📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

وظيفة أخصائي أمن سيبراني لدى Masharah Advisory في مكة وجدة

Cyber Security Specialist
🏢 Masharah Advisory
🕒 نُشرت: (اليوم) 📍 جدة وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

تعلن شركة Masharah Advisory عن توفر وظيفة اختصاصي الأمن السيبراني وأمن البنية التحتية في جدة، السعودية. سيتولى المرشح مسؤولية متطلبات الأمن السيبراني للشركة، وهندسة الأمان، وإدارة المخاطر، وسيكون المرجع الفني الرئيسي مع مزودي الخدمات الخارجيين.

المهام والمسؤوليات

  • الإشراف على وضع الأمن السيبراني وأمن البنية التحتية للشركة وتقييمه باستمرار
  • إجراء تقييمات أمنية لتحديد الفجوات والمخاطر ونقاط الضعف
  • تحديد متطلبات الأمن السيبراني وضوابط الأمان والمعايير الفنية
  • تطوير ومراجعة الهندسة الأمنية تشمل: أمن الشبكات، الجدران النارية، التقسيم الشبكي، DMZ/WAF، VPN/ZTNA، الخوادم والمحاكاة الافتراضية، إدارة الهوية والوصول، EDR/XDR، SIEM/SOC، النسخ الاحتياطي، التعافي من الكوارث، أمن التطبيقات والبيانات
  • تطوير متطلبات الأمن السيبراني وأمن البنية التحتية لمزودي الخدمات الخارجيين
  • تقييم واختيار التقنيات والحلول الأمنية المناسبة
  • قيادة النقاشات الفنية مع مزودي الخدمات في الأمن والشبكات والبنية التحتية
  • الاعتراض على البنى المقترحة والتقنيات والتوصيات المقدمة من البائعين وتقييمها
  • مراجعة التصاميم المعمارية عالية المستوى ومنخفضة المستوى، والعروض الفنية، وقوائم المواد، وخطط التنفيذ
  • الإشراف على تنفيذ الأمان والتحقق من صحة تطبيق الضوابط المتفق عليها
  • إنشاء وإدارة عمليات إدارة الثغرات الأمنية والمعالجة
  • التنسيق لاختبارات الاختراق والتقييمات الأمنية وضمان معالجة النتائج
  • تحديد متطلبات المراقبة والتسجيل وSIEM/SOC وEDR/XDR والتنبيهات
  • وضع متطلبات الاستجابة للحوادث والاحتواء والتعافي
  • مراجعة متطلبات إدارة الهوية والوصول، المصادقة متعددة العوامل، التحكم في الوصول، إدارة الوصول المميز، والتحكم في الوصول الشبكي
  • ضمان التعزيز الأمني والتكوين الآمن لأنظمة البنية التحتية والأمن
  • مراجعة ممارسات GitHub وCI/CD وDevSecOps وأمن التطبيقات عند الحاجة
  • مراجعة متطلبات النسخ الاحتياطي والتعافي من الكوارث واستمرارية الأعمال وRTO/RPO والمرونة ضد برامج الفدية
  • تقييم اعتبارات حماية البيانات وموقع البيانات ونقل البيانات عبر الحدود
  • تحديد متطلبات الأمن السيبراني وحماية البيانات السعودية ودعم جهود الامتثال
  • صيانة سياسات الأمن والمعايير وسجلات المخاطر والبنية الأمنية والوثائق الفنية
  • تقديم تقارير دورية للإدارة حول المخاطر والفجوات والأولويات والتقدم في المعالجة
  • العمل كممثل أمني فني رئيسي بين الشركة ومزودي الخدمات الخارجيين

