وظيفة خبير أنظمة أول (أمن شبكات) لدى وزارة الاتصالات وتقنية المعلومات في الرياض
تفاصيل الوظيفة
تعلن وزارة الاتصالات وتقنية المعلومات عن حاجتها لشغل وظيفة Senior Systems Expert (Network Security) في مدينة الرياض، للمساهمة في عمليات أمن الشبكات من خلال تنفيذ سياسات وضوابط الأمن السيبراني، وحماية البنية التحتية للشبكات، وتحليل الحوادث الأمنية، وتشغيل تقنيات أمن الشبكات، وذلك لدعم حماية الأصول التقنية واستمرارية الخدمة والامتثال لمتطلبات ومعايير الأمن السيبراني.
المهام والمسؤوليات
- دعم تنفيذ سياسات أمن الشبكات، وإدارة تكوينات جدران الحماية (Firewalls)، ومراجعة ضوابط الوصول، وتنفيذ إجراءات العزل للأنظمة عالية المخاطر وفقاً للسياسات والإجراءات المعتمدة.
- تشغيل ومراقبة تقنيات أمن الشبكات، وصيانة وتحديث توقيعات الأمان، والتنسيق مع الجهات المعنية لمعالجة الثغرات الأمنية المؤثرة على مكونات البنية التحتية للشبكات.
- دعم تنفيذ ضوابط أمن تطبيقات الويب، وسياسات تصفية المحتوى وأمن البريد الإلكتروني، والإشراف على تخفيف المخاطر المتعلقة بالوصول وفقاً لمعايير الأمن المعتمدة.
- تحليل الحوادث الأمنية السيبرانية المتعلقة بالشبكات، والمساهمة في تحليل الأسباب الجذرية، وتنفيذ إجراءات المعالجة، وإعداد التقارير والوثائق الفنية ذات الصلة.
- المشاركة في تقييم التقنيات الأمنية الجديدة، وإجراء اختبارات التغيير والتنفيذ، وتقييم تأثيرها على أمن الشبكات واستقرار الخدمة، وتقديم التوصيات المناسبة.
- دعم تنفيذ سياسات الأمن السيبراني والمعايير والضوابط، وصيانة وثائق الضوابط الأمنية، ومراقبة مستويات الامتثال، وتحديد مجالات التحسين.
- تنفيذ السياسات والإجراءات والقوالب والأدوات التشغيلية المعتمدة.
- اتخاذ القرارات التشغيلية المتعلقة بقسم حماية أنظمة الشبكات ضمن الصلاحية المحددة.
- تحديد فرص التحسين المستمر في الأنظمة والعمليات والممارسات التشغيلية وفقاً لأفضل الممارسات الصناعية.
- تحديد المراحل والأنشطة الرئيسية المطلوبة لتحقيق أهداف الخطة التشغيلية لقسم حماية أنظمة الشبكات.
- تنفيذ ومراقبة معايير الأداء ومؤشرات الأداء الرئيسية لقسم حماية أنظمة الشبكات، وضمان التوافق مع الأهداف المحددة.
- عقد اجتماعات دورية مع مدير عام التقنيات الأمنية الرقمية لتقديم تقارير الأداء والإنجازات والتقدم نحو أهداف القسم.
- تمثيل القسم في فرق العمل والمشاركة في المبادرات المشتركة بين الإدارات لدعم التنفيذ والتنسيق الفعال.
- إعداد وتقديم تقارير دورية تغطي أنشطة القسم وأداءه والتقدم نحو الأهداف المحددة.
- حفظ وتوثيق وأرشفة السجلات الداخلية والبيانات والإجراءات والمستندات الداعمة وفقاً للسياسات والمعايير المعمول بها لضمان سهولة الوصول وإدارة المعرفة.
- أداء أي مهام أخرى تُسند إليه ضمن نطاق الدور ومجال التخصص.
الشروط والمتطلبات
- درجة البكالوريوس أو أعلى في تقنية المعلومات، أو علوم الحاسب، أو نظم المعلومات، أو هندسة الحاسب، أو تخصص ذي صلة.
- خبرة مهنية لا تقل عن 6 سنوات في مجال أمن الشبكات والبنية التحتية، تتضمن خبرة عملية متقدمة في تأمين وحماية بيئات الشبكات ضمن بنى تحتية تقنية كبيرة ومعقدة.
المهارات المطلوبة
- خبرة متقدمة في تصميم وتنفيذ وإدارة حلول أمن الشبكات، بما في ذلك جدران الحماية (Firewalls)، وأنظمة كشف/منع الاختراق (IPS/IDS)، والتحكم في الوصول إلى الشبكة (NAC)، والبوابة الآمنة للويب (Secure Web Gateway)، والشبكات الخاصة الافتراضية (VPN)، وتقسيم الشبكات (Network Segmentation)، وغيرها من تقنيات أمن البنية التحتية للشبكات.
