وظيفة مرشد CISO (بدوام جزئي) شاغرة لدى Jobgether في السعودية
تفاصيل الوظيفة
Jobgether تعلن، بالنيابة عن شركة شريكة، عن فرصة عمل كمستشار وموجه لأمن المعلومات (CISO Mentor) بنظام الدوام الجزئي في المملكة العربية السعودية. تهدف هذه الوظيفة إلى تقديم التوجيه الاستراتيجي والدعم لتطوير وظيفة أمن معلومات قابلة للتوسع والنضج داخل بيئة تقنية عالمية سريعة النمو، وذلك من خلال الإرشاد والاستشارة التنفيذية لعدة ساعات شهريًا فقط.
المهام والمسؤوليات
- إرشاد مستشاري أمن المعلومات وتقديم المشورة حول بناء وتوسيع وتحسين برنامج أمن المعلومات بشكل مستمر.
- تقديم التوجيه الاستراتيجي بشأن دفاعات طبقة الشبكة والمحيط، مثل جدار الحماية لتطبيقات الويب (WAF)، وتقييد المعدل، وحماية مكافحة البوتات، وتخفيف هجمات حجب الخدمة الموزعة (DDoS).
- تقديم المشورة حول تأمين واجهات برمجة التطبيقات (APIs) للمنتج ضد الاستغلال والحركة الشاذة والتهديدات الأخرى على مستوى التطبيق.
- تعزيز آليات المصادقة والتفويض وضوابط الوصول والحماية من الثغرات مثل IDOR.
- توجيه عملية إدارة الثغرات، بما في ذلك تحديد الثغرات وترتيب أولوياتها ومعالجتها وتتبعها.
- تقديم المشورة بشأن برامج اختبار الاختراق الخارجي ودعم المعالجة الفعالة للنتائج المحددة.
- توفير القيادة والتوجيه للاستجابة لحوادث أمن المنتج، بما في ذلك إدارة الأزمات والأنشطة بعد الحادث.
- المساعدة في إنشاء عمليات فعالة للكشف والاستجابة بالتعاون مع فرق المراقبة وأمن المعلومات.
- المساهمة بخبرات أمن المعلومات في مبادرات الاحتيال والثقة والسلامة وغيرها من المبادرات متعددة الوظائف ذات الصلة.
- تقديم المشورة بشأن حماية بيانات العملاء من خلال ضوابط الوصول والتشفير والإخفاء وغيرها من الضمانات المناسبة.
- إرشاد الفرق المسؤولة عن برنامج أبطال الأمن (Security Champions) وتعزيز ممارسات التطوير الآمن عبر المنتج والهندسة.
- توفير الإشراف الاستراتيجي والتوجيه لبرنامج مكافأة الثغرات (Bug Bounty).
- المساعدة في إنشاء أطر إدارة المخاطر، وخرائط الامتثال، وممارسات إدارة مخاطر البائعين.
الشروط والمتطلبات
- خبرة لا تقل عن 7 سنوات في أدوار قيادية عليا في أمن المعلومات مثل CISO أو نائب رئيس أمن المعلومات أو رئيس أمن المعلومات، مع سجل قوي في إرشاد أو تقديم المشورة لقادة أمن ناشئين.
- خبرة مثبتة في بناء وتوسيع وإدارة برنامج أمن المعلومات من الصفر (zero-to-one) داخل شركة ناشئة أو مؤسسة متنامية.
- خبرة عملية عميقة في العمل ضمن بيئات شديدة التنظيم مثل التكنولوجيا المالية (FinTech) أو التكنولوجيا الصحية (HealthTech) أو التكنولوجيا الحكومية (GovTech)، بما في ذلك اجتياز عمليات تدقيق صارمة وأطر عمل مثل SOC 2 Type II وISO 27001 وPCI-DSS وHIPAA أو GDPR.
- معرفة معمارية قوية بتأمين الأنظمة الموزعة عالية الإنتاجية والتوفر والسحابية الأصلية عبر AWS أو GCP أو Azure، مع الحفاظ على الأداء وقابلية التوسع.
- فهم قوي لإدارة المخاطر الاستراتيجية والحوكمة والامتثال (GRC)، مع القدرة على إنشاء عمليات إدارة المخاطر والامتثال والمخاطر المتعلقة بالبائعين وتدريب الآخرين على تطبيقها.
- مهارات اتصال تنفيذية استثنائية، بما في ذلك القدرة على ترجمة المخاطر التقنية المعقدة إلى تأثيرات تجارية واضحة، وإرشاد قادة أمن المعلومات في التواصل مع المدراء التنفيذيين ومجالس الإدارة.
