وصف الوظيفة
الأدوار والمسؤوليات
المراجع الأعلى لاعتماد الأمن السيبراني مسؤول عن تقديم خدمات الاعتماد اليومية وضمان أن تقييمات الأطراف الثالثة تتم بشكل عادل ومتسق وموضوعي. يركز الدور على تقييم الامتثال للمعايير الوطنية والدولية للأمن السيبراني، إدارة طلبات الاعتماد، والحفاظ على سلامة عملية الاعتماد. كما يدعم التحسين المستمر لأطر وأدوات ومنهجيات الاعتماد بما يتوافق مع متطلبات الأمن السيبراني الوطنية.
المسؤوليات الرئيسية :
- المسؤول عن إجراء خدمات الاعتماد اليومية.
- الحفاظ على سجلات مفصلة ومنظمة لعملية الاعتماد، مع ضمان الدقة والكمال.
- ضمان الحفاظ على أعلى معايير الكفاءة والحياد وتحقيق الاتساق عبر أنشطة الاعتماد؛
- إجراء أنشطة الامتثال وفقاً لمعايير الأمن.
- الدور التشغيلي لإدارة طلبات مخطط الاعتماد الوطني.
- توثيق الملاحظات/الاستنتاجات بطريقة تكون مفهومة وقابلة للتتبع ومبنية على دليل موضوعي.
- تطوير والمحافظة على إجراءات الاعتماد وأدوات مطلوبة بناءً على إطار الامتثال الوطني لمعلومات الأمن.
- الحفاظ على الحياد والسرية والكشف عن أي تضارب محتمل في المصالح قد يعرّض تقييمًا موضوعيًا للخطر حسب ما هو مطلوب.
- إجراء تقييم اعتماد دوري للمراقبة على الأطراف الثالثة لمراقبة والاطلاع على الامتثال.
- تطوير آليات القياس والامتثال والأدوات لمراقبة التحسينات.
- معرفة بمعايير دولية مختلفة، والتنظيمات، وأفضل الممارسات، (ISO27001، OWASP، PTES، SOC CMM وغيرها) وتطبيقها في الأقل على واحد منها.
- معرفة بالقوانين والأنظمة المحلية في قطاعات مختلفة: الجرائم السيبرانية، PDPPL، التجارة الإلكترونية، إلخ.
- المعرفة بمعايير وأطر الأمن السيبراني الوطنية (NIA، CSF)
- البقاء على اطلاع على أحدث التطورات في الأمن والتهديدات الناشئة والتكنولوجيا المتطورة لضمان أن تظل عملية الاعتماد ذات صلة.
- إدارة التواصل الخارجي أثناء التقييم: من التقديم حتى إصدار القرار.
- العمل كنقطة اتصال تصعيد لمشاكل/طلبات الاعتماد.
- عضو فريق يتعاون مع الفريق للحفاظ على وتحسين برنامج الاعتماد.
المرشح المثالي
التعليم والخبرة:
- درجة البكالوريوس في علوم الحاسب الآلي، تكنولوجيا المعلومات، أنظمة المعلومات، الأمن السيبراني، أو ما يعادلها.
- خبرة لا تقل عن 12 سنة في الأمن المعلوماتي، الأمن السيبراني، تقييم المخاطر، أو الضمان.
- خبرة عملية في تدقيق الأمن المعلوماتي، الاعتماد، أو إدارة الأمن السيبراني.
- الخبرة في الاستشارات الأمنية السيبرانية أو التنفيذ وفق المعايير الوطنية/الدولية تعتبر ميزة.
الشهادات (المفضل):
- مراجع معتمد من NIA، CISSP، CISA، CISM، ISO 27001 Lead Auditor أو ما يعادلها.
المهارات التقنية:
- معرفة قوية بإطارات ومعايير الأمن السيبراني (ISO 27001، NIST، NIA، OWASP، PTES، SOC-CMM، إلخ).
- فهم معايير الاعتماد (ISO/IEC 17011، ISO/IEC 17025) وعمليات الشهادة.
- خبرة في تقييم المخاطر ومنهجيات التدقيق.
- معرفة بالقوانين والأنظمة الوطنية للأمن السيبراني (مثلاً قوانين الجرائم السيبرانية، حماية البيانات، تنظيمات التجارة الإلكترونية).
- وعي قوي بممارسات تدقيق الطرف الثالث والشهادة.
- القدرة على تقييم ضوابط الأمان والامتثال وفقاً للأطر الرسمية بشكل موضوعي.
المهارات الأساسية:
- تفكير تحليلي قوي ومهارات حل المشكلات.
