وظائف مراقب كاميرات في قطر
٧٨٠٥ وظائف شاغرة
We currently have an opportunity for a Senior ICS Security Engineer role. This position is based in Qatar onshore.<br> <br>Duration Two (2) year initial contract with a possibility of extension.<br>Work location Onshore (Ras Laffan/Doha HQ)<br> <br>Key Job Accountabilities<br>Implements Industrial Control Systems (ICS) Security engineering, supports the ICS Security sustainment activities, provides project support and participates in ICS Security audits, risk assessments, technology evaluations, & self-assessments, advises ICS Custodians and ICSE Technicians to ensure ICS Security maintenance performance is achieved, and supports in periodic reviews of ICS security equipment strategies, ICS Security Policy and Design Specifications.<br>Support the implementation of ICS Security engineering specifications and related procedures, work practices, , manuals, and development of equipment strategies for new projects. Identify limitations of existing systems, recommend best practices and upgrades.<br>Review the design such as System Architecture, Network Architecture, Functional Design Specifications, Detailed Design Specifications, Interface Agreements and ensure compliance to ICS Security engineering specifications.<br>Participate, review the ICS risk assessments, technology evaluations, and deviation requests, DRP (Disaster Recovery Plan) simulations.<br>Validate the system built through FAT, SAT for the department. <br>Coordinate and ensure deliverables as per the Operational Readiness Procedure to ensure smooth handover to ICS Security Operations.<br>Participate in ICS Security incident investigations or Root Cause Failure Analysis, continuous improvement and productivity enhancement initiatives.<br>Serve as focal point to ICS Security Custodians and ICSE Technicians to ensure alignment with the ICS Security Policy & Specifications.<br>Provide technical support for clarifying, following and implementing ICS Security Policy requirements across engineering sections, development teams, expansion teams, and operations.<br>Support in planning and conducting periodic ICS Security self-assessments to evaluate compliance to the ICS Security Policy.<br>Participate in life cycle management review of ICS in scope inventory and update inventory periodically.<br> <br>Qualifications<br>Bachelor’s degree in Engineering (Instrumentation & Control, Electrical, Electronic, Computer) or Computer Science. <br> <br>Knowledge and Experience<br>6 years’ experience in Oil and Gas Industry operations, technical, engineering with ICS Security Experience.<br>Experience of implementing security controls within an OT environment.<br>Understanding of different Industrial Control Systems environments. <br>ICS System Security Experience, Knowledge of Networking, Security tools , Knowledge of ICS Security monitoring like IDS/IPS, SIEM etc.,<br> <br>Technical and Business Skills <br>Proficient in written and spoken English.<br>Computer Literate.<br>Excellent interpersonal skills, highly proficient in handling personnel, administrative, organizational and logistical issues. <br>Solve issues associated with ICS Security design, sustainment.<br>Lead ownership of issues related to ICS Security to support and drive continuous improvement.<br> <br><br>People are our business worldwide<br> <br>Orion Group was founded in 1987 and is now one of the largest, independent, international recruitment companies. We have a network of 200 employees working from 24 offices, delivering a range of services – Talent Acquisition, Recruitment Outsourcing Services, Retained Search, Global Workforce Solutions, Completions & Commissioning and Materials Management – across 68 countries. As a global leader in workforce solutions, we recruit personnel across the Engineering & Technical, Office & Commercial, Scientific and Skilled Trades disciplines, for sectors including Oil & Gas, Life Science, Power & Utilities, Constructions & Infrastructure, Manufacturing and Renewables.
Job Overview<br><br>An experienced HSE Officer is required to support daily Health, Safety and Environmental activities across facilities management operations. The successful candidate will conduct inspections, monitor compliance, support incident investigations and promote safe working practices.<br><br>Key Responsibilities<br><br>Conduct daily site inspections. Perform hazard identification and risk assessments. Monitor Permit-to-Work activities. Ensure PPE compliance. Deliver Toolbox Talks. Conduct HSE inductions. Support emergency response activities. Investigate incidents and near misses. Maintain HSE documentation and records. Monitor contractor compliance. Report HSE observations and corrective actions. Promote continual improvement in HSE performance.<br><br>Minimum Qualifications<br><br>Diploma, Certificate or Technical Qualification in:Occupational Health & Safety Environmental Management Engineering Science Related discipline<br>Mandatory Certifications<br><br>NEBOSH International General Certificate IOSH Managing Safely (or equivalent)<br><br>Preferred Training<br><br>First Aid Fire Safety Risk Assessment Toolbox Talk Delivery Work Permit Control Incident Reporting<br><br>Experience<br><br>Minimum 3–5 years' relevant HSE experience. Experience within:Facilities Management Cleaning Services Pest Control Waste Management Maintenance Logistics Warehousing Construction Port Operations Similar operational environments<br>Required Competencies<br><br>Site HSE Inspections Hazard Identification Permit-to-Work Monitoring Contractor Supervision PPE Compliance Emergency Response Incident & Near-Miss Reporting HSE Documentation Strong communication and teamwork skills
<p>من المتوقع أن يقدم
<strong>المقاول CSEA</strong> دعمًا عمليًا لقسم هندسة الأمن السيبراني والهندسة المعمارية من خلال المساهمة في أنشطة الأمن المعماري، والمراجعات الأمنية الفنية، وتنفيذ الضوابط، وتقييمات المخاطر وخدمات الاستشارات عبر أنظمة المؤسسة والبُنى التحتية وبيئات السحابة والتطبيقات.</p><p>من المتوقع أن يمتلك المقاول:</p><ul><li><p>خبرة عملية في منهجيات هندسة الأمن المؤسسي والتقنيات الأمنية الحديثة، بما في ذلك إدارة الهوية والوصول IAM، ونظام معلومات الأمن SIEM، ونُظم التهديد والاستجابة EDR/XDR، وجدار الحماية التطبيقي WAF، وSASE، والنهج بدون ثقة، وأمن السحابة، وأدوات أتمتة الأمن.</p></li><li><p>معرفة قوية بأمن بنية تكنولوجيا المعلومات التحتية، بما في ذلك أمان الشبكات، وأمن السحابة، وأمن نقاط النهاية، وأمن الهوية، ومبادئ تصميم الهندسة المعمارية الآمنة.</p></li><li><p>معرفة قوية بأمن التطبيقات، بما في ذلك دورة حياة البرمجيات الآمنة SDLC، وDevSecOps، وأمن واجهات البرمجة API، وممارسات الترميز الآمن، ونمذجة تهديدات التطبيقات.</p></li><li><p>خبرة في تنفيذ والتحقق والمراجعة للضوابط الأمنية عبر بنية تحتية لتكنولوجيا المعلومات ومنصات السحابة مثل AWS وAzure وGCP، وتطبيقات المؤسسة.</p></li><li><p>خبرة في تطوير وصيانة وتعزيز مكتبات الضوابط الأمنية، وأنماط الأمان، والخلفيات، ومعايير الهندسة المعمارية، مع ضمان تكاملها في أنشطة الهندسة المعمارية الأمنية.</p></li><li><p>فهم قوي لمعايير الأمن السيبراني والقوانين والأطر، بما في ذلك NIST وISO/IEC 27001 وCIS Controls وGDPR وPCI-DSS ومتطلبات الامتثال التنظيمية أو التنظيمية الأخرى.</p></li><li><p>فهم قوي لأفضل ممارسات الأمن السيبراني، بما في ذلك هندسة الشبكات الآمنة، وحماية نقاط النهاية، وإدارة الهوية والوصول، وأمن السحابة، وDevSecOps، وتصميم الدفاع في عمق.</p></li><li><p>خبرة في إجراء مراجعات تصميم الأمن وتقييمات المعمارية ونمذجة التهديدات وتقييمات المخاطر الفنية وتقييمات الفجوات الأمنية.</p></li><li><p>القدرة على دعم وحدات العمل وفرق المشاريع وفرق IT وأصحاب المصلحة الأمنيين في اختيار وتصميم وتنفيذ أنظمة معلومات وتكنولوجيات آمنة.