Duties and Responsibilities
- Ability to work independently or under minimum supervision on all projects related to security thereby acting as a Subject Matter Expertise in the field
- Deploy and maintain Information Security solutions at ARO with proper planning, KPIs formulation and SLAs effective management with third party vendors.
- Evaluate and ensure security robustness to IT and security systems in specific.
- Manage and implement Infrastructure security and maintain proper reports for each IT domain respectively.
- Documents information security systems configuration and operational procedures, policy, and processes in line with GRC guidance, ARAMCO security standard, ISO 27001 and NCA recommendations.
- Investigate security breach following Incident management practices and internal procedures to guide IT management on restoration, recovery, and security requirements.
- Manage the periodic maintenance of security systems and applications to ensure new threats are identified and managed and the security of the organization’s assets are maintained and secured to the latest standards.
- Manage and continuously promote new ways to enhance the security, processes and procedures of end point security, AD, Network security, DLP, Security Operations Center, IT Asset Management security, Applications security, IT Incident Management, Penetration Testing, and all security solutions.
- Manage Security Operations Center process, handles alerts effectively in timely manner according to criticality, maintains KPIs, operationalize and maintains vulnerability management.
- Maintain security solutions contracts, license forecast for proper planning and budgeting, and technical healthiness and capacity.
- Coordinate security threat analysis and testing.
- Review threats and vulnerabilities periodically and document actions made.
- Document security breaches and assess the damage they cause.
- Lead the security team to perform tests and uncover network vulnerabilities.
- Ensure all IT systems and process are complied with IT Policy/Procedures and well documented.
- Foresee any opportunities of improvement and be an advocate to Implement next generation solutions to minimize the risk of cyber-attacks.
Qualifications & Experience
- Bachelor’s degree in computer science with experience within IT operations and security domains
- Previous experience working with offshore rigs and/or working on shore based
- Cisco CCNA Security Certification, CCNP Security Certification or CCSP is desirable
- Experience/understanding of ITIL methodology and ITSM in IT Services/Operations environmen
- Certified CISSP, CompTIA Security+, SSCP, CISM, or CISA as per seniority leve
Skills
- Excellent leadership and critical thinking skill
- Ability to communicate security concepts to a broad range audience (technical and non-technical
- Strong written and oral communication skill
- Good interpersonal skill
- Good understanding of the organization’s goals and objective
- Able to work both as part of a team or under own initiativ
- Able to take responsibility for own actions and performanc
- Have a positive attitude to customer problems and incidents in a high-pressured environmen
- Keen attention to detai
- The ability to multitask across multiple incident
- Understanding of SLAs and KPI
- Deliver on IT management security expectations and target