JOB PURPOSE To deploy, operate and maintain the appropriate data security solutions and tools and implement necessary controls to protect the bank's information systems against internal and external threats in alignment with the bank's approved security architecture framework.
1.Monitor, implement and operate appropriate levels of Data security controls and systems according to enterprise Data security solutions on day-to-day basis, in order to keep business secured proactively against identified threats.
2.Provide first-level support for all managed systems and platforms including: Content Filtering, Sandboxing and others, in order to maintain business operations according to approved service level agreement.
3.Secure the access to corporate data and crown-jewels information through the operations of Data Loss Prevention (DLP), Secure Domain Name Services (DNS), Data Base (DB) Security, Internet based traffic content filtering, at all levels of the data security architecture in order to safeguard and limit access to key information system assets at all layers.
4.Implement, Operate, and Maintain Date Security, Protection and Classification program technologies, in order to provide the required levels of assurance that CIB information Security Data security policies applied and enforced.
5.Provide data security technical expertise for Project Management in order to enable bank's Business Strategic Projects through maintaining a secure Software Development Life Cycle (SDLC) in the organization that complies with Business Strategic objectives, policies, procedures, rules and regulations.
6.Perform analysis of data security needs and contribute to design, integration, and installation of hardware and software, to ensure effective security architecture and controls over enterprise applications.
7.Ensure that data security current and new tools and technologies are deployed in line with architectural requirements, and the organization's data loss prevention strategy and policies, in order to ensure effective controls according to business/compliance/regulation requirements.
8.Employ data confidentiality, integrity and availability controls in order to mitigate the risk of disclosure or alteration of sensitive information.
9.Provide technical expertise and guide the administration of data security tools that control and monitor information security, in order to keep business up and running seamless.
10.Develop and maintain monthly Key Performance Indicators (KPIs), security reports and dashboards across various data security solutions, in order to provide business with the required visibility.
11.Work with information systems owners and administrators to understand their data security needs and assist with implementing practices and procedures in alignment with CIB security policies.
12.Support Security Operations Centre and Information Security in Identifying, developing, and implementing mechanisms to detect/prevent data security incidents/gaps in order to enhance compliance with and support of security standards and procedures in place.
13.Respond to discovered security incidents by informing appropriate custodians, determining root cause, and identifying and executing remedial actions (if necessary) required to re-establish respective information system security.
14.Define and enhance, appropriate levels of Data security controls and systems according to data security solutions on regular basis, in order to keep business secured proactively against known threats.
15.Act as the technical lead in the development of responses to Request for Information (RFIs) and Request for Proposals (RFPs).
Policies, Processes and Procedures
16.Follow all relevant department policies, processes, standard operating procedures and instructions so that work is carried out in a controlled and consistent manner.
Day-to-day Operations
17.Follow the day-to-day operations related to own jobs in the IT Security, Control & Quality Assurance department to ensure continuity of work.
Compliance
18.Comply with all relevant CBE regulations, banking laws, AML regulations and internal CIB policies and code of conduct in order to maintain CIB's sound legal position and mitigate any potential risks.
Desired Candidate Profile
Qualifications & ExperienceBachelor's degree of Engineering, Computer Science or equivalent is must.
Engineer: Minimum of 3 5 years of experience in IT Security and related disciplines.
Should have an understanding of TCP/IP protocols, networking and firewall concepts.
Enterprise data security architecture and software are required.
Understanding of IT operations: help desk, end-point management and server management
Experience in configuring and implementing technical security solutions
Capability to effectively prioritize and execute tasks under pressure and time constrains.
Recommended CertificationsMicrosoft Certified Systems Administrator: Security
GIAC Information Security Fundamentals & CCNP Security
SkillsGood command of English and Arabic languages
Good Communication, Negotiation and Time Management skills
Good Analytical and Problem-solving skills
الغرض من الوظيفة نشر وتشغيل وصيانة حلول وأدوات أمان البيانات الملائمة وتنفيذ الضوابط اللازمة لحماية أنظمة معلومات البنك من التهديدات الداخلية والخارجية بما يتوافق مع إطار هندسة الأمان المعتمد للبنك.
1. مراقبة وتنفيذ وتشغيل مستويات مناسبة من ضوابط وأمن البيانات والأنظمة وفق حلول أمان البيانات المؤسسية بشكل يومي، بهدف الحفاظ على الأمن التنظيمي بشكل استباقي ضد التهديدات المعروفة.
2. تقديم الدعم من المستوى الأول لجميع الأنظمة والمنصات المدارة بما فيها: تصفية المحتوى، الرملنة (Sandboxing) وغيرها، للحفاظ على عمليات الأعمال وفق اتفاقية مستوى الخدمة المعتمدة.
3. تأمين الوصول إلى بيانات الشركة ومعلومات Crown Jewels عبر عمليات منع فقدان البيانات (DLP)، خدمات اسم النطاق الآمنة (DNS)، أمان قاعدة البيانات، وتصفية محتوى حركة المرور عبر الإنترنت، على جميع مستويات هندسة أمان البيانات من أجل حماية وتقليل الوصول إلى أصول أنظمة المعلومات الرئيسية في جميع الطبقات.
