الهدف: (ملخص عن الوظيفة)
نبحث عن مهندس أمن سيبراني قيادي ذو خبرة عالية لقيادة تصميم وتنفيذ وتحسين تدابير الأمن السيبراني باستمرار عبر بيئتنا الهجينة. يتطلب هذا الدور الإشراف على أمن البنية التحتية والتطبيقات والسحابة، وإدارة أنظمة الكشف عن التهديدات والاستجابة لها، وتوجيه الوضع الأمني للبرمجيات المطورة داخلياً، وضمان الامتثال التنظيمي من خلال أطر الحوكمة والمخاطر والامتثال (GRC). المرشح المثالي يتمتع بعمق تقني وقدرات قيادية وعقلية استباقية لحماية أصولنا الرقمية وعملياتنا التجارية.
المسؤوليات:
هندسة واستراتيجية الأمن تصميم ودمج وصيانة بنية أمنية شاملة للبيئات المحلية والسحابية ضمان طبولوجيا شبكة آمنة بما في ذلك التجزئة والتحكم في الوصول وأنفاق VPN قيادة تطوير وإنفاذ سياسات وإجراءات الأمن وأفضل الممارسات العمل عن كثب مع المطورين ومهندسي تقنية المعلومات لدمج الأمن في تصميم التطبيقات والبنية التحتية مركز العمليات الأمنية (SOC)، ونظام إدارة المعلومات والأحداث الأمنية (SIEM)، وإدارة التهديدات الإشراف على تشغيل وضبط مركز العمليات الأمنية (SOC) بما في ذلك منصات SIEM إدارة حماية النقاط الطرفية من خلال حلول EDR ومطاردة التهديدات إدارة وتحسين أنظمة أمن البريد الإلكتروني للحماية من التصيد والبرمجيات الخبيثة والرسائل غير المرغوب فيها، مع ضمان الامتثال لسياسات الأمن التنظيمية قيادة جهود الاستجابة للحوادث وتطوير استراتيجيات الوقاية من التهديدات أمن التطبيقات والسحابة الإشراف على فحص الثغرات واختبار الاختراق للتطبيقات المطورة داخلياً قيادة نشر وتحسين جدار حماية تطبيقات الويب (WAF) لحماية تطبيقات الويب الحيوية للأعمال تنفيذ أفضل الممارسات الأمنية وإنفاذ السياسات عبر بيئات السحابة المتعددة الحوكمة والمخاطر والامتثال (GRC) قيادة برامج الامتثال المتعلقة بالأمن السيبراني (مثل SOC 2 Type 2، ISO 27001) قيادة مبادرات الحوكمة والمخاطر والامتثال متعددة الوظائف ودعم التدقيق الداخلي والخارجي إدارة تقييمات المخاطر الأمنية واقتراح استراتيجيات التخفيف التوثيق والتعاون الاحتفاظ بتوثيق مفصل للضوابط والسياسات والأنظمة والحوادث الأمنية التخطيط وإجراء جلسات توعية أمنية ربع سنوية لتثقيف الموظفين حول التهديدات السيبرانية الناشئة، وأفضل الممارسات الأمنية، وسياسات الأمن الخاصة بالمنظمة العمل بشكل تعاوني مع مهندسي البرمجيات وفرق الشبكات وDevOps ووحدات الأعمال
المتطلبات
الحد الأدنى من المتطلبات:
التعليم: درجة البكالوريوس في الهندسة، علوم الحاسب، أمن المعلومات أو مجال ذي صلة الخبرة: 7 سنوات في أدوار الأمن السيبراني وأمن المعلومات 5+ سنوات من الخبرة العملية في هندسة الأمن وإدارة التهديدات المؤهلات الضرورية للوظيفة خبرة مثبتة في: هندسة الأمن لإعدادات السحابة الهجينة/المحلية جدران الحماية، WAF، EDR، SIEM، UTM، IPS، الوكيل (Proxy)، وتخفيف هجمات DDoS بروتوكولات أمن الشبكات، والتقسيم الشبكي، وVPNs، ونماذج التحكم في الوصول مجموعة المهارات الضرورية للوظيفة مهارات حل المشكلات والتحليل: القدرة على تشخيص وحل القضايا التقنية المعقدة بكفاءة المهارة في تصميم وتنفيذ حلول تقنية قابلة للتوسع وآمنة المهارات التنظيمية: قدرة قوية على إدارة مشاريع متعددة وترتيب المهام حسب الأولوية بفعالية الالتزام بالمواعيد النهائية والحفاظ على معايير الجودة العالية التواصل والعمل الجماعي: مهارات تواصل كتابية ولفظية ممتازة القدرة على التعاون بفعالية مع أعضاء الفريق وأصحاب المصلحة شهادات (مستحسنة): CISSP، CISM، CEH، OSCP، CCSP شهادات أمن السحابة (مثل AWS Security Specialty، Microsoft SC-100/SC-200) شهادات حوكمة تقنية المعلومات (مثل ISO 27001 LA، CISA)
Objective: (summary about the position)
