Al Safi Danone تعلن عن وظيفة قائد أمن تقنية المعلومات في الرياض
تفاصيل الوظيفة
تسعى شركة الصافي دانون (Al Safi Danone) في الرياض إلى تعيين قائد أمن المعلومات (IT Security Lead) لتنفيذ وإدارة برنامج أمن المعلومات المؤسسي لحماية الأنظمة والبيانات والأصول الرقمية من التهديدات السيبرانية وضمان الامتثال التنظيمي.
المهام والمسؤوليات
- امتلاك استراتيجية أمن المعلومات، إطار السياسات، وخريطة الطريق الأمنية للمؤسسة.
- تنسيق وصيانة سياسات ومعايير وإجراءات أمن المعلومات.
- إنتاج تقارير ربع سنوية عن مخاطر الأمن لمدير عمليات تقنية المعلومات.
- إجراء تقييمات سنوية لمخاطر أمن المعلومات؛ صيانة سجل المخاطر المؤسسي وخطط المعالجة.
- ضمان الامتثال للوائح ذات الصلة بما في ذلك قانون حماية البيانات الشخصية السعودي (PDPL) واللائحة العامة لحماية البيانات (GDPR) وإطار هيئة الاتصالات والفضاء والتقنية (NCA ECC).
- التعاون مع وظيفة مركز العمليات الأمنية (SOC) في المراقبة والتنبيه.
- قيادة أنشطة الاستجابة للحوادث؛ امتلاك خطة الاستجابة للحوادث ودفاتر التشغيل لأحداث الأمن السيبراني من المستوى P1/P2.
- إدارة خلاصات معلومات التهديدات وبرنامج إدارة الثغرات؛ تحديد أولويات التصحيح بناءً على التعرض للمخاطر.
- إجراء اختبارات الاختراق المنتظمة، وتمارين الفريق الأحمر، وتقييمات الأمن؛ معالجة النتائج ضمن اتفاقيات مستوى الخدمة المتفق عليها.
- الإشراف على الكشف والاستجابة للنقاط الطرفية (EDR) باستخدام Microsoft Defender for Endpoint عبر جميع أجهزة المؤسسة.
- إدارة تخطيط استمرارية الأعمال (BCP) والتعافي من الكوارث (DR) لسيناريوهات الأحداث السيبرانية.
- تحديد وحوكمة بنية أمن SAP S/4HANA بما في ذلك التحكم في الوصول المبني على الأدوار، وفصل المهام (SoD)، وتسجيل التدقيق.
- مراجعة مخرجات تصميم أمن SAP التي ينتجها مُتكامل الأنظمة؛ والتحقق من مطابقتها لمعايير أمن المؤسسة.
- إجراء تحليل تضارب فصل المهام (SoD) أثناء اختبار قبول المستخدم وقبل التشغيل؛ ضمان المعالجة قبل النقل إلى الإنتاج.
- إدارة متطلبات الأمن لجميع أنظمة التطبيقات: SalesBuzz، SalesCode، Shelfr، SO99، وتطبيقات SaaS الخارجية.
- التعاون مع برنامج إدارة الهوية والوصول (IAM) الخاص بالمجموعة (AFG) بما في ذلك إدارة الوصول المميز (PAM) وتنفيذ نموذج الثقة المعدومة (Zero Trust).
- حوكمة عمليات توفير وإلغاء توفير المستخدمين وشهادات الوصول عبر جميع الأنظمة بما في ذلك SAP وM365.
- إدارة تكوين أمن Azure Active Directory/Entra ID: MFA، الوصول المشروط، PIM، وحماية الهوية.
- تحديد وتطبيق مبادئ الوصول بأقل امتياز وسياسات فصل الأدوار عبر أنظمة تقنية المعلومات والأعمال.
- إجراء مراجعات وصول ربع سنوية وتدقيق صلاحيات المستخدمين؛ الإبلاغ عن الاستثناءات لمدير عمليات تقنية المعلومات.
- تقديم برنامج التوعية والتدريب الأمني على مستوى المؤسسة؛ تتبع معدلات الإكمال ونتائج محاكاة التصيد.
- إدارة تقييمات مخاطر أمن الطرف الثالث وسلسلة التوريد؛ تضمين متطلبات الأمن في عقود الموردين.
- التواصل مع التدقيق الداخلي بشأن نتائج التدقيق المتعلقة بالأمن؛ تطوير ومتابعة خطط المعالجة.
- التحضير والدعم لعمليات التدقيق التنظيمية الخارجية والشهادات بما في ذلك NCA ECC وISO 27001 ومتطلبات أمن هيئة الزكاة والضريبة والجمارك (ZATCA).
- إنتاج لوحات مقاييس أمن شهرية تغطي مشهد التهديدات وحالة الثغرات ووضع الامتثال.
الشروط والمتطلبات
- درجة البكالوريوس في الأمن السيبراني، علوم الحاسب، نظم المعلومات، أو مجال ذي صلة.
- شهادة CISM (مدير أمن المعلومات المعتمد) - مطلوبة، أو CISA - مفضلة.