الشروط والمتطلبات

  • 3-5+ سنوات خبرة مهنية في الأمن السيبراني، أمن البنية التحتية، أمن الشبكات، هندسة الأمان أو مجال قريب
  • فهم عملي قوي لمبادئ الأمن السيبراني وهندسة الأمان
  • خبرة مثبتة في إجراء التقييمات الأمنية وتحديد الفجوات والمخاطر
  • معرفة قوية بأمن الشبكات: الجدران النارية / NGFW، IPS/IDS، التقسيم الشبكي، VLANs، DMZ، VPN / ZTNA، الوصول الآمن عن بُعد
  • فهم جيد لأمن الخوادم والمحاكاة الافتراضية والأجهزة الطرفية والبنية التحتية
  • معرفة بإدارة الهوية والوصول (IAM)، المصادقة متعددة العوامل (MFA)، التحكم في الوصول (RBAC)، إدارة الوصول المميز (PAM)
  • خبرة أو فهم قوي لـ EDR/XDR وSIEM/SOC والمراقبة الأمنية والتسجيل المركزي
  • فهم لجدار الحماية لتطبيقات الويب (WAF) وأمن الويب/التطبيقات
  • معرفة بعمليات إدارة الثغرات الأمنية واختبار الاختراق
  • فهم للنسخ الاحتياطي والتعافي من الكوارث واستمرارية الأعمال وRTO/RPO والمرونة ضد برامج الفدية
  • الإلمام بـ GitHub وCI/CD وDevSecOps وأمن التطبيقات (ميزة قوية)
  • القدرة على مراجعة وتقييم والاعتراض على البنى التقنية وتصاميم الأمان والتكوينات والعروض المقدمة من البائعين
  • خبرة قوية في التواصل مع الأطراف الفنية والبائعين ومزودي الخدمات
  • مهارات تحليلية وحل مشكلات قوية
  • القدرة على العمل بشكل مستقل وتحمل مسؤولية متطلبات وقرارات الأمن السيبراني
  • مهارات تواصل كتابية وشفهية قوية باللغة الإنجليزية. مهارات الاتصال بالعربية ميزة إضافية

المهارات المطلوبة

المهارات الأساسية تشمل: القدرة على تحديد وتقييم وتصميم وتوصية وقيادة وتنفيذ والتحقق والتحسين في مجال الأمن السيبراني. يجب أن يكون المرشح قادراً على الانتقال بين النقاشات الإدارية والنقاشات الفنية التفصيلية مع مهندسي الأمن. الشهادات التالية تعتبر ميزة قوية: CISSP / CISM، Security+، CCNA / CCNP، شهادات Palo Alto Networks، شهادات Fortinet، شهادات ISO 27001 أو شهادات أخرى ذات صلة.

المزايا

نموذج العمل هجين (عن بُعد / حضور حسب احتياجات العمل)، الحضور في الموقع عادة مرة أو مرتين أسبوعياً في جدة، مع حضور إضافي عند الحاجة للاجتماعات الهامة أو النقاشات مع البائعين أو أنشطة التنفيذ أو التقييمات أو التدقيق. الوظيفة بدوام كامل.

عرض النص الأصلي للإعلان

🚨 We’re Hiring | Cybersecurity & Infrastructure Security Specialist


Company: [Masharah Company]


We are looking for an experienced Cybersecurity & Infrastructure Security Specialist to take ownership of the company’s cybersecurity requirements, security architecture, risk management, and overall security posture.


This role will serve as the company’s technical security authority and primary security representative when dealing with external cybersecurity, infrastructure, network, and technology service providers.


The successful candidate will be responsible for identifying security risks and gaps, defining the required security controls, evaluating and selecting appropriate solutions, leading technical discussions with service providers, overseeing implementation, and validating that the delivered environment meets the company’s security requirements.


🔹 Key Responsibilities


* Own and continuously assess the company’s overall cybersecurity and infrastructure security posture.

* Conduct security assessments and identify security gaps, risks, vulnerabilities, and areas requiring improvement.

* Define cybersecurity requirements, security controls, and technical security standards.

* Develop and review security architecture covering:

  * Network Security

  * Firewalls / NGFW

  * Network Segmentation

  * DMZ / WAF

  * VPN / ZTNA

  * Servers & Virtualization

  * Identity & Access Management

  * EDR/XDR

  * SIEM / SOC

  * Backup & Disaster Recovery

  * Application & Data Security

* Develop cybersecurity and infrastructure security requirements for external service providers.

* Identify, evaluate, and recommend appropriate cybersecurity technologies and solutions.

* Lead technical meetings and discussions with cybersecurity, network, infrastructure, and other service providers.

