وظيفة مهندس أمن سيبراني لدى IT Security Training & Solutions - I(TS)² في الرياض
تفاصيل الوظيفة
تعلن شركة IT Security Training & Solutions - I(TS)² عن توفر وظيفة Security Architect في مدينة الرياض. تتضمن الوظيفة تأمين معلومات المؤسسة من خلال تحديد متطلبات الأمان، تخطيط وتنفيذ واختبار أنظمة الأمان، وإعداد معايير وسياسات الأمان، بالإضافة إلى توجيه أعضاء الفريق.
المهام والمسؤوليات
- مراجعة إجراءات أمان النظام الحالية وتقديم توصيات وتنفيذ التحسينات.
- إجراء اختبارات نظام منتظمة وضمان المراقبة المستمرة لأمن الشبكة.
- وضع جداول زمنية للمشاريع للتحديثات المستمرة للنظام.
- إنشاء إجراءات التعافي من الكوارث وإجراء تدريبات على اختراق الأمان.
- الاستجابة الفورية لجميع حوادث الأمان وتقديم تحليلات شاملة بعد الحادث.
- تنمية ثقافة الوعي الأمني وترتيب التعليم المستمر للموظفين لضمان الالتزام بسياسات الأمان في جميع الأوقات.
- إنشاء حلول توازن بين متطلبات العمل ومتطلبات أمن المعلومات والأمن السيبراني.
- تحديد فجوات التصميم الأمني في البنى الحالية والمقترحة والتوصية بالتغييرات أو التحسينات.
- تعزيز إنجازات فريق الأمان من خلال تخطيط تقديم الحلول والإجابة على الأسئلة التقنية والإجرائية لأعضاء الفريق الأقل خبرة وتعليم العمليات المحسنة وتوجيه أعضاء الفريق.
- تحديد متطلبات الأمان من خلال تقييم استراتيجيات العمل ومتطلباته والبحث في معايير أمن المعلومات وإجراء تحليلات أمان النظام وتحليلات الثغرات وتقييم المخاطر ودراسة البنية/المنصة وتحديد قضايا التكامل وإعداد تقديرات التكلفة.
- تخطيط أنظمة الأمان من خلال تقييم تقنيات الشبكة والأمان وتطوير متطلبات الشبكات المحلية والواسعة والشبكات الخاصة الافتراضية وأجهزة التوجيه وجدران الحماية والأجهزة الأمنية ذات الصلة وتصميم البنى التحتية للمفاتيح العامة بما في ذلك استخدام سلطات التصديق والتوقيعات الرقمية والأجهزة والبرامج مع الالتزام بالمعايير الصناعية.
- تنفيذ أنظمة الأمان من خلال تحديد منهجيات ومعدات كشف الاختراق وتوجيه تركيب المعدات والبرامج ومعايرتها وإعداد التدابير الوقائية والتصحيحية وإنشاء المفاتيح ونقلها وصيانتها وتقديم الدعم الفني وإكمال التوثيق.
- التحقق من أنظمة الأمان من خلال تطوير وتنفيذ نصوص اختبار.
- الحفاظ على الأمان من خلال مراقبة وضمان الامتثال للمعايير والسياسات والإجراءات وإجراء تحليلات الاستجابة للحوادث وتطوير وتنفيذ برامج تدريبية.
- ترقية أنظمة الأمان من خلال مراقبة البيئة الأمنية وتحديد الثغرات الأمنية وتقييم وتنفيذ التحسينات.
- إعداد تقارير أمان النظام من خلال جمع وتحليل وتلخيص البيانات والاتجاهات.
- تحديث المعرفة الوظيفية من خلال تتبع وفهم الممارسات والمعايير الأمنية الناشئة والمشاركة في الفرص التعليمية وقراءة المنشورات المهنية والحفاظ على الشبكات الشخصية والمشاركة في المنظمات المهنية.
- تعزيز سمعة القسم والمنظمة من خلال تحمل مسؤولية إنجاز المهام الجديدة والمختلفة واستكشاف فرص إضافة قيمة إلى الإنجازات الوظيفية.
الشروط والمتطلبات
- خبرة 10 سنوات أو أكثر في مجال الأمن السيبراني مع 4 سنوات أو أكثر في دور مماثل.
- خبرة واسعة في أمن المعلومات و/أو إدارة مخاطر تكنولوجيا المعلومات مع التركيز على الأمان والأداء والموثوقية.
- درجة البكالوريوس في علوم الحاسوب أو الأمن السيبراني (يفضل الماجستير في الأمن السيبراني).
- الشهادات المطلوبة: SABSA (Sherwood Applied Business Security Architecture) و CISSP (Certified Information Systems Security Professional). الشهادات الاختيارية: TOGAF, Zachman Framework, CISM, CISA, ISSAP, ISSEP.
- اللغة الإنجليزية بمستوى طلاقة تجارية. اللغة العربية ميزة إضافية.
المهارات المطلوبة
- فهم متين لبروتوكولات الأمان، التشفير، المصادقة، التفويض والأمان.
- معرفة باعتبارات أمن الحوسبة السحابية بما في ذلك خروقات البيانات، المصادقة المكسورة، الاختراق، اختطاف الحسابات، التهديدات الداخلية، الأطراف الثالثة، التهديدات المتقدمة المستمرة (APTs)، فقدان البيانات وهجمات حجب الخدمة (DoS).
- معرفة بإطار إدارة الهوية والوصول (IAM) - إطار السياسات الأمنية والتقنيات التي تحد وتتبع وصول الأفراد داخل المؤسسة إلى موارد تكنولوجيا الحساسة.
