Job description
Role Purpose
The Cybersecurity Engineer is responsible for the day-to-day security of KDF's information systems, applications, networks, and digital services. The role covers security monitoring, vulnerability management, and incident handling, and contributes to KDF's cybersecurity governance, risk, and compliance activities under the direction of the Divisional Head – Technology & Digitalization Transformation. The position reports to the Assistant Manager – Technology & Cybersecurity.
As KDF's first dedicated cybersecurity position, the role suits a practitioner who can assess the current environment, identify gaps, and recommend practical improvements rather than wait for direction. The role also offers direct involvement in KDF's ISO 27001 certification programme.
Key Roles and Responsibilities
- Run day-to-day security monitoring across endpoint protection platforms and Microsoft Defender, investigating and escalating alerts as required.
- Investigate suspicious activity, phishing reports, and identity-related security events through to resolution.
- Conduct vulnerability scans, assess and prioritise findings, and drive remediation with infrastructure and application teams until closure.
- Handle cybersecurity incidents, including containment, evidence collection, root-cause review, and documentation.
- Administer and review multi-factor authentication, Conditional Access policies, privileged accounts, and periodic user access reviews.
- Assess KDF's current security posture, identify control gaps, and recommend improvements with clear justification and priority.
- Maintain the cybersecurity risk register and contribute to the development of policies, standards, and procedures.
- Support KDF's ISO 27001 certification programme, including control implementation, evidence preparation, and closure of nonconformities within agreed timelines.
- Maintain security records and evidence, including access review records, incident logs, vulnerability scan results, and remediation history.
- Support internal and external audits by preparing evidence and tracking closure of findings and corrective actions.
- Contribute to alignment with the NIST Cybersecurity Framework and applicable Kuwait regulatory requirements.
- Support the evaluation and implementation of additional security capabilities, including centralised log management and SIEM.
- Deliver cybersecurity awareness activities, including phishing simulations and refresher training.
- Prepare regular security reports and dashboards for management, highlighting risks, trends, and recommended actions.
Skills
Requirements
- Bachelor's degree in Computer Science, Information Technology, Computer Engineering, Management Information Systems, or a related discipline. A degree or specialisation in Cybersecurity is an advantage.
- Minimum five years of hands-on cybersecurity experience, including direct responsibility for monitoring and incident handling.
- Practical working experience with Microsoft Defender for Endpoint and Office 365, and Microsoft Entra ID, including Conditional Access and MFA administration.
- Experience with vulnerability scanning tools and end-to-end remediation follow-up.
- Exposure to SIEM or centralised log management platforms, ideally Microsoft Sentinel.
- Working knowledge of ISO 27001 and the NIST Cybersecurity Framework. Prior involvement in an ISO 27001 implementation or certification is a strong advantage.
- Sound judgement and the ability to work independently in a small team with limited supervision.
- Clear written and spoken English, with the ability to explain security matters to non-technical colleagues.
Certifications
- CompTIA Security+ or Microsoft SC-200 required, or willingness to obtain within the first year.
- Microsoft SC-300, CEH, or ISO 27001 Lead Implementer an advantage.
وصف الوظيفة
الغرض من الدور
يكون مهندس الأمن السيبراني مسؤولاً عن الأمن اليومي لأنظمة معلومات كِ.د.ف، وتطبيقاتها، وشبكاتها، وخدماتها الرقمية. يغطي الدور المراقبة الأمنية، وإدارة الثغرات، والتعامل مع الحوادث، ويساهم في حوكمة الأمن السيبراني والمخاطر والامتثال في كِ.د.ف تحت إشراف رئيس القسم – التكنولوجيا والتحول الرقمي. يبلغ الموقع إلى مساعد المدير – التكنولوجيا والأمن السيبراني.
بوصفه أول موقع مركّز للأمن السيبراني في كِ.د.ف، يناسب الدور ممارساً يمكنه تقييم البيئة الحالية، وتحديد الثغرات، وتقديم تحسينات عملية بدلاً من انتظار التوجيه. كما يُتيح الدور مشاركة مباشرة في برنامج اعتماد ISO 27001 التابع لكِ.د.ف.
