وصف الوظيفة
وصف الوظيفة:
يدعم أخصائي أمن المعلومات مدير أمن المعلومات في تعزيز الوضع العام للأمن السيبراني في جامعة الإمارات العربية المتحدة (UAEU). يضمن هذا الدور التنفيذ الفعّال والتحسين المستمر لنظام إدارة أمن المعلومات (ISMS) بما يتوافق مع ISO/IEC 27001:2022، ومعايير UAE IA، واللوائح الحكومية. يشرف على حوكمة أمن المعلومات وإدارة المخاطر والامتثال. يجري الأخصائي تقييمات أمنية ويدعم عمليات التدقيق الداخلي والخارجي. يراقب وضع المخاطر ويحافظ على سجل مخاطر أمن المعلومات. ينسق التحقيق في حوادث أمنية كبيرة ويقترح إجراءات تصحيحية. يضمن أن تُصمَّم وتُنفَّذ وتُراقب ضوابط الأمن بشكل صحيح. يدعم تقييمات مخاطر أمن الطرف الثالث والبائعين. يساهم الأخصائي في وضع السياسات، ومبادرات التوعية، والتقارير التنظيمية. يتعاون مع تكنولوجيا المعلومات، ومركز عمليات الأمن (SOC)، ووحدات الأعمال لحماية البيانات المؤسسية وموارد البحث. • دعم مدير أمن المعلومات في تطبيق وصيانة وتحسين مستمر لنظام إدارة أمن المعلومات (ISMS) لدى UAEU بما يتوافق مع ISO/IEC 27001:2022، ومعايير UAE IA، واللوائح المعمول بها. • تطوير ومراجعة والحفاظ على سياسات الأمن المعلوماتي والمعايير والإجراءات وخطوط الأساس الأمنية الفنية. • إجراء تقييمات مخاطر أمن المعلومات للأنظمة، والمشروعات، والمبادرات السحابية، والحفاظ على سجل مخاطر أمن المعلومات. • رصد وضع الأمن السيبراني للجامعة وتقديم تحليل المخاطر والتوصيات لمدير أمن المعلومات والإدارة العليا. • إجراء تقييمات ضوابط الأمن، ومراجعات الامتثال، وتحليلات الثغرات لضمان التنفيذ الفعّال لإجراءات الأمن. • دعم التدقيقات الداخلية والخارجية من خلال إعداد الوثائق والأدلة وخطط التصحيح. • الإشراف على أنشطة إدارة الثغرات، والتحقق من جهود الإصلاح، والتقرير عن اتجاهات التعرض للمخاطر. • تنسيق ودعم التحقيق في الحوادث السيبرانية الكبيرة، مع التأكد من التوثيق الصحيح، وتحليل السبب الجذري، واتخاذ الإجراءات التصحيحية. • مراجعة بنى النظام وتغييرات البنية التحتية ونُهج نشر التكنولوجيا الجديدة لضمان تطبيق مبادئ الأمن عند التصميم. • إجراء تقييمات أمن الطرف الثالث والبائعين، ومراجعة المتطلبات الأمنية في العقود، ومراقبة الامتثال المستمر. • ضمان التنفيذ الفعّال لعنصرين التحكمين التقني والإداريين بما في ذلك إدارة الوصول، والتشفير، والتسجيل، والمراقبة. • دعم تعزيز الوعي الأمني والتثقيف وبرامج محاكاة التصيد عبر الجامعة. • إعداد لوحات أمنية دورية وتقريري الامتثال وملخصات المخاطر للإدارة والسلطات التنظيمية. • التعاون مع تكنولوجيا المعلومات، ومركز عمليات الأمن، ومالكي البيانات، ووحدات الأعمال لتعزيز فاعلية الضوابط والمرونة التشغيلية. • تعزيز التحسين المستمر لقدرات الأمن السيبراني في UAEU وممارسات الحوكمة والامتثال التنظيمي. • أداء أي مهام إضافية لأمن المعلومات كما يكلفه مدير أمن المعلومات أو الإدارة.
أدنى المؤهلات:
درجة البكالوريوس في علوم الحاسوب، تكنولوجيا المعلومات، الأمن السيبراني
الخبرة/المهارات:
3+ سنوات في دور مشابه.
أفضيلة المؤهلات:
درجة البكالوريوس في علوم الحاسوب، تكنولوجيا المعلومات، الأمن السيبراني
Job description
Job Description:
The Information Security Specialist supports the Information Security Manager in strengthening UAEU’s overall cybersecurity posture. This role ensures effective implementation and continuous improvement of the ISMS aligned with ISO/IEC 27001:2022, UAE IA Standards, and government regulations. It oversees information security governance, risk management, and compliance activities. The specialist conducts security assessments and supports internal and external audits. The role monitors risk posture and maintains the information security risk register. It coordinates investigation of significant security incidents and recommends corrective actions. The position ensures security controls are properly designed, implemented, and monitored. It supports third-party and vendor security risk assessments. The specialist contributes to policy development, awareness initiatives, and regulatory reporting. The role collaborates with IT, SOC, and business units to protect institutional data and research assets. • Support the Information Security Manager in implementing, maintaining, and continuously improving UAEU’s Information Security Management System (ISMS) in alignment with ISO/IEC 27001:2022, UAE IA Standards, and applicable regulations. • Develop, review, and maintain information security policies, standards, procedures, and technical security baselines. • Conduct information security risk assessments for systems, projects, and cloud initiatives, and maintain the Information Security Risk Register. • Monitor the University’s cybersecurity risk posture and provide risk analysis and recommendations to the Information Security Manager and senior management. • Perform security control assessments, compliance reviews, and gap analyses to ensure effective implementation of security measures. • Support internal and external audits by preparing documentation, evidence, and remediation plans. • Oversee vulnerability management activities, validate remediation efforts, and report on risk exposure trends. • Coordinate and support investigation of significant cybersecurity incidents, ensuring proper documentation, root cause analysis, and corrective actions. • Review system architectures, infrastructure changes, and new technology deployments to ensure security-by-design principles are applied. • Conduct third-party and vendor security assessments, review security requirements in contracts, and monitor ongoing compliance. • Ensure effective implementation of technical and administrative controls including access management, encryption, logging, and monitoring. • Support security awareness, education, and phishing simulation programs across the University. • Prepare periodic security dashboards, compliance reports, and risk summaries for management and regulatory authorities. • Collaborate with IT, SOC, data owners, and business units to strengthen control effectiveness and operational resilience. • Promote continuous improvement of UAEU’s cybersecurity capabilities, governance practices, and regulatory compliance. • Perform any additional information security duties as assigned by the Information Security Manager or management.
Minimum Qualifications:
Bachelor’s degree in computer science, Information Technology, Cybersecurity
Experience/Skills:
3+ years in a similar role.
Preferred Qualifications:
Bachelor’s degree in computer science, Information Technology, Cybersecurity