Job description
Responsible for protecting information assets and technical systems from security risks and threats in accordance with approved policies and standards. Monitors security controls and procedures to detect vulnerabilities and incidents, address them, and mitigate their impacts. Additionally, contributes to raising the organization's security maturity level by developing security controls and procedures, enhancing cyber awareness, and monitoring compliance with information security requirements.
- Monitor and assess security risks and vulnerabilities, analyze incidents and threats, and take corrective and preventive actions to mitigate their impacts and enhance the level of protection.
- Support the implementation of information security governance, risk management, and compliance frameworks, ensuring the application of security controls to maintain confidentiality, integrity, availability of information, and service continuity.
- Apply and monitor information security controls across the organization's systems, networks, and applications in accordance with approved policies, standards, and security procedures.
- Monitor security events and alerts, analyze indicators and reports to detect suspicious activities or intrusion attempts, and raise necessary recommendations.
- Contribute to the management and remediation of security vulnerabilities by conducting periodic scans, tracking remediation plans, and ensuring priority vulnerabilities are closed.
- Evaluate security risks associated with technical systems and services within the organization, identify risks, and establish appropriate procedures and controls to mitigate them.
- Review information and system access permissions to ensure the enforcement of the principle of least privilege, monitor unauthorized accounts and privileges, and prepare security reports and logs.
- Monitor compliance with government information security requirements and standards, conduct periodic assessments and reviews, document non-compliance cases, and track corrective actions.
- Perform other job-related duties and responsibilities as assigned.
Qualifications & Experience: Bachelor's degree with 8 years of experience, or Master's degree with 6 years of practical experience.
Specialization: Information Security, Cybersecurity, Computer Science, Information Technology, Computer Engineering, or any related fields from an accredited university.
الوصف الوظيفي
مسؤول عن حماية أصول المعلومات والنظم التقنية من المخاطر والتهديدات الأمنية وفقًا للسياسات والمعايير المعتمدة. ويقوم بمراقبة الضوابط والإجراءات الأمنية لاكتشاف الثغرات والحوادث ومعالجتها والحد من آثارها. بالإضافة إلى ذلك، يساهم في رفع مستوى النضج الأمني للمنظمة من خلال تطوير الضوابط والإجراءات الأمنية، وتعزيز الوعي السيبراني، ومراقبة الالتزام بمتطلبات أمن المعلومات.
- مراقبة وتقييم المخاطر والثغرات الأمنية، وتحليل الحوادث والتهديدات، واتخاذ الإجراءات التصحيحية والوقائية للحد من آثارها وتعزيز مستوى الحماية.
- دعم تنفيذ أطر حوكمة أمن المعلومات، وإدارة المخاطر، والالتزام، وضمان تطبيق الضوابط الأمنية للحفاظ على السرية، والسلامة، وتوافر المعلومات، واستمرارية الخدمات.
- تطبيق ومراقبة ضوابط أمن المعلومات عبر أنظمة وشبكات وتطبيقات المنظمة وفقًا للسياسات والمعايير والإجراءات الأمنية المعتمدة.
- مراقبة الأحداث والتنبيهات الأمنية، وتحليل المؤشرات والتقارير لاكتشاف الأنشطة المشبوهة أو محاولات الاختراق، ورفع التوصيات اللازمة.
- المساهمة في إدارة ومعالجة الثغرات الأمنية من خلال إجراء الفحوصات الدورية، ومتابعة خطط المعالجة، وضمان إغلاق الثغرات ذات الأولوية.
- تقييم المخاطر الأمنية المرتبطة بالأنظمة والخدمات التقنية داخل المنظمة، وتحديد المخاطر، ووضع الإجراءات والضوابط المناسبة للحد منها.
- مراجعة صلاحيات الوصول إلى المعلومات والأنظمة لضمان تطبيق مبدأ الحد الأدنى من الصلاحيات، ومراقبة الحسابات والصلاحيات غير المصرح بها، وإعداد التقارير والسجلات الأمنية.
- مراقبة الالتزام بمتطلبات ومعايير أمن المعلومات الحكومية، وإجراء التقييمات والمراجعات الدورية، وتوثيق حالات عدم الالتزام، ومتابعة الإجراءات التصحيحية.
- القيام بأي مهام ومسؤوليات أخرى ذات صلة بالوظيفة حسب التكليف.
المؤهلات والخبرة: درجة البكالوريوس مع 8 سنوات من الخبرة، أو درجة الماجستير مع 6 سنوات من الخبرة العملية.
التخصص: أمن المعلومات، الأمن السيبراني، علوم الحاسب، تقنية المعلومات، هندسة الحاسب، أو أي مجالات ذات صلة من جامعة معتمدة.