Job Description
Roles & Responsibilities
Commissions the preparation and the implementation of necessary operational security software updates, firewall installation, hardware additions, and any authorized technical changes related to the security functions to ensure compliance both with internal security policies etc. and applicable laws and regulations required security levels.
Design and manage processes for detection, investigation, correction, and/or prosecution of operational security breaches, violations, and incidents.
Benchmark, analyze report on, and make recommendations for the improvement of Operational Technology (OT) security infrastructure.
Works with management to ensure that as new equipment, facilities, services, and systems are installed that the OT security issues are addressed.
Typically, a background in technical Operational Technology (OT) roles such as architecture, security program development or operations, with a clear and abiding interest in operational security.
Liaison with and offers technical direction to related operational security governance functions (such as Physical Security/Facilities, Risk Management, Legal and Compliance) plus senior and middle managers throughout the organization as necessary, on information security matters such as routine security activities plus emerging security risks and control technologies.
Plan, implement and upgrade security measures and controls.
Protect digital files and operational security systems against unauthorized access, modification, or destruction.
Maintain data and monitor/review security access authorizations.
Manage network, intrusion detection and prevention systems.
Work out on the security tools such as security asset inventory management and risk management reporting to security information and event management system (SIEM).
Define, implement, and maintain corporate security manuals, policies, procedures & instructions.
Coordinate further security plans, awareness received from vendors and take required actions.
Security assessments of network infrastructure, hosts and applications.
Work out on ICS security related audit findings and maintain corrective actions.
Download, validate and apply the latest Antivirus DAT file to AV server and ensure published to all ICS machines by continuously monitor the AV server dashboard.
Asset identification, monitoring and analysis using supportive tools (IPS, firewall log, system events and antivirus reports.
ICS Firewall Events log, DNS, Router, and switches Events log analysis.
Validation and deployment of firmware and software updates, deactivate of unnecessary software's or access.
Define and implement backup schedule for all ICS assets, System configuration backups, Machines image backups, Router and switches backups, FW backups.
Manage User accounts ICS, network, and security equipment.
Support Project execution team to integrate new Operational Technology (OT) system in Plant security framework.
Work out on Audit findings and observations.
Work out with ICS modifications as requested.
Collect and archive system logs, events, change logs, failure events etc. To support audit and forensic analysis.
Ensure that all implementation activities are complied with published ICS policies, instructions, procedures,
Desired Candidate Profile
Bachelor's Degree in Information security Technology, Computer Science or Electronic/Electrical Engineer.
Must be ICS certified from SANS, however following certificates will be great additional advantage for the candidate: -
GIAC GICSP (Global Industrial Cybersecurity Professional).
ISA CAP (Certified Automation Professional).
Cybersecurity for Automation, Control, and SCADA Systems (ISA-99/IEC-62443) - ISA
Advanced SCADA Security - Red Tiger/ any other vendor.
Industrial Cybersecurity for OPC - Matrikon/any other vendor.
OPC-UA Hands-on Training Level-3 - OPCTI.
3-5 years at least of field experience in OT Cybersecurity domain in Oil & gas & petrochemical industry.
Excellent knowledge of common IT/OT ICS specialization areas related to PLC's, DCS's, PDCS, Firewalls, networks, and switches.
Exposure of implementing IT/OT security policies and regulations.
Knowledge of international & national standards frameworks such as ISA99, IEC62433, IEC61511, IEC62351, IEC62591 ISO27001, 27002, 27005 Compliance regulations.
Extensive knowledge of several ICS DCS/PDCS/PLC/ESD/Servers, routers, switches & firewalls technologies within several OEM technologies such as, Siemens, HIMA, TRICONEX, HONEYWELL, GE, Allan Bradley, CISCO, MacAfee.
وصف الوظيفة
الأدوار والمسؤوليات
يقوم بإنشاء وتنفيذ التحديثات اللازمة لبرامج الأمان التشغيلي، وتثبيت جدران الحماية، وإ additions الهاردوير، وأي تغييرات تقنية مصرح بها تتعلق بوظائف الأمان لضمان الامتثال داخلياً لسياسات الأمان... وغيرها من المستندات وترخيصها. (يرجى الملاحظة: تم تقطيع النص الأصلي في الجزء التعليقات لتمكين الترجمة الصحيحة؛ إذا كان هناك جمل ناقصة في النص العربي، يرجى تزويدي بجملة كاملة.)
تصميم وإدارة العمليات للكشف والتحقيق والتصحيح و/أو المحاكمة لخرقات وأحداث الأمان التشغيلية.
المقارنة، تحليل التقرير وتقديم التوصيات لتحسين بنية أمان التكنولوجيا التشغيلية (OT).
يعمل مع الإدارة لضمان معالجة قضايا أمان OT عند تثبيت معدات جديدة ومنشآت وخدمات وأنظمة.
