وظيفة أخصائي أول أمن البيانات والامتثال لدى Exquitech Group في الرياض
تفاصيل الوظيفة
تقدم شركة Exquitech Group فرصة عمل في الرياض، السعودية، لوظيفة Senior Data Security & Compliance Specialist للعمل ضمن فريق متخصص في تنفيذ حلول أمن البيانات والحوكمة باستخدام Microsoft Puruvieow لعملاء منطقة MEA.
نبذة عن الوظيفة
نبحث عن متخصص متمرس في أمن البيانات والامتثال لقيادة تنفيذ سياسات أمن البيانات وتصنيفها والاحتفاظ بها والحوكمة باستخدام Microsoft Purview. يتطلب المرشح خبرة لا تقل عن 4 سنوات في مجال أمن البيانات، منها سنتان على الأقل من الخبرة العملية مع Microsoft Purview، وتحديداً في منع فقدان البيانات (DLP) وتصنيف البيانات وCASB وقدرات الحوكمة مثل سياسات الاحتفاظ وإدارة مخاطر الداخلية وإدارة السجلات. يتضمن الدور الإشراف على عضو فريق واحد على الأقل مع إمكانية توسع القيادة. تعتبر الخبرة في حلول أمن البيانات من طرف ثالث قيمة مضافة.
المهام والمسؤوليات
- تصميم وتنفيذ وتحسين حلول أمن البيانات باستخدام Microsoft Purview أو أدوات DLP وحوكمة البيانات الرائدة الأخرى.
- تطوير وتطبيق سياسات DLP وإدارة مخاطر الداخلية (Insider Risk Management) وDSPM للذكاء الاصطناعي وCASB لمنع الوصول غير المصرح به للبيانات وضمان الامتثال.
- تنفيذ استراتيجيات تصنيف البيانات ووضع العلامات لتعزيز حماية البيانات.
- تحديد وإدارة سياسات الاحتفاظ بالبيانات بما يتماشى مع المتطلبات التنظيمية والتجارية.
- نشر وإدارة ماسح AIP المحلي لتصنيف وحماية البيانات المحلية.
- دمج CASB مع جدران الحماية المحلية لتعزيز ضوابط الأمان والرؤية في بيئات السحابة والمحلية.
- قيادة تنفيذ وتكوين Microsoft Priva وMicrosoft Purview Data Map.
- ضمان الامتثال للوائح الصناعية مثل GDPR وNCA وISO 27001.
- دعم مبادرات إدارة وضع أمن البيانات (DSPM) من خلال تقييم المخاطر ومراقبة تدفقات البيانات وتحسين سياسات الأمان.
- بناء قوالب وأتمتة لتنفيذ حوكمة وأمن البيانات لضمان الاتساق والكفاءة في عمليات النشر.
- أتمتة نشر السياسات والتكوينات الأمنية باستخدام أدوات مثل PowerShell وAPIs وأدوات Microsoft Security & Compliance.
- نشر سياسات MDM وMAM وConditional Access لمعالجة الفجوات الأمنية وتعزيز ضوابط الوصول.
- الإشراف على تنفيذ المشاريع المتعلقة بالأمن بدءاً من تحديد النطاق الأولي حتى دعم ما بعد النشر.
- تطوير التصاميم عالية المستوى (HLD) والمنخفضة المستوى (LLD) لتنفيذ المشاريع وتقييم بيئات العملاء وإنشاء RFIs وIRLs حسب الحاجة.
- مراقبة والاستجابة لحوادث أمن البيانات وضمان التحقيق والحل المناسبين.
- تحليل مخاطر أمن البيانات وتنفيذ أفضل الممارسات للتخفيف من التهديدات.
- تحسين السياسات والضوابط الأمنية بناءً على احتياجات العمل المتطورة.
- الإشراف على عضوين فريق على الأقل مع إمكانية زيادة مسؤوليات القيادة.
- العمل عن كثب مع الفرق متعددة الوظائف والعملاء لمواءمة السياسات الأمنية مع أهداف العمل وضمان التنفيذ السلس.
- التعاون مع أصحاب المصلحة لتحسين وضع الأمن وسياسات الحوكمة استجابةً لاحتياجات العمل المتطورة.
- تقديم ورش عمل للمستخدمين النهائيين والمشرفين لضمان الفهم والاعتماد الصحيح لأدوات الامتثال وأمن البيانات.
- المساهمة في نطاق العمل (SOW) وتحديد نطاق المشروع مع تحديد مخرجات واضحة وخرائط طريق للتنفيذ.
