📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

مصدر تعلن عن وظيفة مهندس عمليات أمن أول في الرياض

Sr. Security Operation Engineer
🏢 Masdr - مصدر
🕒 نُشرت: (اليوم) 📍 الرياض وظائف الأمن والسلامة
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

شركة مصدر (Masdr)، المتخصصة في تقديم الحلول الرقمية المتكاملة للقطاعين العام والخاص، تعلن عن حاجتها لشغل وظيفة مهندس عمليات أمن أول (Sr. Security Operation Engineer) في مدينة الرياض، السعودية.

نبذة عن الوظيفة

تتولى الشركة تمكين الكفاءة التشغيلية وتعزيز تجربة العملاء واتخاذ القرارات المبنية على البيانات من خلال التقنيات الرقمية المتقدمة. يهدف هذا الدور إلى قيادة وإدارة وتشغيل وتحسين الأنظمة المؤسسية، منصات الهوية، تقنيات مكان العمل الرقمية، حوكمة الأجهزة الطرفية، وأمن المراسلات، مع ضمان عمليات آمنة وموثوقة وقابلة للتوسع، والعمل بصفته المالك التقني التنفيذي خلال المرحلة التأسيسية لوضع المعايير التشغيلية والأسس التقنية.

المهام والمسؤوليات

  • توفير القيادة التقنية العملية لوظيفة عمليات الأمن السيبراني، وتخطيط أنشطة أمن المعلومات وتحديد أولوياتها والإشراف عليها، مع توجيه أعضاء الفريق وتعزيز التميز التقني وتبادل المعرفة.
  • إنشاء وتحسين العمليات والمعايير والإجراءات والوثائق التشغيلية للأمن السيبراني، وضمان تقديم خدمات الأمن بفعالية وموثوقية.
  • التعاون مع أصحاب المصلحة الداخليين لتنفيذ وصيانة قدرات الأمن السيبراني، والإشراف تقنياً على البائعين الخارجيين ومزودي خدمات الأمن المُدارة (MSSPs) وشركاء التنفيذ.
  • دعم عمليات التدقيق من خلال تقديم الأدلة الفنية وتنسيق معالجة النتائج الفنية، والحفاظ على الوثائق الداعمة للامتثال للمتطلبات الأمنية والتنظيمية.
  • مراقبة الأداء التشغيلي، وإعداد تقارير بمقاييس الأمن السيبراني الرئيسية، وقيادة مبادرات التحسين المستمر.
  • قيادة والمشاركة الفعالة في العمليات الأمنية اليومية، وتطوير الإجراءات التشغيلية والأدلة التشغيلية وسير عمل الاستجابة.
  • تصميم وتنفيذ وإدارة وصيانة منصة SIEM المؤسسية، وتطوير قواعد الكشف ولوحات المعلومات والتنبيهات وحالات الاستخدام للمراقبة، ومراقبة الأحداث الأمنية والتحقيق فيها والاستجابة لها.
  • نشر وتكوين وإدارة وصيانة حلول EDR/XDR المؤسسية، والتحقيق في التهديدات على الأجهزة الطرفية وتنسيق الاحتواء والتعافي.
  • قيادة التحقيق التقني والاستجابة لحوادث الأمن السيبراني، وإجراء تحليل السبب الجذري وتنسيق الاحتواء والاستئصال والتعافي والمعالجة، وصيانة واختبار خطط وإجراءات الاستجابة للحوادث.
  • إجراء مراقبة استباقية للتهديدات وأنشطة صيد التهديدات (Threat Hunting)، وتحليل استخبارات التهديدات وتحديد مؤشرات الاختراق (IOCs) والتهديدات الناشئة.
  • تنسيق عمليات مركز عمليات الأمن (SOC) داخلياً أو مع مزود خارجي، ومراجعة الحوادث المرفوعة وضمان الامتثال لمستويات الخدمة التشغيلية.
  • تصميم وتنفيذ وإدارة وصيانة حلول إدارة الهوية والوصول (IAM) وإدارة الوصول المميز (PAM)، وإدارة الحسابات المميزة والمصادقة والتفويض وحماية بيانات الاعتماد ومراقبة الجلسات المميزة، وضمان الامتثال لسياسات الهوية والوصول المميز.
  • تنفيذ وإدارة وصيانة حلول إدارة الثغرات المؤسسية، وإجراء فحص الثغرات وتقييمها وتحديد أولويات المخاطر والتحقق من المعالجة.
  • تنفيذ وصيانة خطوط الأساس الأمنية عبر البنية التحتية المؤسسية وأنظمة التشغيل وقواعد البيانات ومنصات المحاكاة الافتراضية والمنصات السحابية وأجهزة الشبكة، والتحقق من الامتثال لمعايير التصلب (Hardening) المعتمدة.
  • تصميم وتنفيذ وإدارة وصيانة ضوابط الأمن التقني المؤسسية بما في ذلك MFA وحماية الأجهزة الطرفية والتشفير والوصول الآمن عن بُعد وإدارة الشهادات والتسجيل والمراقبة وأمن الشبكات وأمن التطبيقات، وضمان التكوين الآمن لهذه التقنيات.
  • إجراء تقييمات أمنية تقنية ومراجعات تكوين وأنشطة التحقق الأمني، ودعم اختبار الاختراق وتنسيق معالجة النتائج الأمنية المحددة، وتقييم التقنيات الجديدة لضمان تضمين متطلبات الأمان قبل النشر.
  • الحفاظ على وثائق العمليات الأمنية والأدلة التشغيلية والإجراءات الفنية وخطط التعافي، ودعم تمارين التعافي من الكوارث والتدقيقات الفنية وتقييمات الامتثال، وإعداد تقارير تشغيلية ولوحات بيانات ومؤشرات أداء رئيسية ومقاييس أمنية.

