المسمى الوظيفي: أخصائي أمن معلومات الخبرة: أكثر من 10 سنوات الموقع: قطر (حضور موقعي) المدة: سنة قابلة للتجديد المحاور الوظيفية الأساسية: يتحقق من خروقات الأمن وفق الإجراءات المعتمدة ومعايير الأمن ويوصي بالإجراءات اللازمة ويدعم / يتابع لضمان تنفيذها. يتحقق من تقارير الانتهاكات والسجلات المُنشأة من الأنظمة الآلية ويُسَوِّقها ويُ reconciles؟ (تصحيح: ي reconcile reports) حيثما كان مناسبًا (أي يشمل موظفين داخل منظمته) يُجري مقابلات مع المخالفين الصغار ويُعد تقارير وتوصيات للمتابعة من قِبل الإدارة. يقدم الإرشاد والمساعدة في تعريف حقوق الوصول والامتيازات. يعمل ويدير كل من ضوابط الوصول المادية والمنطقية المستخدمة لتوفير وصول مستمر وآمن إلى خدمات المعلومات. يُجري مراجعات للضوابط الأمنية في مناطق محددة جيدًا. يُقيِّم أمان مكونات المعلومات والبنية التحتية. يتحقق من مخاطر هجمات الشبكة ويقترح إجراءات تصحيحية. يُجري تقييمات لمخاطر الأعمال ونقاط الضعف وتحليل تأثير الأعمال على أنظمة المعلومات ذات التعقيد المتوسط. يراجع الامتثال لسياسات ومعايير أمن المعلومات. يُقيّم التكوينات وإجراءات الأمن لالتزامها بالمتطلبات القانونية والتنظيمية. يراجع استخدام الشبكة. يُقيّم تبعات أي استخدام غير مقبول أو خروق أو سياسات الشركة ويقترح الإجراءات المناسبة. يشرح الغرض ويقدم النصائح والإرشادات حول تطبيق وتشغيل ضوابط الأمن الفيزيائية والإجرائية والتقنية الأساسية. (على سبيل المثال الضوابط الأساسية المحددة في IS27002). ينقل مخاطر وضمان المعلومات والمتطلبات بشكل فعال لمستخدمي الأنظمة والشبكات. يحقق في الهجمات المشتبهة ويتولى التحقيق وحل الحوادث الأمنية وفق الإجراءات المعتمدة بما في ذلك إجراءات إدارة الحوادث. يستخدم علم الطب الشرعي عند الحاجة. يرفع التقارير عن النتائج والدروس المستفادة/إجراءات التحسين. يقدم عناصر من مكونات أمان أنظمة الهندسة المعمارية. يتحقق من أسباب الحوادث ويسعى لإيجاد حل.
الملف الشخصي المرغوب فيه للمرشح
المؤهلات: درجة البكالوريوس في علوم الحاسب، تكنولوجيا المعلومات، نظم المعلومات أو تخصص ذي صلة. المعرفة و/أو الخبرة: خبرة أمن معلومات لا تقل عن 10 سنوات ويفضل ضمن صناعة النفط/الغاز. الإلمام بالمعايير الوطنية والدولية ذات الصلة بأمن المعلومات. اكتساب والحفاظ على الخبرة وفق أطر الكفاءة المعنية بتقنية المعلومات. معرفة عملية جيدة بأمن المعلومات مرفقة بمعرفة مكافئة بنشاطات الشركات الأخرى التي تستخدم تقنية المعلومات. فهم مبادئ وممارسات تطوير وصيانة متطلبات أمن المعلومات. المهارات التقنية والعملية: يقيم المخاطر وتأثير التشريعات ويعزز الامتثال بنشاط. لديه فهم جيد لتطبيقات الأعمال في تكنولوجيا المعلومات. فعال ومقنع في كل من التواصل الخطي والشفهي
Job Role: IT Security Specialist Expereince: 10+ years Location: Qatar (Onsite) Duration: 1 year renewable Key Job Accountabilities: Investigates security breaches in accordance with established procedures and security standards and recommends required actions and supports / follows up to ensure these are implemented. Investigates and reconciles violation reports and logs generated by automated systems. Where appropriate (i.e. involving employees within own organisation) interviews minor offenders and compiles reports and recommendations for management follow-up. Provides guidance and assistance in defining access rights and privileges. Operates and administers both physical and logical access controls used in order to provide continuous and secure access to information services. Conducts security control reviews in well defined areas. Assesses security of information and infrastructure components. Investigates and assesses risks of network attacks and recommends remedial action. Conducts business risk and vulnerability assessments and business impact analysis for medium complexity information systems. Reviews compliance with information security policies and standards. Assesses configurations and security procedures for adherence to legal and regulatory requirements. Reviews network usage. Assesses the implications of any unacceptable usage and breaches of privileges or corporate policy. Recommends appropriate action. Explains the purpose of and provides advice and guidance on the application and operation of elementary physical, procedural and technical security controls. (For example the key controls defined in IS27002). Communicates information assurance risks and requirements effectively to users of systems and networks. Investigates suspected attacks and undertakes the investigation and resolution of security incidents, in accordance with established procedures including incident management procedures. Uses forensics where appropriate . Reports on findings and lessons learnt / improvement actions. Delivers elements of the security components of system architectures. Investigates causes of incidents and seeks resolution.
Desired Candidate Profile
Qualifications: Bachelor s degree in Computer Science, Information Technology, Information Systems or other relevant discipline. Knowledge and/or Experience: 10 years Information Security experience ideally within the oil/gas industry. Conversant with relevant Information Security national and international standards. Attain and maintain experience in accordance with relevant IT competency frameworks. Good working knowledge of Information Security coupled with equivalent knowledge of the activities of those businesses and other organizations that employ IT. Understanding of the principles and practices involved in development and maintenance of Information Security requirements Technical and Business Skills: Assesses and evaluates risk and the impact of legislation, and actively promotes compliance. Possesses a good understanding of IT business applications. Effective and persuasive in both written and oral communication