📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

Trace Systems Inc. تعلن عن وظيفة ضابط أمن نظم معلومات (ISSO) في الرياض

Information Systems Security Officer (ISSO)
🏢 Trace Systems Inc.
🕒 نُشرت: (اليوم) 📍 الرياض وظائف الأمن والسلامة
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

تسعى شركة Trace Systems Inc. لتعيين مسؤول أمن نظم المعلومات (ISSO) للعمل في الرياض، المملكة العربية السعودية، لدعم عقد USMTM CITS.

نبذة عن الوظيفة

يتولى مسؤول أمن نظم المعلومات (ISSO) دعم الوضع الأمني السيبراني، والترخيص، والمراقبة المستمرة، وإدارة الثغرات، والاستجابة للحوادث، وتنفيذ ضوابط الأمان، والجاهزية للتدقيق، والامتثال للأنظمة المهمة المصنفة وغير المصنفة.

المهام والمسؤوليات

  • دعم تنفيذ واستدامة إطار إدارة المخاطر (RMF) التابع لوزارة الدفاع للأنظمة والشبكات المخصصة.
  • تطوير ومراجعة وصيانة خطط أمن النظم (SSPs) وبيانات تنفيذ الضوابط وأوصاف النظام وخطط الطوارئ والاستجابة للحوادث ووثائق الترخيص.
  • دعم أنشطة الترخيص الأولية والمتكررة للحصول على ترخيص التشغيل (ATO) والحفاظ عليه.
  • صيانة خطط العمل والمحاور الزمنية (POA&Ms) وتتبع المعالجة والتحقق من أدلة الإغلاق وتنسيق التصرف في نتائج الأمن السيبراني.
  • إعداد تقارير تقييم الأمان وتقييمات المخاطر وأدلة تقييم الضوابط ووثائق المراقبة المستمرة.
  • التنسيق مع جهات الأمن: IAM وISSM ومسؤولي الترخيص والمقيمين ومقدمي خدمات الأمن السيبراني والمنظمات العليا.
  • إجراء تحليلات تأثير أمني وتقديم توصيات أمنية من خلال عمليات مجلس مراقبة التكوين.
  • مراقبة الوضع الأمني باستخدام أدوات معتمدة لفحص الثغرات والامتثال وأمن نقاط النهاية والتسجيل والمسح.
  • مراجعة نتائج المسح والنشرات الأمنية وإعلانات الثغرات (IAVAs) والتوجيهات والإشعارات، وتحديد الأولويات والتنسيق مع الفرق الفنية للمعالجة.
  • التحقق من تنفيذ أدلة تقنية تخفيف التهديدات (STIGs) وخطوط الأساس الأمنية والتصحيحات والتخفيف والتسجيل وضوابط الوصول والإجراءات التصحيحية.
  • دعم التصنيف الأولي للحوادث والإبلاغ والتحقيق والاحتواء والاستئصال والاسترداد والإشعارات وأنشطة ما بعد الحادث.
  • مراجعة سجلات النظام والتطبيق والتدقيق والأمان بحثًا عن شذوذ أو نشاط غير مصرح به أو مؤشرات اختراق.
  • دعم إدارة الحسابات والوصول المميز وPKI والرموز وكلمات المرور وإدارة دورة حياة الهوية والشهادات وبيانات اعتماد SIPR عند الترخيص.
  • دعم اختبارات الأمان والتفتيش والتدقيق والتقييمات والمقاييس والإحاطات والتوعية والتدريب القائم على الأدوار ووثائق الاستمرارية.
  • تقديم إرشادات أمنية سيبرانية توازن بين الامتثال وتوفر المهمة والمخاطر التشغيلية والمتطلبات الفنية.
  • المشاركة في أنشطة الصيانة والاستجابة للطوارئ والدعم خارج ساعات العمل والاستعداد عند الحاجة لأحداث أمنية سيبرانية.