</p></li><li><p>خبرة في أتمتة الأمن والبرمجة باستخدام أدوات ولغات مثل Python وPowerShell وBash وTerraform وAnsible أو تقنيات مشابهة.</p></li><li><p>القدرة على دعم التحقيقات الأمنية وأنشطة الاستجابة للحوادث والتحليل الجنائي وتحليل السبب الجذري وتوصيات التحسين بعد الحادث عند الحاجة.</p></li><li><p>خبرة في تقديم الاستشارة الفنية والدعم الاستشاري في مشاريع ومبادرات ومهام CSEA كما يطلبه رئيس قسم CSEA.</p></li><li><p>قدرة ممتازة على ترجمة مفاهيم الأمن السيبراني الفنية والمخاطر والتوصيات إلى لغة أعمال واضحة لأصحاب المصلحة تقنيين وغير تقنيين.</p></li><li><p>خبرة في المشاركة في لجان الأمن السيبراني ولاجتماعات العمل الفنية وBoards مراجعة المعمارية واجتماعات المشاريع والمناقشات الأمنية عبر الوظائف.</p></li><li><p>مهارات رفع المشكلات وتحليلية واتخاذ القرار قوية، مع القدرة على تقييم بيئات تقنية معقدة وتوصية حلول أمنية عملية.</p></li><li><p>القدرة على العمل بشكل مستقل مع التعاون الفعّال مع مهندسي الأمن المعماريين، ومحللي SOC، وفرق IT وتطبيقات والمديرين المسؤولين عن المشاريع وأصحاب المصلحة من الأعمال.</p></li><li><p>مهارات تواصل شفهية وكتابية ممتازة، مع القدرة على توثيق نتائج الأمن والمعمارية والتقييمات والمخاطر وإجراءات الإصلاح بشكل واضح ومهني.</p></li><li><p>القدرة على توجيه ودعم أعضاء فريق CSEA حسب الحاجة من خلال نقل المعرفة ومشاركة الخبرة الفنية والمساهمة في تطوير قدرات الأمن السيبراني والهندسة المعمارية الداخلية.</p></li></ul><p><strong>النتيجة الرئيسية</strong><br></p><p>قد يُتوقع من المقاول دعم أو تسليم:</p><ul><li><p>مراجعات معمارية الأمن</p></li><li><p>تقارير مراجعة التصميم الأمني</p></li><li><p>نماذج التهديد وتقييمات المخاطر</p></li><li><p>خرائط الضوابط الأمنية والتوصيات</p></li><li><p>نماذج معمارية وخلفيات ومعايير</p></li><li><p>تقارير الاستشارة الفنية الأمنية</p></li><li><p>توصيات التصميم الآمن للبنية التحتية، والسحابة، والتطبيقات</p></li><li><p>خرائط طريق تحسين الأمن</p></li><li><p>دعم الاستجابة للحوادث والتحقيقات والتحليل الفني</p></li><li><p>جلسات نقل المعرفة لأعضاء CSEA</p></li></ul><p><br></p><p><strong>الملف المرشح المطلوب</strong></p><p><strong>المتطلبات</strong></p><p><strong>التعليم:<br></strong></p><ul><li><p>درجة البكالوريوس في مجال تقني مثل الأمن السيبراني، علوم الحاسوب، الهندسة الحاسوبية، أمن المعلومات، تقنية المعلومات، أو تخصص ذي صلة. ويفضل درجة أعلى أو شهادات مهنية ذات صلة.</p></li></ul><p>الخبرة:</p><ul><li><p>حد أدنى 10 سنوات من الخبرة ذات الصلة في الأمن السيبراني، أمن المعلومات، هندسة الأمن، أو أمن بنية تكنولوجيا المعلومات، مع خبرة عملية لا تقل عن 3 سنوات في هندسة الأمن، والهندسة الأمنية، أو هندسة الأمن المؤسسي.</p></li></ul><p>الشهادات المفضلة:</p><ul><li><p>يفضل شهادات CISSP وCISM وSABSA وTOGAF.</p></li><li><p>يفضل شهادات أمن السحابة مثل CCSP وAzure Security Engineer أو AWS Security Specialty.</p></li><li><p>يفضل شهادات الأمن السيبراني مثل GCIH وGCIA وGSEC أو Security+.</p></li><li><p>شهادات أخرى ذات صلة بالأمن السيبراني أو أمان السحابة أو الهندسة المعمارية قد تعتبر.</p></li></ul><p><strong><em>الطلاقة في اللغتين الإنجليزية والعربية مطلوبة.</em></strong></p>
Primary Purpose Of The Job<br><br>Governance and execution of the Information Security Management System (ISMS) including developing policies,standards and procedures required for the corporate information security in both an Information technology (IT) and Operational Technology (OT) capacity. Define required information security policies, standards and procedures related to their areas of operation as well as raising awareness of those polices, standards and procedures. Ensure adequate an effective IT controls exist to meet applicable current and future security compliance requirements. --Conduct compliance and operational maturity assessments to ensure optimal operation of the information and operational technology environments under the guidelines of the ISMS. Develop reporting Metrics, dashboards and evidences of compliance activities. Coordinate with IT stakeholders, project managers, and business owners to facilitate vendor risk assessments, due diligence review and security requirements definition. Maintain third-party assessment documentation.<br><br>Stay updated on the latest security trends, emerging threats and best practices to continuously improve the overall security posture.<br><br>Collaborate with cross-functional teams, including AI and digital functions, to ensure alignment of security governance with emerging technologies and applied intelligence initiatives. Carry out other Security related activities as assigned by team Lead.<br><br>Required Experience And Skills<br><br> Bachelor degree in information security, computer science, or engineering. Professional certifications in information security management and standards compliance (e.g., CISSP, CISM, CRISC, GIAC, ISO27001, etc.) and experience with control frameworks (e.g., NIST Cybersecurity Control Framework)<br><br>Educational Qualifications<br><br> 10+ years of relevant professional experience. Experience with large ICS & ICT environments in the Energy sector, preferably in Oil & Gas. Experience with and understanding of customized information security management systems. Experience in defining Governance, Risk, and Compliance (GRC) processes and leveraging industry-standard GRC tools and products. Knowledge of information security capabilities and requirements analysis. Knowledge of relevant state laws, industry regulations, and security standards. Excellent written, verbal and presentation communication skills
About the Role:We are seeking a skilled Application Security Specialist to strengthen the security of applications across their full lifecycle. You will work closely with development, Dev Ops, and QA teams to ensure secure design, development, and deployment of web, mobile, API, and thick-client applications. The role focuses on identifying vulnerabilities, performing security testing, enabling secure coding practices, and integrating security into CI/CD pipelines as part of a Dev Sec Ops approach.<br>Key Responsibilities:Conduct penetration testing across web, mobile, API, and thick-client applications. Perform automated security scanning (SAST, DAST, SCA) to identify vulnerabilities in code, configurations, and dependencies. Carry out threat modelling during the design phase to identify risks and define mitigation strategies. Perform secure code reviews and provide developer-friendly remediation guidance. Integrate security controls into CI/CD pipelines to enable Dev Sec Ops practices. Develop and deliver secure coding training and awareness sessions for development teams. Evaluate and recommend application security tools and technologies. Prepare and maintain documentation for security assessments, vulnerabilities, and application security standards.<br>Required Skills & Experience:3+ years of experience in application security, secure software development, or penetration testing. Strong hands-on experience with web, mobile, API, and application security testing. Proficiency with Burp Suite (required) and familiarity with tools such as Snyk, HCL App Scan, Fortify, and Postman. Strong understanding of secure coding practices and at least one programming language. Experience with Dev Sec Ops and CI/CD pipeline integration. Strong knowledge of OWASP Top 10, ASVS, MASVS, WSTG, and MSTG. Understanding of vulnerability classes, exploitation techniques, and remediation approaches. Strong analytical, reporting, and communication skills.<br>Qualifications:Bachelor’s degree in Computer Science, Information Security, or related field.<br>Preferred Certifications:Off Sec (OSWA, OSWE)e Learn Security (e WPT, e WPTX) GIAC / SANS (SEC542, GWAPT) Other relevant application security certifications<br>Additional Advantage:Knowledge of Qatar National Information Assurance (NIA) framework.
