📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

شبكة نقاط الطرود الوطنية (Parcelat) تعلن عن وظيفة مهندس أمن تقنية معلومات في الرياض

IT Security Engineer
🕒 نُشرت: (منذ يومين) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة National Parcel Stations Network | Parcelat (شبكة محطات الطرود الوطنية) عن توفر وظيفة مهندس أمن تقنية المعلومات (IT Security Engineer) في الرياض. تهدف هذه الوظيفة إلى دعم تطبيق معايير الأمان والمراقبة ومتطلبات الامتثال الأساسية، وهي مناسبة للخريجين الجدد الراغبين في التعلم تحت إشراف فريق تقنية المعلومات.

المهام والمسؤوليات

  • المساعدة في تطبيق معايير أمن تقنية المعلومات والسياسات الأمنية الداخلية.
  • دعم أنشطة الامتثال المتعلقة بأنظمة الأمن السيبراني السعودية والمتطلبات الداخلية.
  • المساهمة في الحفاظ على الوثائق الأمنية وقوائم المراجعة وأدلة التدقيق الأساسية.
  • التنسيق مع أعضاء الفريق ذوي الخبرة لمتابعة الإجراءات الأمنية المطلوبة.
  • مراقبة التنبيهات الأمنية ورفع الأنشطة المشبوهة إلى أعضاء الفريق المخضرمين.
  • المساعدة في فحص الثغرات الأمنية ومتابعة حالتها وإصلاحها.
  • دعم عمليات التصحيح والإجراءات التصحيحية من خلال تتبع النتائج ومشاركة التحديثات.
  • الحفاظ على سجلات الحوادث الأمنية والتنسيق مع الفرق المعنية لحلها.
  • تأمين جميع طبقات التطبيقات والبنية التحتية بما في ذلك الواجهات الخلفية والواجهات الأمامية وواجهات APIs وقواعد البيانات والتطبيقات العميلة.
  • إجراء فحص أمني أساسي للكود قبل النشر والإبلاغ عن المخاطر المحددة.
  • تنفيذ ضوابط الوصول والمصادقة والتشفير والتكوينات الآمنة.
  • التعاون مع فريقي DevOps والبنية التحتية لضمان النشر الآمن.
  • تطوير إرشادات الأمان وإجراءات التشغيل المعيارية والتوثيق.
  • إجراء دورات تدريبية وورش عمل لرفع الوعي بين المستخدمين الداخليين والفرق الفنية.
  • تعزيز ثقافة الوعي الأمني في المؤسسة.
  • العمل عن كثب مع فرق البنية التحتية وDevOps والتطوير لضمان بنية آمنة وعمليات آمنة.
  • مراجعة واعتماد الإجراءات الأمنية للأدوات والتطبيقات وعمليات التكامل الجديدة.
  • تقديم المشورة حول متطلبات الأمان للمشاريع والميزات الجديدة أو تكاملات العملاء.
  • التواصل مع الجهات التنظيمية والمراجعين لضمان الامتثال وتقديم التقارير.
  • التنسيق مع البائعين الخارجيين لإجراء التقييمات الأمنية واختبارات الاختراق والشهادات.
  • رفع المخاطر الأمنية الحرجة إلى قيادة تقنية المعلومات والإدارة.

الشروط والمتطلبات

  • درجة البكالوريوس في هندسة الحاسب، علوم الحاسب، الأمن السيبراني، تقنية المعلومات، أو مجال ذي صلة.
  • خريج جديد أو خبرة تصل إلى سنتين في مجال أمن المعلومات أو الأمن السيبراني أو تقنية المعلومات.
  • شهادات أو تدريب معترف به في الأمن السيبراني مثل CompTIA Security+ أو CEH أو ISO 27001 Foundation أو ما يعادلها.
  • فهم أساسي لمفاهيم حوكمة الأمان وإدارة المخاطر والامتثال.
  • معرفة بأمن الشبكات والبنية التحتية (جدران الحماية، VPN، IDS/IPS).
  • معرفة بأمن التطبيقات (الويب، واجهات APIs، تطبيقات الجوال).
  • معرفة بمراقبة الأمان ومنصات SIEM.
  • معرفة بمفاهيم النسخ الاحتياطي واستعادة الكوارث (DR) واستمرارية الأعمال.
  • معرفة بدورة حياة تطوير البرمجيات الآمنة (SSDLC).
  • معرفة بفحص كود الأمان وإدارة الثغرات.
  • الإلمام بأنظمة الأمن السيبراني السعودية وأطرها (NCA ECC, PDPL, ISO 27001) يُفضل.

