الوصف الوظيفي
عن الوظيفة: أخصائي أمن "النقاط النهائية، منع تسريب البيانات وإدارة البيانات (عقد لمدة 12 شهرًا)
الوصف الوظيفي لدور أخصائي الأمن - محلل أمن النقاط النهائية وحماية تسريب البيانات
الهدف الأساسي من الدور: أخصائي الأمن مسؤول عن إدارة سياسات وممارسات أمن المعلومات والبيانات الخاصة بالمؤسسة لضمان قدرة المستخدمين المصرح لهم على الوصول إلى المعلومات بسهولة وحمايتها من حيث السرية والنزاهة والتوفر. واتباع إرشادات أفضل الممارسات الأمنية بشكل جيد. في هذا الدور، يجب التعامل مع جميع المسؤوليات المذكورة أدناه.
* إدارة الخدمات وتشغيل الخدمات
صياغة وحفظ السياسات والمعايير والإجراءات والوثائق الخاصة بالأمن. مراقبة تطبيق وإجراءات العمليات الأمنية والامتثال لها ومراجعة أنظمة المعلومات بحثًا عن أي انتهاكات فعلية أو محتملة للأمن. التأكد من التحقيق الفوري والشامل في جميع الانتهاكات الأمنية المحددة. التأكد من تنفيذ أي تغييرات في النظام مطلوبة للحفاظ على الأمن. التأكد من أن السجلات الأمنية دقيقة وكاملة.
* الاستراتيجية والمعمارية واستراتيجية المعلومات
الحصول على معلومات الثغرات الأمنية والتعامل وفقًا لها، وإجراء تقييمات المخاطر الأمنية لتطبيقات الأعمال والتركيبات المحوسبة؛ تقديم المشورة والتوجيه الموثوقين بشأن الاستراتيجيات الأمنية لإدارة المخاطر المحددة. التحقيق في الانتهاكات الأمنية الكبرى والتوصية بتحسينات الضوابط المناسبة. تفسير السياسة الأمنية والمساهمة في تطوير المعايير والإرشادات التي تتوافق معها. إجراء تقييم المخاطر وتحليل الأثر على الأعمال والاعتماد لجميع أنظمة المعلومات الرئيسية داخل المؤسسة. ضمان الاستجابة المتناسبة لمعلومات الثغرات الأمنية، بما في ذلك الاستخدام المناسب للأدلة الجنائية الرقمية.
* التخطيط والأولويات، التفكير وحل المشكلات
* مراعاة الأهداف والغايات المستقبلية للفريق/الوحدة والمؤسسة عند تحديد أولوية عملك وعمل الآخرين
* إطلاق واستشارة وتطوير أهداف واستراتيجيات وخطط الفريق/الوحدة وتحديد أولوياتها
* توقع وتعديل تقييم أثر التغييرات، مثل السياسات الحكومية/الظروف الاقتصادية، على أهداف الفريق/الوحدة وإطلاق الاستجابات المناسبة
* التأكد من أن خطط العمل والأنشطة الحالية تدعم مبادرات التغيير التنظيمي وتتوافق معها
* تقييم الإنجازات وتعديل المستقبل بناءً على ذلك
* التكنولوجيا
* إظهار فهم قوي للتكنولوجيا ذات الصلة بوحدة العمل، وتحديد واختيار التكنولوجيا الأكثر ملاءمة للمهام الموكلة
* تحديد الفرص لاستخدام مجموعة واسعة من تكنولوجيات الاتصالات لتوصيل رسائل فعالة
* فهم والعمل على ومراقبة الامتثال لسياسات أمن المعلومات والاتصالات واستخدامها
* تحديد طرق للاستفادة من قيمة التكنولوجيا لتحقيق نتائج الفريق/الوحدة، باستخدام التكنولوجيا الحالية للأعمال
* دعم الامتثال لمتطلبات إدارة السجلات والمعلومات والمعرفة في المؤسسة
* المسؤوليات والمهام الرئيسية
* تطوير وتطبيق وإدارة السياسات والبروتوكولات الأمنية لأجهزة النقاط النهائية بما في ذلك أجهزة أسطح المكتب، والأجهزة المحمولة، والهواتف الذكية، والخوادم.
* خبرة عملية تقنية في أمن النقاط النهائية
* فهم لأنظمة التشغيل، وبروتوكولات الشبكات، والأمن، وبيئات الإنترنت
* خبرة في تثبيت الأنظمة وتكوينها وإدارتها لأنظمة التشغيل والتطبيقات
* خبرة في تثبيت البيئة الأمنية وتكوينها ودمجها
* خبرة في استخدام جدران حماية التطبيقات، وجدران حماية SIEM، وIDS/IPS، إلخ.
