The Senior Cybersecurity Certification & QMS Specialist is responsible for managing and continuously improving the quality management system (QMS) that governs cybersecurity certification schemes. The role ensures compliance with international standards and regulatory requirements while enhancing the efficiency, consistency, and reliability of certification processes.
This position combines expertise in cybersecurity certification with strong quality assurance and audit capabilities, including conducting internal audits, managing documentation, and driving corrective and preventive actions. The specialist works closely with technical teams and stakeholders to maintain high standards of certification, support governance activities, and align processes with evolving industry frameworks and best practices.
Key Responsibilities:
Planning, implement, monitoring, improvement and maintenance of quality management system for the different schemes in NISCF.
Ensure that the internal process complies with relevant national and international regulations, guidelines.
Review the quality of technical content.
Continuously assess and improve the efficiency and effectiveness of the certification process.
Oversee the documentation and record-keeping processes to ensure that all records are accurate, complete, and readily accessible. Ensure that the QMS documentation is up-to-date.
Plan and conduct internal audits and reviews of the certification process to verify compliance with established procedures and to identify opportunities for improvement.
Plan and organize scheme management review meetings.
Review the quality of scheme documents i.e. manuals, policies, procedure, forms, templates etc.
Implement corrective and preventive actions to address non-conformities and improve the QMS. Ensure that corrective actions are taken when issues are identified.
Monitoring the changes of requirements (i.e. International Standards (ISO17021, 17024, 17065, 17025, 27006, 9001), National Standards)
Assisting with the development of policies, standards, procedures and guidance based on audit findings
Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across all evaluation and certification activities;
Possess a deep understanding of Common Criteria standards, Protection Profiles, Security Targets, Evaluation Assurance Levels (EALs), and related documentation
Provide guidance and mentorship to CB team members Certifiers and evaluators, ensuring their understanding of the certification process and helping them with complex evaluations.
Assisting with the development of policies, standards, procedures and guidelines.
Make recommendations regarding certification at specific Evaluation Assurance Levels (EALs) based on extensive evaluation expertise and knowledge of the certification process.
Stay up-to-date with the latest developments in security, emerging threats, and evolving technology to ensure the certification process remains relevant.
Desired Candidate Profile
A university Master’s degree-level qualification in IT, information security or a related field. ideally with a focus on security domains
Certification from a recognized Common Criteria certification body and previous experience as a Certifier is desired
IT Security Overview Training and certification
Common Criteria for IT Security Evaluation Training and certification
Minimum10 years experience
5 minimum years of work experience as a Senior IT / Information Security / Cyber Security Auditor and/or Risk Management and/or Cyber Security/Information Security Management.
Proficiency in Arabic and English (spoken and written) is preferred
Other Required Qualifications:
General:
Analytical and problem-solving skills
Proven experience in IT and Information Security Assessment
Common Criteria for IT Security Evaluation Training
Experience in Risk Assessment and management.
Should have hands on experience in information security
Understanding of ISO27001 certification audit requirements
Excellent communication, documentation, and report-writing skills.
In-depth knowledge of security testing methodologies and tools.
Have analytical & assessment experience of formal schemes and can assess a situation in a fair and objective manner in order to arrive at a firm conclusion.
Have training, workshops planning and delivery experience across Government & private sector
Technical:
Proven experience in IT, Information Security and Quality management Audit.
Should have hands on experience in information security, cyber security & Quality management systems.
Experience in Risk management and GAP analysis.
Experience briefing senior executive staff
Experience in Risk Assessment and management including audit methodologies and risk assessment methodologies
Behavioural:
Ability to multitask and work effectively with multiple project teams, sponsors, and customers.
Ability to pay close attention to detail, meet deadlines and work under pressure.
Interpersonal skills
Work autonomously with a high degree of enthusiasm
Specific:
Excellent technical report writing skills.
Have capabilities to understand and interpret the Certification Criteria (ISO/ IEC 17021, ISO/ IEC 17024, ISO/ IEC 27006 and ISO/IEC 17065).
Knowledge of auditing and information assurance standards like ISA, ITAF, ISO17021, ISO19011.
Proficiency in security frameworks and standards like, ISO27001, NIA, CSF Q2022.
Familiarity with third-party audit, Certification and Information Security / Cyber Security audits.
Proven, hands on, experience in Information Security Audit or Information Security Management
المسؤول عن شهادة الأمن السيبراني وتقييم نظام إدارة الجودة (QMS) العليا هو إدارة وتحسين مستمر لنظام إدارة الجودة الذي يحكم مخططات شهادات الأمن السيبراني. يضمن الامتثال للمعايير الدولية والمتطلبات التنظيمية مع تعزيز الكفاءة والتناسق والموثوقية لعمليات الشهادة.
يجمع هذا المنصب بين الخبرة في شهادات الأمن السيبراني مع قدرات ضمان الجودة والتدقيق القوية، بما في ذلك إجراء التدقيقات الداخلية، إدارة الوثائق، وقيادة الإجراءات التصحيحية والوقائية. يعمل الأخصائي بشكل وثيق مع الفرق الفنية وأصحاب المصلحة للحفاظ على معايير عالية لشهادات، دعم أنشطة الحوكمة، وت aligns العمليات مع أطر الصناعة المتطورة وأفضل الممارسات.
المسؤوليات الأساسية:
التخطيط، والتنفيذ، والمراقبة، والتحسين والصيانة لنظام إدارة الجودة للمخططات المختلفة في NISCF.
ضمان امتثال العمليات الداخلية للوائح الوطنية والدولية ذات الصلة، والإرشادات.
