الوصف الوظيفي
يُشرف على أنشطة مركز عمليات الأمن (SOC) بما في ذلك المراقبة والتقييم والتصعيد لضمان حماية مستمرة للبنية التحتية المالية والتجارية.
يشرف على مراحل الاستجابة للحوادث من البداية إلى التعافي لتقليل تأثير التهديدات السيبرانية على أنظمة الدفع.
ينسق سير عمل استجابة الحوادث عبر الفرق الداخلية وأصحاب المصلحة الخارجيين لضمان دفاع منظم وسريع على مستوى المؤسسة.
يعِد كتيبات استجابة للحوادث وإجراءات تشغيلية standardize للأفعال الأمنية وتحسين اتساق الاستجابة.
يطوِّر مجموعات قواعد الكشف المتقدمة وأنماط الشذوذ الأمني لتعزيز قدرات الدفاع الاستباقي للمؤسسة.
يؤسس قدرة استخبارات تهديدات سيبرانية شاملة لدمج مؤشرات الاختراق (IOCs) في أنظمة الكشف النشطة.
ينفذ صيد التهديدات بشكل استباقي عبر نقاط النهاية وبيئات السحابية لتحديد المخاطر الأمنية الخفية وتحيدها.
يدير إدارة الثغرات وتتبع الإصلاح عبر المؤسسة لضمان بقاء منصات الدفع الحرجة آمنة ومحدثة.
يوضح مقاييس الأمن التشغيلي لتقديم تقارير قابلة للتنفيذ للقيادة العليا حول موقف الدفاع لدى المؤسسة.
يقود ويرشد محللي SOC ومستجي الحوادث لتعزيز ثقافة فريق عالية الأداء تركز على التميز التشغيلي.
وصف المهارات
المهارات الشخصية
- قيادة تشغيلية قوية وإدارة فريق.
- القدرة على قيادة الفرق خلال حوادث سيبرانية عالية الضغط.
- مهارات تواصل ممتازة للجمهور التقني والتنفيذي.
- قدرات اتخاذ القرار وإدارة الأزمات قوية.
- التعاون مع فرق الهندسة والاحتيال والمنتجات.
- القدرة على توجيه وتطوير محترفي الدفاع السيبراني.
المهارات التقنية
- فهم عميق لعمليات SOC وعمليات المراقبة الأمنية.
- خبرة في تشغيل SIEM وEDR وNDR وSOAR ومنصات استخبارات التهديدات.
- معرفة قوية بمنهجيات استجابة الحوادث والتحقيقات الرقمية.
- خبرة مع أطر استخبارات التهديدات مثل MITRE ATT&CK.
- خبرة في أدوات إدارة الثغرات وتحديد أولويات التصحيح.
- فهم رصد أمان السحابة عبر AWS أو Azure أو GCP.
- معرفة بتحليل البرمجيات الخبيثة وتكتيكات وتقنيات وإجراءات فاعلي التهديد.
- الاطلاع على تسجيلات الأمان والهندسة في الكشف وتقنيات صيد التهديدات.
الخبرة المهنية
- أكثر من 10 سنوات في الأمن السيبراني أو عمليات الأمن.
- حد أدنى 5 سنوات في إدارة فرق SOC أو عمليات الأمن.
- خبرة في إدارة برامج استجابة الحوادث والأحداث الأمنية السيبرانية عند حدوث أزمات.
- خبرة في تنفيذ قدرات استخبارات التهديدات واصطيادها.
- خبرة في تشغيل برامج إدارة الثغرات على مستوى المؤسسة.
- يثمَّن وجود خبرة في العمل في fintech أو البنوك أو المدفوعات أو بيئات مُنظمة أخرى.
الخبرة الإدارية
الخلفية التعليمية
- درجة البكالوريوس في الأمن السيبراني، علوم الحاسوب، تكنولوجيا المعلومات أو مجال ذات صلة.
- قد تشمل شهادات ذات صلة مثل:
- CISSP – أخصائي أمن نظم المعلومات المعتمد
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- Certified Ethical Hacker (CEH)
- Certified SOC Analyst (CSA)
Job description
Directs Security Operations Center (SOC) activities including monitoring, triage, and escalation to ensure continuous protection of fintech and corporate infrastructure.
Oversees end-to-end incident response phases (detection to recovery) to minimize the impact of cyber threats on payment systems.
Coordinates incident response workflows across internal teams and external stakeholders to ensure a unified and rapid organizational defense.
Architects incident response playbooks and operational procedures to standardize security actions and improve response consistency.
Develops advanced detection rule sets and security anomaly patterns to enhance the organization's proactive defense capabilities.
Establishes a comprehensive cyber threat intelligence capability to integrate indicators of compromise (IOCs) into active detection systems.
Executes proactive threat hunting across endpoints and cloud environments to identify and neutralize hidden security risks.
Governs enterprise-wide vulnerability management and remediation tracking to ensure critical payment platforms remain secure and patched.
Analyzes operational security metrics to provide senior leadership with actionable reporting on the organization's defensive posture.
Leads and mentors SOC analysts and threat responders to foster a high-performing team culture focused on operational excellence.
Skills description
Interpersonal skills
- Strong operational leadership and team management.
- Ability to lead teams during high-pressure cyber incidents.
- Excellent communication skills for technical and executive audiences.
- Strong decision-making and crisis management capabilities.
- Collaboration with engineering, fraud, and product teams.
- Ability to mentor and develop cyber defense professionals.
Technical skills
- Deep understanding of SOC operations and security monitoring processes.
- Experience operating SIEM, EDR, NDR, SOAR, and threat intelligence platforms.
- Strong knowledge of incident response methodologies and digital forensics.
- Experience with threat intelligence frameworks such as MITRE ATT&CK.
- Experience with vulnerability management tools and patch prioritization.
- Understanding of cloud security monitoring across AWS, Azure, or GCP.
- Knowledge of malware analysis and threat actor tactics, techniques, and procedures.
- Familiarity with security logging, detection engineering, and threat hunting techniques.
Professional experience
- 10+ years cybersecurity or security operations.
- Minimum 5 years managing SOC or security operations teams.
- Experience managing incident response programs and cyber crisis events.
- Experience implementing threat intelligence and threat hunting capabilities.
- Experience operating vulnerability management programs at enterprise scale.
- Experience working in fintech, banking, payments, or other regulated environments is highly desirable.
Management experience
Educational background
- Bachelor’s degree in Cyber Security, Computer Science, Information Technology or related field.
- Relevant certifications may include:
- CISSP – Certified Information Systems Security Professional
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- Certified Ethical Hacker (CEH)
- Certified SOC Analyst (CSA)