📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

وظيفة استجابة للحوادث التقنية (OT) شاغرة لدى Accenture Middle East في الرياض

OT Incident Response
🏢 Accenture Middle East
🕒 نُشرت: (اليوم) 📍 الرياض وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

تعلن شركة Accenture Middle East عن توفر فرصة وظيفية في مجال الاستجابة للحوادث لأنظمة التشغيل التقنية (OT) بالرياض، السعودية. مطلوب محلل أمن سيبراني من المستوى الثالث (L3) لمركز عمليات الأمن التقني (OT SOC) لقيادة التحقيقات المتقدمة والاستجابة للحوادث عالية الخطورة في بيئات التحكم الصناعي (ICS).

المهام والمسؤوليات

  • قيادة التحقيق والاستجابة للحوادث المعقدة وعالية الخطورة والهجمات المستهدفة المشتبه بها ضد بيئات OT/ICS.
  • إجراء صيد استباقي للتهديدات (Threat Hunting) يعتمد على الفرضيات عبر شبكات وأصول OT؛ وتصميم وتنفيذ حملات الصيد.
  • إجراء التحليل الجنائي الرقمي والاستجابة للحوادث (DFIR) المخصص للبيئات التقنية، بما في ذلك الاستحواذ والتحليل لمحطات العمل الهندسية وواجهات HMI وأجهزة التحكم والمُلتقطات الشبكية باستخدام طرق تحافظ على سلامة الأدلة وسلامة العمليات.
  • تصميم وبناء وضبط محتوى الكشف وقواعد الربط؛ وإدارة دورة حياة هندسة الكشف لمركز OT SOC.
  • ترجمة معلومات التهديدات التقنية (مثل مجموعات التهديد ELECTRUM/Sandworm وXENOTIME؛ والبرمجيات الخبيثة TRITON/TRISIS وIndustroyer وPIPEDREAM) إلى كشفيات عملية باستخدام إطار MITRE ATT&CK for ICS.
  • تحديد وتوثيق وتحسين دليل الاستجابة للحوادث (Playbooks) وRunbooks الخاصة بـ OT باستمرار.
  • العمل كنقطة تصعيد أولى ومرشد للمحللين من المستويين L1/L2؛ وتقديم التدريب الفني ومراجعة جودة التحقيقات.
  • قيادة ودعم تمارين الطاولة (Tabletop Exercises) وأنشطة الفريق الأرجواني (Purple Team) ومحاكاة الخصم.
  • تقديم المشورة بشأن بنية شبكات OT والتقسيم ومواقع المراقبة لسد فجوات الكشف.
  • إعداد تقارير الحوادث التنفيذية والفنية؛ وإيجاز الجهات المعنية حول السبب الجذري والتأثير والإصلاح.
  • دعم الامتثال والتدقيق وإعداد التقارير التنظيمية وفقًا لمعايير NCA OTCC-1:2022 وECC وISA/IEC 62443، بما في ذلك متطلبات الإبلاغ عن الحوادث للهيئة الوطنية للأمن السيبراني (NCA).

الشروط والمتطلبات

الشهادات المفضلة: - شهادات GIAC: GRID, GCIP, GICSP, GCFA أو GREM (مفضلة بشدة). - شهادات خبيرة من البائعين (Dragos, Claroty, Nozomi).

  • درجة البكالوريوس في الأمن السيبراني أو هندسة الحاسب / الكهرباء / الأجهزة أو مجال ذي صلة (يفضّل الماجستير).
  • خبرة من 6 إلى 10+ سنوات في مجال الأمن السيبراني، بشرط ألا تقل خبرة 4 سنوات في عمليات أمن OT/ICS أو التحليل الجنائي والاستجابة للحوادث (DFIR) أو صيد التهديدات.
  • خبرة عميقة في بروتوكولات OT وهندسة أنظمة التحكم الصناعي (DCS, SCADA, PLC, SIS) ونموذج Purdue.
  • خبرة مثبتة في قيادة الاستجابة للحوادث والتحقيقات الجنائية في بيئات OT/ICS.
  • إتقان قوي لمنصات مراقبة OT (Nozomi, Claroty, Dragos, Tenable OT, Defender for IoT) وهندسة كشف SIEM (Splunk, QRadar, Sentinel).
  • معرفة متقدمة في إطار MITRE ATT&CK for ICS ومعايير NIST SP 800-82 وISA/IEC 62443 وNCA OTCC.

