يبحث بنك لشا عن أفضل الكفاءات وألمع العقول للمساهمة في مرحلة النمو الحالية التي يشهدها البنك. نحن نبحث عن أفراد من الطراز الأول يتمتعون بالشغف والحرص على إضافة قيمة ملموسة منذ اليوم الأول. كل يوم في بنك لشا مختلف، ويقدم تحديات جديدة مع فرص للمساهمة والنمو. نحن نبحث حالياً عن محلل للأمن السيبراني والبنية التحتية.
الغرض من الدور: يقدم محلل الأمن السيبراني والبنية التحتية قدرات تنفيذية قائمة على الخبرة عبر عمليات البنية التحتية والسحابة والأمن السيبراني للبنك، وذلك ضمن الاستراتيجيات والمعايير والتوجيهات التي يحددها رئيس قسم الأمن السيبراني والبنية التحتية. وبالاستناد إلى خبرة عملية واسعة، يتولى هذا الدور الإدارة اليومية للبنية التحتية، ومراقبة الأمن، والأنشطة التشغيلية عبر البيئات المحلية والمستضافة والسحابية - مع ممارسة حكم سليم وقائم على الخبرة لحل المسائل بشكل مباشر عند الاقتضاء، وتصعيد تلك التي تتطلب مزيداً من التوجيه أو الإرشاد - وذلك لدعم مرونة البنية التحتية للبنك ووضعه الأمني.
المسؤوليات:
دعم عمليات البنية التحتية والسحابة: دعم وإدارة البنية التحتية للبنك عبر البيئات المحلية والمستضافة والسحابية، بما في ذلك الشبكات والخوادم والتخزين والمحاكاة الافتراضية وحوسبة المستخدم النهائي. تنفيذ الإدارة اليومية لمنصات البنية التحتية الأساسية، بما في ذلك المحاكاة الافتراضية للخوادم، وخدمات الدليل والهوية، وأنظمة البريد الإلكتروني والرسائل، وأنظمة قواعد البيانات، ونسخ البيانات الاحتياطي والتخزين للمؤسسات. اتباع ممارسات إدارة الخدمات المتوافقة مع ITIL عبر عمليات البنية التحتية، والتي تغطي إدارة الحوادث والمشاكل والتغيير. إدارة نظام مكتب المساعدة/إدارة الخدمات الخاص بالبنك، وضمان استخدامه بفعالية وتسجيل التذاكر وتتبعها وحلها بشكل صحيح.
التعافي من الكوارث واستمرارية الأعمال: إدارة تخطيط وتمارين التعافي من الكوارث للبنية التحتية، وإجراء الاختبارات مقابل أهداف التعافي المحددة. إدارة تقنيات تكرار البيانات التي تدعم بيئات الإنتاج والتعافي من الكوارث.
الأمن السيبراني: إدارة الوضع الأمني السيبراني اليومي للبنك، بما في ذلك مراقبة التهديدات، والاستجابة للحوادث، وإدارة الثغرات الأمنية، وأنشطة تخفيف المخاطر. إدارة العلاقة مع مركز العمليات الأمنية (SOC) للبنك، وتنسيق المراقبة والتنبيه وتصعيد الحوادث. إدارة أدوات الأمن الأساسية، بما في ذلك أمن البريد الإلكتروني وحماية النقاط الطرفية. تنفيذ ضوابط منع فقدان البيانات وحماية/تصنيف المعلومات بما يتماشى مع الاستراتيجية والتوجيهات المحددة من قبل وظيفة أمن المعلومات. إدارة الوصول المشروط وتكوين أمن النقاط الطرفية للوصول عبر الأجهزة المحمولة وأجهزة الموظفين الشخصية (BYOD). إدارة أنشطة التحكم السيبراني التي تدعم متطلبات المخاطر والامتثال والتدقيق الداخلي.
التنفيذ والتصعيد: تنفيذ تغييرات البنية التحتية والأمن بما يتماشى مع المعايير والعمليات التي يحددها رئيس قسم الأمن السيبراني والبنية التحتية، مع تصعيد القرارات التي تتطلب الموافقة أو التوجيه الاستراتيجي. توفير قدرات تنفيذية رفيعة المستوى عبر مسارات عمل البنية التحتية والأمن السيبراني، لضمان استمرارية العمليات في جميع الأوقات.
