Job description
·Develop and enhance the corporate Cybersecurity Strategy and Key Performance Indicators (KPIs) in alignment with the applicable legislation and regulations of the Government of Dubai and the UAE.
·Develop and update corporate cybersecurity policies, methodologies, and programs in accordance with the approved cybersecurity frameworks and standards of the Government of Dubai and the UAE.
·Define and periodically review the roles and responsibilities of all stakeholders involved in implementing cybersecurity controls across the corporate environment.
·Manage cybersecurity risks through a systematic approach to protect the corporate information and technology assets, in compliance with approved policies, procedures, and applicable legislative and regulatory requirements.
·Conduct cybersecurity risk assessments for technology projects and prior to implementing any major changes to the technology infrastructure.
·Develop, maintain, and document cybersecurity requirements to protect corporate external smart applications against cyber threats.
·Develop, maintain, and document cybersecurity requirements for identity and access management (IAM), including user identities, system access, and access privileges across the corporate environment.
·Develop, maintain, and document cybersecurity requirements for backup management and information encryption within the corporate environment.
·Develop, maintain, and document cybersecurity requirements to be incorporated into contracts and agreements with external entities and service providers engaged by the department.
·Master's Degree: Minimum 6 years of experience in Information Security, Cybersecurity, or a related field.
·Bachelor's Degree: Minimum 8 years of experience in Information Security, Cybersecurity, or a related field.
وصف الوظيفة
·ضع وتطوير استراتيجية الأمن السيبراني المؤسسية ومؤشرات الأداء الرئيسية (KPIs) بما يتماشى مع التشريعات والتنظيمات المعمول بها لحكومة دبي والإمارات العربية المتحدة.
·وضع وتحديث سياسات الأمن السيبراني المؤسسية والمنهجيات والبرامج وفق أطر ومعايير الأمن السيبراني المعتمدة من حكومة دبي والإمارات العربية المتحدة.
·تعريف ومراجعة دور ومسؤوليات جميع الأطراف المعنية المشاركة في تطبيق ضوابط الأمن السيبراني عبر بيئة المؤسسة بشكل دوري.
·إدارة مخاطر الأمن السيبراني من خلال نهج منظم لحماية أصول المعلومات والتكنولوجيا المؤسسية، بما يتوافق مع السياسات والإجراءات المعتمدة والمتطلبات التشريعية والتنظيمية المعمول بها.
·إجراء تقييمات مخاطر الأمن السيبراني للمشروعات التقنية وقبل تنفيذ أي تغييرات كبيرة في بنية التقنية التحتية.
·وضع وصيانة وتوثيق متطلبات الأمن السيبراني لحماية التطبيقات الذكية الخارجية المؤسسية من التهديدات السيبرانية.
·وضع وصيانة وتوثيق متطلبات الأمن السيبراني لإدارة الهوية والوصول (IAM)، بما في ذلك هويات المستخدمين، والوصول إلى الأنظمة وامتيازات الوصول عبر البيئة المؤسسية.
·وضع وصيانة وتوثيق متطلبات الأمن السيبراني لإدارة النسخ الاحتياطي وتشفير المعلومات داخل البيئة المؤسسية.
·وضع وصيانة وتوثيق متطلبات الأمن السيبراني ليتم دمجها في العقود والاتفاقيات مع الجهات الخارجية ومقدمي الخدمات الذين تتعاقد معهم الإدارة.
·درجة الماجستير: حد أدنى 6 سنوات من الخبرة في الأمن المعلوماتي، الأمن السيبراني، أو مجال ذي صلة.
·درجة البكالوريوس: حد أدنى 8 سنوات من الخبرة في الأمن المعلوماتي، الأمن السيبراني، أو مجال ذي صلة.