الشروط والمتطلبات

  • تصريح أمني ساري من حكومة الولايات المتحدة بمستوى Secret.
  • الجنسية الأمريكية مطلوبة بسبب طبيعة العمل ومتطلبات العقد.
  • استيفاء متطلبات DoD 8140 المعمول بها لدور العمل (Vulnerability Assessment Analyst - المستوى المتوسط).
  • قد يكون المؤهل من خلال التعليم أو التدريب العسكري أو الشهادات أو مزيج منها: درجة البكالوريوس في الأمن السيبراني أو تكنولوجيا المعلومات أو نظم المعلومات أو علوم الحاسب أو علوم البيانات أو هندسة البرمجيات، أو إكمال تدريب عسكري ذي صلة في الأمن السيبراني أو أمن المعلومات أو الاتصالات أو أمن الشبكات.
  • الشهادات المؤهلة تشمل Security+ أو CEH(P) أو RCCE Level 1 أو Cloud+ أو CPTE أو FITSP-A أو GCED أو GCIH أو GCSA أو GICSP أو GSEC أو PenTest+ أو شهادات أخرى معتمدة من DoD 8140 لدور محلل تقييم الثغرات.
  • خبرة لا تقل عن 8 سنوات في الأمن السيبراني أو أمن المعلومات أو التقييم والترخيص أو المجالات الأمنية ذات الصلة مع زيادة المسؤولية.
  • خبرة مثبتة في دعم DoD RMF وحزم الترخيص واستدامة ATO وPOA&Ms والمراقبة المستمرة وتقييم الضوابط.
  • خبرة في فحص الثغرات وتقييم المخاطر وتحليل الأثر الأمني والاستجابة للحوادث وتتبع المعالجة وSTIGs DISA وخطوط الأساس الأمنية.
  • خبرة في دعم أنظمة المعلومات المصنفة أو البيئات الحكومية الآمنة.
  • معرفة عملية بضوابط الأمان NIST وسياسة الأمن السيبراني لوزارة الدفاع ومتطلبات أمن المعلومات الفيدرالية.
  • مهارات تحليلية قوية وكتابة تقنية وتوثيق وإيجاز وتنسيق مع الجهات المعنية.
  • القدرة على الانتقال إلى الرياض، المملكة العربية السعودية.

المهارات المطلوبة

  • خبرة سابقة كـ ISSO أو ISSM أو مقيم ضوابط أمنية أو محلل أمن سيبراني أو قائد أمن معلومات في برنامج تابع لوزارة الدفاع.
  • خبرة في دعم الجيش أو CENTCOM أو USARCENT أو NETCOM أو DISA أو RCC-SWA أو منظمات الأمن السيبراني المؤسسية الأخرى.
  • خبرة في استخدام eMASS وACAS وSCAP Compliance Checker ومنصات أمن نقاط النهاية وأدوات إدارة السجلات وتقنيات إدارة الثغرات الحكومية.
  • خبرة في دعم بيئات Windows Server وActive Directory وVMware والشبكات وSharePoint والصوت ونقاط النهاية.
  • خبرة في NIST SP 800-53 وعمليات تفتيش الأمن السيبراني ومراجعات الترخيص ودعم المهام العسكرية في الخارج.
عرض النص الأصلي للإعلان
Job Overview

Job Title: Information Systems Security Officer (ISSO)

Job Location: Al Nakhla, Saudi Arabia

Job Responsibilities

Trace Systems is seeking an experienced Information Systems Security Officer (ISSO) to support the USMTM CITS contract in Riyadh, Kingdom of Saudi Arabia. The ISSO supports cybersecurity posture, authorization, continuous monitoring, vulnerability management, incident response, security-control implementation, audit readiness, and compliance for mission-critical classified and unclassified systems.

