Job Summary
The Security Lead will be responsible for the implementation, maintenance, and support of our security systems and procedures. This includes performing regular system audits, preparing security reports, and upgrading our systems to provide maximum security
Key Accountabilities
Attending and participating in Townhalls.Self-Performance Tracking.Self-Career Path Tracking.Self-Development Tracking.Conduct analysis and provide security design requirements for existing or new systems and infrastructure, data, software and facilities.Lead the resolution of security related incidents and provide support.Lead the Group's security awareness program.Provide expert consultation about his/her area of expertise.Directs product strategy for a specific security products, new or established.Provides advice and guidance on the response action plans for information risk events and incidents based on Incident type and severity.Utilize SIEM data and correlated logs containing IDS/IPS, AV, web application firewalls, Operating System events, web proxy, and similar data to establish context and scope.Provide investigation/project assistance by obtaining and analyzing supporting records including customer, company and public records.Assist in the maintenance of Corporate Security’s case file systems.Respond to cyber-security threats, vulnerabilities, events and incidents.Act as technical contributor during major security incidents.Perform the deployment, integration and initial configuration of all new security solutions enhancements to existing security solutions in accordance with standards and best practices.Identify new security protection technologies to enhance business services.Provides project support for security functions.Maintain and operate associated security platforms.Work to identify critical event data for additional analysis and escalation as appropriate.Collaborate with supplier's technical teams and other provider staff as required to mitigate security threats and respond to incidents.Work closely with others to develop and enhance security monitoring, incident response plans and playbooks.Seek to continuously improve event correlation and alerting processes and use cases to detect potential incidents.Mentor, train and encourage more junior staff members.Ensure that all Service Level Agreements pertaining to security events/incidents are met.Perform intrusion analysis in a 24x7x365 environment using SIEM technology, packet captures, reports, data visualization and raw log analysis.First point of escalation and mentor for Security Analysts.Adhere to the architectural design and principles of the enterprise
Knowledge, Skills and Aptitude
- Educational Qualifications and Certifications: Bachelor’s degree in CS/IT/IS/IMS or equivalent, Master’s degree and or equivalent professional certificates are preferred
- Knowledge: DevSecOps.Cybersecurity.Section IV Competency Requirements at L2 preferred L3.Knowledge in one of the following: ERP, HCM, CRM, MS 365, EAM, CMS, SCM, KMS, BI, etc.Knowledge in IT infrastructure.Knowledge in enterprise software.Knowledge of architecture, and design best practices.Knowledge of risk assessment tools, technologies and methods.Knowledge of disaster recovery, computer forensic tools, technologies and methods.Participate In Networking Architecture
- Technical Skills: Understanding of latest security principles, techniques, and protocols.Experience designing secure networks, systems and application architectures.Experience planning, researching and developing security policies, standards and procedures.Experience in data, network and internet security protocols.Proven work experience as a Security Analyst or similar role
- Language Skills: Fluency in both English and Arabic
- Experience: Minimum 6 years working experience same or similar solution.Minimum 6 years’ experience in one of the career paths (business analyst, software engineer, system engineer)
Key Interactions
- Key Internal Contacts: DSD Team.Operational Product Owners
- Purpose of Interaction: Discuss issues on procedure, and configuration changes. Taking directions, and recommendations.
- Key External Contacts: Vendors & Suppliers.Government
- Purpose of Interaction: Manage third party implementation, support, licensing, and contracts.Ensure the continuous compliance with regulations
- Direct Reports: N/A