Primary Purpose Of The Job<br><br>Governance and execution of the Information Security Management System (ISMS) including developing policies,standards and procedures required for the corporate information security in both an Information technology (IT) and Operational Technology (OT) capacity. Define required information security policies, standards and procedures related to their areas of operation as well as raising awareness of those polices, standards and procedures. Ensure adequate an effective IT controls exist to meet applicable current and future security compliance requirements. --Conduct compliance and operational maturity assessments to ensure optimal operation of the information and operational technology environments under the guidelines of the ISMS. Develop reporting Metrics, dashboards and evidences of compliance activities. Coordinate with IT stakeholders, project managers, and business owners to facilitate vendor risk assessments, due diligence review and security requirements definition. Maintain third-party assessment documentation.<br><br>Stay updated on the latest security trends, emerging threats and best practices to continuously improve the overall security posture.<br><br>Collaborate with cross-functional teams, including AI and digital functions, to ensure alignment of security governance with emerging technologies and applied intelligence initiatives. Carry out other Security related activities as assigned by team Lead.<br><br>Required Experience And Skills<br><br> Bachelor degree in information security, computer science, or engineering. Professional certifications in information security management and standards compliance (e.g., CISSP, CISM, CRISC, GIAC, ISO27001, etc.) and experience with control frameworks (e.g., NIST Cybersecurity Control Framework)<br><br>Educational Qualifications<br><br> 10+ years of relevant professional experience. Experience with large ICS & ICT environments in the Energy sector, preferably in Oil & Gas. Experience with and understanding of customized information security management systems. Experience in defining Governance, Risk, and Compliance (GRC) processes and leveraging industry-standard GRC tools and products. Knowledge of information security capabilities and requirements analysis. Knowledge of relevant state laws, industry regulations, and security standards. Excellent written, verbal and presentation communication skills
Primary Purpose Of The Job<br><br>Governance and execution of the Information Security Management System (ISMS) including developing policies,standards and procedures required for the corporate information security in both an Information technology (IT) and Operational Technology (OT) capacity. Define required information security policies, standards and procedures related to their areas of operation as well as raising awareness of those polices, standards and procedures. Ensure adequate an effective IT controls exist to meet applicable current and future security compliance requirements. --Conduct compliance and operational maturity assessments to ensure optimal operation of the information and operational technology environments under the guidelines of the ISMS. Develop reporting Metrics, dashboards and evidences of compliance activities. Coordinate with IT stakeholders, project managers, and business owners to facilitate vendor risk assessments, due diligence review and security requirements definition. Maintain third-party assessment documentation.<br><br>Stay updated on the latest security trends, emerging threats and best practices to continuously improve the overall security posture.<br><br>Collaborate with cross-functional teams, including AI and digital functions, to ensure alignment of security governance with emerging technologies and applied intelligence initiatives. Carry out other Security related activities as assigned by team Lead.<br><br>Required Experience And Skills<br><br> Bachelor degree in information security, computer science, or engineering. Professional certifications in information security management and standards compliance (e.g., CISSP, CISM, CRISC, GIAC, ISO27001, etc.) and experience with control frameworks (e.g., NIST Cybersecurity Control Framework)<br><br>Educational Qualifications<br><br> 10+ years of relevant professional experience. Experience with large ICS & ICT environments in the Energy sector, preferably in Oil & Gas. Experience with and understanding of customized information security management systems. Experience in defining Governance, Risk, and Compliance (GRC) processes and leveraging industry-standard GRC tools and products. Knowledge of information security capabilities and requirements analysis. Knowledge of relevant state laws, industry regulations, and security standards. Excellent written, verbal and presentation communication skills
About Accenture<br><br>Accenture helps the world’s leading enterprises reinvent by building their digital core and unleashing the power of AI to create value at speed for organizations across industries. Our strategy is to be the reinvention partner of choice for our clients and lead in the safe, widespread adoption of AI, and to be the most client-focused, AI-enabled, great place to work in the world. We bring together the talent of our approximately 786,000 people with proprietary assets and platforms, deep process and industry expertise, and leading ecosystem relationships to deliver end-to-end solutions and measurable outcomes at scale. Through our Reinvention Services, we offer broad expertise across Cybersecurity, Digital Core, Finance, Industry and Enterprise, Song, Supply Chain and Engineering, and Talent, with advanced capabilities in AI and Data, Industry and Process, and Technology. We serve approximately 9,000 clients and generated approximately $70 billion in FY25 revenue. Visit us at accenture.com.<br><br>About Accenture Security<br><br>Accenture Security helps organizations prepare for, prevent, detect, respond to, and recover from cyber threats. We bring together deep industry knowledge, advanced security capabilities, and cutting-edge technology to help our clients protect their most critical assets, comply with regulatory requirements, and build resilient security programs.<br><br>Role Overview<br><br>We are looking for a Cloud Security Specialist to strengthen the security posture of our cloud environments, with a strong focus on Google Cloud Platform (GCP) and exposure to AWS and Azure. You will work closely with engineering, Dev Ops, and security teams to design, implement, and operate secure cloud‑native solutions while ensuring compliance with industry and regulatory standards.<br><br>Key Functions<br><br><br>Design and implement security controls across multi‑cloud environments, with primary focus on GCP<br>Secure cloud‑native services including Google Kubernetes Engine (GKE), Compute Engine, and Cloud Storage<br>Implement and manage identity, access, and network security controls across cloud platforms<br>Embed security into CI/CD pipelines and Dev Ops workflows, enabling secure‑by‑design cloud solutions<br><br><br>Responsibilities<br><br><br>Design, deploy, and maintain cloud security architectures aligned with best practices and the shared responsibility model<br>Implement Identity and Access Management (IAM) and Identity‑Aware Proxy (IAP) to enforce least‑privilege access<br>Configure and enforce network security controls using VPCs, Cloud Armor, Cloud VPN, and firewall rules<br>Implement data protection mechanisms including encryption, key management, and data loss prevention using Cloud KMS and Secret Manager<br>Monitor, detect, and respond to cloud security events leveraging Security Command Center, Cloud Logging, and Cloud Monitoring<br>Perform cloud security assessments, vulnerability analysis, and misconfiguration reviews<br>Support cloud‑related incident response and forensic activities<br>Integrate security controls into Infrastructure as Code (Terraform or similar)<br>Ensure compliance with frameworks such as ISO 27001, NIST, and National Cybersecurity Authority (NCA / ECC)<br>Develop and maintain cloud security policies, standards, and hardening guidelines<br>Partner with engineering teams to remediate findings and continuously improve security posture<br><br><br>Qualifications<br><br><br>3–6 years of experience in cloud security, cybersecurity, or infrastructure security<br>Hands‑on experience securing at least one major cloud platform (GCP preferred)<br>Strong understanding of cloud architecture and the shared responsibility model<br>Solid knowledge of:<br>Identity and Access Management<br>Network security, segmentation, firewalls, and private connectivity<br>Data protection and encryption practices<br>Experience with cloud security services such as:<br>Security Command Center<br>Cloud KMS<br>Cloud Armor<br>Ability to identify, analyze, and remediate cloud misconfigurations and vulnerabilities<br>Familiarity with Infrastructure as Code (Terraform or similar)<br>Experience integrating security into CI/CD pipelines<br>Understanding of compliance frameworks (ISO 27001, NIST, NCA/ECC preferred)<br>Strong troubleshooting, documentation, and communication skills<br>Ability to work independently and proactively drive security initiatives<br><br>To learn more about life @AccentureMiddleEast, follow us on social media and keep up with our latest news . Accenture Middle East Africa : Linked In, Instagram, Facebook, Twitter, You Tube.