- خبرة في تأمين بيئات الشبكات عبر مراكز البيانات والمنصات السحابية والبيئات الهجينة.
- خبرة قوية في تحديد وتقييم المخاطر والثغرات الأمنية السيبرانية المتعلقة بالشبكات، ووضع خطط المعالجة وتخفيف المخاطر.
- معرفة قوية بأطر الأمن السيبراني والمعايير والضوابط، مع إلمام مثبت بمتطلبات وضوابط الأمن السيبراني الصادرة عن الهيئة الوطنية للأمن السيبراني (NCA) في المملكة العربية السعودية.
- يفضل الحصول على الشهادات المهنية التالية: CCNP Security / CCIE Security، CISSP، CISM، Fortinet NSE / Fortinet Certified Professional or Expert، Palo Alto Networks Certified Network Security Engineer (PCNSE)، Check Point CCSA / CCSE، وشهادات أمن السحابة مثل CCSP أو ما يعادلها.
عرض النص الأصلي للإعلان
Job Description
Contribute to network security operations by implementing cybersecurity policies and controls, protecting network infrastructure, analyzing security incidents, and operating network security technologies. The role supports the protection of technology assets, service continuity, and compliance with applicable cybersecurity requirements and standards.
Key Responsibilities
- Support the implementation of network security policies, manage firewall configurations, review access controls, and execute isolation measures for high-risk systems in accordance with approved security policies and procedures.
- Operate and monitor network security technologies, maintain and update security signatures, and coordinate the remediation of vulnerabilities affecting network infrastructure components with relevant stakeholders.
- Support the implementation of web application security controls, content filtering and email security policies, and oversee the mitigation of access-related risks in line with approved security standards.
- Analyze network-related cybersecurity incidents, contribute to root cause analysis, implement remediation measures, and prepare relevant technical reports and documentation.
- Participate in the assessment of new security technologies, conduct change and implementation testing, evaluate their impact on network security and service stability, and provide appropriate recommendations.
- Support the implementation of cybersecurity policies, standards, and controls; maintain security control documentation; monitor compliance levels; and identify areas for improvement.
- Implement approved policies, processes, procedures, templates, and operational tools.
- Make operational decisions related to the Network Systems Protection Section within the assigned level of authority.
- Identify continuous improvement opportunities across systems, processes, and operational practices in line with leading industry practices.
- Define key milestones and activities required to achieve the objectives and operational plan of the Network Systems Protection Section.
- Implement and monitor performance standards and KPIs for the Network Systems Protection Section, ensuring alignment with established objectives.
- Conduct regular progress meetings with the Director of Digital Security Technologies to report on performance, achievements, and progress toward departmental objectives.
- Represent the section in working groups and participate in cross-functional initiatives to support effective execution and coordination.
- Prepare and submit periodic reports covering section activities, performance, and progress against established objectives.
- Maintain, document, and archive internal records, data, procedures, and supporting documentation in accordance with applicable policies and standards to ensure effective accessibility and knowledge management.
- Perform any other duties assigned within the scope of the role and area of specialization.
Job Requirements
- Bachelor's degree or higher in Information Technology, Computer Science, Information Systems, Computer Engineering, or a related discipline.
- Minimum of 6 years of professional experience in network and infrastructure security, including advanced hands-on experience in securing and protecting network environments within large-scale and complex technology infrastructures.
- Advanced experience in the design, implementation, and administration of network security solutions, including Firewalls, IPS/IDS, Network Access Control (NAC), Secure Web Gateway, VPN, Network Segmentation, and other network infrastructure security technologies.
- Experience securing network environments across data centers, cloud platforms, and hybrid infrastructure environments.
- Strong experience in identifying and assessing network-related cybersecurity risks and vulnerabilities, as well as developing remediation and risk mitigation plans.
- Strong knowledge of cybersecurity frameworks, standards, and controls, with demonstrated familiarity with the cybersecurity requirements and controls issued by Saudi Arabia's National Cybersecurity Authority (NCA).
Preferred Professional Certifications
- CCNP Security / CCIE Security
- CISSP
- CISM
- Fortinet NSE / Fortinet Certified Professional or Expert
- Palo Alto Networks Certified Network Security Engineer (PCNSE)
- Check Point CCSA / CCSE
- Cloud Security certifications such as CCSP or equivalent.
رقم الإعلان لدى المصدر: 4458896268