وصف الوظيفة
نحن نبحث عن مسؤول أمان الشبكات والمعلومات لدعم عمليات الشبكة اليومية وأنشطة الأمن السيبراني، لضمان بنية تحتية لتقنية المعلومات آمنة وموثوقة ومتينة.
سيساعد الدور في مراقبة الشبكات، ومراقبة أحداث الأمن، وإدارة الجدران النارية وVPN، وأمن نقاط النهاية، وإدارة الثغرات، واستجابة الحوادث، والضوابط الأمنية، وأنشطة الامتثال للأمن المعلوماتي.
المرشح المثالي لديه أساس قوي في الشبكات والأمن السيبراني، وخبرة عملية في أدوات الأمن ومنصات SIEM، والقدرة على العمل بشكل تعاوني مع فرق البنية التحتية والتطبيقات والأمن المعلوماتي والمخاطر والامتثال والتدقيق وشركاء التكنولوجيا الخارجيين.
المسؤوليات الرئيسية رصد أداء الشبكة والتوفر وأحداث الأمن لتحديد القضايا والتهديدات والشذوذ المحتمل.
رصد والاستجابة لحوادث الأمن السيبراني والتنبيهات وأحداث الأمن وفق الإجراءات المُعرفة وSLA.
المساعدة في إدارة وصيانة الجدران النارية وVPN وأجهزة الشبكة والضوابط الأمنية الشبكية الأخرى.
دعم تطبيق وصيانة ومراقبة ضوابط الأمن المعلوماتي والسياسات والإجراءات.
إجراء تقييمات ثغرات أساسية ودعم أنشطة معالجة الثغرات وتتبع التصحيح.
دعم أمن نقاط النهاية، ومكافحة الفيروسات، وحلول حماية النقاط النهائية.
رصد وحفظ سجلات الأمان والتقارير والوثائق التشغيلية ذات الصلة.
المساعدة في التحقيقات الأمنية، وتحليل الحوادث، والتصعيد والحل.
دعم استكشاف أعطال الشبكة والأمن والتنسيق مع فرق البنية التحتية والتطبيق عند اللزوم.
المساعدة في أنشطة إدارة مخاطر الأمن السيبراني وتنفيذ ضوابط الأمن.
دعم عمليات التدقيق والامتثال الأمني المعلوماتي وجمع الأدلة.
المساهمة في الامتثال لـ ISO 27001 والسياسات والمعايير والإجراءات الداخلية للأمن.
الحفاظ على وثائق أمان دقيقة، وسجلات الحوادث، والتقارير، وإجراءات التشغيل.
العمل عن كثب مع فرق بنية IT الداخلية والبنية الشبكية والتطبيق والأمن المعلوماتي والمخاطر والامتثال والتدقيق.
التنسيق مع بائعي الأمن السيبراني الخارجيين ومقدمي خدمات الأمن المدارة وبائعي الجدران النارية/SIEM/أمن النقاط النهائية وشركاء بنية تقنية المعلومات عند الحاجة.
دعم التحسين المستمر للأمن الشبكي ورصد الأمن السيبراني والاستجابة للحوادث والعمليات التشغيلية.
المهارات التقنية المطلوبةشبكات فهم من الأساسي إلى المتوسط لمفاهيم الشبكات.
فهم قوي لـ TCP/IP والتوجيه والتبديل.
الإلمام بأجهزة الشبكة وبنية الشبكة التحتية.
فهم لمراقبة توفر الشبكة وأداءها.
الإلمام بتقنيات الجدران النارية وVPNات.
الأمن السيبراني فهم مبادئ الأمن السيبراني الأساسية.
معرفة أساسية بإدارة مخاطر الأمن السيبراني.
فهم أساسي لهندسة الأمن.
فهم أساسي لتحليل التهديدات.
فهم أساسي لإدارة الحوادث الأمنية والاستجابة للحوادث.
الإلمام بأمن النقاط النهاية وحلول مكافحة الفيروسات.
التعرض لتقييم الثغرات وتتبعها وإدارة التصحيح.
الخبرة أو التعرض لرصد الأمن وتحليل أحداث الأمن.
الخبرة في أدوات SIEM.
الإلمام بأدوات الأمن ومنصات الرصد الأمني.
الامتثال الأمني والأطر فهم أطر ومعايير وضوابط الأمن المعلوماتي.
