وصف الوظيفة
الأدوار والمسؤوليات
هدف الوظيفة حماية أصول المؤسسة وضمان مرونتها من خلال قيادة المراقبة الأمنية الاستباقية، والاستجابة للحوادث، وتخفيف التهديدات، والتحسين المستمر لعمليات الأمن السيبراني.
البيئة الداخلية: إدارة GEPD، توريد البلازما، التصنيع، المبيعات، المالية، اللوجستيات والمشتريات. الخارجية: البائعون والجهات الحكومية. المسؤولية الرئيسية - قيادة وتنسيق أنشطة المراقبة الأمنية، والكشف عن التهديدات، والاستجابة للحوادث عبر بيئات تكنولوجيا المعلومات والعمليات. - حماية أنظمة التحكم الصناعي والأصول التشغيلية الحرجة من خلال المراقبة المستمرة، وتحليل التهديدات، وتخفيف المخاطر. - مراقبة موقف الأمن لأنظمة التحكم الصناعي (ICS)، وشبكات SCADA، والأصول التشغيلية الحرجة، وتحديد المخاطر وتصعيدها عند الحاجة. - إعداد وتقديم تقارير الأمن، وتحليلات الحوادث، وتقييمات المخاطر، والقياسات التشغيلية للإدارة والجهات المعنية. - تقييم الأولويات وتتبع معالجة الثغرات الأمنية وفجوات التحكم داخل بيئات IT و OT. - تطوير، والحفاظ، وتحسين حالات استخدام المراقبة الأمنية، وقواعد الكشف، وplaybooks الاستجابة للحوادث، والإجراءات التشغيلية إن لزم الأمر. - التعاون مع أصحاب المصلحة الداخليين والشركاء الخارجيين لتعزيز المرونة السيبرانية وضمان تشغيل آمن للأعمال. - تعزيز قدرات عمليات الأمن من خلال تحسين العمليات، ودمج معلومات التهديدات، والتميز التشغيلي. - دعم الامتثال، والتدقيق، والمتطلبات التنظيمية المتعلقة بالأمن السيبراني وحماية البنية التحتية الحيوية. مهارات الحوسبة: البرمجة والأتمتة باستخدام Python أو PowerShell أو Bash. المهارات الشخصية: اتصالات شفهية وكتابية ممتازة. القدرة على تعدد المهام في بيئة سريعة ومرهقة. المتعلم السريع. القدرة على التفاعل بفعالية مع الموظفين على جميع المستويات. الانتباه الشديد للتفاصيل. مهارات تحليلية قوية. اللغات: الإنجليزية والعربية مكتوبة ومتحادثة بطلاقة.
الملف المرشح المطلوب
المتطلبات الأكاديمية
درجة البكالوريوس في علوم الحاسب، الهندسة الحاسوبية/الاتصالات، الأمن المعلوماتي أو مجال مشابه
الخبرة المهنية المطلوبة- 5+ سنوات من الخبرة في الأمن السيبراني، مع 3+ سنوات في دور SOC أو الاستجابة للحوادث
- خبرة عملية في منصات (SIEM) خاصة Splunk وتحليل السجلات.
- معرفة قوية بتقنياتEndpoint Detection and Response (EDR/XDR).
- معرفة قوية بمراقبة الأمن والكشف عن التهديدات والاستجابة للحوادث.
- معرفة جيدة بمبادئ أمان الشبكات، بما في ذلك TCP/IP، الجدران النارية، IDS/IPS، VPNs وبروتوكولات الشبكة.
- معرفة جيدة بإدارة أنظمة Windows وLinux وأمانها.
- معرفة جيدة بإدارة تقييم الثغرات والتخفيف منها.
- معرفة قوية بتحليل معلومات تهديدات السيبرانية وتقنيات صيد التهديدات.
- معرفة قوية بالتحقيق في حوادث الأمن، وتحليل السبب الجذري، وأساسيات علوم الأدلة الرقمية.