- خبرة موثقة في تصميم وقيادة برامج الاستجابة للحوادث على مستوى المؤسسات، بما في ذلك إدارة الأزمات والاتصالات بعد الاختراق.
- قدرة مثبتة على بناء وتعزيز ثقافة أمنية أولى عبر وظائف الهندسة والمنتج والأعمال.
- مهارات قوية في الإرشاد والتدريب وإدارة أصحاب المصلحة وحل المشكلات الاستراتيجي.
- إجادة اللغة الروسية بطلاقة.
المزايا
- دوام جزئي يتطلب بضع ساعات فقط شهريًا.
- بيئة عمل تعتمد على العمل عن بُعد مع مرونة العمل من بولندا.
- فرصة لتقديم المشورة وإرشاد قيادات أمن المعلومات مع تحقيق تأثير استراتيجي هادف.
- التعاون مع فريق دولي موزع من خبراء التكنولوجيا وأمن المعلومات.
- التعرض لمنتجات رقمية معقدة وموزعة عالميًا وعالية المستوى وتحديات أمنية.
- التزام مرن مصمم ليناسب الالتزامات المهنية الأخرى.
عرض النص الأصلي للإعلان
As a CISO Mentor, you will advise and support the development of a mature, scalable Information Security function within a fast-growing, globally distributed technology environment. This part-time role is designed for an experienced security executive who can provide strategic guidance while helping emerging security leaders navigate complex challenges. You will contribute expertise across product security, governance, risk and compliance, incident response, cloud security, and security culture. Your guidance will help strengthen defenses, improve security processes, and establish scalable practices without compromising product performance or business agility. You will work closely with security, engineering, product, monitoring, and business teams, sharing practical knowledge and executive-level perspective. This is an opportunity to make meaningful impact through focused mentorship and strategic advisory support while working only several hours per month.
Accountabilities
- Mentor and advise security leaders on building, scaling, and continuously improving an Information Security program.
- Provide strategic guidance on perimeter and network-layer defenses, including WAF, rate limiting, anti-bot protections, and DDoS mitigation.
- Advise on securing product APIs against abuse, anomalous traffic, and other application-level threats.
- Strengthen authentication, authorization, access controls, and protections against vulnerabilities such as IDOR.
- Guide the Vulnerability Management process, including vulnerability identification, prioritization, remediation, and tracking.
- Advise on external penetration testing programs and support effective remediation of identified findings.
- Provide leadership and guidance for product security Incident Response, including crisis management and post-incident activities.
- Help establish effective detection and response processes in collaboration with monitoring and security teams.
- Contribute security expertise to Fraud, Trust & Safety, and related cross-functional initiatives.
- Advise on customer data protection through access controls, encryption, masking, and other appropriate safeguards.
- Mentor teams responsible for the Security Champions program and promote secure development practices across product and engineering.
- Provide strategic oversight and guidance for the Bug Bounty program.
- Help establish risk management frameworks, compliance roadmaps, and vendor risk management practices.
- 7+ years of experience in senior Information Security leadership roles such as CISO, VP of Security, or Head of Information Security, with a strong track record of mentoring or advising emerging security leaders.
- Proven zero-to-one experience building, scaling, and managing an Information Security program from the ground up within a startup or scaling organization.
- Deep practical experience operating in highly regulated environments such as FinTech, HealthTech, or GovTech, including successfully navigating rigorous audits and frameworks such as SOC 2 Type II, ISO 27001, PCI-DSS, HIPAA, or GDPR.
- Strong architectural knowledge of securing high-throughput, highly available, distributed systems and cloud-native environments across AWS, GCP, or Azure, while maintaining performance and scalability.
- Strong understanding of strategic Governance, Risk, and Compliance, with the ability to establish risk management, compliance, and vendor risk processes and coach others in applying them.
- Exceptional executive communication skills, including the ability to translate complex technical risks into clear business impacts and mentor security leaders in communicating with C-level executives and Boards.
- Demonstrated experience designing and leading enterprise-grade Incident Response programs, including crisis management and post-breach communications.
- Proven ability to build and promote a security-first culture across engineering, product, and business functions.
- Strong mentoring, coaching, stakeholder management, and strategic problem-solving abilities.
- Fluent Russian.
- Part-time engagement requiring only several hours per month.
- Remote-first working environment with the flexibility to work from Poland.
- Opportunity to advise and mentor security leadership while having a meaningful strategic impact.
- Collaboration with an international, distributed team of technology and security professionals.
- Exposure to complex, globally distributed, high-scale digital products and security challenges.
- Flexible engagement designed to fit alongside other professional commitments.
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
رقم الإعلان لدى المصدر: 4460235946