أرسل لي وظائف مثل هذه
الخبرة
8 - 15 سنوات
الراتب الشهري
($6,481 - $7,561) ر.ق 24,000 - 28,000
التعليم
بكالوريوس في التكنولوجيا/ الهندسة(أي)
الجنسية
أي مواطن عربي, أي مواطن دول مجلس التعاون الخليجي, البحريني
جنس
أي
عدد الشواغر
1 عدد الشواغر
الوصف الوظيفي
الأدوار والمسؤوليات
Security Configuration Assessment (IT & OT)
• Perform detailed configuration assessments of IT and OT environments against CIS Benchmarks, NIST guidelines, and internal standards.
• Review firewall rulesets ensuring least privilege, network segmentation, and policy compliance.
Assess network devices (routers, switches, load balancers, SSE/SASE gateways) for secure configurations.
• Validate OS hardening, patch compliance, and configuration baselines.
• Evaluate Network Access Control (NAC) configurations for effective coverage and policy enforcement.
• Recommend configuration hardening measures to reduce attack surface and improve resilience.
• Review SASE/SSE deployments to ensure secure access, data protection, and consistent policy enforcement.
Technical Risk Identification
• Identify and assess technical security risks across IT, OT, and cloud assets.
• Conduct or coordinate penetration testing of cloud workloads, web applications, APIs, and internal infrastructure.
• Perform container and Kubernetes security assessments (GKE, AKS).
• Map findings from vulnerability scans, pen tests, and configuration reviews to operational and business impacts.
• Conduct red team and adversary simulation exercises to validate detection and response capabilities.
• Contribute to risk documentation, validation, and reporting for management visibility.
Vulnerability Remediation Management
• Track, monitor, and manage vulnerabilities across IT and OT environments.
• Prioritize vulnerabilities based on risk, exploitability, and business impact.
• Coordinate with infrastructure, application, and OT teams to ensure timely remediation and validation of fixes.
• Maintain dashboards and executive summaries showing vulnerability trends and remediation metrics.
Security Assurance
• Develop and manage security assurance programs across IT, OT, and cloud domains.
• Track and report Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) to measure program effectiveness.
• Conduct periodic control and compliance reviews to validate adherence to baselines and risk mitigation plans.
• Identify and document gaps or deviations and drive remediation through collaboration with responsible teams.
الملف الشخصي المطلوب للمرشحين
8+ years of hands-on experience of experience in security assessment, penetration testing, and security assurance.
Arabic Speaker is preferred
• Demonstrated experience in both manual and automated penetration testing, including red team/adversary simulation exercises.
• Deep understanding of security configuration benchmarks and risk assessment methodologies.
• Strong technical expertise in GCP and Azure cloud environments.
• Hands-on experience with: Firewall rule reviews and network device configuration assessments, OS and application hardening and OT/ICS security assessments.
• Proficiency in tools such as Burp Suite, Metasploit, Nmap, Nessus, Qualys, Wireshark.
• Experience with cloud-native security services (GCP Security Command Center, Azure Defender, Prisma Cloud CNAPP).
• Familiarity with regulatory frameworks such as ISO 27001, NIST CSF, IEC 62443, Qatar NIA, QCSF.
• Strong analytical, problem-solving, and communication skills.
Education:
• Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience).
Certifications:
• CISSP, OSCP, OSEP, CRISC, OSCE, CCSK, CRTE.
• Cloud Specific Certifications (GCP Professional Cloud Security Engineer, Azure Security Engineer Associate), GICSP - preferred
Required Skillsets:
• In-depth knowledge of security assurance frameworks and vulnerability management processes.
• Expertise in firewall configuration auditing, network segmentation, and zero trust architecture.
• Proficiency in conducting manual and automated penetration testing and red teaming assessments.
• Proficiency in cloud security controls, Kubernetes/container security, and IaC security validation.
• Strong understanding of OT and ICS security principles.
• Familiarity with threat modeling, control validation, and risk reporting.
• Ability to translate complex technical findings into business risk context and provide actionable recommendations.
• Excellent report writing and presentation skills for both technical and executive stakeholders
نوع العمل
- دوام كامل
القطاع المهني للشركة
- تكنولوجيا المعلومات - خدمات البرمجيات
المجال الوظيفي / القسم
- إدارة النظام
- إدارة الشبكات
- الأمن (برامج تكنولوجيا المعلومات)
الكلمات الرئيسية
- Security Operations Officer
- Cybersecurity Specialist
- Security Engineer
- Cloud Security
- Information Security Officer
- Security Specialist
تنويه: نوكري غلف هو مجرد منصة لجمع الباحثين عن عمل وأصحاب العمل معا. وينصح المتقدمون بالبحث في حسن نية صاحب العمل المحتمل بشكل مستقل. نحن لا نؤيد أي طلبات لدفع الأموال وننصح بشدة ضد تبادل المعلومات الشخصية أو المصرفية ذات الصلة. نوصي أيضا زيارة نصائح أمنية للمزيد من المعلومات. إذا كنت تشك في أي احتيال أو سوء تصرف ، راسلنا عبر البريد الإلكتروني abuse@naukrigulf.com
Starlink WLL
Mohamed Shiras - Recruiter
PO Box 201213 Level 20, Manarat Tower Lusail, Doha, Qatar
وظائف مماثلة
أخصائي أمن المعلومات
Dicetek LLC
- 7 - 14 سنوات
- دبي - الإمارات العربية المتحدة
Information Security Officer
INTALEQ
- 8 - 15 سنوات
- Doha - Qatar
Security Operations Officer- Data Security Specialist
INTALEQ
- 8 - 15 سنوات
- Doha - Qatar
Advisor Security & Crisis Management
Oman Investment Authority
- 14 - 16 سنوات
- Muscat - Oman
مدير الأمن السيبراني
Client of Ethics HR
- 8 - 13 سنوات
- القاهرة - مصر