وصف الوظيفة<br><br>المهمة هي حماية أصول معلومات المؤسسة من خلال تحديد استراتيجية الأمن وإدارة المخاطر والتهديدات التي قد تؤثر على المنظمة بشكل فعال. يوفر رئيس أمن المعلومات قيادة في إنشاء بيئة تشغيل آمنة ومرنة، ويروج لثقافة أمن قوية، ويضمن الامتثال للمتطلبات التنظيمية والحوكمة المعمول بها. وبصفته قائدًا تنفيذيًا، يُقدم رئيس أمن المعلومات المشورة للإدارة التنفيذية في المسائل المتعلقة بالأمن ويضمن أن تبقى أهداف الأمن متوافقة مع أولويات الأعمال وأهداف المؤسسة.<br><br>المسؤوليات<br><br>فهم عميق لأهداف أعمال المنظمة وبيئة التشغيل والأصول المعلوماتية الحيوية. تعريف استراتيجية الأمن المعلوماتي وضمان التوافق مع أهداف الشركة. إنشاء وصيانة إطار حوكمة الأمن للمؤسسة. تعريف والإشراف على سياسات الأمن والمبادرات الأمنية الاستراتيجية. التأكد من تحديد مخاطر الأمن وتقييمها وإدارتها بشكل مناسب. تعزيز الوعي الأمني وت fostering ثقافة المساءلة عبر المؤسسة. تقديم إشراف تنفيذي أثناء الحوادث الأمنية الكبرى ووضع الأزمات. ضمان الامتثال للوائح والمعايير وأحكام الحوكمة المعمول بها. تقييم فعالية قدرات الأمن ومبادرات التحسين بشكل دوري. تعريف مقاييس تنفيذية ومؤشرات أداء لقياس فاعلية الأمن وخطر التعرض. إعداد تقارير دورية لقيادة التنفيذ عن وضع الأمن في المؤسسة والمخاطر الرئيسية الأولويات الاستراتيجية. تنسيق الأنشطة المتعلقة بالأمن مع قادة الأعمال وأصحاب المصلحة الرئيسيين في الشركة. العمل كنقطة المحاذاة الأساسية بين أولويات العمل وأهداف الأمن. الإشراف على مخاطر الأمن الطرف الثالث وضمان الحوكمة الملائمة لمقدمي الخدمات الخارجيين. تحديد أولويات الاستثمار الاستراتيجي وإدارة ميزانية الأمن لدعم أهداف العمل. رئاسة أو رعاية لجنة حوكمة الأمن في المؤسسة. <br><br>المؤهلات<br><br>درجة البكالوريوس في علوم الحاسوب، تكنولوجيا المعلومات، الأمن السيبراني، أو مجال ذي صلة من جامعة معترف بها. درجة الماجستير ذات صلة تعتبر ميزة.<br><br>المواطن القطري (إلزامي)<br><br>حد أدنى 10+ سنوات من الخبرة ذات الصلة في الأمن المعلوماتي، إدارة مخاطر السيبراني، أو أدوار قيادية ذات صلة.<br><br>حد أدنى 3–5 سنوات من الخبرة في إدارة عمل مماثل – قيادة وظيفة الأمن المعلوماتي / الأمن السيبراني أو تقديم المشورة على المستوى التنفيذي. خبرة في تعريف استراتيجية أمن معلوماتي متوافقة مع أهداف الأعمال، وإدارة مخاطر وتهديدات الأمن من البداية للنهاية. خبرة مثبتة في أطر تنظيمية قطرية (NCSA، NIA، CIIP، PDPPL). قدرة مثبتة على المشاركة والتأثير في الإدارة التنفيذية، العروض والجهات المعنية الرئيسية. خبرة في قيادة فرق متعددة التخصصات وإدارة مواقف وحوادث عالية الضغط ومعقدة. شهادات ذات صلة مثل CISSP، CISM، CISA، CRISC، أو ما يعادلها مطلوبة. فهم قوي للأمن، والمخاطر، والحوكمة، والإطارات التنظيمية. القدرة على ترجمة متطلبات الأمن إلى أولويات أعمال ومبادرات استراتيجية. القدرة على تعزيز ونشر ثقافة الوعي الأمني عبر المؤسسة. قيادة حوادث الأمن والأزمات<br><br>التقني<br><br>استراتيجية الأمن والحوكمة إدارة المخاطر والتهديدات التنظيم والامتثال (NCSA، NIA، CIIP، PDPPL) هندسة الأمن والمرونة إدارة الحوادث والأزمات حوكمة الأمن لدى الطرف الثالث/المورّدين<br><br>السلوكي<br><br>التفكير الاستراتيجي والنقدي التأثير التنفيذي وإدارة صاحب المصلحة القيادة وإدارة الفريق توجيه النتائج الاتصالات الفعالة النزاهة والحرص
Position Purpose Summary Principal Information Security Assurance Engineer/ Specialist lead and enforce enterprise-wide security assurance initiatives by evaluating and strengthening security mechanisms across systems, applications, and databases. Conduct comprehensive audits to detect and prevent unauthorized or malicious activities by users and administrators. Drive the adoption and continuous improvement of a secure SDLC framework across the be IN. Oversee and execute regular penetration testing and vulnerability assessments to safeguard the integrity, confidentiality, and availability of information assets. Provide strategic, administrative, and technical leadership to support the Director of Information Security in developing and implementing robust cybersecurity strategies.<br>Key Responsibilities and Accountabilities Review audit log of user applications, profile administration activities and privileged users, review objects/services access and usage. Audit operational change due to the change request. Audit privileged level access and changes to services, applications, databases. Ensure security mechanisms are considered within the SDLC. Conduct periodically internal penetration testing in assigned areas and contribute to the assessment of the security posture across all of infrastructure and oversee scheduled and event/service driven external penetration testing. Conduct vulnerability scanning and be able to interpret the results. Tracks and coordinate the security patching activities with relevant teams and provide the required support. Assess change request for the risk it poses to application and databases security and review the subsequent impact on operations. Approve the request after checking for approval from necessary authorities. Examine mechanisms and technologies in achieving and optimizing security controls and processes. To provide support and analysis during and after a security incidents, as necessary. Analyzes general information assurance-related technical problems and provide support in solving these problems. Research security enhancements and make recommendations to management. Coordinate the activities related to Information Security Projects.<br>Education Minimum Bachelor Degree in IT, Computer Science, Cyber Security, Business Administration or related field.<br>Experience Minimum 6 years of experience in IT domain, penetration testing, professional experience in corporate Applications Security, Analysis and Solutions Delivery or in any similar role.<br>Please refer to our privacy policy to know more about how we process your personal data
Position Purpose Summary Principle Information Security Assurance Engineer/ Specialist lead and enforce enterprise-wide security assurance initiatives by evaluating and strengthening security mechanisms across systems, applications, and databases. Conduct comprehensive audits to detect and prevent unauthorized or malicious activities by users and administrators. Drive the adoption and continuous improvement of a secure SDLC framework across the be IN. Oversee and execute regular penetration testing and vulnerability assessments to safeguard the integrity, confidentiality, and availability of information assets. Provide strategic, administrative, and technical leadership to support the Director of Information Security in developing and implementing robust cybersecurity strategies.<br>Key Responsibilities and Accountabilities Review audit log of user applications, profile administration activities and privileged users, review objects/services access and usage. Audit operational change due to the change request. Audit privileged level access and changes to services, applications, databases. Ensure security mechanisms are considered within the SDLC. Conduct periodically internal penetration testing in assigned areas and contribute to the assessment of the security posture across all of infrastructure and oversee scheduled and event/service driven external penetration testing. Conduct vulnerability scanning and be able to interpret the results. Tracks and coordinate the security patching activities with relevant teams and provide the required support. Assess change request for the risk it poses to application and databases security and review the subsequent impact on operations. Approve the request after checking for approval from necessary authorities. Examine mechanisms and technologies in achieving and optimizing security controls and processes. To provide support and analysis during and after a security incidents, as necessary. Analyzes general information assurance-related technical problems and provide support in solving these problems. Research security enhancements and make recommendations to management. Coordinate the activities related to Information Security Projects.<br>Education Minimum Bachelor Degree in IT, Computer Science, Cyber Security, Business Administration or related field.<br>Experience Minimum 6 years of experience in IT domain, penetration testing, professional experience in corporate Applications Security, Analysis and Solutions Delivery or in any similar role.<br><br>Please refer to our privacy policy to know more about how we process your personal data
