIS وIEC 62443 وغيرها من الأطر المطبقة.
- التعاون مع فرق مركز العمليات الأمنية (SOC) والعمليات لضمان تضمين متطلبات تسجيل الأمان والمراقبة والكشف والاستجابة في تصاميم الحلول.
- الحفاظ على توثيق البنية الأمنية والمخططات وسجلات القرارات وخرائط الضوابط.
- مواكبة التهديدات الناشئة وتقنيات الأمان وأفضل الممارسات المعمارية.
الشروط والمتطلبات
- خبرة لا تقل عن 6 سنوات في بيئات التقنيات التشغيلية (OT) بما في ذلك أنظمة التحكم الصناعي (ICS) وSCADA وPLCs وHMIs ومحطات العمل الهندسية وقواعد البيانات التاريخية والشبكات الصناعية.
- فهم معماري شبكات OT ونموذج Purdue والمناطق والقنوات الصناعية والتجزئة بين IT/OT.
- خبرة في تصميم حلول الوصول الآمن عن بُعد لموردي OT والمهندسين وفرق الدعم.
- معرفة معايير وأطر أمان OT وخاصة IEC 62443 وNIST SP 800-82 وممارسات أمان البنية التحتية الحيوية ذات الصلة.
- القدرة على تقييم مخاطر OT مع مراعاة السلامة والتوفر واستمرارية الإنتاج والقيود التشغيلية.
- خبرة في أدوات اكتشاف أصول OT وأدوات الرؤية ومراقبة الشبكات وتقنيات الكشف السلبي.
- الإلمام بالبروتوكولات الصناعية مثل Modbus وDNP3 وOPC وProfinet وEtherNet/IP وBACnet أو ما يشابهها.
- خبرة في دعم إدارة الثغرات الأمنية لـ OT والضوابط التعويضية والمعالجة القائمة على المخاطر.
- القدرة على تصميم تجزئة آمنة لشبكات OT وقواعد جدار الحماية وخوادم القفز (Jump Servers) وهندسة المنطقة العازلة (DMZ) وتدفقات البيانات الخاضعة للرقابة بين IT وOT.
- معرفة عمليات النسخ الاحتياطي الآمن واستعادة البيانات بعد الكوارث وقيود التحديث وإدارة دورة الحياة لأنظمة OT.
- خبرة في العمل مع فرق تشغيل المصانع والفرق الهندسية وموردي الأتمتة ومركز العمليات الأمنية وفرق الأمن السيبراني.
- القدرة على الموازنة بين متطلبات الأمن السيبراني والسلامة التشغيلية ووقت التشغيل والقيود الخاصة بالموقع.
- خبرة في دعم التخطيط للاستجابة للحوادث في OT وتمارين الطاولة وحالات استخدام المراقبة الأمنية.
- فهم الأمن المادي وأنظمة السلامة وعلاقتها بالأمن السيبراني في البيئات الصناعية.
- خبرة في إعداد توثيق أمان OT والمخططات المعمارية وتقييمات المخاطر وخرائط طريق المعالجة.
عرض النص الأصلي للإعلان
Key Responsibilities
- Design and maintain enterprise security architecture aligned with business, technology, and compliance requirements.
- Define security standards, reference architectures, patterns, and guardrails for cloud, network, applications, identity, data, and infrastructure.
- Review solution designs and ensure security requirements are embedded from the early design stage.
- Conduct security architecture assessments for new systems, platforms, integrations, and transformation programs.
- Identify security risks, recommend controls, and support risk treatment plans.
- Work with infrastructure, cloud, application, network, IAM, SOC, GRC, and OT teams to ensure secure-by-design implementation.
- Translate business and technical requirements into practical security controls.
- Support implementation of Zero Trust, defense-in-depth, segmentation, least privilege, secure access, and secure monitoring models.
- Define security requirements for third-party integrations, APIs, remote access, cloud workloads, and critical systems.
- Support security governance by reviewing exceptions, deviations, and architecture waivers.
- Provide technical guidance to project teams during design, build, testing, and deployment phases.
- Ensure solutions comply with internal policies, regulatory requirements, and relevant standards such as ISO 27001, NIST, CIS, IEC 62443, and other applicable frameworks.
- Collaborate with SOC and operations teams to ensure security logging, monitoring, detection, and response requirements are included in solution designs.
- Maintain security architecture documentation, diagrams, decision records, and control mappings.
- Stay updated on emerging threats, security technologies, and architecture best practices.
Required Experience & Skills - OT Domain
- Minimum 6 years of experience with Operational Technology (OT) environments, including industrial control systems (ICS), SCADA, PLCs, HMIs, engineering workstations, historians, and industrial networks.
- Understanding of OT network architecture, Purdue Model, industrial zones and conduits, and IT/OT segmentation.
- Experience designing secure remote access solutions for OT vendors, engineers, and support teams.
- Knowledge of OT security standards and frameworks, especially IEC 62443, NIST SP 800-82, and relevant critical infrastructure security practices.
- Ability to assess OT risks while considering safety, availability, production continuity, and operational constraints.
- Experience with OT asset discovery, visibility tools, network monitoring, and passive detection technologies.
- Familiarity with industrial protocols such as Modbus, DNP3, OPC, Profinet, EtherNet/IP, BACnet, or similar.
- Experience supporting OT vulnerability management, compensating controls, and risk-based remediation.
- Ability to design secure OT network segmentation, firewall rules, jump servers, DMZ architecture, and controlled data flows between IT and OT.
- Knowledge of secure backup, disaster recovery, patching constraints, and lifecycle management for OT systems.
- Experience working with plant operations, engineering teams, automation vendors, SOC, and cybersecurity teams.
- Ability to balance cybersecurity requirements with operational safety, uptime, and site-specific limitations.
- Experience supporting OT incident response planning, tabletop exercises, and security monitoring use cases.
- Understanding of physical security, safety systems, and their relationship with cybersecurity in industrial environments.
- Experience preparing OT security documentation, architecture diagrams, risk assessments, and remediation roadmaps
Also, You can forward your CV through below link for more upcoming Job vacancies: https://cv-fnrco.
المصدر: LinkedIn - أُضيفت للموقع في 12 أغسطس 2026