4. تنفيذ وتشغيل وصيانة تقنيات برامج أمان البيانات والتصنيف، لتوفير المستويات المطلوبة من الضمان بأن سياسات أمان البيانات في البنك التزام وتطبق.
5. تقديم خبرة تقنية في أمان البيانات لإدارة المشاريع لتمكين مشاريع الأعمال الاستراتيجية للبنك من خلال الحفاظ على دورة حياة تطوير برمجيات آمنة (SDLC) في المؤسسة بما يتوافق مع أهداف وسياسات وإجراءات وقواعد وتنظيمات الأعمال.
6. إجراء تحليل احتياجات أمان البيانات والمساهمة في التصميم والتكامل والتركيب للأجهزة والبرامج، لضمان عمارة أمان وسيطرة فعالة على تطبيقات المؤسسة.
7. التأكد من أن أدوات وتكنولوجيات أمان البيانات الحالية والجديدة مطبقة بما يتوافق مع المتطلبات المعمارية واستراتيجية وسياسات منع فقدان البيانات للمؤسسة، لضمان ضوابط فعالة وفق متطلبات الأعمال والامتثال والتنظيم.
8. توظيف ضوابط السرية والنزاهة والتavailability للبيانات من أجل الحد من مخاطر الكشف أو التعديل للمعلومات الحساسة.
9. تقديم الخبرة التقنية وتوجيه إدارة أدوات أمان البيانات التي تتحكم وتراقب أمان المعلومات، للحفاظ على استمرارية الأعمال بسلاسة.
10. تطوير وصيانة مؤشرات الأداء الرئيسية الشهرية وتقارير الأمان ولوحات البيانات عبر حلول أمان البيانات المختلفة، لتوفير الرؤية المطلوبة للأعمال.
11. العمل مع مالكي ومشرفي أنظمة المعلومات لفهم احتياجات أمان البيانات لديهم والمساعدة في تنفيذ الممارسات والإجراءات بما يتوافق مع سياسات أمان CIB.
12. دعم مركز عمليات الأمن وأمن المعلومات في تحديد وتطوير وتنفيذ آليات لاكتشاف/منع حوادث أمان البيانات والفجوات من أجل تعزيز الامتثال والدعم للمعايير والإجراءات الأمنية المعمول بها.
13. الرد على الحوادث الأمنية المكتشفة بإبلاغ الأوصياء المناسبين، وتحديد السبب الجذري، وتحديد وتنفيذ إجراءات التصحيح (إذا لزم الأمر) لإعادة تأسيس أمان نظام المعلومات المعني.
14. تعريف وتحسين مستويات مناسبة من ضوابط وأمان البيانات وأنظمتها وفق حلول أمان البيانات بشكل دوري، من أجل إبقاء الأعمال آمنة استباقياً ضد التهديدات المعروفة.
15. العمل كقائد فني في تطوير الردود على طلب المعلومات (RFI) وطلبات العروض (RFP).
السياسات والعمليات والإجراءات
16. اتباع جميع سياسات القسم والعمليات وإجراءات التشغيل القياسية والتعليمات ذات الصلة لضمان أن العمل يتم بطريقة محكومة ومتسقة.
العمليات اليومية
17. اتباع عمليات الأمن المعلوماتي اليومية المرتبطة بالوظائف الخاصة في قسم أمان تكنولوجيا المعلومات والرقابة وضمان الجودة لضمان استمرارية العمل.
الامتثال
18. الامتثال للوائح بنك الكويت المركزي المعنية وقوانين المصارف ولوائح AML وسياسات البنك الداخلي ومدونة السلوك للمحافظة على موقف قانوني سليم لمصرف CIB وتخفيف أي مخاطر محتملة.
المرشح المطلوب
المؤهلات والخبرةدرجة البكالوريوس في الهندسة أو علوم الحاسوب أو ما يعادلها أمر لا بد منه.
المهندس: خبرة minimo 3 إلى 5 سنوات في أمان تقنية المعلومات والتخصصات ذات الصلة.
يجب أن يكون لديه فهم لبروتوكولات TCP/IP ومفاهيم الشبكات والجدار الناري.
هندسة أمان البيانات المؤسسية والبرمجيات مطلوبة.
فهم لعمليات تكنولوجيا المعلومات: خدمة المساعدة، إدارة نقاط النهاية وإدارة الخادم
خبرة في إعداد وتنفيذ حلول أمان فنية
القدرة على تحديد الأولويات وتنفيذ المهام بفاعلية تحت الضغط والقيود الزمنية.
الشهادات الموصى بهاMicrosoft Certified Systems Administrator: Security
GIAC Information Security Fundamentals & CCNP Security
المهاراتإتقان جيد للغتين الإنجليزية والعربية
مهارات تواصل وتفاوض وإدارة الوقت جيدة
مهارات تحليلية وحل المشكلات جيدة