* خبرة في منهجيات نشر برامج أسطح المكتب المؤسسية الشائعة
* تصميم وإنفاذ استراتيجيات لمنع نقل المعلومات الحساسة غير المصرح به. مراقبة وتحليل تدفقات البيانات لتحديد الانتهاكات المحتملة للبيانات والحد منها.
* العمل كمستجيب أول للحوادث الأمنية التي تتضمن أجهزة النقاط النهائية وتسريب البيانات. إجراء تحقيقات شاملة، وتوثيق النتائج، والتوصية بإجراءات المعالجة.
* المراقبة المستمرة للتهديدات والثغرات الأمنية المتعلقة بالنقاط النهائية. البقاء
على اطلاع بأحدث الاتجاهات الأمنية ومعلومات التهديدات لحماية
المؤسسة بشكل استباقي.
* التعاون مع فرق تكنولوجيا المعلومات والامتثال لتطوير وصيانة سياسات
ومعايير وإرشادات أمن النقاط النهائية. ضمان الامتثال للوائح الصناعة وأفضل
الممارسات.
* إدارة وتحسين الأدوات والتكنولوجيات الأمنية مثل برامج مكافحة الفيروسات، وحلول EDR، وXDR، وحلول التشفير، وأنظمة DLP. التأكد من تكوينها وتحديثها بفعالية.
* إنشاء تقارير منتظمة عن حالة أمن النقاط النهائية وجهود منع تسريب البيانات. تقديم الرؤى والتوصيات بناءً على التحليل والنتائج.
* خبرة في تقنيات تحليل البيانات وتقييم جودة البيانات
* امتلاك معرفة بأنشطة دورة حياة البيانات مثل تعاريف البيانات، وتسلسل البيانات (دورة حياة البيانات التي تتضمن أصول البيانات، وما يحدث وأين تنتقل بمرور الوقت) وجودة البيانات
* فهم كيفية استخدام البيانات ضمن عمليات الأعمال وتأثيرها على نتائج عمليات الأعمال المرجوة
* خبرة في تقنيات تحليل البيانات وتقييم جودة البيانات
* امتلاك معرفة بأنشطة دورة حياة البيانات مثل تعاريف البيانات وتسلسل البيانات وجودة البيانات
* المسؤولية عن إجراء تقييمات الثغرات الأمنية واختبارات الاختراق لتحديد
نقاط الضعف الأمنية، وتقييم المخاطر، والتوصية بإجراءات المعالجة.
* اتباع المسؤوليات الرئيسية للمنتجات والمعرفة الجيدة بأفضل ممارسات الأمن
* ما لا يقل عن 5-6 سنوات من الخبرة في الأمن السيبراني، ويفضل أن يكون ذلك في بيئة SOC.
* خبرة في الاستجابة للحوادث، وصيد التهديدات، وDLP، وإدارة الثغرات الأمنية.
* خبرة عملية في أدوات مراقبة أمن النقاط النهائية وتحليل DLP.
* خبرة في الأطر التنظيمية والامتثال مثل GDPR، وHIPAA، وNIA،
وإطار قطر 2022 للأمن السيبراني CSF، وISO 27001 تعتبر ميزة إضافية.
* معرفة قوية بحلول أمن النقاط النهائية، وتقنيات DLP، وبرامج مكافحة الفيروسات. إتقان الاستجابة للحوادث الأمنية وتحليل التهديدات.
* مهارات تحليلية وممتازة في حل المشكلات. القدرة على تحليل المشكلات الأمنية المعقدة وتطوير حلول فعالة.
* اهتمام كبير بالتفاصيل لضمان المراقبة والتحليل والتقارير الدقيقة.
* مهارات تواصل لفظية وكتابية قوية. القدرة على شرح المفاهيم الأمنية بوضوح
للجمهور الفني وغير الفني.
* القدرة على العمل التعاوني مع الفرق متعددة الوظائف وإظهار نهج استباقي
تجاه التحديات الأمنية.
* خبرة عمل مثبتة في Microsoft Antivirus وMicrosoft Defender XDR وEndgame EDR وMicrosoft DLP وMicrosoft Purview وMicrosoft Insider Risk Management وMicrosoft Priva أمر لا بد منه.
* خبرة عمل مع فاحصات الثغرات الأمنية مثل Tenable وBurp suite وغيرها.
* يجب أن يكون لديه معرفة بخصوصية البيانات وحماية البيانات.
Job description
About the job Security Specialist "End Point, DLP and Data mgmt. (12 month contract)
Security specialist Role Description- Endpoint Security and Data Leak Protection Analyst
Primary purpose of the role The Security specialist is responsible for the administration of the organization's information and data security policies and practices to ensure authorized users can readily access information and that the information is protected in terms of confidentiality, integrity and availability. Well follow security best practices guideline. In this role, need to handle all responsibility as following mentioned.
