Information Security Specialist
Tamimi Commercial Information Security Specialist
Key Responsibilities: | | ||||||
| |||||||
1. Security Monitoring & Incident
Response | | ||||||
| |||||||
Monitor
networks and systems for security breaches or suspicious activity. | | ||||||
Investigate
and respond to security incidents and alerts. | | ||||||
Conduct
forensic analysis and root cause investigations. | | ||||||
| |||||||
2. Risk Management & Compliance | | ||||||
| |||||||
Perform
regular risk assessments and vulnerability scans. | | ||||||
Ensure
compliance with internal policies and external regulations (e.g., ISO 27001,
NCA, GDPR). | |||||||
Prepare
reports and documentation for audits and compliance reviews. | | ||||||
| |||||||
3. Security Architecture & Implementation | | ||||||
| |||||||
Assist
in designing and implementing secure network and system architectures. | | ||||||
Configure
firewalls, antivirus software, and intrusion detection/prevention systems. | |||||||
Manage
identity and access controls (IAM), encryption, and endpoint protection. | | ||||||
| |||||||
4. Policy Development & Awareness | | ||||||
| |||||||
Develop
and maintain security policies, procedures, and standards. | | ||||||
Conduct
security awareness training for employees. | | ||||||
Promote
a culture of cybersecurity across the organization. | | ||||||
| |||||||
5. Collaboration & Reporting | | ||||||
| |||||||
Work
with IT and business units to integrate security into projects and
operations. | |||||||
Report
security metrics and incidents to management. | | ||||||
Stay
updated on the latest threats, vulnerabilities, and technologies. | |
Requirements
Qualifications: | ||||||||
Bachelor’s
degree in Cybersecurity, Information Technology, or related field. | ||||||||
3+
years of experience in information security or related roles. | ||||||||
Strong
knowledge of security frameworks, tools, and technologies. | ||||||||
Familiarity
with SIEM, firewalls, endpoint protection, and vulnerability management. | ||||||||
Certifications
such as CISSP, CISM, CEH, or CompTIA Security+ are highly desirable. |