مراجعة جودة المحتوى الفني.
تقييم مستمر وتحسين كفاءة وفاعلية عملية الشهادة.
الإشراف على عمليات الوثائق والسجلات لضمان أن جميع السجلات دقيقة وكاملة ومتاحة بسهولة. التأكد من أن وثائق QMS حديثة.
التخطيط وإجراء التدقيقات والمراجعات الداخلية لعملية الشهادة للتحقق من الالتزام بالإجراءات المعتمدة ولتحديد فرص التحسين.
التخطيط وتنظيم اجتماعات مراجعة إدارة المخطط.
مراجعة جودة وثائق المخطط أي الكتيبات والسياسات والإجراءات والنماذج والقوالب إلخ.
تنفيذ إجراءات تصحيحية ووقائية لمعالجة عدم المطابقة وتحسين QMS. التأكد من اتخاذ إجراءات تصحيحية عند تحديد المشاكل.
مراقبة تغيّر متطلبات المعايير (أي المعايير الدولية ISO17021، 17024، 17065، 17025، 27006، 9001)، والمعايير الوطنية)
المساعدة في تطوير السياسات والمعايير والإجراءات والإرشادات بناءً على نتائج التدقيق
ضمان الحفاظ على أعلى معايير الكفاءة والحياد، وتحقيق الاتساق عبر جميع أنشطة التقييم والشهادة؛
امتلاك فهم عميق لمعايير المعايير الشائعة وملفات الحماية وTargets الأمنية ومستويات ضمان التقييم (EALs) والوثائق ذات الصلة
تقديم الإرشاد والتوجيه لأعضاء فريق CB والمصدّقين والمقيّمين، وضمان فهمهم لعملية الشهادة ومساعدتهم في التقييمات المعقدة.
المساعدة في تطوير السياسات والمعايير والإجراءات والإرشادات.
تقديم توصيات بشأن الشهادة عند مستويات ضمان التقييم المحددة (EALs) بناءً على خبرة تقييم موسعة ومعرفة بعملية الشهادة.
الاطّلاع المستمر على آخر التطورات في الأمن والتهديدات والتقنيات المتطورة لضمان بقاء عملية الشهادة ملائمة.
ملف المرشح المرجو
شهادة ماجستير في تكنولوجيا المعلومات أو أمن المعلومات أو مجال ذي صلة، مع تركيز على مجالات الأمن
شهادة من جهة اعتماد معيارية معترف بها وإثبات سابق كمصدّق مطلوب
تدريب وشهادة في نظرة عامة عن أمان تكنولوجيا المعلومات
تدريب وشهادة في معيار Common Criteria لتقييم أمان تكنولوجيا المعلومات
خبرة لا تقل عن 10 سنوات
5 سنوات على الأقل من الخبرة العملية كمفتش أقدم في تكنولوجيا المعلومات / أمن المعلومات / الأمن السيبراني و/أو إدارة المخاطر و/أو إدارة الأمن السيبراني/أمن المعلومات.
إجادة العربية والإنجليزية (لقطية ومكتوبة) مفضلة
المؤهلات الأخرى المطلوبة:
عام:
مهارات تحليلية وحل المشاكل
خبرة مثبتة في تقييم تكنولوجيا المعلومات وأمن المعلومات
تدريب في Common Criteria لتقييم أمان تكنولوجيا المعلومات
خبرة في تقييم وإدارة المخاطر.
يجب أن يمتلك خبرة عملية في أمن المعلومات
فهم لمتطلبات تدقيق شهادة ISO27001
مهارات تواصل وتنظيم وتوثيق وتقارير ممتازة.
معرفة عميقة بمنهجيات وأدوات اختبار الأمان.
امتلاك خبرة تحليلية وتقييمية لمخططات رسمية والقدرة على تقييم وضع ما بشكل عادل وموضوعي للوصول إلى استنتاج حاسم.
وجود تدريب وورش عمل مخطط وتقديم عبر الحكومة والقطاع الخاص
تقني:
خبرة مثبتة في تدقيق تكنولوجيا المعلومات وأمن المعلومات وإدارة الجودة.
يجب أن يمتلك خبرة عملية في أمن المعلومات، الأمن السيبراني وأنظمة إدارة الجودة.
خبرة في إدارة المخاطر وتحليل الفجوات.
الخبرة في توجيه كبار موظفي التنفيذيين
خبرة في تقييم وإدارة المخاطر بما في ذلك منهجيات التدقيق ومنهجيات تقييم المخاطر
سلوكي:
القدرة على تعدد المهام والعمل بفاعلية مع فرق مشاريع متعددة، ورعاة، والعملاء.
القدرة على الانتباه للتفاصيل والالتزام بالمواعيد والضغط العالي.
مهارات التعامل مع الآخرين
العمل باستقلالية بحرارة عالية
محدد:
مهارات كتابة تقارير تقنية ممتازة.
القدرات على فهم وتفسير معايير الاعتماد (ISO/IEC 17021، ISO/IEC 17024، ISO/IEC 27006 و ISO/IEC 17065).
معرفة بمعايير التدقيق وضمان المعلومات مثل ISA، ITAF، ISO17021، ISO19011.
إتقان أطر ومعايير الأمن مثل ISO27001، NIA، CSF Q2022.
المألوف مع تدقيق الطرف الثالث، والشهادات وتدقيق الأمن المعلوماتي / الأمن السيبراني.
خبرة مثبتة وعملية في تدقيق أمن المعلومات أو إدارة أمن المعلومات