Lead Engineer - IT Cyber Security

Date: 11 Nov 2024

Location: Sohar, Al Batinah North, OM

Company: Sohar Aluminium LLC

JOB PURPOSE

  • Ensure implementation and maintenance of security controls to protect the organization's IT environment and data from various threats.
  • Identify vulnerabilities, respond to security incidents and ensure compliance with relevant IT regulations, policies, procedures, industry standards and guidelines.

Responsibilities

​​​​​​​3.1Threat Analysis and Response:

  • Manage SIEM Solution
  • Monitor for signs of suspicious behavior or potential security breaches
  • Investigate, respond to security incidents and conduct root cause analysis
  • Coordinate and collaborate with relevant teams for implementing remediation measures

​​​​​​​3.2 Incident Management:

  • Enhance incident detection capabilities
  • Keep incident response plans and procedures up to date
  • Coordinate and collaborate response efforts during IT security incidents, including communication with relevant teams

⠀⠀

3.3 Vulnerability Management:

  • Manage vulnerability management solution
  • Conduct regular vulnerability assessments & penetration testing to identify and address security weaknesses in IT environment
  • Coordinate and collaborate with relevant teams to apply patches and updates to address vulnerabilities in operating systems, applications, databases, security appliances and network devices

3.4 Deployment, Rollout, and Management of Projects & Security Solutions:

  • Assist in IT security projects including planning, execution and delivery.
  • Execute deployment plans for Security Solutions
  • Integrate security solutions into the existing IT environment​​​​​​​
  • Automate routine security tasks
  • Monitor Security solutions’ health and performance

⠀⠀

3.5 Compliance and Risk Management:

  • Ensure compliance with relevant IT regulations, policies, procedures, industry standards and guidelines
  • Participate in risk assessments and report risks and coordinate and collaborate with relevant teams to execute risk treatment plans.

​​​​​​​3.6 Security Awareness and Training:

  • Conduct security awareness training for employees to promote best practices and awareness of potential threats.
  • Keep training materials and resources updated to educate staff on security policies and procedures.

 

⠀⠀

​​​​​​3.7 Collaboration and Coordination:

  • Coordinate and collaborate with Automation, Infrastructure, Network, Back-office, Help Desk, Business Applications teams  to ensure security measures are integrated into systems and processes.
  • Work with third-party vendors and partners to evaluate and implement security solutions and practices.

3.8 Documentation and Reporting:

  • Maintain accurate and up-to-date documentation and records of security vulnerabilities, risks, configurations, incidents, response, activities.
  • Prepare and present security reports, highlighting key metrics, trends, and areas for improvement.

Requirements

Essential Qualifications, Experience and Skills

  • Bachelor’s degree in information security, Cyber Security, Computer Science, Networking or equivalent degree
  • Minimum of 5 years of experience in Information Technology including Information Security or Cyber Security
  • Appropriate security certificates such as: Security+, CEH, CSA, CHFI, SIEM certification and any other related certificates

⠀⠀

Technical Experience

  • Solid technical knowledge and background of current and emergining  cyber tecnologies and practices
  • Experience and knowledge in asset security, security engineering, communications and network security, identity and access management, security assessment and testing, security operations, software development security, authentication, authorization, and accountability, cryptography foundations, information security and risk management principles, network foundations, incident management, compliance with international standards such as ISO 27001, NIST, etc.
  • Skills including presentation and communication
  • Excellent English language skills are essential