Position Purpose Summary Principle Information Security Assurance Engineer/ Specialist lead and enforce enterprise-wide security assurance initiatives by evaluating and strengthening security mechanisms across systems, applications, and databases. Conduct comprehensive audits to detect and prevent unauthorized or malicious activities by users and administrators. Drive the adoption and continuous improvement of a secure SDLC framework across the be IN. Oversee and execute regular penetration testing and vulnerability assessments to safeguard the integrity, confidentiality, and availability of information assets. Provide strategic, administrative, and technical leadership to support the Director of Information Security in developing and implementing robust cybersecurity strategies.<br>Key Responsibilities and Accountabilities Review audit log of user applications, profile administration activities and privileged users, review objects/services access and usage. Audit operational change due to the change request. Audit privileged level access and changes to services, applications, databases. Ensure security mechanisms are considered within the SDLC. Conduct periodically internal penetration testing in assigned areas and contribute to the assessment of the security posture across all of infrastructure and oversee scheduled and event/service driven external penetration testing. Conduct vulnerability scanning and be able to interpret the results. Tracks and coordinate the security patching activities with relevant teams and provide the required support. Assess change request for the risk it poses to application and databases security and review the subsequent impact on operations. Approve the request after checking for approval from necessary authorities. Examine mechanisms and technologies in achieving and optimizing security controls and processes. To provide support and analysis during and after a security incidents, as necessary. Analyzes general information assurance-related technical problems and provide support in solving these problems. Research security enhancements and make recommendations to management. Coordinate the activities related to Information Security Projects.<br>Education Minimum Bachelor Degree in IT, Computer Science, Cyber Security, Business Administration or related field.<br>Experience Minimum 6 years of experience in IT domain, penetration testing, professional experience in corporate Applications Security, Analysis and Solutions Delivery or in any similar role.<br><br>Please refer to our privacy policy to know more about how we process your personal data
Position Purpose Summary Principle Information Security Assurance Engineer/ Specialist lead and enforce enterprise-wide security assurance initiatives by evaluating and strengthening security mechanisms across systems, applications, and databases. Conduct comprehensive audits to detect and prevent unauthorized or malicious activities by users and administrators. Drive the adoption and continuous improvement of a secure SDLC framework across the be IN. Oversee and execute regular penetration testing and vulnerability assessments to safeguard the integrity, confidentiality, and availability of information assets. Provide strategic, administrative, and technical leadership to support the Director of Information Security in developing and implementing robust cybersecurity strategies.<br>Key Responsibilities and Accountabilities Review audit log of user applications, profile administration activities and privileged users, review objects/services access and usage. Audit operational change due to the change request. Audit privileged level access and changes to services, applications, databases. Ensure security mechanisms are considered within the SDLC. Conduct periodically internal penetration testing in assigned areas and contribute to the assessment of the security posture across all of infrastructure and oversee scheduled and event/service driven external penetration testing. Conduct vulnerability scanning and be able to interpret the results. Tracks and coordinate the security patching activities with relevant teams and provide the required support. Assess change request for the risk it poses to application and databases security and review the subsequent impact on operations. Approve the request after checking for approval from necessary authorities. Examine mechanisms and technologies in achieving and optimizing security controls and processes. To provide support and analysis during and after a security incidents, as necessary. Analyzes general information assurance-related technical problems and provide support in solving these problems. Research security enhancements and make recommendations to management. Coordinate the activities related to Information Security Projects.<br>Education Minimum Bachelor Degree in IT, Computer Science, Cyber Security, Business Administration or related field.<br>Experience Minimum 6 years of experience in IT domain, penetration testing, professional experience in corporate Applications Security, Analysis and Solutions Delivery or in any similar role.<br><br>Please refer to our privacy policy to know more about how we process your personal data
Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Dubai - United Arab Emirates; Doha, Qatar; Riyadh Saudi Arabia. Minimum qualifications:<br><br>Bachelor's degree in Cybersecurity, with a focus on offensive security or equivalent practical experience.3 years of experience in three of the following security areas: web application security assessment, mobile application security assessment, API security assessment, red team assessments, EDR evasion, exploit development, cloud, social engineering, scripting, tool development. Experience delivering reporting and presentations to both technical and executive audiences. Experience with operating system security across operating systems or Linux.<br><br>Preferred qualifications:<br><br>Certifications related to application security including BSCP, OSWE, e WPTX, e MAPT, 8ksec CMSE or relevant SANS courses. Experience in creating security tools and understanding of underlying programming languages (such as Python, C#, C/C++, Rust, Nim or similar). Experience conducting web application, API, and mobile (i OS and Android) security assessments following industry standards such as OWASP WSTG/ASVS, OWASP Top 10, OWASP API Top 10 and OWASP MASVS/MASTG. Experience in web application and API penetration testing tooling including Burp Suite Professional, Burp Suite extensions, Postman, nuclei, ffuf and sqlmap.<br><br>About The Job<br><br>As a Security Consultant, you will be responsible for helping clients effectively prepare for, proactively mitigate, and detect and respond to cyber security threats. Security Consultants have an understanding of computer science, operating system functionality and networking, cloud services, corporate network environments and how to apply this knowledge to cyber security threats.<br><br>As a Security Consultant, you could work on engagements including assisting clients in navigating technically complex and high-profile incidents, performing forensic analysis, threat hunting, and malware triage. You may also test client networks, applications and devices by emulating the latest techniques to help them defend against threats, and will be the technical advocate for information security requirements and provide an in-depth understanding of the information security domain. You will also articulate and present complex concepts to business stakeholders, executive leadership, and technical contributors and successfully lead complex engagements alongside cross functional teams.<br><br>We are seeking a highly skilled and experienced Application Security Consultant to join the team.<br><br>In this role, you will be responsible for providing cybersecurity consulting services and support to the clients, including assessing and advising clients on both technical and process-based controls for all manner of environments.<br><br>Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.<br><br>Responsibilities<br><br>Conduct comprehensive security assessments of Web applications, APIs, and Mobile applications by identifying, exploiting and validating vulnerabilities using industry-standard methodologies such as the OWASP Web Security Testing Guide (WSTG), OWASP API Security Top 10, and OWASP Mobile Application Security Testing Guide (MASTG). Discover critical vulnerabilities in applications and be able to weaponize them. Expand the team’s capabilities through tool creation, research on offensive techniques, incorporation of threat actor intelligence, internal presentations and knowledge share. Develop comprehensive and accurate reports and presentations for both technical and executive audiences, and act as a trusted advisor to c-level, security leaders and other customer stakeholders. Assist with scoping prospective engagements, leading teams for engagements from kickoff through remediation phase, as well as mentoring other staff.<br><br><br>Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form .
