Job description
Job Purpose:
The responsibility of this role is to support the development and implementation of the Information Security Governance Framework at the Dubai Government Human Resources Department (DGHR), ensuring the confidentiality, integrity, and availability of information assets. This includes monitoring compliance with regulatory information security policies, standards, and requirements, conducting security assessments, managing cybersecurity risks, and supporting cybersecurity initiatives to protect the entity from internal and external threats.
Duties and Responsibilities:
·Support the implementation and monitoring of the Information Security Management System (ISMS) and Business Continuity Management System (BCMS).
·Ensure compliance with Dubai Information Security Regulation (ISR), ISO 27001, ISO 22301 standards, and the entity's security policies, standards, and procedures.
·Periodically review and update information security and business continuity policies, standards, guidelines, and procedures.
·Monitor compliance with information security requirements and controls across various departments, recommending necessary corrective and improvement actions to address non-compliance.
·Contribute to developing and applying information security governance frameworks and control measures to ensure enhanced information security and risk management.
·Contribute to planning, developing, and following up on the ISMS and BCMS risk assessment methodology entity-wide, ensuring alignment with corporate goals and senior management requirements.
·Ensure the selection and application of appropriate administrative, operational, and technical controls for ISMS and BCMS in line with risk assessment results and approved compliance requirements.
·Identify potential security risks and vulnerabilities, recommending appropriate measures and controls to mitigate risks and enhance the cybersecurity posture.
·Evaluate the effectiveness of applied security controls and measure their contribution to mitigating risks and enhancing the cybersecurity posture.
·Monitor and implement controls and requirements for ISO 27001 and ISO 22301 standards, NCEMA requirements, and others.
·Participate in or supervise internal audits for ISMS and BCMS, and follow up on the implementation of resulting corrective actions.
·Coordinate with certification bodies, internal, and external auditors, and represent the entity's management during audits related to ISR, ISMS, BCMS, and follow-up audits, ensuring adherence to approved requirements and standards.
·Track audit findings, observations, and corrective action plans until closure.
·Collect, review, and maintain audit evidence and compliance documentation.
·Coordinate with process owners to measure and monitor the performance of ISMS and BCMS.
·Present and discuss all non-conformities and audit reports with the Information Security Committee, following up on recommendations and corrective actions required to resolve observations.
·Coordinate with external entities to execute and follow up on technical security assessment requirements and controls, including Vulnerability Assessment and Penetration Testing (VAPT), business continuity tests, and other relevant security evaluations and tests.
·Review and verify the results and observations of the Dubai Cybersecurity Index, following up on necessary remediation and improvement actions to enhance security compliance levels within the entity.
·Develop and execute information security awareness programs and campaigns, contributing to fostering a security culture and increasing awareness and adherence to approved security practices and policies.
·Promote and disseminate cybersecurity best practices entity-wide, contributing to raising security awareness and compliance with approved policies and controls.
·Coordinate the execution of phishing simulation tests and security awareness initiatives.
·Provide security guidance and support to employees, contractors, and third parties.
·Measure the effectiveness of awareness programs and prepare reports on their results.
·Contribute to security incident investigations and root cause analysis.
·Ensure security incidents are documented, reported, and handled according to approved procedures.
·Prepare periodic security dashboards, Key Performance Indicators (KPIs), and management reports.
·Monitor and analyze information security performance indicators and compliance levels with approved policies and standards.
·Provide necessary recommendations to develop security controls and enhance the entity's overall security posture.
Educational Qualification:
Bachelor's or Master's degree in Computer Science or Information Technology (Cybersecurity / Information Security / Networks) from an internationally recognized university.
Certifications preferred such as:
·ISO 22301 Lead Implementer / Auditor
·ISO 27001 Lead Implementer / Auditor
·CISA / CISM / CISSP
Years of Experience:
·Bachelor's degree: 4 – 6 years of experience in the field.
·Master's degree: 2 – 4 years of experience in the field.