- شهادة Microsoft SC-200 (محلل عمليات الأمن) أو SC-300 - ميزة إضافية.
- خبرة من 5 إلى 8 سنوات في مجال أمن المعلومات، منها 3 سنوات على الأقل في دور قيادي أمني.
- خبرة مثبتة في تأمين بيئات SAP بما في ذلك تصميم الأدوار، تحليل فصل المهام (SoD)، وتدقيق أمن SAP.
- خبرة في أمن السحابة: Azure Security Center / Defender for Cloud، AWS GuardDuty، أو GCP SCC.
- معرفة بالمتطلبات التنظيمية السعودية: قانون حماية البيانات الشخصية (PDPL) وإطار الأمن السيبراني لهيئة الاتصالات والفضاء والتقنية (NCA ECC) - مفضلة بشدة.
- خبرة قوية في الاستجابة للحوادث والتحقيق الجنائي؛ مهارات تواصل في الأزمات.
- خبرة في قطاع دول مجلس التعاون الخليجي أو السلع الاستهلاكية سريعة الحركة (FMCG) ميزة إضافية.
- مهارات ممتازة في التواصل حول المخاطر؛ خبرة في عرض المخاطر الأمنية على الإدارة التنفيذية ومجلس الإدارة.
عرض النص الأصلي للإعلان
Role Purpose:
The IT Security Lead is responsible for implementing and managing ASD’s enterprise information security programme to protect its systems, data, and digital assets from cyber threats and ensure regulatory compliance. The role establishes and matures the organization's security posture through policy, technology, and awareness - with a specific focus on securing the SAP S/4HANA programme environment, Microsoft platforms, cloud infrastructure, and operational technology. The Security Lead operates within the B-ITSC governance framework and reports on security risk to executive leadership and the board.
Key Accountabilities:
- Own ASD’s information security strategy, policy framework, and security roadmap.
- Coordinate and maintain information security policies, standards, and procedures.
- Produce quarterly security risk reports for the IT Operations Manager.
- Conduct annual information security risk assessments; maintain the enterprise security risk register and treatment plans.
- Ensure compliance with applicable regulations including PDPL (Saudi Personal Data Protection Law), GDPR, and NCA ECC framework.
- Collaborate with the Security Operations Centre (SOC) function, monitoring and alerting.
- Lead incident response activities; own the Incident Response Plan and Playbooks for P1/P2 cyber security events.
- Manage threat intelligence feeds and vulnerability management programme; prioritize patching based on risk exposure.
- Conduct regular penetration testing, red team exercises, and security assessments; remediate findings within agreed SLAs.
- Oversee endpoint detection and response (EDR) using Microsoft Defender for Endpoint across all ASD devices.
- Manage Business Continuity Planning (BCP) and Disaster Recovery (DR) for cyber event scenarios.
- Define and govern the SAP S/4HANA security architecture including role-based access control, segregation of duties (SoD), and audit logging.
- Review SAP security design deliverables produced by the system integrator; validate against ASD’s security standards.
- Conduct SoD conflict analysis during UAT and prior to go-live; ensure remediation before production cutover.
- Manage security requirements for all application systems: SalesBuzz, SalesCode, Shelfr, SO99, and third-party SaaS.
- Collaborate with AFG, ASD’s Identity and Access Management (IAM) programme including Privileged Access Management (PAM) and Zero Trust implementation.
- Govern user provisioning, de-provisioning, and access certification processes across all systems including SAP and M365.
- Manage Azure Active Directory / Entra ID security configuration: MFA, Conditional Access, PIM, and identity protection.
- Define and enforce least-privilege access principles and role segregation policies across IT and business systems.
- Conduct quarterly access reviews and user entitlement audits; report exceptions to the IT Operations Manager.
- Deliver the organisation-wide security awareness and training programme; track completion rates and phishing simulation outcomes.
- Manage third-party and supply chain security risk assessments; include security requirements in vendor contracts.
- Liaise with Internal Audit on security-related audit findings; develop and track remediation action plans.
- Prepare for and support external regulatory audits and certifications, including NCA ECC, ISO 27001, and ZATCA security requirements.
- Produce monthly security metrics dashboards covering threat landscape, vulnerability posture, and compliance status.
Qualifications:
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field.
- CISM (Certified Information Security Manager) - required or CISA - preferred.
- Microsoft SC-200 (Security Operations Analyst) or SC-300 - advantageous.
- 5-8 years of experience in information security, with at least 3 years in a security leadership role.
- Proven experience securing SAP environments including role design, SoD analysis, and SAP security audit.
- Experience with cloud security: Azure Security Center / Defender for Cloud, AWS GuardDuty, or GCP SCC.
- Knowledge of Saudi Arabia regulatory requirements: PDPL and NCA ECC cybersecurity framework - strongly preferred.
- Strong incident response and forensic investigation experience; crisis communication skills.
- GCC or FMCG industry experience is an advantage.
- Excellent risk communication skills; experience presenting security risk to executive and board audiences.
وظائف أخرى لدى Al Safi Danone | الصافي دانون
الصافي دانون تعلن عن وظيفة مدير جودة العمليات في الرياض والخرج