التعرض لـ ISO 27001 وأنشطة الامتثال الأمني المعلوماتي.
فهم سياسات وإجراءات الأمن الداخلي.
التعرض لتدقيقات الأمن السيبراني ومتطلبات الامتثال والوثائق الأمنية.
أنظمة التشغيل وأدوات الإنتاجية معرفة جيدة بنظام Windows OS.
المعرفة الجيدة بتطبيقات Microsoft Office.&br> التعليم درجة البكالوريوس في تكنولوجيا المعلومات أو الأمن السيبراني أو علوم الحاسوب أو الأمن المعلوماتي أو أي مجال ذي صلة.
الشهادات يفضل وجود واحد أو أكثر من الشهادات التالية: CCNA CompTIA Security+ CEH – Hacker أخلاقي معتمد (المستوى الأساسي/المتوسط) الخبرة لا تقل عن سنتين من الخبرة المهنية في الشبكات و/أو الأمن المعلوماتي.
تعرّض عملي لعمليات الشبكة، رصد الأمن السيبراني، أو أمان البنية التحتية.&br> العمل مع أدوات SIEM وحلول رصد الأمن.&br> الخبرة أو التعرض للجدران النارية وVPNs وأمن النقاط النهائية وإدارة الثغرات والضوابط الأمنية.&br> الكفاءات الأساسيةالكفاءات التقنية إدارة مخاطر الأمن السيبراني – أساسي هندسة الأمن – أساسي تحليل التهديدات – أساسي إدارة الحوادث – أساسي تدقيق والتوافق الأمني السيبراني – أساسي كفاءات سلوكية مشاركة أصحاب المصلحة توجيه النتائج التعاون الاتصالات الفعالة التكيف الاحترافية يجب أن يظهر المرشحون القدرة على التواصل بوضوح مع أصحاب المصلحة الفنيين وغير الفنيين، والعمل بشكل تعاوني عبر الفرق، والتكيف مع الأولويات المتغيرة، والمحافظة على مستوى عالٍ من الاحتراف والمسؤولية.
أصحاب المصلحة الرئيسيين البنية التحتية لتقنية المعلومات الداخلية وشبكة الفريق تطبيقات / أنظمة الفرق أمن المعلومات، المخاطر والامتثال فرق التدقيق الداخلي الأقسام الوظيفية الموظفين الذين يحتاجون إلى الوعي الأمني والدعم في الحوادث بائعي technology cybersecurity خارجيين جدران نارية، SIEM، وبسائط حماية النقاط النهائية مقدمو خدمات الأمن المدارة (MSSPs)، حيثما ينطبق شركاء الدعم والبنية التحتية لتكنولوجيا المعلومات الجهات التنظيمية والامتثال، عند الحاجة توقعات الأداء النجاح في هذا الدور سيُقاس من خلال: التعرف السريع والتصعيد والاستجابة لحوادث الأمن ضمن SLA محددة. الحل الفعال لحوادث الأمن بأقل تأثير تشغيلي. الحفاظ على توافر الشبكة العالي ودعم عمليات الشبكة الموثوقة. التعرف والتصعيد الفوري لمسائل أداء الشبكة. تقييم وتتبّع الثغرات ضمن جداول زمنية محددة. التزام عالي بتحديث التصحيحات عبر الأنظمة المدعومة. الالتزام بالضوابط والسياسات والمعايير والإجراءات الأمنية. سجلات الأمن الدقيقة والكاملة والحوادث والتقارير. الدعم الفعال لحماية النقاط النهائية وأدوات الأمن. وثائق وتحديثات أمنية دقيقة ومتابعة للعمليات. أقل عدد من نتائج الأمن أو الامتثال الكبيرة.
Job description
We are looking for a Network & Information Security Officer to support day-to-day network operations and cybersecurity activities, ensuring a secure, reliable, and resilient IT infrastructure.
The role will support network monitoring, security event monitoring, firewall and VPN administration, endpoint security, vulnerability management, incident response, security controls, and information security compliance activities.
The ideal candidate will have a solid foundation in networking and cybersecurity, hands-on exposure to security tools and SIEM platforms, and the ability to work collaboratively with infrastructure, applications, information security, risk, compliance, audit, and external technology partners.
Key Responsibilities Monitor network performance, availability, and security events to identify potential issues, threats, and anomalies.