- تطوير وصيانة وثائق التنفيذ وأدلة المستخدمين النهائيين والأدلة الإدارية لدعم تبني التكنولوجيا.
- ضمان توفر ووظائف بيئة اختبار تقنية للاختبار الداخلي والتجربة مع التقنيات الجديدة.
الشروط والمتطلبات
- درجة البكالوريوس في علوم الحاسب أو تكنولوجيا المعلومات أو الأمن السيبراني أو مجال ذي صلة.
- خبرة لا تقل عن 4 سنوات في تنفيذ حلول أمن البيانات والامتثال والحوكمة مع تركيز قوي على Microsoft Purview.
- سنتان على الأقل في دور إشرافي مع الإشراف على تنفيذ وتقديم مبادرات حماية البيانات والامتثال.
- خبرة عملية في تنفيذ حلول Microsoft Purview Information Protection بما في ذلك DLP وتصنيف البيانات وسياسات الاحتفاظ والامتثال التنظيمي.
- خبرة في تنفيذ متطلبات حوكمة البيانات وإدارة المخاطر والامتثال التنظيمي وفق أطر مثل GDPR وNCA وISO 27001.
- خبرة واسعة في العمل مع Microsoft Purview Compliance Portal وInsider Risk Management وeDiscovery وAudit.
- خبرة في سياسات DLP عبر خدمات Microsoft 365 بما في ذلك Teams وSharePoint وOneDrive وExchange Online.
- فهم قوي لـ Microsoft Information Protection (MIP) للتصنيف والتشفير وإدارة الحقوق.
- الإلمام بـ Microsoft Defender for Cloud Apps لمراقبة أمن البيانات واكتشاف التهديدات.
- معرفة بـ Microsoft Intune لإدارة الأجهزة المحمولة (MDM) وإدارة التطبيقات المحمولة (MAM) وتكامله مع سياسات الوصول المشروط (Conditional Access).
- القدرة على التواصل الفعال مع أصحاب المصلحة التقنيين وغير التقنيين حول استراتيجيات حماية البيانات ومتطلبات الامتثال.
- شهادة GIAC Certified Data Protection أو ما يعادلها.
- شهادات بائعين في أدوات DLP وتصنيف البيانات أو حوكمة البيانات.
- يفضل: شهادة Microsoft Certified: Information Protection Administrator Associate (SC-400).
- يفضل: شهادة Cybersecurity Architect Expert (SC-100).
المهارات المطلوبة
- قدرات قيادية قوية وإدارة فريق.
- مهارات ممتازة في إدارة المشاريع.
- معرفة في تصميم وهندسة الحلول الأمنية.
- إتقان أدوات أمن البيانات مثل DLP وتصنيف البيانات وCASB.
- قدرات تحليلية وحل مشكلات قوية مع الانتباه للتفاصيل والقدرة على العمل تحت الضغط.
- مهارات تواصل فعالة والتفاعل مع العملاء.
- فهم شامل لممارسات وطرق ضمان الجودة.
- خبرة عملية في تنفيذ حلول Microsoft Purview.
- خبرة مثبتة في تكوين واستكشاف أخطاء الحلول الأمنية.
- الالتزام بمواكبة الاتجاهات الناشئة في أمن البيانات والمخاطر والتقنيات وأفضل الممارسات.
عرض النص الأصلي للإعلان
Employment Type: Full-Time
Job Summary:
We are seeking a skilled Data Security & Compliance Specialist to lead the implementation of data security, classification, retention, and governance policies using Microsoft Purview for customers across the MEA region. The ideal candidate will have at least 4 years of focused experience in the data security field, including a minimum of 2 years of hands-on experience with Microsoft Purview, specifically in Data Loss Prevention, Data Classification, Cloud Access Security Broker, and governance capabilities such as retention policies, Insider Risk Management, and Records Management.
This role involves overseeing at least one team member, with potential for expanded leadership responsibilities. Strong expertise in Microsoft Purview is required, and experience with third-party data security solutions is highly valued, making this an excellent opportunity for professionals with a diverse security background. Familiarity with MDM & MAM solutions, particularly Microsoft Intune, as well as conditional access policies is a plus. This position offers a dynamic environment with opportunities for growth and leadership in the data security domain.
Key Responsibilities
1. Data Security & Governance Implementation
- Design, implement, and optimize data security solutions using Microsoft Purview or other leading DLP and data governance tools.
- Develop and enforce DLP, Insider Risk Management, DSPM for AI and CASB policies to prevent unauthorized data access and ensure compliance.
