Position information
Department: Information Technology / Cybersecurity
Reports to: Cybersecurity Manager
Direct reports:
Location: [Location]
Employment type: Full-time
Position purpose
The Head of Cybersecurity is responsible for leading the day-to-day cybersecurity function, managing cybersecurity operations, and overseeing the implementation of security controls across the organisation's Information Technology (IT) and Operational Technology (OT) environments. The role provides technical leadership to a small cybersecurity team and ensures cybersecurity risks are effectively identified, assessed, monitored, and mitigated.
Working under the direction of the Cybersecurity Manager, the Head of Cybersecurity is accountable for the execution of the cybersecurity strategy, governance requirements, security operations, compliance activities, and cybersecurity improvement initiatives.
Key responsibilities
Cybersecurity leadership
- Lead and manage the cybersecurity team, providing technical guidance, mentoring, and performance management.
- Coordinate cybersecurity activities across IT, OT, Digital, and business functions.
- Act as the primary escalation point for cybersecurity operational issues.
- Develop team capabilities, skills, and professional development plans.
- Foster a strong cybersecurity culture throughout the organization.
Security operations
- Oversee Security Operations Centre (SOC) activities, whether internally delivered or outsourced.
- Monitor security alerts, incidents, vulnerabilities, and threats.
- Ensure effective incident detection, triage, investigation, containment, and recovery.
- Lead cyber incident response activities and coordinate post-incident reviews.
- Ensure cybersecurity monitoring and logging capabilities are maintained and optimized.
Governance, risk and compliance
- Support the implementation and maintenance of the cybersecurity governance framework.
- Manage cybersecurity risk assessments and risk treatment activities.
- Maintain the cybersecurity risk register and track remediation actions.
- Ensure compliance with applicable cybersecurity standards, regulatory requirements, and corporate policies.
- Support internal and external cybersecurity audits.
Security architecture and controls
- Ensure security controls are implemented and maintained across infrastructure, endpoints, cloud services, applications, and OT environments.
- Review and approve security designs for new projects and technology implementations.
- Support secure network segmentation and defense-in-depth strategies.
- Oversee vulnerability management and remediation programs.
Identity and access management
- Ensure privileged access management and identity governance controls are implemented and monitored.
- Oversee periodic access reviews and segregation of duties assessments.
- Support implementation of role-based access control (RBAC) frameworks.
- Ensure compliance with least-privilege principles and account management standards.
Vulnerability management
- Direct vulnerability assessment and scanning activities.
- Prioritize remediation activities based on business risk.
- Monitor closure of identified vulnerabilities.
- Provide reporting on remediation status and risk exposure.
Third-party security
- Assess cybersecurity risks associated with suppliers and vendors.
- Participate in vendor security reviews and due diligence assessments.
- Ensure cybersecurity requirements are incorporated into contracts and procurement processes.
Business continuity and resilience
- Support disaster recovery and business continuity planning.
- Participate in cyber resilience exercises and simulations.
- Ensure cybersecurity recovery requirements are incorporated into continuity plans.
Security awareness
- Develop and maintain cybersecurity awareness and training programs.
- Promote security best practices across all levels of the organization.
- Coordinate phishing simulation and awareness campaigns.
Reporting and performance management
- Prepare cybersecurity dashboards and reports for management.
- Provide regular updates to the Cybersecurity Manager on security posture, incidents, risks, and initiatives.
- Track cybersecurity KPIs and KRIs.
- Monitor progress against the cybersecurity roadmap.
Key deliverables
- Cybersecurity risk register
- Security incident reports
- Vulnerability management reports
- Compliance and audit reports
- Cybersecurity KPI/KRI dashboard
- Security awareness program
- Security standards and procedures
- Incident response plans
- Privileged access reviews
- Third-party security assessments
- Cybersecurity roadmap progress reporting
Required qualifications
Essential
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.
- Minimum 8-10 years of cybersecurity experience.
- Minimum 3-5 years of cybersecurity leadership or management experience.