- معرفة جيدة بإدارة الهوية والوصول (IAM) وأمان الدليل النشط.
- معرفة جيدة بمفاهيم أمان السحابة ومراقبتها لبيئات السحابة المؤسسية.
- معرفة بآليات OT وICS وSCADA ومراقبتها أمنيًا مفضلة بقوة.
- معرفة قوية بإدارة أدوات الأمن وتعديلها، بما في ذلك تطوير قواعد الكشف.
- معرفة قوية بإعداد تقارير الأمن وتطوير لوحات البيانات وتحليل البيانات.
- خبرة عملية في ما لا يقل عن اثنين من أطر ومعايير الأمن السيبراني المذكورة مثل: إطار عمل NIST للأمن السيبراني ISO/IEC 27001 IEC 62443 MITRE ATT&CK
Job Description
Roles & Responsibilities
Job Objective To safeguard organizational assets and ensure business resilience by leading proactive security monitoring, incident response, threat mitigation, and continuous improvement of cybersecurity operations. Environment Internal : GEPD management, plasma procurement, manufacturing, sales, finance, logistics and procurement. External : Vendors and governmental authorities. Key responsibility - Lead and coordinate security monitoring, threat detection, and incident response activities across IT and OT environments. - Protect industrial control systems and critical operational assets through continuous monitoring, threat analysis, and risk mitigation. - Monitor the security posture of industrial control systems (ICS), SCADA networks, and critical operational assets, identifying and escalating risks as required. - Prepare and present security reports, incident analyses, risk assessments, and operational metrics to management and key stakeholders. - Assess, prioritize, and track remediation of security vulnerabilities and control gaps within IT and OT environments. - Develop, maintain, and improve security monitoring use cases, detection rules, incident response playbooks, and operational procedures if required. - Collaborate with internal stakeholders and external partners to strengthen cyber resilience and ensure secure business operations. - Enhance security operations capabilities through process improvement, threat intelligence integration, and operational excellence. - Support compliance, audit, and regulatory requirements related to cybersecurity and critical infrastructure protection. Computing Skills Scripting and automation using Python, PowerShell, or Bash. Personal Skills Excellent verbal and written communication skills. Ability to multi-task in a fast paced, high-pressure environment. Quick Learner. Ability to interact effectively with employees at all levels. Strong attention to detail Strong analytical thinking skills Languages Excellent written and spoken English and Arabic
Desired Candidate Profile
Academic experience required
Bachelor's degree in computer science, Computer/Communication Engineering, Information Security or similar field
Professional Experience Required- 5+ years of experience in cybersecurity, with 3+ years in a SOC or incident response role
- Hands-on experience in (SIEM) platforms specially Splunk and log analysis.
- Stronge knowledge of Endpoint Detection and Response (EDR/XDR) technologies.
- Stronge knowledge of Security monitoring, threat detection, and incident response.
- Good knowledge of Network security fundamentals, including TCP/IP, firewalls, IDS/IPS, VPNs, and network protocols.
- Good knowledge of Windows and Linux system administration and security.
- Good knowledge of Vulnerability assessment and remediation management.
- Stronge knowledge of Cyber threat intelligence analysis and threat hunting techniques.
- Stronge knowledge of Security incident investigation, root cause analysis, and digital forensics fundamentals.
- Good knowledge of Identity and Access Management (IAM) and Active Directory security.
- Good knowledge Cloud security concepts and monitoring for enterprise cloud environments.
- Knowledge of Operational Technology (OT), Industrial Control Systems (ICS), and SCADA security monitoring are highly preferred.
- Stronge knowledge of Security tool administration and tuning, including detection rule development.
- Stronge knowledge of Security reporting, dashboard development, and data analysis.
- Hands-on experience of at least two of the cybersecurity frameworks and standards below such as: NIST Cybersecurity Framework ISO/IEC 27001 IEC 62443 MITRE ATT&CK