- معرفة جيدة بالمخاطر الحالية لتكنولوجيا المعلومات وخبرة في تنفيذ حلول أمنية.
- خبرة في تنفيذ المصادقة متعددة العوامل، الدخول الموحد (SSO)، تقنيات إدارة الهوية أو ما يتعلق بها.
- القدرة على التفاعل مع شريحة واسعة من الموظفين لشرح وتنفيذ إجراءات الأمان.
- مهارات تواصل كتابية وشفهية ممتازة بالإضافة إلى الفطنة التجارية والنظرة التجارية.
- مهارات قوية في التفكير النقدي والتحليل.
- مهارات قيادة وإدارة مشاريع وبناء فرق قوية، بما في ذلك القدرة على قيادة الفرق ودفع المشاريع والمبادرات في عدة أقسام.
- القدرة المثبتة على تحديد المخاطر المرتبطة بالعمليات التجارية والعمليات التشغيلية وبرامج أمن المعلومات ومشاريع تكنولوجيا المعلومات.
- القدرة على أن تكون خبيراً في أمن المؤسسة يمكنه شرح المواضيع التقنية لغير المتخصصين تقنياً.
عرض النص الأصلي للإعلان
Job Description:
Secures enterprise information by determining security requirements; planning, implementing, and testing security systems; preparing security standards, policies, and procedures; mentoring team members. Expected to have a thorough understanding of complex IT & security systems and stay up to date with the latest security standards, systems and authentication protocols, as well as best practice security products.
Responsibilities:
In addition to anticipating possible security threats and identifying areas of weakness in a network system, a Security Architect must respond promptly and effectively to possible breaches of security. Additional responsibilities include:
·Reviewing current system security measures and recommending and implementing enhancements
·Conducting regular system tests and ensuring continuous monitoring of network security
·Developing project timelines for ongoing system upgrades
·Establishing disaster recovery procedures and conducting breach of security drills
·Promptly responding to all security incidents and providing thorough post-event analyses
- Cultivates a culture of security awareness, and arranging continuing education of personnel to ensure security policies are adhered to at all times.
- Create solutions that balance business requirements with information and cyber security requirements
- Identify security design gaps in existing and proposed architectures and recommend changes or enhancements
- Enhances security team accomplishments and competence by planning delivery of solutions; answering technical and procedural questions for less experienced team members; teaching improved processes; mentoring team members.
- Determines security requirements by evaluating business strategies and requirements; researching information security standards; conducting system security and vulnerability analyses and risk assessments; studying architecture/platform; identifying integration issues; preparing cost estimates.
- Plans security systems by evaluating network and security technologies; developing requirements for local area networks (LANs), wide area networks (WANs), virtual private networks (VPNs), routers, firewalls, and related security and network devices; designs public key infrastructures (PKIs), including use of certification authorities (CAs) and digital signatures as well as hardware and software; adhering to industry standards.
- Implements security systems by specifying intrusion detection methodologies and equipment; directing equipment and software installation and calibration; preparing preventive and reactive measures; creating, transmitting, and maintaining keys; providing technical support; completing documentation.
- Verifies security systems by developing and implementing test scripts.
- Maintains security by monitoring and ensuring compliance to standards, policies, and procedures; conducting incident response analyses; developing and conducting training programs.
- Upgrades security systems by monitoring security environment; identifying security gaps; evaluating and implementing enhancements.
- Prepares system security reports by collecting, analyzing, and summarizing data and trends.
- Updates job knowledge by tracking and understanding emerging security practices and standards; participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations.
- Enhances department and organization reputation by accepting ownership for accomplishing new and different requests; exploring opportunities to add value to job accomplishments.
Experience & Skills:
·10+ years in Cyber Security with 4+ years in similar role
·Extensive experience in information security and/or IT risk management with a focus on security, performance and reliability
·Solid understanding of security protocols, cryptography, authentication, authorisation and security
- Security architecture, demonstrating solutions delivery, principles and emerging technologies - Designing and implementing security solutions. This includes continuous monitoring and making improvements to those solutions, working with an information security team.
- Consulting and engineering in the development and design of security best practices and implementation of solid security principles across the organization, to meet business goals along with customer and regulatory requirements.
- Security considerations of cloud computing: They include data breaches, broken authentication, hacking, account hijacking, malicious insiders, third parties, APTs, data loss and DoS attacks.
·Identity and access management (IAM) - the framework of security policies and technologies that limit and track the access of those in an organization to sensitive technology resources.
·Good working knowledge of current IT risks and experience implementing security solutions
·Experience implementing multi-factor authentication, single sign-on, identity management or related technologies
·Ability to interact with a broad cross-section of personnel to explain and enforce security measures
·Excellent written and verbal communication skills as well as business acumen and a commercial outlook
- Strong critical thinking and analytical skills
- Strong leadership, project and team-building skills, including the ability to lead teams and drive projects and initiatives in multiple departments
- Demonstrated ability to identify risks associated with business processes, operations, information security programs and technology projects
- The ability to be the enterprise security subject matter expert who can explain technical topics to those without a technical background
Education:
- Bachelor’s degree ideally in Computer Science or Cyber Security. Masters in Cyber Security preferred.
Certifications:
- Must Have: SABSA (Sherwood Applied Business Security Architecture) and CISSP (Certified Information Systems Security Professional) certifications.
- Optional: TOGAF, Zachman Framework, CISM, CISA, Information Systems Security Architecture Professional (ISSAP), Information Systems Security Engineering Professional (ISSEP)
Languages: English - business fluent. Arabic a plus.