📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

وظيفة مدير أمن تقنية المعلومات لدى ArcelorMittal Tubular Products Al-Jubail في الشرقية الجبيل السعودية

Manager, IT Security
🏢 ArcelorMittal Tubular Products Al-Jubail
🕒 نُشرت: (اليوم) 📍 الجبيل وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

شركة ArcelorMittal Tubular Products Al-Jubail في الجبيل (المنطقة الشرقية) تعلن عن توفر وظيفة مدير أمن تقنية المعلومات (Manager, IT Security) لقيادة استراتيجية وحوكمة وتشغيل برنامج أمن المعلومات بالشركة.

نبذة عن الوظيفة

مدير أمن تقنية المعلومات مسؤول عن قيادة استراتيجية وحوكمة وعمليات برنامج أمن المعلومات اليومية في الشركة. يوفر هذا الدور توجيهاً استراتيجياً وقيادة عملية لأمن المعلومات وإدارة المخاطر والامتثال والاستجابة للحوادث، مما يضمن سرية وسلامة وتوفر أنظمة المعلومات. يدير المدير فريقاً من متخصصي أمن المعلومات، ويضع السياسات والمعايير الأمنية، ويتعاون مع فرق تقنية المعلومات والتقنية التشغيلية والأمن السيبراني والأعمال لدمج الأمن في كل مبادرة تقنية وتجارية.

المهام والمسؤوليات

  • تطوير وامتلاك وتحسين استراتيجية أمن المعلومات ومخططها وهندستها المعمارية بالتزامن مع ISO 27001 وNIST واللوائح الوطنية والصناعية المعمول بها.
  • قيادة وتوجيه وإدارة فريق أمن المعلومات (كبار المتخصصين والمتخصصين)، بما في ذلك تخطيط العمل وإدارة الأداء وتطوير القدرات والتخطيط للخلافة.
  • الإشراف على تنفيذ وإدارة تقنيات أمن المعلومات المؤسسية، مثل جدران الحماية وأنظمة كشف/منع الاختراق وحماية نقاط النهاية ومكافحة البرمجيات الخبيثة وبوابات البريد الإلكتروني الآمنة وSIEM وإدارة الثغرات وإدارة الوصول المميز (PAM).
  • الإشراف على تقييمات المخاطر المؤسسية وبرامج إدارة الثغرات واختبارات الاختراق، وتحديد أولويات التوصيات وتتبعها والإبلاغ عن معالجتها.
  • امتلاك برنامج الاستجابة للحوادث الأمنية بالمنظمة - قيادة الاستجابة للحوادث الكبرى والثغرات والتحقيقات الجنائية وتحليل الأسباب الجذرية ومراجعات ما بعد الحادث.
  • إنشاء وصيانة واختبار خطط التعافي من الكوارث (DR) واستمرارية الأعمال (BCP) للأنظمة والخدمات الحرجة أمنياً.
  • تطوير واعتماد وتطبيق سياسات ومعايير وإجراءات وإرشادات أمن المعلومات عبر المنظمة، ودفع برامج التوعية والتدريب المستمرة لجميع الموظفين.
  • ضمان الامتثال للأطر التنظيمية والتعاقدية والصناعية المطبقة (ISO 27001, NIST, SOX, GDPR/PDPL, SOC 2 وغيرها)، والعمل كنقطة اتصال رئيسية لمراجعات الأمن الداخلية والخارجية.
  • إدارة ميزانية أمن المعلومات وعلاقات البائعين ومفاوضات العقود وشراء أدوات وخدمات الأمن بالتعاون مع المشتريات والمالية.
  • التنسيق مع فرق البنية التحتية والشبكات والتطبيقات والسحابة وخدمة المكتب لدمج مبادئ الأمن عند التصميم في المشاريع والأنظمة وعمليات إدارة التغيير.
  • تقديم تقارير ولوحات معلومات منتظمة حول الوضع الأمني والتعرض للمخاطر ومؤشرات الأداء الرئيسية واتجاهات الحوادث لإدارة تقنية المعلومات والإدارة التنفيذية.

الشروط والمتطلبات

  • درجة البكالوريوس في علوم الحاسب أو أمن المعلومات أو الأمن السيبراني أو مجال ذي صلة؛ ويفضل درجة الماجستير أو شهادة مهنية في أمن المعلومات/الإدارة.
  • خبرة لا تقل عن 10 سنوات متقدمة في مجال أمن المعلومات/الأمن السيبراني، تتضمن 3-5 سنوات على الأقل في دور إداري أو قيادي يشرف على عمليات أمن المعلومات.

