Kualitatem Inc. تعلن عن وظيفة أخصائي إدارة الهويات والصلاحيات في الرياض
تفاصيل الوظيفة
تعلن شركة Kualitatem Inc. عن توفر وظيفة أخصائي إدارة الهوية والصلاحيات (Identity and Entitlement Management Specialist - IAM / PAM) في الرياض، بوزارة الثقافة بالدرعية، للعمل على إدارة دورة حياة الهوية، وصلاحيات الوصول، والمصادقة، والحوكمة، والوصول المميز عبر أنظمة المؤسسة.
الشروط والمتطلبات
- درجة البكالوريوس في علوم الحاسب، أمن المعلومات، الأمن السيبراني، أو مجال ذي صلة
- خبرة لا تقل عن 6 سنوات في حوكمة أو هندسة أو تشغيل IAM
- شهادة في IAM، PAM، CISSP، Microsoft Identity، أو ما يعادلها (ميزة إضافية)
المهارات المطلوبة
- خبرة قوية في منصات Identity Governance and Administration (IGA) و Privileged Access Management (PAM)
- فهم عميق لدورة حياة الهوية، نماذج التحكم في الوصول، وإدارة الصلاحيات
- خبرة في دمج حلول IAM مع تطبيقات المؤسسة، الأدلة، أنظمة الموارد البشرية، والأنظمة الأخرى
- خبرة عملية في SSO، MFA، المصادقة الحديثة، ومبادئ Zero Trust
- خبرة في تطبيق مبدأ أقل امتياز (Least Privilege) وفصل المهام (Segregation of Duties)
- فهم المعايير الأمنية والمتطلبات التنظيمية وممارسات حوكمة الوصول
- مهارات قوية في إدارة أصحاب المصلحة، التحليل، التوثيق، وإعداد التقارير
- إلمام بمنصات IAM/IGA (مثل Microsoft Entra ID، Active Directory) وأدوات PAM
- معرفة بإدارة الجلسات المميزة، الوصول في الوقت المناسب (JIT)، التحكم في الوصول على أساس الأدوار (RBAC)
- قدرة على المراقبة الأمنية والاستجابة للحوادث المتعلقة بالهوية
- الكفاءات الأساسية: حوكمة IAM وPAM، إدارة دورة حياة الهوية، حوكمة الوصول، إدارة الوصول المميز، المصادقة والتفويض، المخاطر والامتثال، إدارة أصحاب المصلحة، المراقبة الأمنية، التقارير والتوثيق، حل المشكلات
المهام والمسؤوليات
- إدارة دورة حياة الهوية الكاملة بما في ذلك عمليات الانضمام والنقل والمغادرة (JML)
- إدارة توفير الهوية وإلغاء توفيرها عبر الأنظمة المتصلة
- التحقيق في حالات فشل التوفير ومشاكل المزامنة وعدم اتساق الهوية
- مراجعة وتتبع طلبات الوصول وضمان الحصول على الموافقات المناسبة
- إدارة خدمات المصادقة بما في ذلك SSO و MFA
- التحقيق في سلوكيات تسجيل الدخول غير الطبيعية وفشل المصادقة ومحاولات الوصول المشبوهة
- مراقبة المزامنة بين أنظمة الموارد البشرية والأدلة ومصادر الهوية والتطبيقات المتصلة
- دعم حملات التصديق الدوري على الوصول ومراجعة الصلاحيات
- تحديد ومعالجة الحسابات غير النشطة أو اليتيمة أو المفرطة الصلاحيات أو غير المناسبة
- مراقبة التنبيهات الأمنية المتعلقة بـ IAM والتنسيق مع فرق الأمن السيبراني بشأن حوادث الهوية
- إعداد تقارير IAM تغطي مراجعات الوصول وأنشطة المصادقة ومخاطر الهوية والامتثال للسياسات
- تتبع النتائج الأمنية المتعلقة بالهوية والتنسيق لإجراءات التصحيح حتى الإغلاق
- إعداد تقارير دورية حول حوكمة الهوية ومراجعات الوصول ومؤشرات مخاطر الهوية
- إدارة الحسابات والصلاحيات المميزة عبر الأنظمة والتطبيقات وقواعد البيانات والبنية التحتية
- مراجعة طلبات الوصول المميز وضمان وجود الموافقات والمبررات المناسبة
- مراقبة الجلسات المميزة وتحديد الأنشطة الإدارية غير المصرح بها أو المشبوهة
- التحقيق في التنبيهات المتعلقة بالنشاط المميز غير الطبيعي وانتهاكات السياسات
- تنفيذ وحوكمة الوصول المميز في الوقت المناسب (Just-in-Time) و عند الطلب
- ضمان تطبيق الضوابط المناسبة على الحسابات المميزة المشتركة والعامة
- مراجعة سجلات وتسجيلات الجلسات المميزة لدعم التحقيقات وتقييم المخاطر
- تحديد ومعالجة الحسابات غير الضرورية أو غير النشطة أو المفرطة الصلاحيات
- فرض مبادئ أقل امتياز وفصل المهام (Segregation of Duties)
- التنسيق للمراجعات الدورية للحسابات والصلاحيات المميزة مع مالكي الأنظمة والأعمال
- ضمان مراقبة الأنشطة المميزة والتحكم فيها وإمكانية تتبعها بشكل مناسب
عرض النص الأصلي للإعلان
Role: Identity and Entitlement Management Specialist (IAM / PAM)
Headcount: 2
Minimum Qualification: Bachelor’s degree
Minimum Experience: 6 years
Location: Ministry of Culture, Al-Diriyah, Riyadh
Role Summary
We are seeking an experienced Identity and Entitlement Management Specialist (IAM / PAM) to manage and govern identity lifecycle, access controls, authentication, identity governance, and privileged access across enterprise systems.