Job Description<br><br>Role- Cyber Security Analyst<br><br>Experience - 7+ years<br><br>Mandatory Skills<br><br>Cyber Security Incident Response<br><br>Cyber Security Monitoring<br><br>SOC Operations – L2<br><br>Forensic Analysis<br><br>Threat Analysis & Incident Investigation<br><br>Role & Responsibilities<br><br>Monitor and analyze security events/incidents.<br><br>Perform triage, escalation, and response activities for security incidents.<br><br>Provide L2 SOC support and incident management.<br><br>Perform malware analysis and reverse engineering.<br><br>Analyze logs, network traffic, forensic data, and threat intelligence.<br><br>Validate threats, assess impact, and recommend remediation actions
Job Description<br><br>Role- Cyber Security Analyst<br><br>Experience - 7+ years<br><br>Mandatory Skills<br><br>Cyber Security Incident Response<br><br>Cyber Security Monitoring<br><br>SOC Operations – L2<br><br>Forensic Analysis<br><br>Threat Analysis & Incident Investigation<br><br>Role & Responsibilities<br><br>Monitor and analyze security events/incidents.<br><br>Perform triage, escalation, and response activities for security incidents.<br><br>Provide L2 SOC support and incident management.<br><br>Perform malware analysis and reverse engineering.<br><br>Analyze logs, network traffic, forensic data, and threat intelligence.<br><br>Validate threats, assess impact, and recommend remediation actions
Key Responsibilities Customer Engagement & Strategy Opportunity Qualification: Partner with Account Executives to technically qualify sales leads, ensuring alignment between client budgets, timelines, and our delivery capabilities. Requirement Gathering & Analysis: Lead deep-dive discovery sessions to uncover clients' current security posture, pain points, regulatory compliance gaps, and business objectives. Customer Workshops & Assessments: Design and execute technical workshops and high-level maturity assessments to identify vulnerabilities and position relevant security frameworks. Solution Architecture & Proposal Development Solution Architecture & Design: Architect robust, end-to-end cybersecurity solutions that integrate seamlessly into diverse client environments (on-premises, hybrid, and multi-cloud). RFI/RFP/RFQ Response Preparation: Own the technical response strategy for complex tenders, ensuring comprehensive compliance, competitive differentiation, and timely submission. Bill of Material (BoM) Creation: Engineer accurate, cost-optimized multi-vendor BoMs, leveraging vendor frameworks and discount structures to maximize profitability. Statement of Work (SoW) Preparation: Author highly detailed SoWs that define the exact project scope, technical deliverables, assumptions, milestones, and out-of-scope boundaries to mitigate delivery risk. Technical Validation & Sales Enablement Technical Presentations & Demonstrations: Deliver high-impact technical presentations and tailored product demonstrations that clearly articulate the business value and ROI of the proposed architecture. Proof of Concept (PoC) Management: Define success criteria, scope, and execute PoCs and Proof of Values (PoVs) to technically validate solutions and overcome buyer hesitations. Vendor Coordination: Maintain strong relationships with strategic security vendors to stay ahead of product roadmaps, secure specialized deal pricing, and co-architect complex solutions. Project Handover to Delivery Teams: Lead comprehensive post-sale handover sessions with implementation and delivery teams to ensure flawless execution. Sales Enablement: Conduct internal training sessions for the broader sales team on new security technologies, vendor programs, and competitive displacement strategies.<br>Technical Competencies The ideal candidate must demonstrate mid-to-senior level architectural and conceptual expertise across the following domains:Network & Edge Security: Secure Web Gateway (SWG), Forward/Reverse Proxy Solutions, Web Application Firewall (WAF), and DDoS Protection. Content & Endpoint Security: Next-Generation Endpoint Security, Endpoint Detection & Response (EDR), Extended Detection & Response (XDR), and Email Security ecosystems. Security Operations & Automation: Security Orchestration, Automation, and Response (SOAR), Threat Intelligence Platform (TIP) integration, and Vulnerability Management life cycles. Identity & Access Governance: Privileged Access Management (PAM), Identity and Access Management (IAM), and Directory Services. Modern Security Architectures: Zero Trust Architecture (ZTA) design, Secure Access Service Edge (SASE), and Security Service Edge (SSE). Cloud & Data Security: Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWPP), Data Loss Prevention (DLP), and data encryption/masking strategies.<br>Preferred Vendor Knowledge While platform-agnostic architectural skills are essential, practical presales or implementation experience with a combination of the following vendor ecosystems is highly valued:Next-Gen Firewall & SASE: Palo Alto Networks (Strata/Prisma), Fortinet (Forti Gate/Forti SASE) Endpoint & XDR: Paloalto, Trend Micro, Crowd Strike Network Visibility & NDR: Extra Hop, Darktrace, Vectra AI, Trellix Application & Edge Delivery: F5 (BIG-IP, Distributed Cloud), Cloudflare Email Security: Proofpoint, Fortinet, Trellix Identity & Privileged Access: Delinea, Xage, Beyond Trust Cloud Security & SSE: Zscaler, Netskope Vulnerability Management: Tenable, Trellix Qualifications & Certifications Academic Background Required: Bachelor’s degree from an accredited institution in Computer Science, Cyber Security, Information Technology, Computer Engineering, or a closely related technical field.<br>Professional Certifications Candidates are expected to hold, or be actively pursuing, certifications that validate both broad security knowledge and vendor-specific expertise:Core Security Knowledge: CISSP (preferred), CISM, or CCSP. Technical Foundations: CEH (Certified Ethical Hacker) or Comp TIA Security+. Vendor-Specific Tracks: Fortinet NSE (Level 4 or higher), Palo Alto Networks PCNSE, or Cisco Security Certifications (CCNP Security).<br>Experience Requirements Presales Expertise: At least 3–5 years dedicated to a customer-facing Cyber Security Presales role, driving technical wins within a System Integrator or Value-Added Reseller (VAR). Consulting & Design: Proven track record of conducting security consultations and building defense-in-depth enterprise architectures. Tendering Proficiency: Demonstrable experience independently managing, writing, and winning high-value RFP/RFI responses for both commercial enterprises and public sector/government entities. Sector Exposure: Significant experience navigating the distinct procurement processes, compliance requirements, and stakeholder landscapes of enterprise corporations and government agencies.<br>Soft Skills & Leadership Attributes Executive Presentation Skills: Ability to command a room, articulating highly technical, granular security risks into clear, business-driven outcomes for C-level executives. Communication & Relationship Management: Exceptional verbal and written communication skills; a natural ability to build rapport and establish long-term technical credibility with clients. Analytical Thinking & Problem Solving: Methodical approach to deconstructing chaotic, poorly defined client environments into structured, secure, and compliant architectures. Collaboration & Time Management: Ability to self-manage tight tender deadlines, multi-task across concurrent sales opportunities, and collaborate seamlessly across cross-functional teams (Sales, Delivery, Finance, Vendors). Leadership Potential: Drive to mentor junior presales engineers, take ownership of specific technology practices, and champion internal process improvements.
