وظيفة مهندس معماري أول لأمن السحابة, Mandiant, Cloud and Infrastructure لدى Google في السعودية
تفاصيل الوظيفة
تعلن Google عن وظيفة Senior Cloud Security Architect ضمن فريق Mandiant في Cloud and Infrastructure، مقر العمل الرياض (السعودية) مع إمكانية العمل عن بُعد. يجب أن يكون لدى المتقدم تصريح عمل في السعودية، حيث لا يتوفر دعم لتأشيرة عمل.
نبذة عن الوظيفة
بصفتك جزءًا من فريق خدمات تحويل الأمن (STS) في Mandiant، ستساعد المؤسسات في بناء برنامج عمليات أمني فعال يقلل المخاطر التنظيمية ويخفف تأثير الاختراقات الأمنية. ستستخدم أحدث المعايير الصناعية وتجربة Mandiant في الاستجابة للحوادث والاستخبارات والممارسات الدفاعية المدارة لمساعدة العملاء على احتواء الحوادث الأمنية وتحويل برامجهم الأمنية. في هذا الدور، ستعمل ضمن فرق لمعالجة المشاريع والتواصل مع العملاء وتقديم المساعدة السريعة في أنشطة الاحتواء والمعالجة، مع إنشاء وتقديم مخرجات عالية الجودة. ستقوم بتقييم احتياجات الضحايا بسرعة والاستعانة بموارد Mandiant المختلفة.
المهام والمسؤوليات
- تقديم المشورة والدعم لبرنامج الأمن السيبراني للمنظمة العميلة على المستوى التكتيكي (مثل البنية التحتية، السحابة، التطوير، المشاريع، التقنية، الاستجابة للحوادث، المعالجة، وأنشطة التعافي عبر مختلف التقنيات).
- إدارة المشاريع والإشراف عليها، بما في ذلك التحقق وتتبع المهام التفصيلية للمعالجة في مهام الاستجابة للحوادث التي تمتد عبر مسارات عمل متعددة وتخصيص الموارد وتتبع التقدم لتقييمات الأمان.
- التواصل بشأن استراتيجيات المعالجة ومسارات العمل مع أصحاب المصلحة من العملاء، بما في ذلك الكوادر الفنية والإدارة التنفيذية والمستشارين القانونيين.
- تحديد أصحاب المصلحة الداخليين للعملاء، وبناء العلاقات، وتوقع الاحتياجات طويلة الأجل وترجمتها إلى خدمات Mandiant، وحشد الموارد وتعزيز الفرص.
- إشراك الفرق لتخطيط وتنسيق عمليات إعادة تعيين كلمات المرور على مستوى المؤسسة.
الشروط والمتطلبات
- درجة البكالوريوس في علوم الحاسب، نظم المعلومات، الأمن السيبراني، أو مجال تقني ذي صلة، أو خبرة عملية معادلة.
- خبرة 5 سنوات في مجال الأمن السيبراني.
- خبرة في تطوير خطط المشاريع وقيادة الفرق لتنفيذ التوصيات التقنية.
- خبرة في توثيق متطلبات المشروع التي تحدد النطاق والجدول الزمني والتسليمات التقنية.
- خبرة في إدارة البرامج والقيادة التقنية.
- يفضل: خبرة في ضوابط الأمان المؤسسي في البنى التحتية المحلية والسحابية، بنية الثقة الصفرية (Zero Trust)، بنية منصات المؤسسات الآمنة، موفري الهوية مثل Google Cloud Platform وActive Directory وSalesforce وهويات B2B/B2C ومنصات التعاون.
- يفضل: خبرة في الشبكات المؤسسية واستراتيجيات تجزئة الشبكة، إدارة البرامج والمشاريع الرشيقة (Agile)، منهجية SCRUM، DevSecOps، ممارسات GRC، إطار NIST للأمن السيبراني وغيرها.
- يفضل: خبرة في تعزيز أمان نقاط النهاية (Endpoint Hardening) لأنظمة Windows وUnix وفرض ضوابط الأمان.
- يفضل: خبرة في إدارة الوصول المميز (Privileged Access Management).
- القدرة على التواصل مع العملاء الداخليين والخارجيين وشرح التفاصيل التقنية بوضوح وإيجاز.
- القدرة على السفر بنسبة تصل إلى 50% من الوقت.
عرض النص الأصلي للإعلان
Note: By applying to this position you will have an opportunity to share your preferred working location from the following:
In-office locations: Riyadh Saudi Arabia.
Remote location(s): Saudi Arabia.Minimum qualifications:
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, related technical field, or equivalent practical experience.
- 5 years of experience working within a cybersecurity domain.
- Experience developing project plans and leading teams to implement technical recommendations.
- Experience documenting project requirements that define scope, schedule, and technical deliverables.
- Experience in program management and technical leadership.
- Experience with enterprise security controls in on-premises and Cloud Infrastructures, Zero Trust Architecture, Secure Enterprise Platforms Architecture, Identity providers such as, Google Cloud Platform, Active Directory, Salesforce, B2B/B2C identities and collaboration platforms.
- Experience with enterprise networking and network segmentation strategies, agile program and project management, SCRUM methodology, DevSecOps, GRC practices, NIST cybersecurity framework and others.
- Experience with Windows and Unix endpoint hardening and security control enforcement.
- Experience with privileged access management.
- Ability to communicate with internal and external customers, explaining technical details clearly and concisely.
- Ability to travel up to 50% of the time.
In this role, you will work in teams to address projects, communicate with clients, expediting assistance with containment and remediation activities, while creating and presenting high-quality deliverables. You will quickly assess victim needs, engage various Mandiant resources.Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.
Responsibilities
- Advise and support the client organization’s cybersecurity program at a tactical level (e.g., infrastructure, cloud, development, projects, technology, incident response, remediation, and recovery activities across various technologies).
- Manage and govern projects, including validation and tracking detailed remediation tasks for incident response remediation engagements spanning multiple workstreams and resource assignments and tracking progress for security assessments.
- Communicate remediation strategies and workstreams to client stakeholders, including technical staff, executive leadership, and legal counsel.
- Identify client internal stakeholders, build relationships, anticipate long-term needs and translate to Mandiant services, rally resources and foster opportunities.
- Engage teams to plan and coordinate enterprise-scale password resets.