وصف الوظيفة
الأدوار والمسؤوليات
مراقبة الأمن والكشف عن التهديدات • الإدارة، الإدارة والدعم في نشر وضبط أدوات أمن OT (Nozomi, Forescout).
مراقبة بيئات OT/ICS باستخدام SIEM ومنصات مراقبة أمن OT
الكشف والتحليل والاستجابة للتهديدات السيبرانية التي تستهدف أنظمة التحكم الصناعية
دعم وضمان استراتيجيات التقسيم الدقيق لدوائر شبكة OT (التوافق مع نموذج Purdue)
التعاون مع فرق الهندسة لتنفيذ إجراءات الاحتواء في بيئات OT الحية بشكل آمن
إجراء صيد التهديدات عبر البيئات الصناعية باستخدام بيانات الشبكة والسجلات
التعامل مع دعم الاستجابة للحوادث لأحداث OT السيبرانية مع الحد الأدنى من التعطيل التشغيلي
الحفاظ على وضوح أصول OT وخطوط الأساس لسلوك الشبكة
الامتثال لـ IEC 62443، NIST ICS، ومعايير الأمن التنظيمية
العمل مع تقنيات الجدار الناري، IDS/IPS، NAC والتقسيم في شبكات OT
الهندسة الكشف وإدارة حالات الاستخدام • تطوير وضبط قواعد كشف OT والتوصيل المنطقي في منصات SIEM.
مواءمة حالات الكشف مع MITRE ATT&CK لإطار ICS
تقليل الإيجابيات الكاذبة وتحسين دقة ونطاق الكشف
مراجعة وتحسين عتبات الإنذار ومنطق الكشف بشكل دوري
دعم هندسة أمن OT المدمجة مع SIEM، IDS/IPS، بروكرات الحزم، وأدوات التقسيم
المساعدة في إدراج مصادر السجلات، وتطوير المحللات، وتطبيع بيانات OT
تحسين لوحات المعلومات والتنبيهات والتقارير لرؤية تشغيلية
رؤية الشبكة OT، تحليل الحزم وتوجيه الحركة • تشغيل بنى موزعات الحزم وتقنيات TAP لتمكين رؤية كاملة لشبكة OT.
إجراء فحص عميق لحزم بروتوكولات صناعية (Modbus، DNP3، OPC-UA، IEC 104، Ethernet/IP).
تحليل حركة المرور الشرقية-الغربية والشمالية-الجنوبية للبحث عن نشاط مريب والتحرك الجانبي
تحديد الاتصالات غير المصرح بها والشذوذ في البروتوكولات
دعم جمع القياس الشبكي لبيئات OT
رؤية الأصول والصيد التهديدي وإدارة الامتثال • الحفاظ على جرد أصول OT ورؤية بنية الشبكة الشاملة.
تحديد الأجهزة غير المصرح بها والاتصالات غير المشروعة وأصول OT الظلية
إجراء صيد تهديدات استباقي باستخدام السجلات والقياس الشبكي والتحليلات السلوكية
ترابط معلومات التهديد مع مخاطر بيئة OT وثغراتها
الامتثال لـ IEC 62443، NIST ICS، معايير ISO وسياسات الأمن الداخلية
دعم التدقيقات الداخلية/الخارجية وتوفير أدلة أمان لتقارير الامتثال
المساهمة في تقييمات المخاطر ومبادرات تحسين وضعية أمان OT
التقارير وإدارة الجهات المستفيدة • تحضير وتقديم تقارير أمان OT (الحوادث، المخاطر، والاتجاهات)
الحفاظ على لوحات معلومات للثغرات والتهديدات وحالة الامتثال
إبلاغ الحوادث والمخاطر الحاسمة إلى SOC وOT وأصحاب المصالح في الأعمال
تقديم تقارير مستوى التنفيذي عن وضع أمان OT والتعرض
متابعة حالة الإصلاح وتتبع SLAs
دعم متطلبات التدقيق والتقارير التنظيمية (IEC 62443، NIST ICS)
الملف المرشح المطلوب
المتطلبات التعليمية والشهادات • درجة البكالوريوس في الأمن السيبراني، أمن المعلومات، علوم الكمبيوتر أو مجال ذي صلة.