Seeking a highly experienced Security Lead Engineer to lead the design, implementation, and continuous improvement of cybersecurity measures across our hybrid environment. This role requires overseeing infrastructure, application, and cloud security; managing threat detection and response systems; guiding the security posture of internally developed software; and ensuring regulatory compliance through GRC frameworks. The ideal candidate brings technical depth, leadership capabilities, and a proactive mindset to protect our digital assets and business operations.
Responsibilities:
Security Architecture & Strategy Design, integrate, and maintain end-to-end security architecture for on-premises and cloud environments Ensure secure network topology including segmentation, access control, and VPN tunnels Lead development and enforcement of security policies, procedures, and best practices Work closely with developers and IT architects to embed security into application and infrastructure design SOC, SIEM, and Threat Management Oversee the operation and tuning of Security Operations Center (SOC) including SIEM platforms Manage endpoint protection through EDR and threat-hunting solutions Manage and enhance email security systems to protect against phishing, malware, and spam, ensuring compliance with organizational security policies Lead incident response efforts and develop threat prevention strategies Application and Cloud Security Supervise vulnerability scanning and penetration testing for internally developed applications Lead WAF deployment and optimization to protect business-critical web applications Implement security best practices and policy enforcement across multi-cloud environments Governance, Risk & Compliance (GRC) Drive cybersecurity-related compliance programs (e.g., SOC 2 Type 2, ISO 27001) Lead cross-functional GRC initiatives and support internal/external audits Manage security risk assessments and recommend mitigation strategies Documentation & Collaboration Maintain detailed documentation for security controls, policies, systems, and incidents Plan and conduct quarterly security awareness sessions to educate staff on emerging cyber threats, security best practices, and the organization's security policies Work collaboratively with software engineers, network teams, Dev Ops, and business units
Requirements
Min requirements:
Education: Bachelor's degree in engineering, Computer Science, Information Security or a related field Experience: 7 years in cybersecurity and information security roles 5+ years of hands-on experience in security architecture and threat management Qualifications necessary for the vacancy Proven expertise in: Security architecture for hybrid cloud/on-prem setups Firewalls, WAF, EDR, SIEM, UTM, IPS, Proxy, and DDoS mitigation Network security protocols, subnetting, VPNs, and access control models Set of skills necessary for the vacancy Problem-Solving and Analytical Skills: Ability to diagnose and resolve complex technical issues efficiently Skilled in designing and implementing scalable and secure IT solutions Organizational Skills: Strong ability to manage multiple projects and prioritize tasks effectively Commitment to meeting deadlines and maintaining high-quality standards Communication and Teamwork: Excellent written and verbal communication skills Ability to collaborate effectively with team members and stakeholders Certifications (Desirable): CISSP, CISM, CEH, OSCP, CCSP Cloud security certifications (e.g., AWS Security Specialty, Microsoft SC-100/SC-200) IT governance certifications (e.g., ISO 27001 LA, CISA)