Job description
The CSEA Contractor is expected to provide hands-on support to the Cyber Security
Engineering and Architecture section by contributing to security architecture
activities, technical security reviews, control implementation, risk
assessments and advisory services across enterprise systems, infrastructure,
cloud environments and applications.
The
contractor is expected to have:
- Hands-on experience with Enterprise Security Architecture methodologies and modern security technologies, including IAM, SIEM, EDR/XDR, WAF, SASE, Zero Trust, cloud security, and security automation tools.
- Strong knowledge of IT infrastructure security, including network security, cloud security, endpoint security, identity security, and secure architecture design principles.
- Strong knowledge of application security, including secure SDLC, DevSecOps, API security, secure coding practices, and application threat modeling.
- Experience implementing, validating, and reviewing security controls across IT infrastructure, cloud platforms such as AWS, Azure, and GCP, and enterprise applications.
- Experience developing, maintaining, and enhancing security control libraries, security patterns, baselines, and architecture standards, while ensuring their integration into security architecture and engineering activities.
- Strong understanding of cybersecurity standards, laws, and frameworks, including NIST, ISO/IEC 27001, CIS Controls, GDPR, PCI-DSS, and other relevant regulatory or compliance requirements.
- Strong understanding of cybersecurity best practices, including secure network architecture, endpoint protection, identity and access management, cloud security, DevSecOps, and defense-in-depth design.
- Experience conducting security design reviews, architecture assessments, threat modeling, technical risk assessments, and security gap assessments.
- Ability to support business units, project teams, IT teams, and security stakeholders in selecting, designing, and implementing secure information systems and technology solutions.
- Experience with security automation and scripting using tools and languages such as Python, PowerShell, Bash, Terraform, Ansible, or similar technologies.
- Ability to support security investigations, incident response activities, forensic analysis, root cause analysis, and post-incident improvement recommendations when required.
- Experience providing technical consultation and advisory support on CSEA-related projects, initiatives, and engagements as requested by the CSEA Section Head.
- Excellent ability to translate technical cybersecurity concepts, risks, and recommendations into clear business language for both technical and non-technical stakeholders.
- Experience participating in cybersecurity committees, technical working groups, architecture review boards, project meetings, and cross-functional security discussions.
- Strong problem-solving, analytical, and decision-support skills, with the ability to assess complex technical environments and recommend practical security solutions.
- Ability to work independently while also collaborating effectively with security architects, SOC analysts, IT teams, application teams, project managers, and business stakeholders.
- Excellent verbal and written communication skills, with the ability to document security findings, architecture recommendations, risks, and remediation actions clearly and professionally.
- Ability to mentor and support CSEA team members as needed by transferring knowledge, sharing technical expertise, and contributing to the development of internal cybersecurity engineering and architecture capabilities.
Key
Deliverables:
The
contractor may be expected to support or deliver:
- Security architecture reviews
- Security design review reports
- Threat models and risk assessments
- Security control mapping and recommendations
- Architecture patterns, baselines, and standards
- Technical security advisory reports
- Secure design recommendations for infrastructure, cloud, and applications
- Security improvement roadmaps
- Support for incident response, investigations, and technical analysis
- Knowledge transfer sessions for CSEA members
RequirementsEducation:
- Bachelor’s
degree in a technology-related field, such as Cybersecurity, Computer Science,
Computer Engineering, Information Security, Information Technology, or a
related discipline. A higher degree or relevant professional certifications are
preferred.
Experience:- Minimum of 10 years relevant experience in
cybersecurity, information security, security engineering, or IT infrastructure
security, with at least 3 years of hands-on experience in cybersecurity
architecture, security engineering, or enterprise security architecture.
Preferred Certifications:- CISSP, CISM, SABSA, or TOGAF certifications preferred.
- Cloud security certifications such as CCSP, Azure Security Engineer, or AWS Security Specialty preferred.
- Cybersecurity certifications such as GCIH, GCIA, GSEC, or Security+ preferred.
- Other relevant cybersecurity, cloud security, or architecture certifications considered.
Proficiency in English & Arabic is required.
وصف الوظيفة
من المتوقع أن يقدم CSEA المقاول دعمًا عمليًا لقسم هندسة وأرشفة الأمن السيبراني من خلال الإسهام في أنشطة بنية الأمن، ومراجعات الأمن الفني، وتنفيذ الضوابط، وتقييمات المخاطر وخدمات الاستشارة عبر أنظمة المؤسسة والبنية التحتية وبيئات السحابة والتطبيقات.
من المتوقع أن يمتلك المقاول التالي:
- خبرة عملية في مناهج هندسة الأمن المؤسسية وتقنيات الأمن الحديثة، بما في ذلك IAM، SIEM، EDR/XDR، WAF، SASE، Zero Trust، أمان السحابة، وأدوات أتمتة الأمن.
- معرفة قوية بأمان بنية تكنولوجيا المعلومات، بما في ذلك أمان الشبكات وأمان السحابة وأمان نقاط النهاية وأمان الهوية ومبادئ تصميم الهندسة الآمنة.
- معرفة قوية بأمان التطبيقات، بما في ذلك دورة حياة التطوير الآمنة (Secure SDLC)، DevSecOps، أمان API، ممارسات التشفير الآمن، ونمذجة تهديدات التطبيق.