المهارات المطلوبة

  • الاستعداد للتعلم وتطوير المهارات الأمنية التقنية.
  • عقلية تراعي المخاطر مع الاهتمام بالتفاصيل.
  • قدرة أساسية على فهم المعايير الأمنية وترجمتها إلى مهام تشغيلية يومية.
  • التعاون والتأثير عبر الفرق التقنية وغير التقنية.
  • موقف استباقي تجاه الوعي الأمني والتوثيق والتحسين المستمر.
  • إدارة الثغرات واختبار الاختراق والاستخبارات عن التهديدات.
  • مراقبة الأمان وأدوات SIEM.
  • أمن الشبكات وجدران الحماية وVPN والتشفير وإدارة الهوية والوصول (IAM).
  • أفضل ممارسات أمن التطبيقات.
  • التخطيط للنسخ الاحتياطي واستعادة الكوارث واستمرارية الأعمال.
  • إجادة اللغة الإنجليزية (شرط أساسي).
  • إجادة اللغة العربية (مفضلة).
عرض النص الأصلي للإعلان
Job Description:

The IT Security Engineer supports the implementation of security standards, monitoring activities, and basic compliance requirements to help protect IT systems, applications, and data.

This role is suitable for a fresh graduate who will learn and assist in security awareness, code scanning before deployments, vulnerability follow-up, and applying Saudi cybersecurity regulations under the guidance of senior IT team members.

Responsibilities:

Security Governance & Compliance Support:

  • Assist in implementing IT security standards and internal security policies
  • Support compliance activities related to Saudi cybersecurity regulations and internal requirements
  • Help maintain security documentation, checklists, and basic audit evidence
  • Coordinate with senior team members to follow up on required security actions

Threat & Vulnerability Management:

  • Monitor security alerts and escalate suspicious activities to senior IT team members
  • Assist in vulnerability scanning and follow up on remediation status
  • Support patching and corrective actions by tracking findings and sharing updates
  • Maintain security incident logs and coordinate with relevant teams for incident resolution.

Application & Infrastructure Security:

  • Secure all application and infrastructure layers, including web, backend, APIs, databases, and client applications.
  • Perform basic code security scanning before deployments and report identified risks
  • Implement access control, authentication, encryption, and secure configurations.
  • Collaborate with DevOps and Infra teams to ensure secure deployment of pipelines.

Knowledge Management & Training:

  • Develop security guidelines, SOPs, and documentation.
  • Conduct training sessions and workshops to raise awareness among internal users and technical teams.
  • Promote a security-conscious culture across the organization.

Collaboration & Technical Delivery:

  • Work closely with Infra, DevOps, and Development teams for secure architecture and operations.
  • Review and approve security measures for new tools, applications, and integrations.
  • Advice on security requirements for new projects, features, or customer integrations.

Job Relations:

  • Reports to: IT Infrastructure Lead / IT Manager
  • Internal Relations: DevOps Engineer, Infra Engineer, QA, Development Teams, IT Support

External Communications:

  • Communicate with regulators and auditors to ensure compliance and provide reports
  • Liaise with external vendors for security assessments, penetration tests, and certifications
  • Escalate critical security risks to IT leadership and management

Requirements

  • Bachelor's degree in Computer Engineering, Computer Science, Cybersecurity, Information Technology, or related field
  • Fresh graduate or up to 2 years of experience in Information Security, Cybersecurity, or IT.
  • Relevant cybersecurity certifications or training, such as CompTIA Security+, CEH, ISO 27001 Foundation, or equivalent certifications.
  • Basic understanding of security governance, risk management, and compliance concepts.

Knowledge of:

  • Network and infrastructure security (Firewalls, VPNs, IDS/IPS).
  • Application security (Web, APIs, Mobile Applications).
  • Security monitoring and SIEM platforms.
  • Backup, Disaster Recovery (DR), and Business Continuity concepts.
  • Secure Software Development Lifecycle (SSDLC).
  • Security code scanning and vulnerability management.
  • Saudi cybersecurity regulations and frameworks (NCA ECC, PDPL, ISO 27001) awareness is preferred.

Competencies:

  • Willingness to learn and develop technical security skills
  • Risk-aware mindset with attention to detail
  • Basic ability to understand security standards and translate them into daily operational tasks
  • Collaboration and influence across technical and non-technical teams
  • Proactive attitude toward security awareness, documentation, and continuous improvement

Skills & Languages:

  • Vulnerability management, penetration testing, and threat intelligence
  • Security monitoring and SIEM tools
  • Network security, firewalls, VPNs, encryption, IAM
  • Application security best practices
  • Backup, disaster recovery, and business continuity planning
  • Fluent in English (required)
  • Arabic proficiency (preferred)
المصدر: LinkedIn - أُضيفت للموقع في 27 أغسطس 2026
رقم الإعلان لدى المصدر: 4459802230