Cyber Security Defense Senior Specialist

Alfalak Electronic Equipment & Supplies Co. — جدة - منطقة مكة المكرمة — دوام كامل

Key Responsibilities:

Vulnerability management and Penetration testing

• Develop, review and update penetration testing methodologies, ensuring comprehensive coverage and adherence to industry best practices.

• Conduct threat modelling and vulnerability assessments to identify potential weaknesses in infrastructure, applications, and systems and provide recommendations for remediation.

• Coordinate penetration testing, source code review, application security testing, and red teaming activities.

• Responsible for vulnerability scanning activities on systems and assets, Vulnerability scanners health and deployment across the different segments of network, configuration review, and all associated activities related to vulnerability management preparation of vulnerability reports to IT.

• Follow-up on vulnerability remediation status and actions taken in coordination with IT department.

• Maintain vulnerability management KPI and follow up remediation with IT security for identified vulnerabilities.

Threat Hunting and Threat Management

• Responsible for threat intelligence activities, and coordination of threat hunting activities.

• Manage compromise assessment, Yara scanning, and sigma scanning activities to identify and address potential breaches and preparation of reports for IT actions accordingly.

• Triage and resolve advanced vector attacks such as botnets and advanced persistent threats (APTs).

• Gather and analyze threat intelligence from internal and external sources.

• Follow updates on threats posted or received from relevant authorities and ensure these updates are reflected on IT systems as applicable.

• Monitor external data sources to keep understanding of emerging cybersecurity threats and determine which security issues may have an impact on the organization.

SOC monitoring & Cyber incident management

• Responsible for the monitoring and investigation of Cybersecurity events and incidents and act as first responder forensics analysis and investigation.

• Maintain an incident repository for organization incidents with different incident classifications.

• Correlate incident data to identify vulnerabilities and help in coordinating a mitigation for these vulnerabilities that might impact the company.

• Use knowledge of threat actors and activities to prepare organization's response to a cyber incident.

• Implement the containment strategy during data loss or breach events.

• Analyse malicious activity to determine vulnerabilities exploited, exploitation methods and effects on system and information.

• Responsible to work with the SOC all raised cyber security incidents.

• Implement the event management processes.

• Responsible for onboarding the new assets to extend SOC monitoring over them.

• Responsible for the SIEM health status and coordinating any required activity related to the SIEM with the outsourced vendor.

• Provide use case creation/tuning recommendations to administrators based on findings during investigations or threat reviews.

• Monitor the performance on all outsourced functions to SOC to ensure vendor conformance to agreed SLAs and KPIs.

QUALIFICATIONS:

• Bachelor’s degree in computer science, Information Technology

• Experience with Security Assessment tools

• Experience in Vulnerability management and Penetration testing

• Knowledge of SIEM solutions

• Knowledge of log formats and ability to aggregate and parse log data for syslog, http logs, DB logs for investigation purposes.

• In-depth experience with log search tools

• Relevant professional certificates in Certified Incident Handler (GCIH), Certified Threat Intelligence Analyst (CTIA), Certified Digital Forensics Examiner (CDFE), Offensive

• Security Certified Professional, Certified Ethical Hacker (CEH), and Certified Web Assessor (OSWA) certification are highly desirable.

التقديم على هذه الوظيفة

جاري التحميل...