远程工作雷达

网络安全专员

Cyber Security Specialist

开发工程职能支持未标注地域
公司Smartera 3S
薪资未公开
工作地点Egypt
地域资格未标注地域
时区要求日间重叠约 3 小时,需偶尔早起或晚睡
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →

我们寻找一位有5年以上经验的网络安全专家,以保护组织的系统、网络和数据免受安全威胁。理想的候选人将监控安全基础设施,识别漏洞,响应事件,并在IT环境中实施安全控制和最佳实践。该职位位于埃及,远程工作以支持组织在沙特阿拉伯王国(KSA)的运营和系统。

主要职责

  • 监控安全系统、网络和应用程序中的可疑活动和潜在威胁
  • 对系统、网络和应用程序进行漏洞评估和渗透测试
  • 调查、响应并修复安全事件和泄露
  • 实施和管理安全工具,如防火墙、IDS/IPS、SIEM、EDR和杀毒软件解决方案
  • 对基础设施和应用程序进行定期安全审计和风险评估
  • 制定、更新并执行安全策略、标准和流程
  • 管理身份和访问管理(IAM),包括用户配置、基于角色的访问和特权访问管理
  • 为员工开展安全意识培训和钓鱼模拟活动
  • 与IT和开发团队合作,将安全嵌入系统设计和SDLC(DevSecOps)
  • 进行日志分析和威胁狩猎,主动检测异常
  • 管理补丁管理和漏洞修复流程
  • 确保符合监管和行业标准(ISO 27001、NIST、GDPR、PCI-DSS等)
  • 准备事件报告、安全评估和审计文档
  • 跟踪最新的威胁、漏洞和安全技术
  • 支持KSA的合规工作(NCA ECC、PDPL、SAMA CSF,视情况而定),包括审计和与KSA姐妹实体合规团队的协调

要求

  • 计算机科学、信息安全或相关领域的学士学位
  • 5年以上网络安全、信息安全或相关领域的实际工作经验
  • 熟悉网络安全概念(防火墙、VPN、IDS/IPS、网络分段)
  • 有使用SIEM工具(Splunk、QRadar、ArcSight或类似工具)进行监控和分析的经验
  • 有使用漏洞评估和渗透测试工具(Nessus、Qualys、Burp Suite、Metasploit)的实际经验
  • 熟悉终端安全、EDR等技术
查看英文原文

We are looking for an experienced Cyber Security Specialist with 5+ years of experience to protect theorganization's systems, networks, and data from security threats. The ideal candidate will monitor securityinfrastructure, identify vulnerabilities, respond to incidents, and implement security controls and bestpractices across the IT environment. This role is based in Egypt, working remotely to support theorganization's operations and systems in the Kingdom of Saudi Arabia (KSA).

Key Responsibilities

  • Monitor security systems, networks, and applications for suspicious activity and potential threats
  • Conduct vulnerability assessments and penetration testing on systems, networks, and applications
  • Investigate, respond to, and remediate security incidents and breaches
  • Implement and manage security tools such as firewalls, IDS/IPS, SIEM, EDR, and antivirus solutions
  • Perform regular security audits and risk assessments across infrastructure and applications
  • Develop, update, and enforce security policies, standards, and procedures
  • Manage identity and access management (IAM), including user provisioning, role-based access, andprivileged access management
  • Conduct security awareness training and phishing simulation campaigns for employees
  • Collaborate with IT and development teams to embed security into system design and SDLC (DevSecOps)
  • Perform log analysis and threat hunting to detect anomalies proactively
  • Manage patch management and vulnerability remediation processes
  • Ensure compliance with regulatory and industry standards (ISO 27001, NIST, GDPR, PCI-DSS, etc.)
  • Prepare incident reports, security assessments, and documentation for audits
  • Stay current with emerging threats, vulnerabilities, and security technologies
  • Support KSA regulatory compliance efforts (NCA ECC, PDPL, SAMA CSF where applicable), includingaudits and coordination with the KSA sister entity's compliance team

Requirements

  • Bachelor's degree in Computer Science, Information Security, or related field
  • 5+ years of hands-on experience in cyber security, information security, or a related role
  • Strong knowledge of network security concepts (firewalls, VPNs, IDS/IPS, network segmentation)
  • Experience with SIEM tools (Splunk, QRadar, ArcSight, or similar) for monitoring and analysis
  • Hands-on experience with vulnerability assessment and penetration testing tools (Nessus, Qualys, BurpSuite, Metasploit)
  • Solid understanding of endpoint security, EDR/XDR solutions, and antivirus management
  • Experience with identity and access management (IAM), MFA, and privileged access management (PAM)
  • Knowledge of security frameworks and standards (ISO 27001, NIST CSF, CIS Controls)
  • Understanding of cloud security principles (AWS/Azure/GCP security controls)
  • Familiarity with incident response processes and digital forensics fundamentals
  • Knowledge of encryption, PKI, and secure communication protocols
  • Scripting skills (Python, PowerShell, or Bash) for automation and analysis
  • Strong understanding of OWASP Top 10 and secure coding principles
  • Knowledge of KSA regulatory requirements, including NCA Essential Cybersecurity Controls (ECC),SDAIA's Personal Data Protection Law (PDPL), and SAMA Cyber Security Framework where applicable tofinancial operations

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位