وصف الوظيفة
الأدوار والمسؤوليات
يتولى استشاري شهادات الأمن السيبراني الأول قيادة وتنفيذ أنشطة تقييم الشهادات لتقييم امتثال المؤسسات للمعايير الوطنية والدولية للأمن السيبراني وأمن المعلومات. يضمن الدور قرارات شهادات عادلة ومتسقة وموضوعية مع الإشراف على فرق التقييم، وإدارة حالات الشهادات، والحفاظ على سلامة عملية الشهادة. كما يساهم في تطوير منهجيات وأدوات وأطر شهادات متوافقة مع المتطلبات التنظيمية والاعتماد. المسؤوليات الأساسية: تقديم خدمات الشهادات؛ يتولى مقيم الأمن information / الأمن السيبراني اليومي مراجعة وتقييم الطلبات؛ إدارة الفريق وتوزيع الحالات؛ الاحتفاظ بسجلات مفصلة ومنظمة لعملية الشهادة، وضمان الدقة والكمال؛ التأكد من الحفاظ على أعلى معايير الكفاءة والحيادية وتحقيق الاتساق عبر أنشطة الشهادات؛ مراجعة امتثال المعلومات/الأمن السيبراني للمنظمات المختلفة مع المعايير الوطنية والدولية وأفضل الممارسات في الأمن السيبراني/أمن المعلومات؛ تقييم تصميم وفاعلية ضوابط أمن المعلومات/الأمن السيبراني التشغيلية؛ توثيق الملاحظات/النتائج بطريقة يسهل فهمها وتتبعها وتستند إلى أدلة موضوعية؛ تطوير والحفاظ على إجراءات الشهادات والأدوات المطلوبة القائمة على إطار الامتثال الوطني لأمن المعلومات؛ الحفاظ على الحياد والسرية والإفصاح عن أي تضارب محتمل في المصالح قد يعرّض التقييم للانحياز كما هو مطلوب؛ تطوير آليات وأدوات القياس والامتثال لمراقبة التحسينات؛ تقديم توصية بشأن نتيجة التقييم؛ مواكبة أحدث التطورات في الأمن، والتهديدات الناشئة، والتقنية المتطورة لضمان بقاء عملية الشهادة ذات صلة؛ إجراء تقييمات مخاطر سيبرانية وكشوف تدقيق في الأمن المعلوماتي بشكل فعال وكفء؛ تطوير وتقديم تدريب داخلي وورش عمل لتعزيز وبناء قدرات الأمن السيبراني والامتثال والضمان والتدقيق داخل الفريق؛ إدارة التواصل الخارجي أثناء التدقيق: من الطلب حتى إصدار القرار.
المرشح المطلوب
- درجة البكالوريوس في تكنولوجيا المعلومات، أنظمة معلومات حاسوبية، الأمن السيبراني، أو ما يعادلها.
- خبرة مهنية لا تقل عن 20 عامًا في تكنولوجيا المعلومات/أمن المعلومات/الأمن السيبراني.
- خبرة لا تقل عن 4 سنوات كمراجِع أول، مقيم، أو في أدوار إدارة مخاطر/أمن سيبراني.
- الخبرة في الاستشارات الأمنية السيبرانية أو التنفيذ المتوافق مع المعايير الوطنية/الدولية ميزة.
- الشهادات (مفضل): CISSP، CISA، CISM، CRISC، ISO 27001 Lead Auditor/Implementer، أو ما يعادلها.
- المهارات التقنية: معرفة قوية بتقييم مخاطر الأمن السيبراني ومنهجيات التدقيق. خبرة في أطر ومعايير الأمن (ISO 27001، NIST، NIA، CSF، إلخ). فهم معايير الشهادة والاعتماد (ISO/IEC 17021، 17024، 17065، 17006، ISO 19011، ISA، ITAF). خبرة عملية في تدقيق وضمان أمن المعلومات. وعي قوي بالتهديدات والتقنيات السيبرانية المتطورة.
