وظيفة مستشار أمن شبكات (مراجعة جدران الحماية) شاغرة لدى SIGMA بالرياض
Network Security Consultant (Firewall Review)
🏢 SIGMA
تفاصيل الوظيفة
تعلن شركة SIGMA عن توفر وظيفة مستشار أمن شبكات (مراجعة جدران الحماية) في مدينة الرياض.
المهام والمسؤوليات
- مراجعة تكوينات جدران الحماية لدى العميل عبر المناطق المختلفة (On-prem، OT/ICS، Cloud).
- تدقيق قواعد جدران الحماية الحالية لتحديد الإدخالات المسموحة بشكل مفرط أو القديمة، وتطبيق التحسينات.
- تقييم هيكل تجزئة الشبكة لضمان الفصل المنطقي بين البيئات وفرض ضوابط الوصول باستخدام ACLs.
- توثيق جميع الخدمات والمنافذ المسموح بها لكل قطاع.
- تحديد تدفقات حركة المرور المشروعة للشبكة وتطبيق سياسة الرفض الافتراضي (Default-Deny).
- تحديث القواعد لضمان تجزئة شبكة تكنولوجيا المعلومات بشكل مناسب وتقييد الخدمات بحركة المرور المصرح بها فقط.
- دمج سجلات جدران الحماية مع نظام SIEM لتحسين الرؤية واكتشاف الحوادث.
- إنشاء عملية مراجعة دورية لتقييم تكوينات جدران الحماية وقوائم ACL.
- ضمان امتثال جميع التغييرات لمعايير NCA و ISO و NIST والمعايير العالمية ذات الصلة.
- تحديث وصيانة توثيق تجزئة الشبكة وقواعد جدران الحماية.
- إعداد مصفوفة الاتصالات (Communication Matrix) بصيغة XLSX/CSV تتضمن الأعمدة: المصدر، الوجهة، المنافذ، البروتوكولات، المبرر، الإصدار، تاريخ الموافقة.
- تطوير سياسة جدران الحماية بناءً على مصفوفة الاتصالات وتحديد القواعد لحركة المرور الواردة والصادرة.
- إعداد عرض تقديمي يلخص مصفوفة الاتصالات وسياسات جدران الحمية بصيغ PDF و PPT و Docx و XLS مع قسم للموافقة.
- إجراء مراجعة شاملة لمصفوفة الاتصالات وسياسة جدران الحماية وعرض النتائج على أصحاب المصلحة للحصول على الموافقة.
- مرحلة الاكتشاف: مراجعة مخططات بنية الشبكة الحالية وسياسات الأمن، وإجراء مقابلات مع مسؤولي الأنظمة والمطورين ومهندسي الشبكات وفريق أمن المعلومات لفهم متطلبات الاتصال.
- مرحلة التطوير: صياغة مصفوفة الاتصالات الأولية بناءً على المتطلبات المجمعة، والتعاون مع أصحاب المصلحة لتحسينها والتحقق منها، وتحويل المصفوفة النهائية إلى مسودة سياسة لجدران الحماية.
- مرحلة المراجعة والموافقة: إجراء مراجعة شاملة، وتقديم النتائج والمبررات لأصحاب المصلحة، ودمج الملاحظات والحصول على الموافقات اللازمة.
الشروط والمتطلبات
- جميع أعضاء الفريق العاملين في هذا المشروع يجب أن يكونوا متواجدين في الموقع (On-site).
- جميع الموارد يجب أن تكون حاصلة على شهادات مهنية ذات صلة (Certified).
- الالتزام بسياسات وإجراءات تقنية المعلومات وأمن المعلومات الخاصة بالعميل، ويجب التوقيع على إقرار بذلك قبل بدء أي من أنشطة المشروع.
المهارات المطلوبة
- خبرة في مراجعة تكوينات جدران الحماية وتحليل قواعدها وتطبيق سياسة الرفض الافتراضي.
- إلمام بتجزئة الشبكات وضوابط الوصول باستخدام ACLs.
- معرفة بمعايير الأمن السيبراني مثل NCA و ISO و NIST.
- القدرة على توثيق وإعداد مصفوفات الاتصالات وسياسات جدران الحماية بتنسيقات منظمة.
- فهم لبيئات الشبكات المختلفة (On-prem، OT/ICS، Cloud).
- مهارات تحليلية وقدرة على إجراء مقابلات مع أصحاب المصلحة لتحديد متطلبات الاتصال.
عرض النص الأصلي للإعلان
• Review CLIENT’s firewall configurations across zones.
• Audit existing firewall rules to identify overly permissive or obsolete entries and apply optimizations.
• Assess network segmentation structure to ensure logical separation between environments and enforce access controls using ACLs.
• Document all allowed services and ports per segment.
• Define legitimate network traffic flows and apply a default-deny policy.
• Update rules to ensure the IT network is adequately segmented and services are restricted to authorized traffic only.
• Integrate firewall logs with the SIEM for improved visibility and incident detection.
• Establish a periodic review process to evaluate firewall and ACL configurations.
• Ensure all changes comply with NCA, ISO, NIST, and global relevant standards.
• Update and maintain documentation for network segmentation and firewall rules.
• Review firewall configurations across on-prem, OT/ICS, and cloud clusters.
• Audit existing rules to identify overly permissive or obsolete entries; apply optimizations and default-deny policy.
• Assess network segmentation between zones.
• Deliver the Communication Matrix in XLSX/CSV with columns: Source, Destination, Ports, Protocols, Justification, Version, Approval Date.
• Final firewall must undergo security architecture review by CLIENT- architecture Cybersecurity.