عادةً ما يكون لديه خبرة سابقة في أدوار تقنية OT مثل الهندسة المعمارية، وتطوير برامج الأمان أو العمليات، مع اهتمام واضح ودائم بالأمان التشغيلي.
التواصل وتقديم التوجيه الفني لوظائف الحوكمة الأمنية التشغيلية ذات الصلة (مثل الأمن الفيزيائي/المرافق، إدارة المخاطر، الشؤون القانونية والامتثال) بالإضافة إلى المدراء التنفيذيين والمتوسطين في جميع أنحاء المؤسسة حسب الضرورة، في مسائل الأمن المعلوماتي مثل أنشطة الأمن الروتينية إلى المخاطر الأمنية الناشئة وتكنولوجيات التحكم.
المخطط والتنفيذ والتطوير ل إجراءات ووسائل الأمان.
حماية الملفات الرقمية وأنظمة الأمان التشغيلية من الوصول غير المصرح به، والتعديل، أو التخريب.
الحفاظ على البيانات ومراجعة/مراقبة تفويضات الوصول الأمني.
إدارة الشبكات وأنظمة كشف ودفع الهجمات.
التعامل مع أدوات الأمن مثل إدارة مخزون أصول الأمن وتقرير إدارة المخاطر إلى نظام معلومات وأحداث الأمن (SIEM).
تعريف، تطبيق، والحفاظ على أدلة وسياسات الأمن المؤسسية والإجراءات والتعليمات.
تنسيق خطط الأمان الإضافية والتوعية المستلمة من الموردين واتخاذ الإجراءات اللازمة.
تقييمات أمنية للبنية التحتية للشبكة والمضيفات والتطبيقات.
التعامل مع نتائج تدقيق متعلقة بالأمان ICS والحفاظ على إجراءات تصحيحية.
تنزيل والتحقق وتطبيق أحدث ملف DAT لمضاد الفيروسات على خادم AV وضمان نشره على جميع أجهزة ICS من خلال مراقبة لوحة عرض خادم AV باستمرار.
تحديد الأصول، المراقبة والتحليل باستخدام أدوات داعمة (IPS، سجل الجدار الناري، أحداث النظام وتقارير مضاد الفيروسات).
تحليل سجلات أحداث جدار حماية ICS وDNS وRouter وSwitches.
التحقق ونشر تحديثات البر Firmware والبرامج، تعطيل البرامج غير الضرورية أو الوصول.
تحديد وتنفيذ جدول النسخ الاحتياطي لجميع أصول ICS، نسخ احتياطي لتكوين النظام، نسخ صور الأجهزة، نسخ احتياطي للموجهات والمفاتيح، نسخ FW.
إدارة حسابات المستخدم ICS، الشبكة، ومعدات الأمان.
دعم فريق تنفيذ المشروع لدمج نظام OT جديد في إطار أمان المصنع.
التعامل مع نتائج التدقيق والملاحظات.
التعامل مع تغييرات ICS كما هو مطلوب.
جمع وأرشفة سجلات النظام، الأحداث، سجلات التغيير، أحداث الفشل وغيرها لدعم التدقيق والتحليل الجنائي.
التأكد من أن جميع أنشطة التنفيذ متوافقة مع سياسات ICS المنشورة والإرشادات والإجراءات،
الملف المطلوب للمرشح
درجة البكالوريوس في تكنولوجيا أمن المعلومات، علوم الحاسوب أو الهندسة الإلكترونية/الكهربائية.
يجب أن يكون معتمد ICS من SANS، ومع ذلك ستعزز الشهادات التالية الميزة الإضافية للمرشح: -
GIAC GICSP (محترف الأمن السيبراني الصناعي العالمي).
ISA CAP (Professional Automation Certified).
Cybersecurity for Automation, Control, and SCADA Systems (ISA-99/IEC-62443) - ISA
Advanced SCADA Security - Red Tiger/أي بائع آخر.
Industrial Cybersecurity for OPC - Matrikon/أي بائع آخر.
OPC-UA Hands-on Training Level-3 - OPCTI.
خبرة ميدانية لا تقل عن 3-5 سنوات في مجال الأمن السيبراني OT في قطاع النفط والغاز والبتروكيماويات.
معرفة ممتازة بمجالات تخصص IT/OT ICS المتعلقة بـ PLCs، DCSs، PDCS، جدران الحماية، الشبكات والمفاتيح.
التعرض لتطبيق سياسات وأحكام الأمن IT/OT.
معرفة بإطارات المعايير الدولية والوطنية مثل ISA99، IEC62433، IEC61511، IEC62351، IEC62591 ISO27001، 27002، 27005 والامتثال.
معرفة واسعة بعدة تقنيات ICS DCS/PDCS/PLC/ESD/Servers، وأجهزة التوجيه والمفاتيح وجدران الحماية ضمن تقنيات OEM متعددة مثل سيمنز، HIMA، TRICONEX، هانيويل، GE، Allen Bradley، CISCO، McAfee.