Monitor and respond to cybersecurity incidents, alerts, and security events in accordance with defined procedures and SLAs.
Assist with the administration and management of firewalls, VPNs, network devices, and other network security controls .
Support the implementation, maintenance, and monitoring of information security controls, policies, and procedures.
Conduct basic vulnerability assessments and support vulnerability remediation and patch tracking activities.
Support endpoint security, antivirus, and endpoint protection solutions.
Monitor and maintain security logs, reports, and relevant operational documentation.
Assist with security investigations, incident analysis, escalation, and resolution.
Support network and security troubleshooting and coordinate with relevant infrastructure and application teams when required.
Assist with cybersecurity risk management activities and implementation of security controls.
Support information security audits, compliance activities, and evidence collection.
Contribute to compliance with ISO 27001 , internal security policies, standards, and procedures.
Maintain accurate security documentation, incident records, reports, and operational procedures.
Work closely with internal IT infrastructure, network, application, information security, risk, compliance, and audit teams.
Coordinate with external cybersecurity vendors, managed security service providers, firewall/SIEM/endpoint security vendors, and IT infrastructure partners where required.
Support continuous improvement of network security, cybersecurity monitoring, incident response, and operational processes.
Required Technical SkillsNetworking Basic to intermediate understanding of networking concepts.
Strong understanding of TCP/IP, routing, and switching .
Familiarity with network devices and network infrastructure.
Understanding of network availability and performance monitoring.
Familiarity with firewalls and VPN technologies .
Cybersecurity Understanding of fundamental cybersecurity principles.
Basic knowledge of cybersecurity risk management .
Basic understanding of security architecture .
Basic understanding of threat analysis .
Basic understanding of security incident management and incident response .
Familiarity with endpoint security and antivirus solutions.
Exposure to vulnerability assessment, vulnerability tracking, and patch management.
Experience or exposure to security monitoring and security event analysis.
Experience with SIEM tools .
Familiarity with security tools and security monitoring platforms.
Security Compliance & Frameworks Understanding of information security frameworks, standards, and controls.
Exposure to ISO 27001 and information security compliance activities.
Understanding of internal security policies and procedures.
Exposure to cybersecurity audits, compliance requirements, and security documentation.
Operating Systems & Productivity Tools Good working knowledge of Windows OS .
Good knowledge of Microsoft Office applications.
Education Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Information Security , or a related field.
Certifications Candidates with one or more of the following certifications are preferred: CCNA CompTIA Security+ CEH – Certified Ethical Hacker (basic/intermediate level) Experience Minimum 2 years of professional experience in networking and/or information security .
Practical exposure to network operations, cybersecurity monitoring, or infrastructure security.
Experience working with SIEM tools and security monitoring solutions.
Experience or exposure to firewalls, VPNs, endpoint security, vulnerability management, and security controls.
Key CompetenciesTechnical Competencies Cybersecurity Risk Management – Basic Security Architecture – Basic Threat Analysis – Basic Incident Management – Basic Cybersecurity Audit & Compliance – Basic Behavioral Competencies Stakeholder Engagement Results Orientation Collaboration Effective Communication Adaptability Professionalism Candidates should demonstrate the ability to communicate clearly with both technical and non-technical stakeholders, work collaboratively across teams, adapt to changing priorities, and maintain a strong level of professionalism and accountability.
Key StakeholdersInternal IT Infrastructure & Network Team Applications / Systems Teams Information Security, Risk & Compliance Teams Internal Audit Business departments Employees requiring security awareness and incident support External Cybersecurity technology vendors Firewall, SIEM, and endpoint security vendors Managed Security Service Providers (MSSPs), where applicable IT infrastructure vendors and support partners Regulatory and compliance entities, where required Performance Expectations Success in this role will be measured through: Timely identification, escalation, and response to security incidents within defined SLAs.
Effective resolution of security incidents with minimal operational impact.
Maintaining high network availability and supporting reliable network operations.
Timely identification and escalation of network performance issues.
Vulnerabilities being assessed, tracked, and remediated within defined timelines.
High patch compliance across supported systems.
Adherence to security controls, policies, standards, and procedures.
Accurate and complete security logs, incident records, and reports.
Effective support of endpoint protection and security tools.
Accurate and up-to-date security documentation and process adherence.
Minimal major security or compliance findings.