Job description
Title:
IT Cybersecurity Project Lead
IT Cyber Security Project Lead
Position Information
Job Title: IT Cyber Security Head
Department: Information Technology / Cybersecurity
Reports To: IT Cyber Security Head
Location: [Location]
Employment Type: Full-Time
Position Purpose
The Cybersecurity Operations Engineer is responsible for the implementation, operation, monitoring, and continuous improvement of cybersecurity controls across the organization's Information Technology (IT) and Operational Technology (OT) environments.
The role focuses on security monitoring, incident response, vulnerability management, endpoint security, identity security, and security tooling administration. The position plays a key role in protecting organizational assets from cyber threats while supporting compliance with cybersecurity policies, standards, and regulatory requirements.
The Cybersecurity Operations Engineer works closely with IT infrastructure, cloud, network, application, and OT teams to ensure security controls are implemented and operating effectively.
Key Responsibilities
Security Operations
- Monitor security events and alerts generated by security monitoring platforms.
- Investigate suspicious activities and security incidents.
- Perform incident triage, containment, eradication, and recovery activities.
- Support cyber incident response and forensic investigations.
- Participate in on-call cyber incident response activities where required.
- Maintain incident records and lessons learned documentation.
Security Monitoring & SIEM
- Administer and maintain SIEM platforms.
- Develop and tune detection rules and alert thresholds.
- Monitor log sources and ensure adequate security event coverage.
- Investigate security alerts and escalate critical findings.
- Develop use cases and threat detection analytics.
Endpoint and Server Security
- Manage Endpoint Detection and Response (EDR/XDR) solutions.
- Support endpoint protection platforms such as Microsoft Defender, CrowdStrike, Trend Micro, or equivalent.
- Monitor and investigate endpoint threats.
- Ensure security agents remain operational and compliant.
- Support server hardening and security baseline implementation.
Vulnerability Management
- Perform vulnerability scanning activities.
- Analyse vulnerability assessment reports.
- Prioritize remediation actions based on risk.
- Coordinate remediation efforts with infrastructure and application teams.
- Monitor closure of identified vulnerabilities.
- Produce vulnerability metrics and reporting.
Identity and Access Management
- Support privileged access management solutions.
- Monitor privileged account usage.
- Assist with periodic access reviews.
- Support identity governance activities.
- Ensure compliance with least-privilege principles.
Security Tool Administration
- Administer cybersecurity technologies including:
- SIEM
- EDR/XDR
- PAM
- Vulnerability Management Platforms
- Email Security Solutions
- Web Security Gateways
- Security Monitoring Platforms
- Threat Intelligence Platforms
- Maintain health and performance of cybersecurity systems.
- Support technology upgrades and deployment activities.
Threat Management
- Monitor emerging cyber threats and vulnerabilities.
- Review threat intelligence feeds.
- Assess threats for organisational relevance.
- Recommend protective measures and compensating controls.
- Support threat hunting activities.
OT/Industrial Cybersecurity Support
- Assist with cybersecurity monitoring of OT environments.
- Support IEC 62443-aligned control implementation.
- Monitor OT security events and vulnerabilities.
- Participate in OT risk assessments.
- Support secure network segmentation initiatives.
Security Compliance
- Assist in design and implementation of cybersecurity policies and standards.
- Support cybersecurity audits and assessments.
- Maintain operational evidence for compliance activities.
- Support implementation of NIST, ISO 27001, and IEC 62443 requirements.
Reporting
- Prepare operational cybersecurity reports.
- Produce incident and vulnerability metrics.
- Maintain dashboards and KPI reporting.
- Provide regular status updates to the Head of Cybersecurity.
Key Deliverables
- Security Incident Reports
- Vulnerability Assessment Reports
- SIEM Monitoring Dashboards
- Threat Intelligence Briefings
- Security Control Compliance Reports
- Security Monitoring Use Cases
- Security Technology Health Reports
- Privileged Access Monitoring Reports
- Cybersecurity KPIs and Metrics
Required Qualifications
Essential
- Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.
- Minimum 3-5 years of cybersecurity operations experience.
- Experience supporting enterprise security technologies.
- Experience investigating cybersecurity incidents.
- Experience with security monitoring and vulnerability management.