Job Skills:
·Information Security and Business Continuity Management (ISMS / BCMS)
·Governance, Risk, and Compliance Management (GRC)
·Conducting and facilitating security audits and following up on results
·Assessing security risks and vulnerabilities and applying appropriate controls
·Preparing reports, dashboards, and communicating with internal and external entities
Behavioral Competencies:
·Effective Communication
·Excellence in Execution
·Community Service and Responsiveness to Stakeholder Needs
·Organizational Understanding
Job description
هدف الوظيفة:
تتمثل مسؤولية هذا الدور في دعم تطوير وتنفيذ إطار حوكمة أمن المعلومات في دائرة الموارد البشرية لحكومة دبي، بما يضمن سرية وسلامة وتوافر أصول المعلومات. ويشمل ذلك مراقبة الالتزام بسياسات ومعايير ومتطلبات أمن المعلومات التنظيمية، وإجراء تقييمات أمنية، وإدارة مخاطر الأمن السيبراني، ودعم مبادرات الأمن السيبراني لحماية الجهة من التهديدات الداخلية والخارجية.
المهام والمسؤوليات:
·دعم تنفيذ ومتابعة نظام إدارة أمن المعلومات (ISMS) ونظام إدارة استمرارية الأعمال (BCMS).
·ضمان الامتثال للوائح نظام أمن المعلومات في إمارة دبي (ISR)، ومعايير ISO 27001، وISO 22301، وسياسات ومعايير وإجراءات الأمن الخاصة بالجهة.
·مراجعة وتحديث سياسات ومعايير وإرشادات وإجراءات أمن المعلومات واستمرارية الأعمال بشكل دوري.
·متابعة مستوى الامتثال لمتطلبات وضوابط أمن المعلومات عبر الإدارات المختلفة، والتوصية بالإجراءات التصحيحية والتحسينية اللازمة لمعالجة حالات عدم الامتثال.
·المساهمة في تطوير وتطبيق أطر حوكمة أمن المعلومات والضوابط الرقابية بما يضمن تعزيز أمن المعلومات وإدارة المخاطر.
·المساهمة في تخطيط وتطوير ومتابعة منهجية تقييم مخاطر نظام إدارة أمن المعلومات (ISMS) ونظام إدارة استمرارية الأعمال (BCMS) على مستوى الجهة، بما يضمن توافقها مع الأهداف المؤسسية ومتطلبات الإدارة العليا.
·ضمان اختيار وتطبيق الضوابط الإدارية والتشغيلية والتقنية المناسبة لنظام إدارة أمن المعلومات (ISMS) ونظام إدارة استمرارية الأعمال (BCMS) بما يتوافق مع نتائج تقييم المخاطر ومتطلبات الامتثال المعتمدة.
·تحديد المخاطر والثغرات الأمنية المحتملة، والتوصية بالإجراءات والضوابط المناسبة لتخفيف المخاطر وتعزيز مستوى الأمن السيبراني.
·تقييم فعالية الضوابط الأمنية المطبقة وقياس مدى مساهمتها في الحد من المخاطر وتعزيز مستوى الأمن السيبراني.
·متابعة وتنفيذ الضوابط والمتطلبات الخاصة بمعايير ISO 27001 و ISO 22301 ومتطلبات NCEMA وغيرها.
·المشاركة أو الإشراف على تنفيذ أعمال التدقيق الداخلي على نظام إدارة أمن المعلومات (ISMS) ونظام إدارة استمرارية الأعمال (BCMS)، ومتابعة تنفيذ الإجراءات التصحيحية الناتجة عنها.
·التنسيق مع جهات الاعتماد والمدققين الداخليين والخارجيين، وتمثيل إدارة الجهة خلال عمليات التدقيق الخاصة بضوابط نظام أمن المعلومات (ISR) ونظام إدارة أمن المعلومات (ISMS) ونظام إدارة استمرارية الأعمال (BCMS) وتدقيقات المتابعة، بما يضمن الالتزام بالمتطلبات والمعايير المعتمدة.