- كتابة تقارير تقنية ووثائق ممتازة.
- القدرة على التواصل بوضوح مع أصحاب المصلحة الفنيين والإداريين رفيعي المستوى.
- خبرة في تقديم ورش عمل، تدريبات، أو جلسات مشاركة المعرفة.
- انتباه قوي للتفاصيل والقدرة على العمل تحت الضغط وبمواعيد نهائية ضيقة.
الكفاءات السلوكية:
- مهارات عالية في العمل الجماعي والتعاون.
- نزاة عالية من النزاهة والحياد والاحتراف.
- القدرة على إدارة عدة أصحاب مصلحة وأولويات مت competing.
- مهارات تواصل وتفاعل شخصي قوية.
- مبادرة ذاتية، واعتماد على النفس، والقدرة على العمل بشكل مستقل مع إشراف محدود.
اللغة:
التوافر:
مدة العقد 12 شهراً، مع إمكانية التمديد وفقاً لاحتياجات القسم.
Job Description
Roles & Responsibilities
The Senior Cybersecurity Accreditation Auditor is responsible for delivering day-to-day accreditation services and ensuring that assessments of third parties are conducted in a fair, consistent, and objective manner. The role focuses on evaluating compliance with national and international cybersecurity standards, managing accreditation applications, and maintaining the integrity of the accreditation process. It also supports continuous improvement of accreditation frameworks, tools, and methodologies aligned with national cybersecurity requirements.
Key Responsibilities :
- Responsible for the conduct of the day to day of accreditation services.
- Maintain detailed and organized records of the accreditation process, ensuring accuracy and completeness.
- Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across accreditation activities;
- Undertake compliance activities against security standards.
- Operational role, to manage national accreditation scheme applications.
- Document observations/findings in such a manner that they are clearly understandable and traceable and are based on objective evidence.
- Develop and maintain accreditation procedures and required tools based on National Information Security Compliance framework.
- Maintain impartiality, confidentiality and to declare any potential conflicts of interest that might jeopardize an objective assessment as required.
- Perform periodic surveillance accreditation assessment on Third parties to monitor and review compliance.
- Develop measurement and compliance mechanisms & tools to monitor improvements.
- Knowledge of various international standards, regulation, and best practices, (ISO27001, OWASP, PTES, SOC CMM etc.) and implementation experience against at least one.
- Knowledge of Local Laws & Regulations in different sectors: Cybercrime, PDPPL, eCommerce, etc.
- Knowledge about national cyber security standards and frameworks (NIA, CSF )
- Stay up to date with the latest developments in security, emerging threats, and evolving technology to ensure the accreditation process remains relevant.
- Manage the external communication during the assessment: from the application till the issue of decision.
- Act as escalation point of contact for accreditation issues/requests.
- Team player who collaborates with the team to maintain, improve the accreditation program.
Desired Candidate Profile
Education & Experience:
- Bachelor s degree in Computer Science, Information Technology, Information Systems, Cybersecurity, or equivalent.
- Minimum 12 years of experience in Information Security, Cybersecurity, Risk Assessment, or Assurance.
- Hands-on experience in information security auditing, accreditation, or cybersecurity management.
- Experience in cybersecurity consulting or implementation aligned with national/international standards is an advantage.
Certifications (Preferred):
- NIA Certified Auditor, CISSP, CISA, CISM, ISO 27001 Lead Auditor or equivalent.
Technical Skills:
- Strong knowledge of cybersecurity frameworks and standards (ISO 27001, NIST, NIA, OWASP, PTES, SOC-CMM, etc.).
- Understanding of accreditation standards (ISO/IEC 17011, ISO/IEC 17025) and certification processes.
- Experience in risk assessment and audit methodologies.
- Knowledge of national cybersecurity laws and regulations (e.g., Cybercrime laws, data protection, eCommerce regulations).
- Strong awareness of third-party audit and certification practices.
- Ability to assess security controls and compliance against formal schemes objectively.
Core Skills:
- Strong analytical thinking and problem-solving abilities.
- Excellent technical report writing and documentation skills.
- Ability to communicate clearly with technical and senior executive stakeholders.
- Experience in delivering workshops, training, or knowledge-sharing sessions.
- Strong attention to detail and ability to work under pressure and tight deadlines.
Behavioral Competencies:
- Strong teamwork and collaboration skills.
- High level of integrity, impartiality, and professionalism.
- Ability to manage multiple stakeholders and competing priorities.
- Strong interpersonal and communication skills.
- Proactive, self-driven, and able to work independently with minimal supervision.
Language:
Availability:
The contract duration is 12 months, with the possibility of extension based on departmental requirements.