Job description
BUSINESS UNIT STATEMENT
To support our business strategy and digital transformation, AXA is setting up a new information security practice to ensure a coordinated response to the increasing threat of cybersecurity, enabling consistent decision-making across the organization.
Our vision of information security is to protect our stakeholders by securing our information resources, managing our cyber risks and enabling effective and efficient business strategies that are fully sponsored by executives and supported by all AXA employees.
MISSION
The main mission of the Security Engineer Vulnerability and threat Management is to perform scans and reports using the Qualys Guard tool.
You’ll be responsible of performing and scheduling compliance and vulnerability scans on AXA network activity and infrastructure and generating reports to different teams (such as server admins, network administrators in order to mitigate scanned vulnerabilities).
The role consists also of integrating and managing different assets in the Qualys Guard modules.
Security Management:
- Conduct vulnerability scanning and assessment functions related to various clients, environments, technologies, systems and appliances
- Coordinate effectively with representatives of different Business Units and technology specialists
- Integrate and manage assets in Qualys
- Effectively communicate security vulnerabilities and risks to issue owners and assist in remediation efforts
- Govern and enforce cybersecurity policies and vulnerability remediation deadlines
- Develop and maintain executive dashboards and/or regular reports to communicate department-specific cybersecurity risks and threats
Reporting Service:
• Provide a monthly/Weekly analysis of common vulnerabilities and compliance issues
• Produce a periodic dashboard demonstrating remediation progress and cases’ status
QUALIFICATIONS
Education
- Minimum Bac+5 in Networks and Security.
Certification
- An information Security Certification is highly desired (CCNA R&S, CCNA Security, NSE4, PCCSA, MCSA, CEHv9/v10…or/and equivalent)
Work Ethics
- Due to the sensitive nature of the task, the role holder must have a demonstrated high level of work ethics, secrecy and discretion. A background check will be performed.
Overall work experience in the field:
- Global technical vision of the main security tools / environments:
PKI, SIEM, SOC, authentication, IPSEC, AD security, operating system security, Windows account security
- Experience managing data security programs like Password Vaulting, Privileged Access Management (Cyber Ark)
- Experience with Identity Management concepts and processes including authorization, authentication, segregation of duties
- Knowledge of best practices around data security
- Experience using an ITSM tool such as ServiceNow
- Strong fundamentals in networking protocols and troubleshooting
- Knowledge of hacking techniques, cyber threats and security trends
- At least 2 years’ experience in the cybersecurity industry
SKILLS & ABILITIES
- Experience with vulnerability management tools (e.g. Kenna, Nexpose, Tenable, Qualys, etc.)
- Hands-on experience with Qualys, a certification is a plus
- Work on maturing vulnerability management & Compliance program services and processes
- Develop and improve KPIs, metrics, and trend analysis for vulnerability management functions
- Take part of the implementation and operational best practices while taking ownership of tasks and/or project workstreams
- PowerShell and Python scripting skills
- Coding skills, such as HTML, CSS, Power Query and other languages
- Analytical thinking, time management and coordination skills
- Fluent English (Very important)
وصف العمل
بيان وحدة الأعمال
لدعم استراتيجية أعمالنا وتحولنا الرقمي، تقوم AXA بإعداد ممارسة جديدة للأمن information security لضمان استجابة منسقة لتزايد تهديدات الأمن السيبراني، مما يمكن من اتخاذ قرارات متسقة عبر المنظمة.
رؤيتنا للأمن المعلوماتي هي حماية أصحاب المصلحة من خلال securing مواردنا المعلوماتية، إدارة مخاطرنا السيبرانية وتمكين استراتيجيات أعمال فعالة وكفؤة مدعومة من قبل المدراء التنفيذيين وموظفي AXA جميعاً.
المهمة
المهمة الرئيسية لمهندس الأمن المعني بإدارة الثغرات والتهديدات هي إجراء فحوصات وتقارير باستخدام أداة Qualys Guard.
ستكون مسؤولاً عن إجراء وجدولة فحص الامتثال والثغرات على نشاط شبكة AXA وبنيتها التحتية وتوليد تقارير لمختلف الفرق (مثل مديري الخوادم، مديري الشبكات من أجل التخفيف من الثغرات التي تم فحصها).
كما تتضمن الدور أيضاً دمج وإدارة أصول مختلفة في وحدات Qualys Guard.
إدارة الأمن:
- إجراء فحص الثغرات وتقييمها المرتبط بمختلف العملاء والبيئات والتقنيات والأنظمة والأجهزة
- التنسيق بشكل فعال مع ممثلي وحدات الأعمال المختلفة والمتخصصين في التكنولوجيا
- دمج وإدارة الأصول في Qualys
- التواصل الفعال حول الثغرات الأمنية والمخاطر لمالكي القضايا والمساعدة في جهود الإصلاح
- حكم وفرض سياسات الأمن السيبراني ومواعيد الإصلاح
- تطوير وصيانة لوحات القيادة التنفيذية و/أو تقارير دورية لنقل مخاطر وتهديدات الأمن السيبراني الخاصة بالقسم
خدمة التقارير:
• تقديم تحليل شهري/أسبوعي لثغرات الشائعة وقضايا الامتثال
• إعداد لوحة معلومات دورية تُظهر تقدم الإصلاح وحالة الحالات
المؤهلات
التعليم
- حد أدنى Bac+5 في الشبكات والأمن.
الشهادة
- شهادة أمن معلوماتي مفضلة للغاية (CCNA R&S، CCNA Security، NSE4، PCCSA، MCSA، CEHv9/v10…أو/و ما يعادلها)
أخلاقيات العمل
- نظرًا لطبيعة المهمة الحساسة، يجب أن يتمتع حامل الدور بمستوى عالٍ من أخلاقيات العمل، السرية والتقدير. سيتم إجراء فحص خلفية.
الخبرة العملية الإجمالية في هذا المجال:
- رؤية تقنية عالمية لأدوات الأمن الرئيسية/البيئات:
PKI، SIEM، SOC، المصادقة، IPSEC، أمان AD، أمان نظام التشغيل، أمان حساب Windows
- خبرة في إدارة برامج أمن البيانات مثل Password Vaulting، Privileged Access Management (Cyber Ark)
- خبرة بمفاهيم وعمليات إدارة الهوية بما في ذلك التفويض، المصادقة، فصل الواجبات
- معرفة أفضل الممارسات حول أمن البيانات
- خبرة باستخدام أداة ITSM مثل ServiceNow
- أسس قوية في بروتوكولات الشبكة واستكشاف الأخطاء
- معرفة بأساليب الاختراق والتهديدات السيبرانية واتجاهات الأمن
- خبرة لا تقل عن سنتين في صناعة الأمن السيبراني
المهارات والقدرات
- خبرة مع أدوات إدارة الثغرات (مثل Kenna، Nexpose، Tenable، Qualys، إلخ)
- خبرة عملية مع Qualys، الشهادة ميزة إضافية
- العمل على نضوج خدمات وعمليات برنامج إدارة الثغرات والامتثال
- تطوير وتحسين مقاييس الأداء KPI والمتابعة والتحليل للثغرات
- المشاركة في تنفيذ وتبني أفضل الممارسات أثناء تحمل مسؤوليات المهام و/أو مسارات المشروع
- مهارات PowerShell وPython للبرمجة
- مهارات التشفير، مثل HTML، CSS، Power Query ولغات أخرى
- التفكير التحليلي، إدارة الوقت وتنسيق المهام
- الإنجليزية بطلاقة (مهم جدًا)