Preferred Certifications
One or more of:
- CompTIA Security+
- CompTIA CySA+
- Microsoft Security Certifications
- SC-200 Security Operations Analyst
- CISSP Associate
- GIAC Certifications
- GSEC
- SSCP
- CEH
Technical Skills
Security Operations
- Incident Response
- Threat Detection
- Threat Hunting
- Security Monitoring
- Digital Forensics Fundamentals
Security Platforms
- Microsoft Sentinel
- Microsoft Defender XDR
- CrowdStrike
- Trend Micro
- Tenable
- Qualys
- Rapid7
- Splunk
- QRadar
Infrastructure Security
- Windows Server
- Active Directory
- Entra ID (Azure AD)
- Linux Administration
- Network Security
- Firewalls
- VPN Technologies
Cloud Security
- Microsoft Azure
- Microsoft 365 Security
- AWS Security Fundamentals
OT Security (Preferred)
- Industrial Control Systems (ICS)
- SCADA Security
- IEC 62443
- OT Network Security
Knowledge Requirements
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-53
- IEC 62443
- ISO 27001
- CIS Critical Security Controls
- Cyber Kill Chain
- MITRE ATT&CK Framework
- Vulnerability Management Processes
- Security Incident Lifecycle Management
Key Competencies
- Analytical Thinking
- Problem Solving
- Technical Troubleshooting
- Incident Management
- Attention to Detail
- Teamwork and Collaboration
- Communication Skills
- Risk Awareness
- Continuous Learning
- Customer Service Orientation
وصف الوظيفة
العنوان:
قائد مشروع أمن تكنولوجيا المعلومات (السيبراني)
قائد مشروع أمن تكنولوجيا المعلومات (السيبراني)
معلومات الوظيفة
العنوان الوظيفي: رئيس أمن تكنولوجيا المعلومات (السيبراني)
القسم: تكنولوجيا المعلومات / الأمن السيبراني
الإشراف على: رئيس أمن تكنولوجيا المعلومات (السيبراني)
الموقع: [الموقع]
نوع التوظيف: دوام كامل
الغرض من الوظيفة
مُهندس عمليات الأمن السيبراني مسؤول عن تنفيذ ومراقبة وتحسين مستمر لضوابط الأمن السيبراني عبر بيئات تكنولوجيا المعلومات (IT) وتكنولوجيا التشغيل (OT) في المؤسسة.
تركز هذه الوظيفة على مراقبة الأمن والاستجابة للحوادث وإدارة الثغرات وأمن النهايات وأمن الهوية وإدارة أدوات الأمن. تلعب هذه الوظيفة دورًا رئيسيًا في حماية أصول المؤسسة من التهديدات السيبرانية مع دعم الامتثال لسياسات ومعايير ولوائح الأمن السيبراني.
يعمل مهندس عمليات الأمن السيبراني بشكل وثيق مع فرق البنية التحتية لتكنولوجيا المعلومات والسحابة والشبكات والتطبيقات وتكنولوجيا التشغيل لضمان تنفيذ ضوابط الأمن بشكل فعال.
المسؤوليات الرئيسية
عمليات الأمن
- مراقبة الأحداث والتنبيهات الأمنية الصادرة عن منصات مراقبة الأمن.
- التحقيق في الأنشطة المشبوهة وحالات الأمن السيبراني.
- تنفيذ إجراءات التثليث containment واحتواء الحوادث واستئصالها واستعادة النظام.
- دعم الاستجابة للحوادث السيبرانية والتحقيقات الجنائية الرقمية.
- المشاركة في أنشطة الاستجابة للحوادث السيبرانية أثناء الدوام (عند الحاجة).
- الحفاظ على سجلات الحوادث ووثائق الدروس المستفادة.
مراقبة الأمن ومنصات SIEM
- إدارة وصيانة منصات SIEM.
- تطوير وضبط قواعد الكشف وعتبات التنبيهات.
- مراقبة مصادر السجلات وضمان تغطية كافية لأحداث الأمن.
- التحقيق في تنبيهات الأمن وتصعيد النتائج الحرجة.
- تطوير حالات الاستخدام وتحليلات كشف التهديدات.
أمن النهايات والخوادم
- إدارة حلول الكشف والاستجابة للنهايات (EDR/XDR).
- دعم منصات حماية النهايات مثل Microsoft Defender وCrowdStrike وTrend Micro أو ما يعادلها.
- مراقبة والتحقيق في تهديدات النهايات.
- ضمان بقاء وكلاء الأمن عاملين ومتوافقين.
- دعم تعزيز خوادم الأمن وتنفيذ معايير الأمان الأساسية.
إدارة الثغرات
- تنفيذ أنشطة مسح الثغرات.
- تحليل تقارير تقييم الثغرات.
- أفضلية إجراءات التخفيف بناءً على المخاطر.
- تنسيق جهود التخفيف مع فرق البنية التحتية والتطبيقات.
- مراقبة إغلاق الثغرات المحددة.
- إنتاج تقارير ومؤشرات أداء الثغرات.
إدارة الهوية والوصول
- دعم حلول إدارة الوصول الامتياز.
- مراقبة استخدام حسابات الامتياز.
- المساعدة في مراجعات الوصول الدورية.
- دعم أنشطة حوكمة الهوية.
- ضمان الامتثال لمبادئ الامتياز الأقل.