- Implement data classification and labeling strategies to enhance data protection.
- Define and manage data retention policies in alignment with regulatory and business requirements.
- Deploy and manage AIP on-premises scanner to classify and protect on-premises data.
- Integrate CASB with on-premises firewalls to strengthen security controls and enhance visibility into both cloud and on-premises environments.
- Lead the implementation and configuration of Microsoft Priva and Microsoft Purview Data Map.
- Ensure compliance with industry regulations such as GDPR, NCA, and ISO 27001.
- Support Data Security Posture Management (DSPM) initiatives by assessing risks, monitoring data flows, and optimizing security policies to enhance data visibility, governance, and protection.
- Build templates and automation for Data Security & Governance Implementation, ensuring consistency and efficiency in deployments.
- Automate policy deployments and security configurations using available methods such as PowerShell, APIs, and Microsoft Security & Compliance tools.
- Deploy MDM, MAM, and Conditional Access policies to address security gaps and enhance access controls.
- Oversee the implementation of security-related projects, from initial scoping to post-deployment support, ensuring timely and budget-compliant execution.
- Develop High-Level Designs (HLD) and Low-Level Designs (LLD) for project implementation, assess customer environments, and create RFIs and IRLs as needed.
2. Monitoring, Incident Response, and Optimization
- Monitor and respond to data security incidents, ensuring proper investigation and resolution.
- Analyze data security risks and implement best practices to mitigate threats.
- Optimize security policies and controls based on evolving business needs.
3. Team Supervision & Cross-Functional Collaboration
- Supervise at least two team members, with potential for increased leadership responsibilities.
- Work closely with cross-functional teams and customers to align security policies with business objectives and ensure seamless implementation.
- Collaborate with stakeholders to continuously enhance security posture and governance policies in response to evolving business needs.
- Deliver end-user and administrator workshops to ensure proper understanding and adoption of data security, classification, governance policies, and compliance tools.
4. Documentation & Project Support
- Contribute to Scope of Work (SOW) and project scoping, defining clear deliverables and implementation roadmaps.
- Develop and maintain implementation documentation, end-user guides, and administrative manuals to support technology adoption.
- Ensure the availability and functionality of a technical test environment for internal testing and experimentation with new technologies, coordinating maintenance, updates, and enhancements as needed.
Qualifications & Experience
Education
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
Experience
- Minimum of 4 years of experience in implementing data security, compliance, and governance solutions, with a strong focus on Microsoft Purview.
- At least 2 years in a supervisory role, overseeing the implementation and delivery of data protection and compliance initiatives.
- Hands-on experience implementing Microsoft Purview Information Protection solutions, including DLP, data classification, retention policies, and regulatory compliance.
- Experience implementing data governance, risk management, and regulatory compliance requirements aligned with frameworks such as GDPR, NCA, and ISO 27001.
- Extensive experience working with Microsoft Purview Compliance Portal, Insider Risk Management, eDiscovery, and Audit.
- Experience with Microsoft Purview Data Loss Prevention (DLP) policies across Microsoft 365 services, including Teams, SharePoint, OneDrive, and Exchange Online.
- Strong understanding of Microsoft Information Protection (MIP) for labeling, encryption, and rights management.
- Familiarity with Microsoft Defender for Cloud Apps for data security monitoring and threat detection.
- Knowledge of Microsoft Intune for Mobile Device Management (MDM) & Mobile Application Management (MAM) and how it integrates with Conditional Access policies for secure access control.
- Ability to effectively communicate data protection strategies, compliance requirements, and risk management policies to both technical and non-technical stakeholders.
Certifications
Required Certifications
- GIAC Certified Data Protection or an equivalent certification.
- Vendor certifications in DLP, Data Classification, Litigation Holds, or governance tools.
- Preferred Certifications
- Microsoft Certified: Information Protection Administrator Associate (SC-400)
- Cybersecurity Architect Expert (SC-100)
Skills
- Strong leadership and team management capabilities.
- Excellent project management skills.
- Knowledge in security solution design and architecture.
- Proficiency in data security tools such as DLP, Data Classification, and CASB.
- Strong analytical and problem-solving abilities, with attention to detail and the ability to work under pressure.
- Effective communication and customer engagement skills.
- Thorough understanding of quality assurance practices and methodologies.
- Hands-on experience in implementing Microsoft Purview solutions.
- Proven experience in configuring and troubleshooting security solutions.
- Commitment to staying updated with emerging data security trends, risks, technologies, and best practices to enhance protection and compliance.