دعم الموردين والأصول: إدارة التعامل اليومي مع موردي البنية التحتية والأمن. الحفاظ على سجلات جرد وأصول أجهزة وبرامج تكنولوجيا المعلومات.
الشراكة التجارية: العمل كنقطة اتصال رئيسية لفرق التطبيقات وأصحاب المصلحة في الأعمال وأمن المعلومات فيما يتعلق بمتطلبات البنية التحتية والأمن للمشاريع والمبادرات.
التحسين المستمر: تحديد وتنفيذ الفرص بشكل استباقي لتحسين استخدام البنية التحتية وأدائها. المساهمة في التحسين المستمر لتوثيق الحوكمة والعمليات، مع الامتثال لسياسة المؤسسة.
مؤشرات الأداء الرئيسية (KPI): لقياس ومراقبة أداء الدور في سياق أنشطة القسم/الإدارة: توفر البنية التحتية: وقت تشغيل البنية التحتية الأساسية وخدمات الرسائل مقابل الأهداف المحددة؛ دعم التعافي من الكوارث: الإنجاز في الوقت المناسب لاختبارات التعافي من الكوارث ومهام تكرار البيانات الموكلة؛ الوضع الأمني السيبراني: دقة وتوقيت أنشطة المراقبة والتنبيه ومعالجة الثغرات الأمنية؛ تنفيذ التغيير: جودة ودقة تغييرات البنية التحتية والأمن المنفذة؛ إدارة التذاكر/الخدمة: دقة وتوقيت حل وتصعيد تذاكر مكتب المساعدة.
الحد الأدنى من الخبرة والمعرفة الأساسية: خبرة 12+ عاماً في إدارة الأنظمة والشبكات والبنية التحتية ضمن بيئات المهام الحرجة عالية التوفر، بما في ذلك خبرة كبيرة في العمل بقدر كبير من الاستقلالية؛ خبرة داخل بنك أو شركة استثمار أو مؤسسة خدمات مالية منظمة أخرى، والعمل على مستوى رفيع؛ خبرة عملية واسعة في بنية Microsoft التحتية للمؤسسات (خدمات الدليل، المحاكاة الافتراضية، البريد الإلكتروني/الرسائل، أنظمة قواعد البيانات) والنسخ الاحتياطي/التخزين للمؤسسات؛ معرفة متقدمة بمستوى الممارس بأساسيات الأمن السيبراني: مراقبة التهديدات، الاستجابة للحوادث، إدارة الثغرات؛ خبرة في المنصات السحابية وبيئات البنية التحتية الهجينة؛ القدرة على المبادرة الذاتية، والقدرة على الاستفادة من الخبرة التقنية العميقة لحل المشكلات بشكل مستقل وممارسة حكم سليم بشأن متى يجب التصعيد مقابل التصرف. درجة البكالوريوس في علوم الكمبيوتر أو تخصص ذي صلة؛ مطلوب شهادة مهنية ذات صلة تغطي الأمن و/أو البنية التحتية السحابية (مثل Security+ أو CySA+ أو شهادة بنية Microsoft/Azure أو ما يعادلها)؛ ويفضل الحصول على شهادة متقدمة مثل CISSP أو CISM.
الكفاءات الأساسية: عمليات البنية التحتية والسحابة، مراقبة الأمن السيبراني والاستجابة له، التنفيذ ضمن المعايير المحددة، دعم الموردين والأصول، عقلية التحسين المستمر.
Lesha Bank is searching for the greatest talent and brightest minds to contribute to the current growth phase at our bank. We are looking for top-tier individuals who are passionate and hungry to add value from day one. Every day at Lesha is different, presenting a new challenge with the opportunity to contribute and grow. We are looking for an Cybersecurity & Infrastructure Analyst.
