Job description
About Ports, Customs and Free Zone Corporation:
The Ports, Customs and Free Zone Corporation (PCFC) was officially established in 2001, under the authority of the Dubai Government. There are a number of entities and institutions operating under its umbrella, including Port Rashid, Jebel Ali Port, Al Hamriya Port, which are managed by Dubai Ports Authority, in addition to the Department of Planning and Development - Trakhees, the Dubai Maritime Authority and the Office of the Marine Agency for Wooden Dhows, as well as the investment arm and security arm of the corporation, represented by Investment Department and Security Department.
TECHNOLOGY SECURITY
- Support the implementation of technology security strategies and controls to protect the organisation’s digital assets and ensure compliance with established security policies, standards and procedures.
- Monitor the organisation’s networks, systems and technology environment for security breaches, potential threats and vulnerabilities, and take appropriate action to mitigate identified risks.
- Support the security incident response process, including the investigation, containment, remediation and resolution of security incidents, ensuring timely documentation, escalation and communication.
- Conduct periodic security assessments, vulnerability reviews and audits to identify potential security gaps and recommend appropriate measures to strengthen the organisation’s security posture.
- Support the development, implementation and enforcement of information security policies, procedures, standards and guidelines to ensure consistent security practices across the organisation.
- Collaborate with IT teams to embed security requirements and controls into the design, development and implementation of technology solutions, minimising potential vulnerabilities and security risks.
- Support the delivery of security awareness and training programmes to promote a strong security-conscious culture across the organisation.
- Maintain up-to-date knowledge of emerging cyber security threats, vulnerabilities, trends and technologies, and provide relevant insights and recommendations to enhance security practices.
- Support the implementation, configuration and maintenance of security tools and technologies, ensuring their effectiveness in protecting the organisation’s systems, information and digital assets.
- Assist in developing and maintaining security documentation, including policies, standards, procedures, security assessments and incident reports, ensuring records are accurate and up to date.
- Coordinate with external security vendors and service providers to support the effective delivery of security services and solutions in accordance with agreed requirements.
- Provide technical guidance and support to IT teams on security-related matters, controls and recognised good practices.
EXPERIENCE
Required (Minimum Experience):A minimum of two years’ experience in Information Technology.
Preferred:Experience in IT security, information security or cyber security.
EDUCATIONAL QUALIFICATIONS AND CERTIFICATIONS
Required (Minimum Qualification):A bachelor’s degree in Information Technology, Computer Science or a related discipline.
Preferred:A recognised professional security certification, such as CompTIA Security+, Certified Ethical Hacker (CEH) or an equivalent certification.
الوصف الوظيفي
نبذة عن مؤسسة الموانئ والجمارك والمنطقة الحرة:
تأسست مؤسسة الموانئ والجمارك والمنطقة الحرة رسمياً في عام 2001، تحت سلطة حكومة دبي. وتعمل تحت مظلتها مجموعة من الجهات والمؤسسات، بما في ذلك ميناء راشد، وميناء جبل علي، وميناء الحمرية، والتي تديرها سلطة موانئ دبي، بالإضافة إلى دائرة التخطيط والتطوير - تراخيص، وسلطة دبي البحرية ومكتب الوكيل البحري للسفن الخشبية، فضلاً عن الذراع الاستثماري والذراع الأمني للمؤسسة، والمتمثلين في إدارة الاستثمار وإدارة الأمن.
أمن التكنولوجيا
- دعم تنفيذ استراتيجيات وضوابط أمن التكنولوجيا لحماية الأصول الرقمية للمؤسسة وضمان الالتزام بسياسات ومعايير وإجراءات الأمن المعتمدة.
- مراقبة شبكات المؤسسة وأنظمتها وبيئتها التكنولوجية لرصد أي اختراقات أمنية والتهديدات والثغرات المحتملة، واتخاذ الإجراءات المناسبة للحد من المخاطر المحددة.
- دعم عملية الاستجابة للحوادث الأمنية، بما في ذلك التحقيق والاحتواء والمعالجة وحل الحوادث الأمنية، مع ضمان التوثيق والتصعيد والتواصل في الوقت المناسب.
- إجراء تقييمات أمنية دورية ومراجعات للثغرات وعمليات تدقيق لتحديد الفجوات الأمنية المحتملة والتوصية بالتدابير المناسبة لتعزيز الجاهزية الأمنية للمؤسسة.
- دعم تطوير وتنفيذ وتطبيق سياسات وإجراءات ومعايير وإرشادات أمن المعلومات لضمان ممارسات أمنية متسقة في جميع أنحاء المؤسسة.
- التعاون مع فرق تكنولوجيا المعلومات لتضمين متطلبات وضوابط الأمن في تصميم وتطوير وتنفيذ الحلول التكنولوجية، مما يقلل من الثغرات والمخاطر الأمنية المحتملة.
- دعم تقديم برامج التوعية والتدريب الأمني لتعزيز ثقافة واعية بالأمن في جميع أنحاء المؤسسة.
- المحافظة على معرفة محدثة بتهديدات الأمن السيبراني الناشئة والثغرات والاتجاهات والتقنيات، تقديم رؤى وتوصيات ذات صلة لتعزيز الممارسات الأمنية.
- دعم تنفيذ وتكوين وصيانة الأدوات والتقنيات الأمنية، لضمان فعاليتها في حماية أنظمة المؤسسة ومعلوماتها وأصولها الرقمية.
- المساعدة في إعداد وصيانة التوثيق الأمني، بما في ذلك السياسات والمعايير والإجراءات وتقييمات الأمن وتقارير الحوادث، وضمان دقة السجلات وتحديثها.
- التنسيق مع موردي ومزودي الخدمات الأمنية الخارجيين لدعم تقديم الخدمات والحلول الأمنية بفعالية وفقاً للمتطلبات المتفق عليها.
- تقديم التوجيه والدعم الفني لفرق تكنولوجيا المعلومات بشأن الأمور المتعلقة بالأمن والضوابط والممارسات الجيدة المعتمدة.
الخبرة العملية
المطلوب (الحد الأدنى من الخبرة):خبرة لا تقل عن سنتين في مجال تكنولوجيا المعلومات.
المفضل:خبرة في أمن تكنولوجيا المعلومات، أو أمن المعلومات، أو الأمن السيبراني.
المؤهلات التعليمية والشهادات
المطلوب (الحد الأدنى من المؤهل):درجة البكالوريوس في تكنولوجيا المعلومات، أو علوم الحاسوب، أو تخصص ذات صلة.
المفضل:شهادة أمنية مهنية معتمدة، مثل CompTIA Security+ أو الهكر الأخلاقي المعتمد (CEH) أو ما يعادلها من شهادات.