إدارة أدوات الأمن
- إدارة تقنيات الأمن السيبراني بما في ذلك:
- SIEM
- EDR/XDR
- PAM
- منصات إدارة الثغرات
- حلول أمن البريد الإلكتروني
- بوابات أمن الويب
- منصات مراقبة الأمن
- منصات استخبارات التهديدات
- الحفاظ على صحة وأداء أنظمة الأمن السيبراني.
- دعم ترقيات ونشر التكنولوجيا.
إدارة التهديدات
- مراقبة التهديدات والثغرات السيبرانية الناشئة.
- مراجعة مصادر استخبارات التهديدات.
- تقييم التهديدات من حيث صلتها بالمؤسسة.
- اقتراح تدابير وقائية وضوابط تعويضية.
- دعم أنشطة صيد التهديدات.
دعم أمن OT/الصناعي
- المساعدة في مراقبة أمن بيئات OT.
- دعم تنفيذ الضوابط المتوافقة مع IEC 62443.
- مراقبة أحداث وثغرات أمن OT.
- المشاركة في تقييمات مخاطر OT.
- دعم مبادرات تقسيم الشبكة الآمنة.
الامتثال الأمني
- المساعدة في تصميم وتنفيذ سياسات ومعايير الأمن السيبراني.
- دعم عمليات التدقيق والتقييمات الأمنية.
- الحفاظ على الأدلة التشغيلية للامتثال.
- دعم تنفيذ متطلبات NIST وISO 27001 وIEC 62443.
التقارير
- إعداد تقارير الأمن السيبراني التشغيلية.
- إنتاج مؤشرات الحوادث والثغرات.
- الحفاظ على لوحات المعلومات والإبلاغ عن مؤشرات الأداء الرئيسية.
- تقديم تحديثات دورية إلى رئيس الأمن السيبراني.
المخرجات الرئيسية
- تقارير حوادث الأمن
- تقارير تقييم الثغرات
- لوحات معلومات مراقبة SIEM
- إحاطات استخبارات التهديدات
- تقارير الامتثال لضوابط الأمن
- حالات استخدام مراقبة الأمن
- تقارير صحة تكنولوجيا الأمن
- تقارير مراقبة الوصول الامتياز
- مؤشرات الأداء الرئيسية والأبعاد الأمنية
المؤهلات المطلوبة
أساسية
- درجة البكالوريوس في الأمن السيبراني أو تكنولوجيا المعلومات أو علوم الكمبيوتر أو الهندسة أو مجال ذي صلة.
- خبرة لا تقل عن 3-5 سنوات في عمليات الأمن السيبراني.
- خبرة في دعم تقنيات الأمن المؤسسية.
- خبرة في التحقيق في حوادث الأمن السيبراني.
- خبرة في مراقبة الأمن وإدارة الثغرات.
الشهادات المفضلة
واحد أو أكثر من:
- CompTIA Security+
- CompTIA CySA+
- شهادات أمن مايكروسوفت
- SC-200 Security Operations Analyst
- CISSP Associate
- شهادات GIAC
- GSEC
- SSCP
- CEH
المهارات الفنية
عمليات الأمن
- الاستجابة للحوادث
- كشف التهديدات
- صيد التهديدات
- مراقبة الأمن
- أساسيات التحقيقات الجنائية الرقمية
منصات الأمن
- Microsoft Sentinel
- Microsoft Defender XDR
- CrowdStrike
- Trend Micro
- Tenable
- Qualys
- Rapid7
- Splunk
- QRadar
أمن البنية التحتية
- خوادم ويندوز
- Active Directory
- Entra ID (Azure AD)
- إدارة لينكس
- أمن الشبكات
- جدران الحماية
- تقنيات VPN
أمن السحابة (مفضل)
- Microsoft Azure
- أمن Microsoft 365
- أساسيات أمن AWS
أمن OT (مفضل)
- أنظمة التحكم الصناعية (ICS)
- أمن SCADA
- IEC 62443
- أمن شبكات OT
المتطلبات المعرفية
- إطار عمل الأمن السيبراني NIST (CSF)
- NIST SP 800-53
- IEC 62443
- ISO 27001
- ضوابط الأمن الحرجة CIS
- سلسلة قتل السيبراني
- إطار عمل MITRE ATT&CK
- عمليات إدارة الثغرات
- إدارة دورة حياة حوادث الأمن
الكفاءات الرئيسية
- التفكير التحليلي
- حل المشكلات
- استكشاف الأخطاء الفنية وإصلاحها
- إدارة الحوادث
- الاهتمام بالتفاصيل
- العمل الجماعي والتعاون
- مهارات التواصل
- الوعي بالمخاطر
- التعلم المستمر
- التوجه نحو خدمة العملاء