يتولى أخصائي أمن المعلومات حماية أنظمة المؤسسة وبياناتها وبُنيتها التقنية من خلال تطبيق ومواءمة ضوابط الأمان والأنشطة المَراقِبة الفعّالة. يدعم هذا الدور أهداف الأمن والامتثال في المؤسسة من خلال تحديد المخاطر، والاستجابة للحوادث الأمنية، وضمان التوافق مع المعايير التنظيمية والصناعية.
• رصد الحوادث الأمنية والإنذارات والاستجابة لها، مع دعم التحقيق والترقية والحل.
• الحفاظ على الضوابط الأمنية وتنفيذها لحماية الأنظمة والتطبيقات والبيانات من التهديدات الداخلية والخارجية.
• إجراء المراقبة الأمنية باستخدام SIEM وأدوات أمان أخرى، وتحليل السجلات والأحداث لتحديد التهديدات المحتملة وتوصية التصحيح.
• دعم أنشطة إدارة الثغرات، بما في ذلك تحديد الأولويات وتتبع التصحيح.
• إجراء تقييمات مخاطر الأمن ودعم التدقيقات الأمنية الداخلية والخارجية.
• ضمان الامتثال لمعايير الأمن والمتطلبات التنظيمية، بما في ذلك PCI-DSS.
• تنفيذ والحفاظ على جدران حماية لتطبيقات الويب (WAF)، وحماية DDoS، وتقنيات الجدار الناري، وضوابط الأمان السحابية الأصلية (مثل Cloudflare وAkamai وخدمات أمان Azure/AWS حيثما كان ذلك مناسباً).
• دعم أمان التطبيقات طوال دورة حياة تطوير البرمجيات، بما في ذلك اختبار أمان التطبيقات ثابت (SAST) باستخدام أدوات مثل Veracode وCheckmarx وTrivy أو ما يماثلها.
• المساهمة في أمان الحاويات وأعباء العمل السحابية، بما في ذلك فحص Docker وKubernetes وصورة الحاوية.
• إجراء اختبارات الاختراق أو دعمها وتقييمات الثغرات وأنشطة التحقق من الأمان باستخدام أدوات معيارية صناعيًا (مثل Kali Linux وBurp Suite وOWASP المنهجيات).
• تطوير وصيانة نصوص الأتمتة باستخدام Python أو PowerShell أو Bash لتحسين عمليات الأمن والمراقبة.
• التعاون بشكل وثيق مع فرق الهندسة والبنية التحتية وDevOps والامتثال لدمج الأمن في عمليات التطوير والتشغيل.
• الحفاظ على وثائق الأمن والإجراءات التشغيلية والمعايير الفنية لدعم جاهزية التدقيق والتناسق التشغيلي.
The Information Security Specialist is responsible for safeguarding the organization’s systems, data, and technology infrastructure by implementing and maintaining effective security controls and monitoring activities.
This role supports the organization’s security and compliance objectives by identifying risks, responding to security incidents, and ensuring alignment with regulatory and industry standards.
• Monitor and respond to security incidents and alerts, supporting investigation, escalation, and resolution.
• Maintain and implement security controls to protect systems, applications, and data against internal and external threats.
• Perform security monitoring using SIEM and other security tools, analysing logs and events to identify potential threats and recommend remediation.
• Support vulnerability management activities, including identifying, prioritising, and tracking remediation of security weaknesses.
• Conduct security risk assessments and support internal and external security audits.
• Ensure compliance with security standards and regulatory requirements, including PCI-DSS.
• Implement and maintain Web Application Firewalls (WAF), DDoS protection, firewall technologies, and cloud-native security controls (e.g. Cloudflare, Akamai, Azure/AWS security services where applicable).
• Support application security throughout the software development lifecycle, including static application security testing (SAST) using tools such as Veracode, Checkmarx, Trivy or similar.
• Assist with container and cloud workload security, including Docker, Kubernetes and container image scanning.
• Perform or support penetration testing, vulnerability assessments and security validation activities using industry-standard tools (e.g. Kali Linux, Burp Suite, OWASP methodologies).
• Develop and maintain automation scripts using Python, PowerShell or Bash to improve security operations and monitoring.
• Collaborate closely with Engineering, Infrastructure, DevOps and Compliance teams to embed security into development and operational processes.
• Maintain security documentation, operational procedures and technical standards to support audit readiness and operational consistency.