الشروط والمتطلبات

  • درجة البكالوريوس في الأمن السيبراني أو أمن المعلومات أو علوم الحاسب أو تقنية المعلومات أو مجال ذي صلة.
  • شهادات مهنية معتمدة في الأمن السيبراني مثل CISSP أو Security+ أو CySA+ أو GCIH أو ما يعادلها.
  • خبرة لا تقل عن 5-6 سنوات متزايدة في عمليات الأمن السيبراني أو أمن المعلومات أو هندسة الأمن.
  • خبرة عملية لا تقل عن 3 سنوات في تنفيذ وإدارة تقنيات الأمن المؤسسية بما في ذلك SIEM وEDR/XDR وIAM/PAM وإدارة الثغرات والمراقبة الأمنية.
  • خبرة في قيادة عمليات الأمن السيبراني والاستجابة للحوادث ومبادرات هندسة الأمن.
  • خبرة في العمل ضمن بيئات مؤسسية أو سحابية والتنسيق مع الفرق الداخلية والبائعين ومزودي خدمات الأمن المُدارة (MSSPs).
عرض النص الأصلي للإعلان

About Masdr

Masdr provides integrated digital data and business solutions to public and private sector organizations, enabling operational efficiency, enhanced customer experience, data-driven decision-making, and compliance with regulatory and cybersecurity requirements through advanced digital technologies and enterprise platforms.


Job Purpose

Lead and directly execute the administration, operation, and continuous improvement of enterprise systems, identity platforms, digital workplace technologies, endpoint governance, and messaging security. The role is responsible for ensuring secure, reliable, and scalable operations while acting as the hands-on technical owner during the initial phase, establishing operational standards, technical foundations, and service maturity as the organization grows.


Generic Accountabilities:


Leadership & Technical Direction

  • Provide hands-on technical leadership for the Cybersecurity Operations function.
  • Plan, prioritize, and oversee cybersecurity operational activities.
  • Mentor team members and promote technical excellence and knowledge sharing.

Operational Excellence

  • Establish and continuously improve cybersecurity operational processes, standards, procedures, and documentation.
  • Ensure the effective and reliable delivery of cybersecurity services.