- Experience across security operations, risk management, governance, and security architecture.
- Experience managing third-party cybersecurity service providers.
Preferred certifications
- CISSP
- CISM
- CRISC
- GSEC
- GIAC certifications
- ISO 27001 Lead Implementer or Lead Auditor
- IEC 62443 Cybersecurity certifications
- Microsoft Security certifications
- CCSP
Knowledge and experience
Technical knowledge
- Security operations and incident response
- SIEM and security monitoring platforms
- Endpoint detection and response (EDR/XDR)
- Microsoft security technologies
- Identity and access management
- Privileged access management
- Vulnerability management
- Cloud security (Azure/AWS)
- Network security
- OT/ICS cybersecurity
- Security architecture principles
Governance knowledge
- NIST Cybersecurity Framework
- NIST SP 800-53
- NIST Incident Response Framework
- IEC 62443
- ISO 27001
- CIS Critical Security Controls
- Risk management frameworks
Key competencies
- Leadership and team management
- Strategic thinking
- Risk-based decision making
- Communication and stakeholder management
- Incident management
- Problem solving
- Vendor management
- Project management
- Analytical thinking
- Report writing and executive presentation skills
Authority levels
The Head of Cybersecurity is authorized to:
- Direct cybersecurity operational activities.
- Lead cybersecurity incident response activities.
- Escalate significant cyber risks to the Cybersecurity Manager.
- Recommend security control implementations.
- Initiate emergency security containment actions during cybersecurity incidents.
- Review and approve cybersecurity operational standards and procedures.
Key performance indicators (KPIs)
- Mean time to detect (MTTD)
- Mean time to respond (MTTR)
- Vulnerability remediation compliance rate
- Security awareness completion rate
- Audit finding closure rate
- Privileged access review completion rate
- Security incident reduction trends
- Cybersecurity roadmap delivery performance
- Third-party security assessment completion rate
- Compliance with security standards and policies
معلومات الوظيفة
القسم: تقنية المعلومات / الأمن السيبراني
يرفع تقاريره إلى: مدير الأمن السيبراني
المرؤوسون المباشرون:
الموقع: [الموقع]
نوع التوظيف: دوام كامل
الغرض من الوظيفة
يتولى رئيس الأمن السيبراني مسؤولية قيادة مهام الأمن السيبراني اليومية، وإدارة عمليات الأمن السيبراني، والإشراف على تنفيذ ضوابط الأمن عبر بيئات تقنية المعلومات (IT) والتقنية التشغيلية (OT) الخاصة بالمؤسسة. يوفر هذا الدور القيادة الفنية لفريق أمن سيبراني صغير ويضمن تحديد مخاطر الأمن السيبراني وتقييمها ومراقبتها والحد منها بشكل فعال.
يعمل رئيس الأمن السيبراني تحت توجيه مدير الأمن السيبراني، وهو مسؤول عن تنفيذ استراتيجية الأمن السيبراني ومتطلبات الحوكمة وعمليات الأمن وأنشطة الامتثال ومبادرات تحسين الأمن السيبراني.
المسؤوليات الرئيسية
قيادة الأمن السيبراني
- قيادة وإدارة فريق الأمن السيبراني، وتوفير التوجيه الفني والإرشاد وإدارة الأداء.
- تنسيق أنشطة الأمن السيبراني عبر مجالات تقنية المعلومات والتقنية التشغيلية والتقنيات الرقمية والقطاعات التشغيلية للمؤسسة.
- العمل نقطة تصعيد رئيسية للمشكلات التشغيلية المتعلقة بالأمن السيبراني.
- تطوير قدرات الفريق ومهاراته وخطط التطوير المهني.
- تعزيز ثقافة أمن سيبراني قوية في جميع أنحاء المؤسسة.
عمليات الأمن
- الإشراف على أنشطة مركز عمليات الأمن (SOC)، سواء المقدمة داخليًا أو من خلال أطراف خارجية.
- مراقبة التنبيهات والحوادث والثغرات الأمنية والتهديدات.
