وصف الوظيفة
المهمة
الغرض من الوظيفة:
مهندس الأمن السيبراني الأول مسؤول عن حماية معلومات الشركة ونُظمها وبنيتها التحتية الرقمية. يضمن الدور دمج الأمن السيبراني في جميع تصميمات الأنظمة والشبكات، مع تعزيز الامتثال للمعايير الدولية والمتطلبات التنظيمية. يقوم بتطوير وتطبيق سياسات الأمان، وقاد عمليات تدقيق منتظمة، ويراقب الأنظمة الداخلية لتحديد المخاطر المحتملة وتخفيفها بشكل استباقي.
بالإضافة إلى ذلك، يعد الدور عامل تمكين رئيسي لاستمرارية الأعمال من خلال تنفيذ واختبار خطط التعافي من الكوارث وضمان تطبيق حوكمة تكنولوجيا المعلومات والامتثال وإطارات إدارة المخاطر بشكل متسق. سيعمل مهندس الأمن السيبراني الأول كخبير متخصص، بالتعاون مع فرق عبر الوظائف، ومشاركة أصحاب المصلحة من جميع المستويات، وضمان وعي الموظفين وقدراتهم من خلال برامج تدريب فعالة.
الملف الشخصي
المسوؤليات/الواجبات
الإشراف والحو Medium Governance
•الإشراف على تقييم واعتماد استثناءات سياسات الأمان وطلبات إدارة التغيير.
•تولي ملكية الحوكمة الخاصة بالأمن السيبراني والسياسات والإجراءات لضمان الامتثال لمتطلبات الأعمال والتنظيمية والقانونية.
•بناء ثقافة أمان قوية عبر الأعمال، مع ضمان فهم كل من الموظفين والشركاء الخارجيين لأهمية اختبارات الأمان والامتثال.
•تقديم تقارير واضحة وشاملة عن الاختبارات وتقييم المخاطر وعمليات التدقيق الأمني للجمهور الفني وغير الفني على حد سواء.
•قيادة تقييم تقنيات حماية المعلومات لتحديد ومعالجة نقاط الضعف المحتملة.
العمليات وإدارة المخاطر
•مراقبة وتقييم أنظمة معالجة البيانات لضمان فاعلية الضوابط المنطقية واتباع المعايير.
•التنسيق مع فرق البنية التحتية وأنظمة الأعمال لتنفيذ ضوابط الأمان والسياسات وتدابير التخفيف من المخاطر.
•إدارة عمليات الاستجابة للحوادث، مع التأكد من التصعيد والت containment والحل في الوقت المناسب.
•قيادة خطط التعافي من الكوارث واستمرارية الأعمال، مع ضمان الاختبار المنتظم والاستعداد.
التحسين المستمر
•تحديد فرص تحسين عمليات الأمن والضوابط والأنظمة بما يتماشى مع أفضل الممارسات الدولية.
•متابعة تطورات التهديدات السيبرانية والتقنيات والمعايير الصناعية من خلال المشاركة في المنتديات المهنية والمؤتمرات الصناعية.
•اقتراح حلول مبتكرة لتعزيز وضع الأمن وتحسين التكاليف وزيادة الإنتاجية.
التقارير والوثائق
•تطوير وتقديم لوحات معلومات الأمن السيبراني في الوقت المناسب، مع إبراز الثغرات والمخاطر والأداء مقارنة بالمعايير.
•ضمان أن تكون تقارير الأمن والسياسات ومسارات التدقيق دقيقة وميسرة الوصول وتلبي المعايير التنظيمية.
مسؤوليات إضافية
•دعم مشاريع تعزيز الأمان لتحسين بنية تكنولوجيا معلومات الشركة.
•القيام بمهمات أخرى وفق توجيهات تتماشى مع أهداف العمل والأمن.
•القدرة على إدارة تقييمات متعددة بشكل مستقل، مع ترتيب الأولويات بفعالية.
•يفضل وجود شهادات ذات صلة في منصات SIEM/SOAR/EDR (مثل Splunk، ELK، LogRhythm، Sentinelone، Palo Alto XSIAM، أو ما يعادلها).
مسؤوليات السلامة
•تعزيز ثقافة السلامة الإيجابية في مكان العمل وحضور اجتماعات أو موجزات السلامة عند الطلب ضمن نطاق عمل الوظيفة.
•الامتثال لمتطلبات سياسة RDMC RQHSE ونظام إدارة السلامة.
•اِعْتِمَاد أن السلامة والأمان والحماية البيئية هي مسؤولية الجميع.
•جميع أعضاء الفريق مسؤولون عن الإبلاغ والتدخل في أي انتهاكات للسلامة أو الأمان أو البيئة.
المؤهلات الأساسية والمعرفة والخبرة
المؤهلات
•درجة البكالوريوس في علوم الحاسوب، تكنولوجيا المعلومات، الأمن السيبراني، أو مجال ذي صلة.
•شهادات مهنية في الأمن السيبراني مفضلة: CISSP، eCIR، OSCP، eCTH.
المعرفة
•فهم قوي لشبكات تكنولوجيا المعلومات، وإدارة الوصول، ومفاهيم استضافة السحابة.
•القدرة على تقييم أنظمة التكنولوجيا من منظور تقني وتجاري.
•براعة في توصيل مواضيع الأمن السيبراني المعقدة للجمهور غير التقني.
•معرفة واسعة بأنظمة تكنولوجيا المعلومات وفهم عميق لمخاطر الأمان المرتبطة.
•الاطلاع على أطر إدارة المخاطر والضبط في الأمن السيبراني.
•الاطلاع على معايير وممارسات الأمن المعلوماتي (مثل ISO 27001، NIST).