·متابعة نتائج التدقيق والملاحظات وخطط الإجراءات التصحيحية حتى الإغلاق.
·جمع ومراجعة وحفظ أدلة التدقيق ووثائق الامتثال.
·التنسيق مع مالكي العمليات لقياس ومراقبة أداء نظام إدارة أمن المعلومات (ISMS) ونظام إدارة استمرارية الأعمال (BCMS).
·عرض ومناقشة جميع حالات عدم المطابقة وتقارير التدقيق مع لجنة أمن المعلومات، ومتابعة التوصيات والإجراءات التصحيحية اللازمة لمعالجة الملاحظات الواردة.
·التنسيق مع الجهات الخارجية لتنفيذ ومتابعة متطلبات وضوابط التقييم الأمني التقني، بما في ذلك تقييمات الثغرات واختبارات الاختراق (VAPT)، واختبارات استمرارية الأعمال، وغيرها من التقييمات والاختبارات الأمنية ذات الصلة.
·مراجعة والتحقق من نتائج وملاحظات مؤشر دبي للأمن السيبراني، ومتابعة تنفيذ إجراءات المعالجة والتحسين اللازمة لتعزيز مستوى الامتثال الأمني في الجهة.
·تطوير وتنفيذ برامج وحملات التوعية بأمن المعلومات، بما يسهم في تعزيز الثقافة الأمنية ورفع مستوى الوعي والالتزام بالممارسات والسياسات الأمنية المعتمدة.
·تعزيز ونشر أفضل ممارسات الأمن السيبراني على مستوى الجهة، بما يسهم في رفع مستوى الوعي الأمني والالتزام بالضوابط والسياسات المعتمدة.
·التنسيق لتنفيذ اختبارات التصيد الإلكتروني ومبادرات التوعية الأمنية.
·تقديم الإرشادات والدعم الأمني للموظفين والمتعاقدين والأطراف الثالثة.
·قياس فعالية برامج التوعية وإعداد التقارير الخاصة بنتائجها.
·المساهمة في تحقيقات الحوادث الأمنية وتحليل الأسباب الجذرية.
·التأكد من توثيق الحوادث الأمنية والإبلاغ عنها والتعامل معها وفق الإجراءات المعتمدة.
·إعداد لوحات المعلومات الأمنية الدورية ومؤشرات الأداء والتقارير الإدارية.
·مراقبة وتحليل مؤشرات أداء أمن المعلومات ومستويات الامتثال للسياسات والمعايير المعتمدة.
·تقديم التوصيات اللازمة لتطوير الضوابط الأمنية وتعزيز الوضع الأمني العام للجهة.
المؤهل العلمي:
شهادة البكالوريوس أو الماجستير في مجال علوم الحاسب أو تقنية المعلومات (الأمن السيبراني / أمن المعلومات / الشبكات) من جامعة معترف بها عالمياً.
يفضل حامل شهادات مثل:
·ISO 22301 Lead Implementer / Auditor
·ISO 27001 Lead Implementer / Auditor
·CISA / CISM / CISSP
سنوات الخبرة:
·شهادة البكالوريوس: من 4 – 6 سنوات من الخبرة في مجال العمل.
·شهادة الماجستير: من 2 – 4 سنوات من الخبرة في مجال العمل.
المهارات الوظيفية:
·إدارة أمن المعلومات واستمرارية الأعمال (ISMS / BCMS)
·إدارة الحوكمة والمخاطر والامتثال (GRC)
·إجراء وتسهيل التدقيقات الأمنية ومتابعة نتائجها
·تقييم المخاطر والثغرات الأمنية وتطبيق الضوابط المناسبة
·إعداد التقارير ولوحات المؤشرات والتواصل مع الجهات الداخلية والخارجية
الكفاءات السلوكية:
التواصل الفعال·
التميز في التنفيذ·
خدمة المجتمع والاستجابة لاحتياجات العاملين من أفراده·
الفهم المؤسسي·