- ضمان الكشف الفعال عن الحوادث وفرزها والتحقيق فيها واحتوائها والتعافي منها.
- قيادة أنشطة الاستجابة للحوادث السيبرانية وتنسيق مراجعات ما بعد الحوادث.
- ضمان الحفاظ على قدرات المراقبة والتسجيل الخاصة بالأمن السيبراني وتحسينها.
الحوكمة والمخاطر والامتثال
- دعم تنفيذ وصيانة إطار حوكمة الأمن السيبراني.
- إدارة تقييمات مخاطر الأمن السيبراني وأنشطة معالجة المخاطر.
- الحفاظ على سجل مخاطر الأمن السيبراني ومتابعة إجراءات المعالجة.
- ضمان الامتثال لمعايير الأمن السيبراني المطبقة والمتطلبات التنظيمية والسياسات المؤسسية.
- دعم عمليات التدقيق الداخلي والخارجي للأمن السيبراني.
بنية الأمن والضوابط الأمنية
- ضمان تنفيذ ضوابط الأمن وصيانتها عبر البنية التحتية والأجهزة الطرفية والخدمات السحابية والتطبيقات وبيئات التقنية التشغيلية (OT).
- مراجعة واعتماد التصاميم الأمنية للمشاريع الجديدة وتطبيقات التكنولوجيا.
- دعم التجزئة الآمنة للشبكة واستراتيجيات الدفاع العميق.
- الإشراف على برامج إدارة الثغرات الأمنية ومعالجتها.
إدارة الهوية والوصول
- ضمان تنفيذ ومراقبة إدارة الوصول المميز وضوابط حوكمة الهوية.
- الإشراف على المراجعات الدورية للوصول وتقييمات الفصل بين المهام.
- دعم تنفيذ أطر التحكم في الوصول القائم على الأدوار (RBAC).
- ضمان الامتثال لمبادئ الحد الأدنى من الصلاحيات ومعايير إدارة الحسابات.
إدارة الثغرات الأمنية
- توجيه أنشطة تقييم الثغرات الأمنية وفحصها.
- تحديد أولويات أنشطة المعالجة بناءً على مخاطر الأعمال.
- مراقبة إغلاق الثغرات الأمنية المحددة.
- تقديم تقارير عن حالة المعالجة ومستوى التعرض للمخاطر.
أمن الأطراف الخارجية
- تقييم مخاطر الأمن السيبراني المرتبطة بالموردين والبائعين.
- المشاركة في المراجعات الأمنية للبائعين وتقييمات العناية الواجبة.
- ضمان إدراج متطلبات الأمن السيبراني في العقود وعمليات المشتريات.
استمرارية الأعمال والمرونة
- دعم التخطيط للتعافي من الكوارث واستمرارية الأعمال.
- المشاركة في تمارين وتمثيلات المرونة السيبرانية.
- ضمان إدراج متطلبات التعافي الخاصة بالأمن السيبراني في خطط الاستمرارية.
التوعية الأمنية
- تطوير وصيانة برامج التوعية والتدريب على الأمن السيبراني.
- تعزيز أفضل الممارسات الأمنية على جميع مستويات المؤسسة.
- تنسيق حملات محاكاة التصيد الاحتيالي والتوعية.
إعداد التقارير وإدارة الأداء
- إعداد لوحات معلومات وتقارير الأمن السيبراني للإدارة.
- تقديم تحديثات منتظمة لمدير الأمن السيبراني حول الوضع الأمني والحوادث والمخاطر والمبادرات.
- تتبع مؤشرات الأداء الرئيسية (KPIs) ومؤشرات المخاطر الرئيسية (KRIs) للأمن السيبراني.
- مراقبة التقدم المحرز مقابل خارطة طريق الأمن السيبراني.