<h2 class="h5">وصف الوظيفة</h2>
<div class="t-break" data-jb-field="description">
حول الوظيفة: مهندس أمان ICS كبير
<ul><li>درجة البكالوريوس في الهندسة (القياس والتحكم، الكهرباء، الهندسة الإلكترونية، الحاسوب) أو علوم الحاسوب.</li></ul> <ul><li>6 سنوات خبرة في عمليات صناعة النفط والغاز، تقنية، هندسية مع خبرة أمان ICS.</li><li>خبرة في تطبيق ضوابط الأمن ضمن بيئة OT.</li><li>فهم لبيئات أنظمة التحكم الصناعية المختلفة.</li><li>خبرة في أمان أنظمة ICS، معرفة بالشبكات، أدوات الأمن، معرفة بمراقبة أمان ICS مثل IDS/IPS، SIEM وغيرها.</li></ul> <ul><li>متمكن من الكتابة والحديث باللغة الإنجليزية.</li><li>المهارة الحاسوبية الكافية.</li><li>مهارات تواصل شخصية ممتازة، ماهر جدًا في التعامل مع الأفراد، الشؤون الإدارية والتنظيمية واللوجستية.</li><li>حل المشكلات المرتبطة بتصميم أمان ICS، واستمرارية الدعم.</li><li>قيادة ملكية القضايا المتعلقة بأمان ICS لدعم وتحفيز التحسين المستمر.</li></ul>
<br>
<br> </div>
<p>نحن نبحث عن <strong>كبير مسؤولي أمن المعلومات / كبير مختبري الأمن السيبراني (الشهادة)</strong> ذوي خبرة عالية لقيادة ودعم أنشطة الحصول على الاعتماد في الأمن السيبراني والتقييم والامتثال. المسؤولية تشمل مراجعة طلبات الاعتماد، وتقييم امتثال المؤسسات للمعايير الوطنية والدولية للأمن، وإجراء تقييمات ومراجعات مخاطر الأمن السيبراني، وضمان الاتساق والحيادية والجودة خلال دورة الاعتماد.</p><p>سيكون المرشح المثالي متمتعاً بخبرة تقنية قوية في حوكمة أمن المعلومات وإدارة المخاطر والامتثال والتدقيق وأطر الاعتماد، إلى جانب قدرات قيادية وإدارة أصحاب المصلحة مثبتة.</p><p><strong>المسؤوليات الأساسية: </strong><br></p><ul><li><p>قيادة وتنفيذ أنشطة تقييم الاعتماد ومراجعة المؤسسات التي تسعى للحصول على اعتماد أمن معلومات / أمن سيبراني.</p></li><li><p>إدارة فرق التقييم، وتخصيص الحالات، والإشراف على عمليات الاعتماد اليومية. <br></p></li><li><p>مراجعة وتقييم امتثال المؤسسات للمعايير وال\إطارات الأمن السيبراني الوطنية والدولية.</p></li><li><p>تقييم تصميم وكفاءة التحكمات في الأمن السيبراني وأمن المعلومات <br></p></li><li><p>إجراء تقييمات مخاطر الأمن السيبراني، والتدقيق، ومراجعات الامتثال.</p></li><li><p>الحفاظ على سجلات دقيقة وكاملة ومنظمة لأنشطة الاعتماد والتقييم.</p></li><li><p>ضمان الحياد والخصوصية والاتساق والالتزام طوال عمليات الاعتماد.</p></li><li><p>توثيق ملاحظات ونتائج التقييم استناداً إلى أدلة موضوعية وضمان إمكانية التتبع.</p><li><p>تطوير والحفاظ على إجراءات الاعتماد والمنهجيات والأدوات الداعمة المتوافقة مع أطر الامتثال الوطنية.</p></li><li><p>تطوير آليات قياس الامتثال وأدوات الرصد لتتبع التحسينات.</p></li><li><p>تقديم التوصيات ونتائج التقييم لأصحاب المصلحة وصانعي القرار.</p></li><li><p>إدارة الاتصالات الخارجية طوال دورة حياة التدقيق والاعتماد، من التقديم حتى إصدار القرار النهائي.</p></li><li><p>البقاء على اطلاع بتهديدات الأمن السيبراني الناشئة والتقنيات والمعايير وأفضل الممارسات في الصناعة.</p></li><li><p>تطوير وتقديم جلسات تدريب داخلية وورش عمل لتعزيز قدرات الفريق في الأمن السيبراني والامتثال والضمان والتدقيق.</p></li><li><p>التعاون بفاعلية مع الفرق الداخلية والعملاء وأصحاب المصلحة عبر مشاريع متعددة.</p></li></ul><p><strong>المصدر من المرشح المطلوب</strong></p><p><strong>المتطلبات</strong></p><p>التعليم:<br></p><ul><li><p>درجة البكالوريوس في تكنولوجيا المعلومات، أنظمة معلومات حاسوبية، الأمن السيبراني، أو مجال ذي صلة.<br></p></li></ul><p>الشهادات المهنية:<br></p><p>يفضل الحصول على شهادة مهنية واحدة على الأقل من الشهادات التالية أو ما يعادلها:<br></p><ul><li><p>CISSP<br></p></li><li><p>CISA<br></p></li><li><p>CISM<br></p></li><li><p>CRISC<br></p></li><li><p>ISO 27001 Lead Auditor / Implementer<br></p></li></ul><p>الخبرة:<br></p><ul><li><p>خبرة مهنية لا تقل عن 7 سنوات في أمن المعلومات / الأمن السيبراني.<br></p></li><li><p>خبرة لا تقل عن 4 سنوات في أحد المجالات التالية على الأقل:</p><ul><li><p>تدقيق أمن المعلومات<br></p></li><li><p>تدقيق الأمن السيبراني<br></p></li><li><p>إدارة المخاطر<br></p></li><li><p>إدارة أمن المعلومات<br></p></li></ul></li><li><p>الخبرة في الاستشارات أو تنفيذ برامج الأمن السيبراني المتوافقة مع المعايير الوطنية أو الدولية مرغوبة بشدة.<br></p></li></ul><p>المهارات الفنية والمعرفة:<br></p><ul><li><p>معرفة قوية بحوكمة الأمن السيبراني وتقييم المخاطر ومنهجيات التدقيق.<br></p></li><li><p>الخبرة في أطر ومعايير الأمن مثل:</p><ul><li><p>ISO 27001<br></p></li><li><p>NIST<br></p></li><li><p>NIA Controls<br></p></li><li><p>CSF Q2022<br></p></li></ul></li><li><p>الإلمام بمعايير الاعتماد والتدقيق بما في ذلك:</p><ul><li><p>ISO/IEC 17021<br></p></li><li><p>ISO/IEC 17024<br></p></li><li><p>ISO/IEC 27006<br></p></li><li><p>ISO/IEC 17065<br></p></li><li><p>ISO 19011<br></p></li><li><p>ITAF<br></p></li><li><p>ISA<br></p></li></ul></li><li><p>خبرة عملية في تدقيق أمن المعلومات وإدارة أمن المعلومات.