The role will focus on ensuring secure and compliant identity management, implementing least-privilege access, monitoring privileged activities, supporting access reviews, and coordinating with cybersecurity and business stakeholders.
Minimum Qualifications
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field.
- Minimum 6 years of experience in IAM governance, engineering, or operations.
- Certification in IAM, PAM, CISSP, Microsoft Identity, or an equivalent certification is an advantage.
Key Requirements
- Strong experience with Identity Governance and Administration (IGA) and Privileged Access Management (PAM) platforms.
- Strong understanding of identity lifecycle management, access control models, and entitlement management.
- Experience integrating IAM solutions with enterprise applications, directories, HR systems, and other business systems.
- Practical experience with SSO, MFA, modern authentication, and Zero Trust principles.
- Experience implementing least privilege and segregation of duties.
- Understanding of security standards, regulatory requirements, and access governance practices.
- Strong stakeholder management, analytical, documentation, and reporting skills.
Key Responsibilities - Identity and Access Management
- Manage the complete identity lifecycle, including Joiner, Mover, and Leaver (JML) processes.
- Manage identity provisioning and deprovisioning across connected systems.
- Investigate provisioning failures, synchronization issues, and identity inconsistencies.
- Review and track access requests and ensure appropriate approvals are obtained.
- Manage authentication services, including SSO and MFA.
- Investigate abnormal login behavior, authentication failures, and suspicious access attempts.
- Monitor synchronization between HR systems, directories, identity sources, and connected applications.
- Support periodic access certification and entitlement review campaigns.
- Identify and remediate inactive, orphan, excessive, or inappropriate accounts and privileges.
- Monitor IAM-related security alerts and coordinate with cybersecurity teams on identity-related incidents.
- Prepare IAM reports covering access reviews, authentication activities, identity risks, and policy compliance.
- Track identity-related security findings and coordinate corrective actions through closure.
- Prepare periodic reports on identity governance, access reviews, and identity-related risk indicators.
Key Responsibilities - Privileged Access Management
- Govern privileged accounts and entitlements across systems, applications, databases, and infrastructure.
- Review privileged access requests and ensure appropriate approvals and business justifications are provided.
- Monitor privileged sessions and identify unauthorized or suspicious administrative activities.
- Investigate alerts related to abnormal privileged activity and policy violations.
- Implement and govern Just-in-Time (JIT) and on-demand privileged access.
- Ensure appropriate controls are applied to shared and generic privileged accounts.
- Review privileged session logs and recordings to support investigations and risk assessments.
- Identify and remediate unnecessary, inactive, or over-privileged accounts.
- Enforce least privilege and segregation of duties (SoD) principles.
- Coordinate periodic reviews of privileged accounts and entitlements with system and business owners.
- Ensure privileged access activities are properly monitored, controlled, and traceable.
Preferred Technical Exposure
- IAM / IGA platforms
- PAM platforms
- Microsoft Entra ID / Active Directory
- SSO and MFA solutions
- Identity provisioning and lifecycle management
- Access certification and entitlement management
- Privileged session management
- Just-in-Time access
- Role-Based Access Control (RBAC)
- Security monitoring and identity-related incident response
Core Competencies
- IAM & PAM Governance
- Identity Lifecycle Management
- Access Governance
- Privileged Access Management
- Authentication & Authorization
- Risk & Compliance
- Stakeholder Management
- Security Monitoring
- Reporting & Documentation
- Problem Solving