Stakeholder & Vendor Management

  • Collaborate with internal stakeholders to implement and maintain cybersecurity capabilities.
  • Provide technical oversight of external vendors, managed security service providers (MSSPs), and implementation partners.

Audit & Compliance Support

  • Support audits by providing technical evidence and coordinating the remediation of technical findings.
  • Maintain documentation supporting compliance with applicable security and regulatory requirements.

Performance & Continuous Improvement

  • Monitor operational performance, report key cybersecurity metrics, and drive continuous improvement initiatives.


Job-Specific Accountabilities:


Security Operations

  • Lead and actively participate in daily cybersecurity operations.
  • Develop and maintain operational procedures, playbooks, and response workflows.

SIEM & Security Monitoring

  • Design, implement, administer, and maintain the enterprise SIEM platform.
  • Develop detection rules, dashboards, alerts, and monitoring use cases.
  • Monitor, investigate, and respond to security events.

EDR / XDR

  • Deploy, configure, administer, and maintain enterprise EDR/XDR solutions.
  • Investigate endpoint threats and coordinate containment and recovery.

Incident Response

  • Lead technical investigation and response to cybersecurity incidents.
  • Perform root cause analysis and coordinate containment, eradication, recovery, and remediation.
  • Maintain and test incident response plans and procedures.

Threat Monitoring & Threat Hunting

  • Perform proactive threat monitoring and threat hunting activities.
  • Analyze threat intelligence and identify indicators of compromise (IOCs) and emerging threats.

Security Operations Center (SOC)

  • Coordinate internal or outsourced SOC operations.
  • Review escalated incidents and ensure compliance with operational service levels.

Identity & Privileged Access Management (IAM/PAM)

  • Design, implement, administer, and maintain Identity and Access Management (IAM) and Privileged Access Management (PAM) solutions.
  • Manage privileged accounts, authentication, authorization, credential protection, and privileged session monitoring.
  • Ensure compliance with identity and privileged access policies.

Vulnerability Management

  • Implement, administer, and maintain enterprise vulnerability management solutions.
  • Perform vulnerability scanning, assessments, risk prioritization, and remediation validation.

Security Hardening

  • Implement and maintain security baselines across enterprise infrastructure, operating systems, databases, virtualization platforms, cloud platforms, and network devices.
  • Validate compliance with approved hardening standards and security baselines.

Technical Security Controls

  • Design, implement, administer, and maintain enterprise technical security controls, including MFA, endpoint protection, encryption, secure remote access, certificate management, logging, monitoring, network security, and application security controls.
  • Ensure security technologies are securely configured and maintained.

Security Assessments

  • Perform technical security assessments, configuration reviews, and security validation activities.
  • Support penetration testing and coordinate remediation of identified security findings.
  • Assess new technologies and solutions to ensure security requirements are incorporated before deployment.

Operational Readiness & Reporting

  • Maintain cybersecurity operational documentation, runbooks, technical procedures, and recovery plans.
  • Support disaster recovery exercises, technical audits, and compliance assessments.
  • Produce operational reports, dashboards, KPIs, and security metrics.


Job Requirements:


Minimum Qualification

Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.

  • Professional cybersecurity certifications (e.g., CISSP, Security+, CySA+, GCIH, or equivalent).


Experience

Minimum 5-6 years of progressive experience in Cybersecurity Operations, Information Security, or Security Engineering.

Minimum 3 years of hands-on experience implementing and administering enterprise security technologies, including SIEM, EDR/XDR, IAM/PAM, Vulnerability Management, and Security Monitoring.

Experience leading cybersecurity operations, incident response, and security engineering initiatives.

  • Experience working in enterprise or cloud environments and coordinating with internal teams, vendors, and managed security service providers (MSSPs).




Let's Shape the Future Together!

المصدر: LinkedIn - أُضيفت للموقع في 17 أغسطس 2026

وظائف أخرى لدى Masdr - مصدر