<br></p></li><li><p>فهم قوي لاتجاهات Threats وتكنولوجيا الأمن السيبراني الناشئة.<br></p></li><li><p>مهارات كتابة تقارير تقنية وتوثيق ممتازة.<br></p></li></ul><p>المهارات الناعمة:<br></p><ul><li><p>قدرات تحليلية وحل مشاكل قوية.<br></p></li><li><p>مهارات اتصال وإدارة أصحاب المصلحة ممتازة.<br></p></li><li><p>القدرة على العمل بشكل مستقل وإدارة أولويات متعددة بفعالية.<br></p></li><li><p>انتباه عالي للتفاصيل وقدرة على العمل تحت الضغط والالتزام بالمواعيد.<br></p></li><li><p>مهارات تفاعل بين الأشخاص والتعاون ضمن الفريق.<br></p></li><li><p>خبرة في تقديم ورش عمل وجلسات تدريب وبرامج توعية.<br></p></li></ul><p>متطلب اللغة:<br></p><ul><li><p>مطلوب الطلاقة في اللغة الإنجليزية.<br></p></li><li><p>العربية ميزة إضافية.</p></li></ul>
<h2 class="h5">وصف الوظيفة</h2>
<div class="t-break" data-jb-field="description">
<span><u><b>ملخص الوظيفة</b></u>
<br></span><p>يقدم ضابط HSE لإدارة المرافق القيادة العملية والفنية والوظيفية عبر أنشطة إدارة المرافق مع ضمان التوافق مع المعايير التنظيمية، أهداف العمل، والمتطلبات التنظيمية. تتحمل هذه الوظيفة مسؤولية دفع الأداء والتنسيق والامتثال والمشاركة مع أصحاب المصلحة وتقديم الخدمة ضمن وظيفة الصحة والسلامة والبيئة. تدعم المنصب مبادرات التحسين المستمر، وتحسين التكلفة، والكفاءة التشغيلية، والنتائج عالية الجودة مع التعاون الوثيق مع الفرق الداخلية والمتعاقدين والعملاء وأصحاب المصلحة في الأعمال.</p><br><br><br><u><b>مسؤوليات الوظيفة 1</b></u>
<br>الإدارة التشغيلية: إدارة أنشطة الصحة والسلامة والبيئة اليومية ضمن بيئة إدارة المرافق لضمان تنفيذ فعال، الامتثال للإجراءات، وتحقيق الأهداف التشغيلية مع الحفاظ على معايير جودة الخدمة والإنتاجية.
التخطيط والتنسيق: تنسيق الجداول الزمنية والقوى والمواد والمقاولين والأنشطة التشغيلية لضمان إتمام المهام والمشروعات والتسليمات في الوقت المحدد وبما يتوافق مع الجداول المعتمدة ومتطلبات العمل.
المشاركة مع أصحاب المصلحة: التواصل مع الأقسام الداخلية والاستشاريين والموردين والمتعهدين والعملاء والفرق التشغيلية لضمان سلاسة الاتصالات وحل القضايا والتوافق على المتطلبات الفنية والتشغيلية.
الامتثال والحوكمة: ضمان الامتثال لسياسات الشركة والالتزامات العقدية والمعايير التنظيمية ومتطلبات HSE وأفضل الممارسات الصناعية ذات الصلة بقطاع إدارة المرافق.
رصد الأداء: مراقبة KPIs التشغيلية والإنتاجية ومعايير الخدمة والقياسات الجودة مع تحديد الثغرات وتنفيذ الإجراءات التصحيحية ودفع مبادرات التحسين المستمر.
التقارير والوثائق: إعداد تقارير تشغيلية وسجلات تقنية وتحديثات التقدم وتحليلات التكاليف وعروض الإدارة لدعم اتخاذ القرار وجاهزية التدقيق وشفافية الأعمال.
تحسين الموارد: دعم الاستغلال الفعال للقوى العاملة والمعدات والميزانيات والمواد والموارد التشغيلية لتحسين الإنتاجية وتقليل الهدر وتحسين تكاليف التشغيل.
إدارة المخاطر والمشكلات: تحديد المخاطر التشغيلية والتحديات الفنية والتأخيرات ومشاكل الأداء مع تنفيذ تدابير التخفيف وآليات التصعيد لتقليل أثر الأعمال.
ضمان الجودة: دعم تنفيذ إجراءات ضمان الجودة ومراقبة الجودة لضمان تلبية الخدمات والتسليمات والمخرجات التشغيلية لتوقعات الشركة والعملاء.
التحسين المستمر: المساهمة في تحسين العمليات والمبادرات الرقمية وت优化 تدفقات العمل وبرامج التميز التشغيلي لتحسين الكفاءة وتقديم الخدمة والأداء العام للأعمال.</p><br><br><u><b>مسؤوليات الوظيفة 2</b></u>
<br><br><b>مسؤوليات إضافية 3</b>
<br><br><u><b>معرفة ومهارات الوظيفة</b></u>
<br>معرفة عمليات القطاع: فهم قوي لمتطلبات التشغيل والمعايير وتدفقات العمل والتوقعات التنظيمية ضمن قطاع إدارة المرافق.
الخبرة الفنية والوظيفية: معرفة متقدمة بعمليات HSE والوثائق ومعايير التقارير والأنظمة والضوابط التشغيلية ذات الصلة بالدور.
تنسيق أصحاب المصلحة: القدرة على إدارة التواصل عبر وظائف متعددة وتنسيق المقاولين ومشاركة العملاء والتعاون الفريق within بيئات تشغيلية سريعة.
الأنظمة والتقارير: الكفاءة في أنظمة ERP وأدوات التقرير وتطبيقات مايكروسوفت أوفيس ولوحات الأداء والمناهج الخاصة بتتبع الأداء.
حل المشكلات واتخاذ القرار: قدرات تحليلية وتنظيمية واتخاذ القرار قوية مع القدرة على حل المشكلات التشغيلية ودعم استمرارية الأعمال.<br><br><u><b>خبرة الوظيفة</b></u>
<br>خبرة صناعية: خبرة مثبتة في قطاع إدارة المرافق تتضمن المسؤوليات التشغيلية والتقنية والمشروعات أو الوظيفية ذات الصلة بالدور.
التنسيق التشغيلي المعروض: خبرة مثبتة في تنسيق الفرق والمتعاقدين وأصحاب المصلحة والموارد وأنشطة تقديم الخدمات ضمن بيئات تشغيلية معقدة.
الامتثال وإدارة الأداء: خبرة في دعم إدارة KPI والتقارير وتحسين العمليات والامتثال للجودة ومبادرات الكفاءة التشغيلية.<br><br><u><b>الكفاءات</b></u>
<br>القيادة
المرونة
الجودة
المرونة
الطلاقة في AI<br><br><u><b>التعليم</b></u>
<br><br><br>
</div>