- خبرة في تنفيذ والتحقق من ومراجعة الضوابط الأمنية عبر بنية IT التحتية والمنصات السحابية مثل AWS وAzure وGCP، وتطبيقات المؤسسة.
- خبرة في تطوير وصيانة وتحسين مكتبات الضوابط الأمنية وأنماط الأمان والخطوط الأساسية ومعايير الهندسة، مع ضمان تكاملها في أنشطة أمان الهندسة المعمارية والهندسة.
- فهم قوي لمعايير الأمن السيبراني والقوانين والأطر التنظيمية، بما في ذلك NIST وISO/IEC 27001 وCIS Controls وGDPR وPCI-DSS وغيرها من المتطلبات التنظيمية أو الامتثال ذات الصلة.
- فهم قوي لأفضل ممارسات الأمن السيبراني، بما في ذلك بنية الشبكة الآمنة، حماية نقاط النهاية، إدارة الهوية والوصول، أمان السحابة، DevSecOps، وتصميم الدفاع في العمق.
- خبرة في إجراء مراجعات تصميم الأمن وتقييمات الهندسة ونمذجة التهديدات وتقييمات المخاطر الفنية وتقييم فجوات الأمن.
- القدرة على دعم وحدات الأعمال وفرق المشاريع وفرق تكنولوجيا المعلومات وأصحاب المصلحة الأمنيين في اختيار وتصميم وتنفيذ أنظمة معلومات آمنة وحلول تكنولوجيا المعلومات.
- خبرة في الأتمتة الأمنية والبرمجة باستخدام أدوات ولغات مثل Python وPowerShell وBash وTerraform وAnsible أو تقنيات مماثلة.
- القدرة على دعم عمليات التحقيق الأمني وأنشطة الاستجابة للحوادث والتحليل الجنائي وتحليل السبب الجذري وتوصيات التحسين بعد الحادث عند الطلب.
- خبرة في تقديم الاستشارات الفنية والدعم الاستشاري في مشاريع ومبادرات وم engagements المرتبطة بـ CSEA وفقًا لطلب رئيس قسم CSEA.
- قدرة ممتازة على ترجمة مفاهيم الأمن السيبراني والتخفيف من المخاطر والتوصيات إلى لغة أعمال واضحة لأصحاب المصلحة teknية وغير teknische.
- خبرة في المشاركة في لجان الأمن السيبراني، وفرق العمل الفنية، ومجالس مراجعة الهندسة المعمارية، والاجتماعات المشاريع، ومناقشات الأمن عبر الوظائف.
- مهارات قوية في حل المشكلات والتحليل ودعم القرار، مع القدرة على تقييم بيئات تقنية معقدة وتقديم حلول أمانية عملية.
- القدرة على العمل بشكل مستقل وفي الوقت نفسه التعاون بفاعلية مع معماريي الأمن ومحللي SOC وفرق IT وفرقاء التطبيقات ومديري المشاريع وأصحاب المصلحة في العمل التجاري.
- مهارات تواصل شفهية وكتابية متميزة، مع القدرة على توثيق نتائج الأمن والتوصيات المعمارية والمخاطر وإجراءات الإصلاح بوضوح واحترافية.
- القدرة على توجيه ودعم أعضاء فريق CSEA حسب الحاجة من خلال نقل المعرفة ومشاركة الخبرة الفنية والمساهمة في تطوير قدرات الهندسة المعمارية والأمن السيبراني الداخلية.
المخرجات الرئيسية:
قد يُطلب من المقاول دعم أو تسليم:
- مراجعات بنية الأمن
- تقارير مراجعة تصميم الأمان
- نماذج التهديد وتقييمات المخاطر
- رسم خرائط الضوابط الأمنية وتوصياتها
- أنماط الهندسة والخطوط الأساسية والمعايير المعمارية
- تقارير استشارات الأمان الفنية
- توصيات تصميم آمن للبنية التحتية والسحابة والتطبيقات
- خرائط طريق لتحسين الأمن
- الدعم في الاستجابة للحوادث والتحقيقات والتحليل الفني
- جلسات نقل المعرفة لأعضاء CSEA
المتطلباتالتعليم:
- درجة البكالوريوس في مجال تقني، مثل الأمن السيبراني، علوم الحاسوب، هندسة الحاسوب، أمن المعلومات، تكنولوجيا المعلومات، أو تخصص ذو صلة. يفضل الحصول على درجة أعلى أو شهادات مهنية ذات صلة.
الخبرة:- حد أدنى 10 سنوات خبرة ذات صلة في الأمن السيبراني، أمن المعلومات، هندسة الأمن، أو أمان بنية IT، مع ما لا يقل عن 3 سنوات خبرة عملية في هندسة الأمن، هندسة الأمن، أو هندسة الأمن المؤسسي.
الشهادات المفضلة:- يفضل شهادات CISSP، CISM، SABSA، أو TOGAF.
- يفضل شهادات أمان السحابة مثل CCSP، مهندس أمان Azure، أو AWS Security Specialty.
- يفضل شهادات الأمن مثل GCIH، GCIA، GSEC، أو Security+.
- يُنظر في شهادات أخرى ذات صلة بالأمن السيبراني أو أمان السحابة أو الهندسة المعمارية.
إتقان اللغة الإنجليزية والعربية مطلوب.