الأدوار والمسؤوليات الأساسية
- إجراء المراقبة الأمنية اليومية عبر منصات حماية نقاط النهاية وMicrosoft Defender، والتحقيق في التنبيهات وتصعيدها حسب الحاجة.
- التحقيق في الأنشطة المشبوهة، وتقارير التصيد، وأحداث الأمان المرتبطة بالهوية حتى الحل النهائي.
- إجراء فحوص الثغرات، وتقييم النتائج وأولويتها، والدفع بالتصحيح مع فرق البنية التحتية والتطبيق حتى الإغلاق.
- التعامل مع حوادث الأمن السيبراني، بما في ذلك الاحتواء، وجمع الأدلة، ومراجعة السبب الجذري، والتوثيق.
- إدارة ومراجعة المصادقة متعددة العوامل، وسياسات الوصول المشروط، والحسابات المميزة، ومراجعات وصول المستخدمين الدورية.
- تقييم وضع الأمان الحالي للمؤسسة، وتحديد فجوات الرقابة، وتقديم تحسينات مع مبررات واضحة وأولويات.
- الحفاظ على سجل مخاطر الأمن السيبراني والمساهمة في تطوير السياسات والمعايير والإجراءات.
- دعم برنامج اعتماد ISO 27001 في كِ.د.ف، بما في ذلك تطبيق الضوابط، وإعداد الأدلة، وإغلاق عدم المطابقة ضمن الجداول الزمنية المتفق عليها.
- الحفاظ على سجلات الأمن والأدلة، بما في ذلك سجلات مراجعة الوصول، وسجلات الحوادث، ونتائج فحص الثغرات، وسجل الإصلاح.
- دعم التدقيقات الداخلية والخارجية من خلال إعداد الأدلة وتتبع إغلاق النتائج والإجراءات التصحيحية.
- المساهمة في التوافق مع إطار عمل NIST للأمن السيبراني والمتطلبات التنظيمية الكويتية المعمول بها.
- دعم تقييم وتنفيذ قدرات أمنية إضافية، بما في ذلك إدارة السجلات المركزية وSIEM.
- تنفيذ أنشطة التوعية بالأمن السيبراني، بما في ذلك محاكاة التصيد وتدريبات التحديث.
- إعداد تقارير أمنية ولوحات معلومات دورية للإدارة، مع إبراز المخاطر والاتجاهات والإجراءات الموصى بها.
المهارات
المتطلبات
- درجة البكالوريوس في علوم الحاسوب، تكنولوجيا المعلومات، هندسة الحاسوب، نظم معلومات الإدارة، أو تخصص ذو صلة. يعتبر الحصول على تخصص في الأمن السيبراني ميزة.
- خمسة أعوام على الأقل من الخبرة العملية في الأمن السيبراني، بما في ذلك المسؤولية المباشرة عن المراقبة والتعامل مع الحوادث.
- خبرة عملية مع Microsoft Defender for Endpoint وOffice 365، وMicrosoft Entra ID، بما في ذلك إدارة الوصول المشروط و MFA.
- خبرة باستخدام أدوات فحص الثغرات والمتابعة الشاملة للإصلاح.
- Exposure إلى SIEM أو منصات إدارة السجلات المركزية، ويفضل Microsoft Sentinel.
- معرفة عملية بـ ISO 27001 وإطار عمل NIST للأمن السيبراني. المشاركة السابقة في تنفيذ أو اعتماد ISO 27001 ميزة قوية.
- حُجْج سليمة وقدرة على العمل بشكل مستقل ضمن فريق صغير بإشراف محدود.
- إنجليزية مكتوبة ومحادثة واضحة، مع القدرة على شرح قضايا الأمن لزملاء غير الفنيين.
الشهادات
- يتطلب شهادة CompTIA Security+ أو Microsoft SC-200، أو الرغبة في الحصول عليها خلال السنة الأولى.
- ميزة الحصول على Microsoft SC-300، CEH، أو ISO 27001 Lead Implementer.