* Challenge and evaluate vendors’ proposed architectures, technologies, configurations, and security recommendations.

* Review security architecture, HLDs, LLDs, technical proposals, BoQs, and implementation plans.

* Oversee security implementation and ensure agreed security requirements and controls are correctly implemented.

* Validate and test security controls before accepting implemented solutions.

* Establish and oversee vulnerability management and remediation processes.

* Coordinate penetration testing and security assessments and ensure findings are properly remediated.

* Define and oversee security monitoring, logging, SIEM/SOC, EDR/XDR, and alerting requirements.

* Establish incident response, containment, recovery, and security incident-handling requirements.

* Define and review IAM, MFA, RBAC, PAM, privileged access, and network access-control requirements.

* Ensure appropriate security hardening and secure configuration of infrastructure and security systems.

* Review GitHub, CI/CD, DevSecOps, and application security practices where applicable.

* Review backup, disaster recovery, business continuity, RTO/RPO, and ransomware-resilience requirements.

* Assess data protection, data residency, and cross-border data-transfer considerations.

* Identify applicable Saudi cybersecurity and data protection requirements and support compliance efforts.

* Maintain cybersecurity policies, standards, risk registers, security architecture, and technical documentation.

* Provide management with regular updates on security risks, gaps, priorities, and remediation progress.

* Act as the primary technical security representative between the company and external service providers.


🔹 Requirements


* 3-5+ years of professional experience in Cybersecurity, Infrastructure Security, Network Security, Security Engineering, or a closely related field.

* Strong practical understanding of cybersecurity principles and security architecture.

* Demonstrated experience conducting security assessments and identifying security gaps and risks.

* Strong knowledge of network security, including:

  * Firewalls / NGFW

  * IPS/IDS

  * Network segmentation

  * VLANs

  * DMZ

  * VPN / ZTNA

  * Secure remote access

* Good understanding of server, virtualization, endpoint, and infrastructure security.

* Knowledge of IAM, MFA, RBAC, PAM, and privileged-access management.

* Experience or strong understanding of EDR/XDR, SIEM, SOC, security monitoring, and centralized logging.

* Understanding of WAF and web/application security.

* Knowledge of vulnerability management and penetration-testing processes.

* Understanding of backup, disaster recovery, business continuity, RTO/RPO, and ransomware resilience.

* Familiarity with GitHub, CI/CD, DevSecOps, and application security is a strong advantage.

* Ability to review, evaluate, and challenge technical architectures, security designs, configurations, and vendor proposals.

* Strong experience communicating with technical stakeholders, vendors, and service providers.

* Strong analytical and problem-solving skills.

* Ability to work independently and take ownership of cybersecurity requirements and decisions.

* Strong written and verbal communication skills in English.

* Arabic communication skills are a plus.


🔹 Preferred Certifications


The following certifications are considered a strong advantage:


* CISSP / CISM

* Security+

* CCNA / CCNP

* Palo Alto Networks certifications

* Fortinet certifications

* ISO 27001-related certifications

* Other relevant cybersecurity or infrastructure security certifications


🔹 What We’re Looking For


We are looking for someone who can own cybersecurity from the company’s side, rather than simply coordinate between vendors.


The ideal candidate should be capable of:


Identify → Assess → Design → Recommend → Lead → Implement → Validate → Improve


You should be comfortable moving between management-level discussions and detailed technical discussions with cybersecurity and infrastructure engineers.


You will be expected to independently assess proposed solutions, identify security gaps, challenge vendors when necessary, and ensure that the company’s security requirements are properly addressed.


📍 Position Details


Location: Jeddah, Saudi Arabia

Work Model: Hybrid : (Remote/attendance) based on work needs.

(Expected) Onsite Attendance: Typically once/twice per week in Jeddah, with additional attendance when required for important meetings, vendor discussions, implementation activities, assessments, audits, or other business needs.

Employment Type: Full-Time


📩 To Apply: Please send your CV,

To [office@masharah.com]


Please share this opportunity with anyone who may be a suitable candidate.

المصدر: LinkedIn - أُضيفت للموقع في 20 أغسطس 2026