  • Support implementation and sustainment of the Department of Defense Risk Management Framework for assigned systems and network enclaves.
  • Develop, review, and maintain System Security Plans, control implementation statements, system descriptions, contingency and incident response plans, and authorization artifacts.
  • Support initial and recurring authorization activities required to obtain and maintain Authority to Operate status.
  • Maintain Plans of Action and Milestones, track remediation, validate closure evidence, and coordinate disposition of cybersecurity findings.
  • Prepare Security Assessment Reports, risk assessments, control-assessment evidence, and continuous-monitoring documentation.
  • Coordinate with Government IAM, ISSM, authorizing officials, assessors, cybersecurity service providers, and higher-level organizations.
  • Perform security-impact analyses and provide cybersecurity recommendations through Configuration Control Board processes.
  • Monitor security posture using approved vulnerability, compliance, endpoint-security, logging, and scanning tools.
  • Review scan results, security bulletins, IAVAs, directives, and notifications; prioritize and coordinate remediation with technical teams.
  • Verify implementation of STIGs, security baselines, patches, mitigations, logging, access controls, and corrective actions.
  • Support incident triage, reporting, investigation, containment, eradication, recovery, notifications, and after-action activities.
  • Review system, application, audit, and security logs for anomalies, unauthorized activity, or indicators of compromise.
  • Support account management, privileged access, PKI, token, password, identity lifecycle, certificates, and SIPR credential processes when authorized.
  • Support security testing, inspections, audits, assessments, metrics, briefings, awareness, role-based training, and continuity documentation.
  • Provide cybersecurity guidance that balances compliance, mission availability, operational risk, and technical requirements.
  • Participate in maintenance, emergency response, after-hours support, and on-call activities when cybersecurity events require.

Minimum Qualifications

  • Active, in-scope US Government issued Secret clearance.
  • Due to the nature of the work and contract requirements: US Citizenship is required.
  • Candidates must meet the applicable DoD 8140 qualification requirements for the assigned work role. DoD 8140 Work Role(s): 541 - Vulnerability Assessment Analyst, Proficiency Level: Intermediate; and may qualify through education, military training, certifications, or a combination thereof. DoD identifies Work Role 541 as the Vulnerability Assessment Analyst role.
  • Qualifying education or training may include a bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Data Science, Software Engineering or completion of relevant military cyber, information assurance, communications, or network security training.
  • Qualifying certifications may include Security+, CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or other DoD 8140-approved certifications applicable to the Vulnerability Assessment Analyst work role. Higher proficiency-level or equivalent DoD 8140-approved certifications applicable to the assigned work role may also be accepted.
  • Eight (8) or more years of progressively responsible cybersecurity, information assurance, assessment and authorization, or related security experience.
  • Demonstrated experience supporting DoD RMF, authorization packages, ATO sustainment, POA&Ms, continuous monitoring, and control assessments.
  • Experience with vulnerability scanning, risk assessment, security-impact analysis, incident response, remediation tracking, DISA STIGs, and security baselines.
  • Experience supporting classified information systems or secure Government environments.
  • Working knowledge of NIST security controls, DoD cybersecurity policy, and federal information-security requirements.
  • Strong analytical, technical writing, documentation, briefing, and stakeholder-coordination skills.
  • Ability to relocate to Riyadh, Kingdom of Saudi Arabia.

Desired Qualification

  • Previous experience as an ISSO, ISSM, security control assessor, cybersecurity analyst, or information assurance lead on a DoD program.
  • Experience supporting Army, CENTCOM, USARCENT, NETCOM, DISA, RCC-SWA, or other enterprise cybersecurity organizations.
  • Experience with eMASS, ACAS, SCAP Compliance Checker, endpoint-security platforms, log-management tools, and Government vulnerability-management technologies.
  • Experience supporting Windows Server, Active Directory, VMware, networks, SharePoint, voice, and endpoint environments.
  • Experience with NIST SP 800-53, cybersecurity inspections, authorization reviews, and overseas or military mission support.

Trace Systems

Trace Systems, headquartered in Vienna, Virginia, was founded to support and defend our nation's security interests at home and abroad-- whenever and wherever. We provide cybersecurity, intelligence, communications, networking and information technology services, systems, and solutions to the United States Department of Defense, Intelligence Community and Department of Homeland Security.

To Apply: We invite you to put your talents to work by joining a growing team of dynamic professionals here at Trace Systems! Be part of a culture at our leading edge company where you can achieve great things while fostering a satisfying and rewarding career progression. Please apply directly through the website at: www.tracesystems.com. #jointracesystems

Trace Systems is an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
المصدر: LinkedIn - أُضيفت للموقع في 17 أغسطس 2026

وظائف أخرى لدى Trace Systems Inc.