o GIAC Global Industrial Cyber Security Professional (GICSP)
o ISA/IEC 62443 شهادة الأمن السيبراني
o GIAC Response and Industrial Defense (GRID)
o ISA Certified Automation Cybersecurity Specialist (IACS)
المهارات التقنية الخاصة بالوظيفة • أنظمة OT/ICS (SCADA، DCS، PLC)
هندسة شبكة OT (نموذج Purdue، DMZ، التقسيم)
التقسيم الدقيق وZero Trust لـ OT
تحليل الحزم وفحص الحزم العميق (DPI)
بروكرات الحزم وتقنيات TAP/SPAN
أدوات SIEM ومراقبة OT (Sentinel، Nozomi، Forcescout)
الاستجابة للحوادث في بيئات OT
صيد تهديد OT والكشف عن الشذوذ
الكشف والتحليل للتهديدات
الجدار الناري الصناعي والوصول عن بُعد الآمن
إدارة ثغرات OT ورؤية الأصول
الامتثال (IEC 62443، NIST ICS)
Job Description
Roles & Responsibilities
Security Monitoring & Threat Detection • Administration, management, and Support deployment and tuning of OT security tools (Nozomi, Forescout).
Monitor OT/ICS environments using SIEM and OT security monitoring platforms
Detect, analyze, and respond to cyber threats targeting industrial control systems
Support and ensure micro segmentation strategies for OT network zones (Purdue Model alignment)
Collaborate with engineering teams to safely implement containment actions in live OT environments
Conduct threat hunting across industrial environments using network and log data
Handle and support incident response for OT cyber events with minimal operational disruption
Maintain OT asset visibility and network behavior baselines
Ensure compliance with IEC 62443, NIST ICS, and organizational security standards
Work with firewall, IDS/IPS, NAC, and segmentation technologies in OT networks
Detection Engineering & Use Case Management • Develop and tune OT-specific detection rules and correlation logic in SIEM platforms.
Align detection use cases with MITRE ATT&CK for ICS framework.
Reduce false positives and improve detection accuracy and coverage.
Periodically review and optimize alert thresholds and detection logic.
Support OT security architecture integrating SIEM, IDS/IPS, packet brokers, and segmentation tools.
Assist in onboarding log sources, parser development, and normalization of OT data.
Optimize dashboards, alerts, and reporting for operational visibility.
OT Network Visibility, Packet Analysis & Traffic Engineering • Operate packet brokers and TAP infrastructure to enable full OT network visibility.
Perform deep packet inspection of industrial protocols (Modbus, DNP3, OPC-UA, IEC 104, Ethernet/IP).
Analyze east-west and north-south traffic for suspicious activity and lateral movement.
Identify unauthorized communications and protocol anomalies.
Support network telemetry collection for OT environments.
Asset Visibility, Threat Hunting & Compliance Management • Maintain complete OT asset inventory and network topology visibility.
Identify unauthorized devices, rogue connections, and shadow OT assets.
Conduct proactive threat hunting using logs, network telemetry, and behavioral analytics.
Correlate threat intelligence with OT environment risks and vulnerabilities.
Ensure compliance with IEC 62443, NIST ICS, ISO standards, and internal security policies.
Support internal/external audits and provide security evidence for compliance reporting.
Contribute to risk assessments and OT security posture improvement initiatives.
Reporting & Stakeholder Management • Prepare and present OT security reports (incidents, risks, and trends)
Maintain dashboards for vulnerabilities, threats, and compliance status
Communicate critical incidents and risks to SOC, OT, and business stakeholders
Provide executive-level reporting on OT security posture and exposure
Track remediation status and SLA Tracking
Support audit and regulatory reporting requirements (IEC 62443, NIST ICS)
Desired Candidate Profile
Education and Certification Requirements • Bachelor’s degree in Cybersecurity, Information Security, Computer science or related field.
o GIAC Global Industrial Cyber Security Professional (GICSP)
o ISA/IEC 62443 Cybersecurity Certificate
o GIAC Response and Industrial Defense (GRID)
o ISA Certified Automation Cybersecurity Specialist (IACS)
Job Specific Technical Skills • OT/ICS systems (SCADA, DCS, PLC)
OT network architecture (Purdue Model, DMZ, segmentation)
Microsegmentation & Zero Trust for OT
Packet analysis & Deep Packet Inspection (DPI)
Packet brokers & TAP/SPAN technologies
SIEM & OT monitoring tools (Sentinel, Nozomi, Forcescout)
Incident response in OT environments
OT threat hunting & anomaly detection
Threat Detection & Analysis
Industrial firewalling & remote access security
OT vulnerability management & asset visibility
Compliance (IEC 62443, NIST ICS)