الخبرة
•5-7 سنوات خبرة في الأمن السيبراني أو مجال ذي صلة
•خلفية هندسية قوية مع خبرة تقنية موثقة.
•خبرة مثبتة في إدارة الأمن السيبراني ضمن بيئات معقدة وديناميكية.
•خبرة صناعية في قطاعات الخدمات مثل المالية أو مجالات ذات صلة مرغوبة بشدة.
•معرفة صلبة بالبنية التحتية للشبكة، وإدارة Linux/Windows، ورصد النظم، مع خبرة في القياس الأمني (الجدار الناري، EDR، الواب، ومصادر سجل أخرى).
السلوكيات والخبرات المرغوبة
•مهارات تواصل ومهارات قيادية ممتازة، مع القدرة على التأثير وإشراك أصحاب المصلحة على جميع المستويات.
•مهارات اتصال قوية، مع القدرة على ترجمة المفاهيم التقنية إلى قيمة أعمال واضحة.
•اتخاذ قرار حازم وواثق، مع القدرة على قيادة تغيير تنظيمي.
•بحماس، مبادر، ومتحفز ذاتيًا، مع التزام قوي بالتعلم المستمر.
•منظم للغاية، دقيق التفاصيل، ومرن تحت الضغط.
Job description
Mission
JOB PURPOSE:
The Sr Cybersecurity Engineer is responsible for safeguarding the company’s information, systems, and digital infrastructure. The role ensures that cybersecurity is embedded within all system and network designs, while driving compliance with international standards and regulatory requirements. The position develops and enforces security policies, leads regular audits, and monitors internal systems to proactively identify and mitigate potential risks.
In addition, the role is a key enabler of business continuity by implementing and testing disaster recovery plans and ensuring IT governance, compliance, and risk management frameworks are consistently applied. The Sr. Cyber Security will act as a subject matter expert, collaborating with cross-functional teams, engaging stakeholders at all levels, and ensuring staff awareness and capability through effective training programs.
Profile
RESPONSIBILITIES/DUTIES
Supervision & Governance
•Oversee the assessment and approval of security policy exceptions and change management requests.
•Take ownership of cybersecurity governance, policies, and procedures to ensure compliance with business, regulatory, and legal requirements.
•Build a strong security culture across the business, ensuring both employees and external partners understand the importance of security testing and compliance.
•Provide clear and comprehensive reports on testing, risk assessments, and security audits to both technical and non-technical audiences.
•Lead the evaluation of information protection technologies to identify and address potential weaknesses.
Operations & Risk Management
•Monitor and assess data processing systems to ensure logical controls are effective and up to standards.
•Coordinate with infrastructure and business systems teams to implement security controls, policies, and risk mitigation measures.
•Manage incident response processes, ensuring timely escalation, containment, and resolution of security events.
•Drive disaster recovery and business continuity plans, ensuring regular testing and readiness.
Continuous Improvement
•Identify opportunities to improve security processes, controls, and systems in line with international best practices.
•Stay updated with evolving cyber threats, technologies, and industry benchmarks by participating in professional forums and industry conferences.
•Recommend innovative solutions to strengthen security posture, optimize costs, and enhance productivity.
Reporting & Documentation
•Develop and deliver timely cybersecurity dashboards, highlighting gaps, risks, and performance against benchmarks.
•Ensure security reports, policies, and audit trails are accurate, accessible, and meet organizational standards.
Additional Responsibilities
•Support security-related enhancement projects to strengthen the company’s IT infrastructure.
•Perform other assignments as directed in alignment with business and security objectives.
•Ability to manage multiple assessments independently, prioritizing tasks effectively.
•Relevant certifications in SIEM/SOAR/EDR platforms (e.g., Splunk, ELK, LogRhythm, Sentinelone, Palo Alto XSIAM, or equivalent) are preferred.
Safety Responsibilities
•Promote a positive safety culture within the workplace and attend any safety-related meetings or briefings as required within the job role.
•Comply with the requirements of RDMC RQHSE Policy and Safety Management System.
•Be mindful that Safety, Security, and Environmental protection are everyone’s responsibility.
•All staff members are accountable for reporting and intervening in any Safety, Security, or Environmental violations.
ESSENTIAL QUALIFICATIONS, KNOWLEDGE & EXPERIENCE
Qualifications
•Bachelor’s degree in Computer Science, Information Technology, Cyber Security, or a related field.
•Professional Cyber Security certifications preferred: CISSP, eCIR, OSCP, eCTH.
Knowledge
•Strong understanding of IT networks, access management, and cloud-hosting concepts.
•Ability to assess technology systems from both a technical and business perspective.
•Skilled in communicating complex cybersecurity topics to non-technical audiences.
•Broad knowledge of IT systems and in-depth understanding of associated security risks.
•Familiarity with cybersecurity risk management and control frameworks.
•Familiarity with information security standards and best practices (e.g., ISO 27001, NIST).
Experience
•5-7 years of experience in cybersecurity or a related field
•Strong engineering background with demonstrated technical expertise.
•Proven experience in managing cybersecurity within complex and dynamic environments.
•Industry experience in service sectors such as finance or related fields is highly desirable.
•Solid knowledge of network infrastructure, Linux/Windows administration, and system monitoring, with expertise in security telemetry (firewall, EDR, proxy, and other log sources).
DESIRED BEHAVIORS & EXPERIENCES
•Excellent interpersonal and leadership skills, with the ability to influence and engage stakeholders at all levels.
•Strong communication skills, with the ability to translate technical concepts into clear business value.
•Assertive and confident decision-maker, with the ability to drive organizational change.
•Enthusiastic, proactive, and self-motivated, with a strong commitment to continuous learning.
•Highly organized, detail-oriented, and resilient under pressure.