- المهارات الأساسية: مهارات تحليلية وتقييمية وحل مشكلات ممتازة. مهارات كتابة تقارير تقنية وتوثيق قوية. القدرة على تفسير أطر الامتثال ومعايير الشهادة بشكل موضوعي. مهارات تواصل وعرض ممتازة باللغة الإنجليزية (كتابة وتحدثًا). خبرة في تقديم التدريب وورش العمل عبر القطاعين الحكومي والخاص.
- الكفاءات السلوكية: دقة عالية في التفاصيل والقدرة على العمل تحت الضغط وبمواعيد نهائية ضيقة. مهارات تفاعل ومتابعة مع أصحاب المصلحة قوية. القدرة على العمل بشكل مستقل بمستوى عالٍ من الاحترافية والنزاهة. القدرة على إدارة مهام متعددة وفرق عابرة للوظائف بكفاءة. الالتزام بالحياد والسرية وممارسات التقييم الأخلاقية.
- اللغة: الإنجليزية (مطلوب)
- التوفر: في أقرب وقت ممكن
- مدة العقد 12 شهرًا، مع إمكانية التمديد وفقًا لاحتياجات القسم.
Job Description
Roles & Responsibilities
The Senior Cybersecurity Certification Consultant is responsible for leading and executing certification assessment activities to evaluate organizations compliance with national and international cybersecurity and information security standards. The role ensures fair, consistent, and objective certification decisions while overseeing assessment teams, managing certification cases, and maintaining the integrity of the certification process. It also contributes to developing certification methodologies, tools, and frameworks aligned with regulatory and accreditation requirements. Key Responsibilities : Delivery of certification services Senior Information Security / Cyber Security Assessor is responsible for the day to day certification application assessment review, validation Manage the team and assign the cases Maintain detailed and organize records of the certification process, ensuring accuracy and completeness Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across certification activities Review different organizations Information Security / Cyber Security compliance to national or international standards and best practices in Information Security / Cyber Security Evaluate the design and operating effectiveness of Information Security / Cyber Security controls Document observations/findings in such a manner that they are clearly understandable and traceable and are based on objective evidence Develop and maintain certification procedures and required tools based on National Information Security Compliance framework Maintain impartiality, confidentiality and to declare any potential conflicts of interest that might jeopardize an objective assessment as required Develop measurement and compliance mechanisms & tools to monitor improvements Provide a recommendation on the outcome of an assessment Stay up to date with the latest developments in security, emerging threats, and evolving technology to ensure the certification process remains relevant Conduct efficient and effective Cyber Security risk assessments and Information Security / Cyber Security audit procedures Develop and deliver internal training and workshop to upscale and build Information Security / Cyber Security, compliance, assurance and audit capabilities within the team. Manage the external communication during the audit: from the application till the issue of decision
Desired Candidate Profile
- Bachelor s degree in Information Technology, Computer Information Systems, Cyber Security, or equivalent.
- Minimum 20 years of professional experience in IT / Information Security / Cyber Security.
- At least 4 years of experience as a senior auditor, assessor, or in cybersecurity risk/security management roles.
- Experience in cybersecurity consulting or implementation aligned with national/international standards is an advantage.
- Certifications (Preferred) CISSP, CISA, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or equivalent certifications.
- Technical Skills Strong knowledge of cybersecurity risk assessment and audit methodologies. Expertise in security frameworks and standards (ISO 27001, NIST, NIA, CSF, etc.). Understanding of certification and accreditation standards (ISO/IEC 17021, 17024, 17065, 17006, ISO 19011, ISA, ITAF). Hands-on experience in information security auditing and assurance. Strong awareness of evolving cybersecurity threats and technologies.
- Core Skills Excellent analytical, evaluation, and problem-solving abilities. Strong technical report writing and documentation skills. Ability to interpret compliance frameworks and certification criteria objectively. Excellent communication and presentation skills in English (written and verbal). Experience delivering training and workshops across government and private sectors.
- Behavioral Competencies High attention to detail and ability to work under pressure and tight deadlines. Strong interpersonal and stakeholder management skills. Ability to work independently with high levels of professionalism and integrity. Capability to manage multiple assignments and cross-functional teams effectively. Commitment to impartiality, confidentiality, and ethical assessment practices.
- Language: English (required)
- Availability: As soon as possible
- The contract duration is 12 months, with the possibility of extension based on departmental requirements.