Purpose of the role:The Cybersecurity & Infrastructure Analyst provides experienced, execution capacity across the Bank's infrastructure, cloud, and cybersecurity operations, operating within the strategy, standards, and direction set by the Cybersecurity & Infrastructure Lead. Drawing on significant hands-on experience, the role carries out day-to-day infrastructure administration, security monitoring, and operational activity across on-premise, hosted, and cloud environments — exercising sound, experience-based judgment to resolve matters directly where appropriate, and escalating those requiring further guidance or direction — in support of the Bank's infrastructure resilience and cybersecurity posture.
RESPONSIBILITIES:
Infrastructure & Cloud Operations Support and administer the Bank's infrastructure estate across on-premise, hosted, and cloud environments, including networks, servers, storage, virtualization, and end-user computing. Carry out day-to-day administration of core infrastructure platforms, including server virtualization, directory and identity services, email and messaging systems, database systems, and enterprise backup and storage. Follow ITIL-aligned service management practices across infrastructure operations, covering incident, problem, and change management. Manage the Bank's help desk/service management system, ensuring it is used effectively and tickets are properly logged, progressed, and resolved.
Disaster Recovery & Business Continuity Manage infrastructure disaster recovery planning and exercises, conducting testing against defined recovery objectives. Administer data replication technologies supporting production and DR environments.
Cybersecurity Manage the Bank's day-to-day cybersecurity posture, including threat monitoring, incident response, vulnerability management, and risk mitigation activity. Manage the relationship with the Bank's Security Operations Center (SOC), coordinating monitoring, alerting, and incident escalation. Administer core security tooling, including email security and endpoint protection. Execute data loss prevention and information protection/classification controls in line with strategy and direction set by the Information Security function. Manage conditional access and endpoint security configuration for mobile and BYOD access. Manage cyber control activity supporting Risk, Compliance, and Internal Audit requirements.
Delivery & Escalation Carry out infrastructure and security changes in line with standards and processes set by the Cybersecurity & Infrastructure Lead, escalating decisions requiring sign-off or strategic direction. Provide senior delivery capacity across infrastructure and cybersecurity workstreams, ensuring continuity of operations at all times.
Vendor & Asset Support Manage day-to-day engagement with infrastructure and security vendors. Maintain IT hardware and software inventory and asset records.
Business Partnership Act as a senior point of contact for application teams, business stakeholders, and Information Security on infrastructure and security requirements for projects and initiatives.
Continuous Improvement Proactively identify and implement opportunities to optimize infrastructure utilization and performance. Contribute to continual improvement of governance and process documentation, complying with organizational policy.
KEY PERFORMANCE INDICATORS (KPI) To measure and monitor the performance of the role in the context of the Section/Department's activities Infrastructure availability: uptime of core infrastructure and messaging services against defined targets DR support: timely completion of assigned DR testing and replication tasks Cybersecurity posture: timeliness of monitoring, alerting, and vulnerability remediation activity Change execution: quality and accuracy of infrastructure and security changes carried out Ticket/service management: timeliness and quality of help desk ticket resolution and escalation
Minimum Experience & Essential Knowledge12+ years of experience in systems, network, and infrastructure administration within mission-critical, high-availability environments, including significant experience operating with a high degree of autonomy Experience within a bank, investment firm, or other regulated financial services organization, operating at a senior level Extensive hands-on experience with enterprise Microsoft infrastructure (directory services, virtualization, email/messaging, database systems) and enterprise backup/storage Advanced, practitioner-level knowledge of cybersecurity fundamentals: threat monitoring, incident response, vulnerability management Experience with cloud platforms and hybrid infrastructure environments A proven self-starter, able to draw on deep technical experience to resolve issues independently and exercise sound judgment on when to escalate versus act. Bachelor's degree in Computer Science or a related discipline Relevant industry certification required, covering security and/or cloud infrastructure (e.g., Security+, CySA+, Microsoft/Azure infrastructure certification, or equivalent); advanced certification such as CISSP or CISM preferred
Core Competencies Infrastructure & Cloud Operations Cybersecurity Monitoring & Response Execution within Defined Standards Vendor & Asset Support Continuous Improvement Mindset