المهارات المطلوبة

  • قدرات تحليلية وجنائية وهندسة عكسية وتحليل برمجيات خبيثة متميزة في سياق OT.
  • مهارات قيادية وإرشادية وإدارة أصحاب المصلحة قوية.
  • حكم سليم في الموازنة بين استجابة الأمن السيبراني وسلامة العملية وتوافر التشغيل.
  • مهارات ممتازة في الكتابة والتحدث باللغة الإنجليزية؛ يُفضّل بشدة اللغة العربية للتواصل مع الجهات التنظيمية والتنفيذية.
  • التوفر للتصعيد والاستجابة للحوادث خارج ساعات العمل (On-call).
عرض النص الأصلي للإعلان
Role: OT Incident Response

Location: Riyadh, Saudi Arabia

Role Summary

The OT SOC L3 Analyst is the senior technical authority within the OT SOC, responsible for advanced threat hunting, OT aware digital forensics and incident response (DFIR), detection engineering, and mentoring of L1/L2 analysts. The role leads the response to complex and high-severity OT incidents, develops the SOC's OT detection capability, and serves as the escalation point and subject matter expert for industrial threat scenarios. The analyst translates OT threat intelligence into actionable detections and drives continuous improvement of the SOC's OT defenses.

Responsibilities


  • Lead investigation and response for complex, high severity and suspected targeted attacks against OT/ICS environments.
  • Perform proactive, hypothesis-driven threat hunting across OT networks and assets; design and run hunt campaigns.
  • Conduct OT aware DFIR forensic acquisition and analysis of ICS hosts, engineering workstations, HMIs, controllers and network captures using methods that preserve process safety and evidence integrity.
  • Design, build and tune detection content and correlation rules; own the detection engineering lifecycle for the OT SOC.
  • Operationalize OT threat intelligence (e.g., threat groups such as ELECTRUM/Sandworm and XENOTIME; malware such as TRITON/TRISIS, Industroyer and PIPEDREAM) and map it to detections via MITRE ATT&CK for ICS.
  • Define, document and continuously improve OT incident-response playbooks and runbooks.
  • Serve as senior escalation point and mentor for L1/L2 analysts; provide technical coaching and quality review of investigations.
  • Lead and support OT tabletop exercises and purple team / adversary-emulation activities.
  • Advise on OT network architecture, segmentation and monitoring placement to close detection gaps.
  • Produce executive and technical incident reports; brief stakeholders on root cause, impact and remediation.
  • Support compliance, audit and regulatory reporting aligned to NCA OTCC-1:2022, ECC and ISA/IEC 62443, including incident-notification expectations to the NCA.


  • Qualifications


  • Bachelor's degree in Cybersecurity, Computer/Electrical/Instrumentation Engineering or a related field (Master's a plus).
  • 6-10+ years of cybersecurity experience, with a minimum of 4 years in OT/ICS security operations, DFIR or threat hunting.
  • Deep expertise in OT protocols and ICS architectures (DCS, SCADA, PLC, SIS) and the Purdue model.
  • Proven experience leading OT/ICS incident response and forensic investigations.
  • Strong command of OT monitoring platforms (Nozomi, Claroty, Dragos, Tenable OT, Defender for IoT) and SIEM detection engineering (Splunk, QRadar, Sentinel).
  • Advanced working knowledge of MITRE ATT&CK for ICS, NIST SP 800-82, ISA/IEC 62443 and NCA OTCC.


  • Preferred Certifications

    GRID, GCIP, GICSP, GCFA or GREM (GIAC) strongly preferred


  • Vendor expert-level certifications (Dragos, Claroty, Nozomi).


  • Skills & Attributes


  • Expert analytical, forensic and reverse-engineering / malware-analysis aptitude in an OT context.
  • Strong leadership, mentoring and stakeholder-management skills.
  • Sound judgment in balancing cybersecurity response against process safety and operational availability.
  • Excellent written and verbal communication in English; Arabic strongly preferred for regulator and executive engagement.
  • Available for on-call escalation and incident leadership outside normal hours.


  • المصدر: LinkedIn - أُضيفت للموقع في 17 أغسطس 2026

    وظائف أخرى لدى Accenture Middle East