Communication Matrix and Firewall Policy Development:
Identify and document all communication paths required between production environments (system infra solutions, approximately 70 Application, DB, network solutions, information security solutions), DEV environments, and other segments.
• Include detailed justifications for each allowed communication path.
• Format: Spreadsheet or table format detailing source, destination, ports (Application), protocols, and justification.
• Firewall Policy:
• Translate the communication matrix into a comprehensive firewall policy.
• Clearly define rules for inbound and outbound traffic based on identified communication paths.
• Ensure alignment with industry best practices and organizational security policies.
• Document the firewall policy in a structured format for easy implementation and future updates.
• Approval Documentation:
• Prepare a presentation summarizing the communication matrix and firewall policies in presentable and editable version format in (PDF, PPT, Docx, XLS)
• Full structured and standard document for communication matrix and firewall policies in presentable and editable version format in (PDF, PPT, Docx, XLS) with approval section.
• Include rationale and justifications for each communication path and firewall rule.
• Present to relevant stakeholders for approval and sign-off.
• This document should contain the below sections but not limited to those points.
1. Purpose and Scope
2. Stakeholders
3. Communication Goals
4. Information to be Communicated
5. Communication Methods
6. Responsibility
7. Timing and Schedule
8. Feedback Mechanisms process.
9. Metrics and Evaluation
10. Revision History
11. Approval from all Stakeholders
• Discovery Phase:
• Review existing network architecture diagrams and security policies.
• Conduct interviews with system administrators, developers, network engineers, information security team to understand communication requirements.
• All the project members who will be working in this project must be on-site resource/s and they should be certified
• All the resources must follow CLIENT IT and Information Security policies and procedures and they should be committed to follow these policies and procedures via CLIENT approved documentation process before starting any of the project activities
• Development Phase:
• Draft the initial communication matrix based on gathered requirements.
• Collaborate with stakeholders to refine and validate the matrix.
• Convert the finalized matrix into a draft firewall policy.
• Review and Approval Phase:
• Conduct a comprehensive review of the communication matrix and firewall policy.
• Present findings, rationale, and justifications to stakeholders.
• Incorporate feedback and obtain necessary approvals.
• Audit existing firewall rules to identify overly permissive or obsolete entries and apply optimizations.
• Assess network segmentation structure to ensure logical separation between environments and enforce access controls using ACLs.
• Document all allowed services and ports per segment.
• Define legitimate network traffic flows and apply a default-deny policy.
• Update rules to ensure the IT network is adequately segmented and services are restricted to authorized traffic only.
• Integrate firewall logs with the SIEM for improved visibility and incident detection.
• Establish a periodic review process to evaluate firewall and ACL configurations.
• Ensure all changes comply with NCA, ISO, NIST, and global relevant standards.
• Update and maintain documentation for network segmentation and firewall rules.
• Review firewall configurations across on-prem, OT/ICS, and cloud clusters.
• Audit existing rules to identify overly permissive or obsolete entries; apply optimizations and default-deny policy.
• Assess network segmentation between zones.
• Deliver the Communication Matrix in XLSX/CSV with columns: Source, Destination, Ports, Protocols, Justification, Version, Approval Date.
• Final firewall must undergo security architecture review by CLIENT- architecture Cybersecurity.
Communication Matrix and Firewall Policy Development:
Identify and document all communication paths required between production environments (system infra solutions, approximately 70 Application, DB, network solutions, information security solutions), DEV environments, and other segments.
• Include detailed justifications for each allowed communication path.
• Format: Spreadsheet or table format detailing source, destination, ports (Application), protocols, and justification.
• Firewall Policy:
• Translate the communication matrix into a comprehensive firewall policy.
• Clearly define rules for inbound and outbound traffic based on identified communication paths.
• Ensure alignment with industry best practices and organizational security policies.
• Document the firewall policy in a structured format for easy implementation and future updates.
• Approval Documentation:
• Prepare a presentation summarizing the communication matrix and firewall policies in presentable and editable version format in (PDF, PPT, Docx, XLS)
• Full structured and standard document for communication matrix and firewall policies in presentable and editable version format in (PDF, PPT, Docx, XLS) with approval section.
• Include rationale and justifications for each communication path and firewall rule.
• Present to relevant stakeholders for approval and sign-off.
• This document should contain the below sections but not limited to those points.
1. Purpose and Scope
2. Stakeholders
3. Communication Goals
4. Information to be Communicated
5. Communication Methods
6. Responsibility
7. Timing and Schedule
8. Feedback Mechanisms process.
9. Metrics and Evaluation
10. Revision History
11. Approval from all Stakeholders
• Discovery Phase:
• Review existing network architecture diagrams and security policies.
• Conduct interviews with system administrators, developers, network engineers, information security team to understand communication requirements.
• All the project members who will be working in this project must be on-site resource/s and they should be certified
• All the resources must follow CLIENT IT and Information Security policies and procedures and they should be committed to follow these policies and procedures via CLIENT approved documentation process before starting any of the project activities
• Development Phase:
• Draft the initial communication matrix based on gathered requirements.
• Collaborate with stakeholders to refine and validate the matrix.
• Convert the finalized matrix into a draft firewall policy.
• Review and Approval Phase:
• Conduct a comprehensive review of the communication matrix and firewall policy.
• Present findings, rationale, and justifications to stakeholders.
• Incorporate feedback and obtain necessary approvals.
المصدر: LinkedIn - أُضيفت للموقع في 6 سبتمبر 2026
رقم الإعلان لدى المصدر: 4464019000
رقم الإعلان لدى المصدر: 4464019000