Cybersecurity Engineer
الوصف الوظيفي
Job Purpose
The Cybersecurity Engineer plays a pivotal role in safeguarding the organization’s critical information assets, systems, and networks by designing, implementing, operating, and continuously enhancing robust technical security controls. This position demands a blend of strategic foresight, deep technical acumen in cybersecurity technologies, and the capability to respond decisively to security incidents within a highly regulated operational framework. The ideal candidate will demonstrate exceptional analytical skills, a proactive approach to risk mitigation, and a commitment to maintaining the highest standards of data integrity and confidentiality.
Key Responsibilities
The Cybersecurity Engineer is entrusted with a diverse range of responsibilities to ensure the integrity, availability, and confidentiality of the organization’s digital infrastructure. Core duties include:
- Security Architecture and Implementation: Developing, deploying, and maintaining comprehensive security measures to protect data, systems, and networks from evolving cyber threats. This involves evaluating current security postures, identifying gaps, and implementing tailored solutions to fortify the organization’s defenses.
- Incident Detection and Response: Proactively monitoring security systems to detect anomalies, investigating potential breaches, and executing rapid response protocols to mitigate risks and minimize impact. The role requires a hands-on approach to troubleshooting security and network issues, ensuring minimal disruption to business operations.
- Data Protection and Compliance: Managing and configuring advanced Data Loss Prevention (DLP) solutions, including the creation, tuning, and maintenance of DLP policies to prevent unauthorized data exfiltration. Additionally, the engineer will enforce robust data classification frameworks and implement stringent data protection controls across the enterprise.
- Device and Identity Management: Administering Mobile Device Management (MDM) solutions to secure both corporate-owned and Bring Your Own Device (BYOD) endpoints. The role also involves managing Identity and Access Management (IAM) controls, including user access provisioning, role-based access control (RBAC), and conducting periodic access reviews to ensure adherence to the principle of least privilege.
- Security Technology Operations: Operating, configuring, and monitoring core security technologies such as firewalls, Virtual Private Networks (VPNs), Intrusion Detection/Prevention Systems (IDS/IPS), web proxies, and endpoint protection solutions. The engineer will ensure these systems are optimized for performance and aligned with the organization’s security policies.
- Regulatory Compliance and Reporting: Ensuring all security controls are implemented and managed in strict accordance with the National Cybersecurity Authority’s (NCA) Cybersecurity Essential Controls (ECC) framework. The engineer will support compliance assessments, audits, and reporting to demonstrate adherence to regulatory requirements and industry best practices.
- Vulnerability Assessment and Risk Mitigation: Conducting regular testing to identify vulnerabilities within networks and systems, and implementing remediation strategies to address identified risks. This includes performing penetration testing, security assessments, and collaborating with cross-functional teams to enhance the organization’s security posture.
- Administrative and Communication Duties: Managing daily security operations, generating comprehensive reports, and maintaining clear communication channels with relevant departments to ensure alignment on security initiatives and incident response efforts.
Requirements
Education and Certifications
To qualify for this role, candidates must possess:
- A Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Systems Engineering, or a closely related field.
- Certified Information Systems Security Professional (CISSP) certification, demonstrating a high level of expertise and commitment to the cybersecurity profession.
Professional Experience
Applicants should have a minimum of four years of hands-on experience in:
- Incident detection and response within security operations environments.
- Designing, implementing, and managing security solutions in enterprise settings.
Language Proficiency
Fluency in Arabic and advanced proficiency in English are essential to effectively collaborate with global teams and stakeholders.
Technical Skills and Competencies
The ideal candidate will exhibit strong technical expertise in the following areas:
- Firewall Management: Extensive experience in the configuration, operation, and maintenance of firewall solutions to protect network perimeters.
- Cloud and Endpoint Security: Proficiency in Office 365 Security, VSX, and endpoint security solutions to safeguard cloud-based and on-premises environments.
- Networking Fundamentals: A solid understanding of networking concepts, protocols, and infrastructure security to design and maintain secure network architectures.
- Scripting and Programming: Competency in one or more scripting or programming languages, such as Python, PowerShell, C++, Java, or Ruby, to automate security tasks and develop custom security tools.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.