المهارات المطلوبة

  • معرفة قوية بأطر ومعايير الأمن (ISO 27001, NIST CSF/SP 800-53, COBIT).
  • خبرة عملية واستراتيجية في SIEM وإدارة الثغرات وIDS/IPS وجدران الحماية وحماية نقاط النهاية وPAM ومنصات أمن البريد الإلكتروني.
  • فهم متين لأمن السحابة (Azure, AWS)، وأساسيات أمن الشبكات، وإدارة الهوية والوصول (Active Directory, Azure AD/Entra ID).
  • إلمام بالخوادم والمحاكاة الافتراضية (VMware, Hyper-V)، والشبكات، وأمن الحاويات (Docker, Kubernetes).
  • معرفة عملية بالبرمجة النصية/الأتمتة (PowerShell, Python, Bash) لدعم عمليات الأمن والتقارير.
  • فهم قوي لممارسات ITSM/ITIL، وإدارة التغيير، وأطر حوكمة تقنية المعلومات.
  • قدرات مثبتة في القيادة وإدارة الفرق والتوجيه والإرشاد.
  • مهارات ممتازة في إدارة العلاقات مع أصحاب المصلحة والتواصل التنفيذي، مع القدرة على ترجمة المخاطر التقنية إلى مصطلحات تجارية.
  • مهارات تحليلية قوية واتخاذ القرار وإدارة الأزمات، خاصة أثناء الحوادث الأمنية.
  • القدرة على إدارة الميزانيات والبائعين والمشاريع المتعددة والأولويات المتزامنة.
عرض النص الأصلي للإعلان

ROLE SUMMARY:

The Manager, IT Security is responsible for leading the strategy, governance, and day-to-day operations of the organization's IT Security program across the company. This role provides both strategic direction and hands-on leadership for security operations, risk management, compliance, and incident response, ensuring the confidentiality, integrity, and availability of information systems. The Manager leads a team of IT Security specialists, sets security policy and standards, and partners closely with IT, OT, Cybersecurity and business, to embed security into every technology and business initiative.


ROLES & RESPONSIBILITIES:

• Develop, own, and continuously refine the enterprise IT security strategy, roadmap, and reference architecture aligned with ISO 27001, NIST, and applicable national/industry regulations.

• Lead, mentor, and manage the IT Security team (Senior Specialists and Specialists), including workload planning, performance management, capability development, and succession planning.

• Direct the implementation and administration of enterprise security technologies, including firewalls, IDS/IPS, endpoint protection, anti-malware, email security gateways, SIEM, vulnerability management, and Privileged Access Management (PAM) solutions.

• Oversee enterprise risk assessments, vulnerability management programs, and penetration testing exercises; prioritize, track, and report on remediation of identified risks.

• Own the organization's security incident response program - lead major incident and breach response, forensic investigations, root cause analysis, and post-incident reviews.

• Establish, maintain, and regularly test disaster recovery (DR) and business continuity plans (BCP) for security critical systems and services.

• Develop, approve, and enforce information security policies, standards, procedures, and guidelines across the organization; drive ongoing security awareness and training programs for all employees.

• Ensure compliance with applicable regulatory, contractual, and industry frameworks (ISO 27001, NIST, SOX, GDPR/PDPL, SOC 2, etc.), and act as the primary point of contact for internal and external security audits.

• Manage the IT Security budget, vendor relationships, contract negotiations, and procurement of security tools and services in collaboration with Procurement and Finance.

• Experience in IT Infrastructure, Network, Applications, Cloud, and Service Desk teams to embed security-by-design principles into projects, systems, and change management processes.

• Provide regular reporting and dashboards on security posture, risk exposure, KPIs, and incident trends to IT leadership and executive management.


QUALIFICATION & EDUCATION:

• Bachelor’s degree in computer science, Information Security, Cybersecurity, or a related field; a master’s degree or professional certification in Information Security/Management is preferred.


EXPERIENCE:

• Minimum of 10 years of progressive experience in IT/cybersecurity, including at least 3-5 years in managerial or team-lead capacity overseeing IT security operations.


SKILLS:

Technical Skills

• Strong knowledge of security frameworks and standards (ISO 27001, NIST CSF/SP 800-53, COBIT).

• Hands-on and strategic experience with SIEM, vulnerability management, IDS/IPS, firewalls, endpoint protection, PAM, and email security platforms.

• Solid understanding of cloud security (Azure, AWS), network security fundamentals, and identity and access management (Active Directory, Azure AD/Entra ID).

• Familiarity with servers, virtualization (VMware, Hyper-V), Networks and container security (Docker, Kubernetes).

• Working knowledge of scripting/automation (PowerShell, Python, Bash) to support security operations and reporting.

• Strong understanding of ITSM/ITIL practices, change management, and IT governance frameworks.

Soft Skills and Leadership Competencies

• Proven leadership, team management, coaching, and mentoring capabilities.

• Excellent stakeholder management and executive communication skills, with the ability to translate technical risk into business terms.

• Strong analytical, decision-making, and crisis-management skills, particularly during security incidents.

• Ability to manage budgets, vendors, and multiple concurrent projects and priorities.

المصدر: LinkedIn - أُضيفت للموقع في 23 أغسطس 2026

وظائف أخرى لدى ArcelorMittal Tubular Products Al-Jubail