الوصف الوظيفي
Development of the system’s security testing and maintenance. Analyze the security of processes and integrated systems; apply the principles of cyber-security architecture targeting the services to meet the requirements of encryption, management of authority, confidentiality, safety, and availability. Coordinate with SOC service providers and internal Networks team to proactively manage any network security risks
Main tasks:
Conduct cyber-security testing for the exported applications and/or systems to ensure that they include cyber-security functions such as encryption, access control and identity management.
apply the principles of cyber-security architecture targeting the services to meet the requirements of encryption, management of authority, confidentiality, safety and availability.
Apply cyber-security policies and controls to overlapping applications, such as business-to-business transactions.
Integrate the automated capabilities to update or repair the system software with respect to cyber-security, wherever applicable; and issue the processes and procedures for manually updating and repairing the system software, based on the schedule requirements for current and projected update and fixes packages for the system’s operational environment.
Ensure the implementation of security updates and fixes for commercial products embedded in the system design in accordance with the timeframes provided by the relevant management in the respective operating environment, ensuring cyber protection to all its core functions.
Carry out authorized breaches of computer systems, networks, and their locations using realistic threat methods to assess their security and detect potential vulnerabilities.
Perform several types of cybersecurity assessments at the infrastructure or applications level, including vulnerability scanning, experimental breaches, and intrusion testing.
Use multiple methods of testing through simulating the attacks used by social engineering hackers attempting to breach the system, use social engineering to detect security vulnerabilities (such as security practices or weak password policies).
Prepare assessment reports after breach testing activities are completed, which include results, risk level, mitigation suggestions, and all the technical details needed to duplicate the test results.
Collect information on networks using traditional and alternative methods (such as social network analysis, call chaining, traffic analysis), and document the findings.
Study, document, and discuss security findings with management, leadership, and IT teams, provide advice about the methods to address or reduce system security risks.
المهارات
Technical competencies:
Know tools of designing systems and methods of cybersecurity.
Know the concepts and protocols of computer networks and methodologies of network security.
Know the principles and methods of IT security (such as: firewalls, neutral networks and encryption).
Know processes of system engineering.
Know software engineering.
Know the principles, tools and methods of penetration testing.
Know how to use multiple tactics to simulate attacks used by social engineer to attempt hacking system.
Know the tools of decryption, password and remote access methods.
Know the devices of physical and logical networks, and infrastructure for integrating hubs, routers, switches, firewalls… etc.
Know the arising problems, risks and security gaps.
Behavioral and artistic competencies:
Problem Solving
Communication with individuals and leaders
Strategic Thinking
Analytical Thinking
Critical Thinking
تفاصيل الوظيفة
منطقة الوظيفة المملكة العربية السعودية
قطاع الشركة خدمات الدعم التجاري الأخرى
طبيعة عمل الشركة صاحب عمل (القطاع الخاص)
الدور الوظيفي تكنولوجيا المعلومات
نوع التوظيف دوام كامل
الراتب الشهري غير محدد
عدد الوظائف الشاغرة غير محدد
المرشح المفضل
المستوى المهني متوسط الخبرة
عدد سنوات الخبرة الحد الأدنى: 4
الشهادة بكالوريوس/ دبلوم عالي
العمر الحد الأقصى: 40
https://www.bayt.com/ar/saudi-arabia/jobs/security-operations-center-soc-analyst-4459059/