المخرجات الرئيسية
- سجل مخاطر الأمن السيبراني
- تقارير الحوادث الأمنية
- تقارير إدارة الثغرات الأمنية
- تقارير الامتثال والتدقيق
- لوحة مؤشرات الأداء والمخاطر الرئيسية (KPI/KRI) للأمن السيبراني
- برنامج التوعية الأمنية
- معايير وإجراءات الأمن
- خطط الاستجابة للحوادث
- مراجعات الوصول المميز
- تقييمات أمن الأطراف الخارجية
- تقارير التقدم المحرز في خارطة طريق الأمن السيبراني
المؤهلات المطلوبة
المتطلبات الأساسية
- درجة البكالوريوس في الأمن السيبراني، أو تقنية المعلومات، أو علوم الحاسوب، أو الهندسة، أو أي تخصص ذات صلة.
- خبرة لا تقل عن 8-10 سنوات في مجال الأمن السيبراني.
- خبرة لا تقل عن 3-5 سنوات في قيادة أو إدارة الأمن السيبراني.
- خبرة في عمليات الأمن، وإدارة المخاطر، والحوكمة، وبنية الأمن.
- خبرة في إدارة مزودي خدمات الأمن السيبراني من الأطراف الخارجية.
الشهادات المفضلة
- CISSP
- CISM
- CRISC
- GSEC
- شهادات GIAC
- ISO 27001 Lead Implementer أو Lead Auditor
- شهادات IEC 62443 للأمن السيبراني
- شهادات مايكروسوفت للأمن
- CCSP
المعرفة والخبرة
المعرفة الفنية
- عمليات الأمن والاستجابة للحوادث
- منصات المراقبة الأمنية وSIEM
- الكشف عن تهديدات الأجهزة الطرفية والاستجابة لها (EDR/XDR)
- تقنيات مايكروسوفت الأمنية
- إدارة الهوية والوصول
- إدارة الوصول المميز
- إدارة الثغرات الأمنية
- الأمن السحابي (Azure/AWS)
- أمن الشبكات
- الأمن السيبراني للتقنية التشغيلية/أنظمة التحكم الصناعي (OT/ICS)
- مبادئ بنية الأمن
معرفة الحوكمة
- إطار عمل الأمن السيبراني لنظام NIST
- NIST SP 800-53
- إطار الاستجابة للحوادث لنظام NIST
- IEC 62443
- ISO 27001
- ضوابط الأمن الحيوية لـ CIS
- أطر إدارة المخاطر
الكفاءات الرئيسية
- القيادة وإدارة الفريق
- التفكير الاستراتيجي
- اتخاذ القرارات القائمة على المخاطر
- التواصل وإدارة أصحاب المصلحة
- إدارة الحوادث
- حل المشكلات
- إدارة الموردين والبائعين
- إدارة المشاريع
- التفكير التحليلي
- مهارات كتابة التقارير والعروض التقديمية التنفيذية
مستويات الصلاحية
يُصرح لرئيس الأمن السيبراني بـ:
- توجيه الأنشطة التشغيلية للأمن السيبراني.
- قيادة أنشطة الاستجابة للحوادث السيبرانية.
- تصعيد المخاطر السيبرانية الجسيمة إلى مدير الأمن السيبراني.
- التوصية بتنفيذ ضوابط الأمن.
- البدء في إجراءات احتواء الأمن الطارئة أثناء الحوادث السيبرانية.
- مراجعة واعتماد المعايير والإجراءات التشغيلية للأمن السيبراني.
مؤشرات الأداء الرئيسية (KPIs)
- متوسط الوقت اللازم للاكتشاف (MTTD)
- متوسط الوقت اللازم للاستجابة (MTTR)
- معدل الامتثال لمعالجة الثغرات الأمنية
- معدل إتمام التوعية الأمنية
- معدل إغلاق نتائج التدقيق
- معدل إتمام مراجعة الوصول المميز
- اتجاهات الحد من الحوادث الأمنية
- أداء تنفيذ خارطة طريق الأمن السيبراني
- معدل إتمام تقييم أمن الأطراف الخارجية
- الامتثال لمعايير وسياسات الأمن