* Service Management and Service Operation
Drafts and maintains the policy, standards, procedures, and documentation for security. Monitors the application and compliance of security operations procedures and reviews information systems for actual or potential breaches in security. Ensures that all identified breaches in security are promptly and thoroughly investigated. Ensures that any system changes required to maintain security are implemented. Ensures that security records are accurate and complete.
* Strategy & Architecture and Information Strategy
Obtains and acts on vulnerability information and conducts security risk assessments for business applications and computer installations; provides authoritative advice and guidance on security strategies to manage the identified risk. Investigates major breaches of security and recommends appropriate control improvements. Interprets security policy and contributes to development of standards and guidelines that comply with this. Performs risk assessment, business impact analysis and accreditation for all major information systems within the organization. Ensures proportionate response to vulnerability information, including appropriate use of forensics.
* Plan and priorities, Think and Solve Problems
* Consider future aims and goals of the team/unit and organization when prioritizing own and others' work
* Initiate, priorities, consult on and develop team/unit goals, strategies, and plans
* Anticipate and assess the impact of changes, such as government policy/economic conditions, on team/unit objectives and initiate appropriate responses
* Ensure current work plans and activities support and are consistent with organizational change initiatives
* Evaluate achievements and adjust future accordingly
* Technology
* Demonstrate a sound understanding of technology relevant to the work unit, and identify and select the most appropriate technology for assigned tasks
* Identify opportunities to use a broad range of communications technologies to deliver effective messages
* Understand, act on and monitor compliance with information and communications security and use policies
* Identify ways to leverage the value of technology to achieve team/unit outcomes, using the existing technology of the business
* Support compliance with the records, information, and knowledge management requirements of the organization
* Key accountabilities and Responsibilities
* Develop, implement, and manage security policies and protocols for endpoint devices including desktops, laptops, mobile devices, and servers.
* Technical hands-on experience with endpoint security
* Understanding of operating system, networking protocols, security and Internet environments
* Experience with systems installation, configuration and administration of operating systems and applications
* Experience installing, configuring and integrating a security environment
* Experience using application firewalls, SIEM, IDS/IPS etc.
* Experience with common enterprise desktop software deployment methodologies
* Design and enforce strategies to prevent the unauthorized transmission of sensitive information. Monitor and analyze data flows to identify and mitigate potential data breaches.
* Act as a first responder to security incidents involving endpoint devices and data leaks. Conduct thorough investigations, document findings, and recommend remediation actions.
* Continuously monitor security threats and vulnerabilities related to endpoints. Stay
updated on the latest security trends and threat intelligence to proactively protect the
organization.
* Collaborate with IT and compliance teams to develop and maintain endpoint security
policies, standards, and guidelines. Ensure compliance with industry regulations and best
practices.
* Manage and optimize security tools and technologies such as antivirus software, EDR, XDR, encryption solutions, and DLP systems. Ensure they are effectively configured and updated.
* Generate regular reports on the status of endpoint security and data leak prevention efforts. Provide insights and recommendations based on analysis and findings.
* Experience with data analysis and data quality assessment techniques
* Possesses knowledge of data lifecycle activities such as data definitions, data lineage (data life cycle that includes the data's origins, what happens and where it moves over time) and data quality
* Understands how data is used within business processes and its impact on desired business process outcomes
* Experience with data analysis and data quality assessment techniques
* Possesses knowledge of data lifecycle activities such as data definitions, data lineage and data quality
* Responsible for conducting vulnerability assessments and penetration tests to identify
security weaknesses, evaluate risks, and recommend remediation measures.
* Following Products key responsibilities well know best practice security
* Minimum of 5-6 years of experience in cybersecurity, preferably within a SOC
environment.
* Experience in incident response, threat hunting, DLP, and vulnerability management.
* Hands-on experience with Endpoint security monitoring and DLP analysis tools.
* Experience with regulatory and compliance frameworks such as GDPR, HIPAA, NIA,
Qatar 2022 CSF, ISO 27001 is a plus.
* Strong knowledge of endpoint security solutions, DLP technologies, and antivirus software. Proficiency in security incident response and threat analysis.
* Excellent analytical and problem-solving skills. Ability to analyze complex security issues and develop effective solutions.
* High attention to detail to ensure accurate monitoring, analysis, and reporting.
* Strong verbal and written communication skills. Ability to clearly articulate security
concepts to technical and non-technical audiences.
* Ability to work collaboratively with cross-functional teams and demonstrate a proactive
approach to security challenges.
* Proven work experience with Microsoft Antivirus, Microsoft Defender XDR, Endgame EDR, Microsoft DLP, Microsoft Purview, Microsoft Insider Risk Management and Microsoft Priva is a must.
* Work experience with Vulnerability scanners like Tenable, Burp suite etc.
* Should have knowledge of data privacy and data protection.