إنوفيشن تيم تعلن عن وظيفة مشرف Keycloak أول في الرياض
تفاصيل الوظيفة
شركة إنوفيشن تيم تبحث عن Senior Keycloak Administrator للعمل في الرياض، المملكة العربية السعودية. في هذا الدور، ستتولى قيادة تصميم وتنفيذ وإدارة البنية التحتية للهوية والوصول (IAM) باستخدام Keycloak، وضمان المصادقة والترخيص الآمنين لتطبيقات المؤسسة، وتحسين أداء النظام، والتعاون مع الفرق المشتركة لدمج Keycloak مع البيئات السحابية والمحلية.
المهام والمسؤوليات
- إدارة وتكوين Keycloak: تثبيت وتكوين وصيانة خوادم Keycloak، بما في ذلك إدارة العالمات (realms)، وربط المستخدمين (مثل LDAP/AD)، وتطوير السمات والواجهات المخصصة لصفحات تسجيل الدخول والتسجيل ولوحات الإدارة.
- تصميم وتنفيذ حلول IAM: تصميم ونشر حلول مصادقة/ترخيص آمنة باستخدام Keycloak ودعم بروتوكولات OIDC وOAuth2 وSAML؛ الدمج مع التطبيقات الداخلية/الخارجية وواجهات API وخدمات الطرف الثالث لاتحاد الهوية.
- إدارة البنية التحتية: إدارة مجموعات Keycloak (clustering) والإتاحة العالية (high-availability) وضبط الأداء والمراقبة؛ التعامل مع الترقيات والنسخ الاحتياطية وتعطيل الكوارث لضمان تشغيل بنسبة 99.9%.
- الأمان والامتثال: تطبيق التحكم في الوصول القائم على الأدوار (RBAC) والأذونات الدقيقة والسياسات؛ إجراء تدقيقات أمنية وتقييمات للثغرات وضمان الامتثال لمعايير مثل GDPR وHIPAA أو SOC 2.
- استكشاف الأخطاء وتحسين الأداء: تشخيص وحل الحوادث المتعلقة بفشل المصادقة ومشكلات الرموز (tokens) أو مشكلات التكامل؛ تحسين قابلية التوسع (scalability) لـ Keycloak في البيئات السحابية (مثل AWS وAzure) أو البيئات المختلطة.
- التعاون والتوثيق: العمل مع فرق التطوير و DevOps والأمان لتقديم إرشادات حول أفضل الممارسات؛ الاحتفاظ بتوثيق شامل للتكوينات والعمليات وأدلة استكشاف الأخطاء.
- التطوير المخصص (حسب الحاجة): تطوير وصيانة إضافات Keycloak المخصصة أو المزوّدين (providers) أو البرامج النصية باستخدام Java أو REST API لتلبية الوظائف المخصصة.
الشروط والمتطلبات
- خبرة لا تقل عن 5 سنوات في إدارة IAM، مع 3 سنوات على الأقل تركيز على Keycloak، وسجل حافل في نشر حلول المؤسسات.
- خبرة متقدمة مع ميزات Keycloak (العالمات، العملاء، الأدوار، المستخدمين، الأحداث، وAdmin REST API).
- معرفة قوية ببروتوكولات الهوية (OAuth2، OIDC، SAML، JWT) والأدوات المرتبطة (مثل LDAP وKerberos).
- خبرة في العمل مع الحاويات (Docker وKubernetes) والمنصات السحابية (AWS وAzure).
- الإلمام بقواعد البيانات (PostgreSQL وMySQL) لتخزين Keycloak وأدوات المراقبة (Prometheus وGrafana).
عرض النص الأصلي للإعلان
We are seeking an experienced Senior Keycloak Administrator to lead the design, implementation, and ongoing management of our identity and access management (IAM) infrastructure using Keycloak. In this role, you will ensure secure authentication and authorization for enterprise applications, optimize system performance, and collaborate with cross-functional teams to integrate Keycloak with cloud and on-premises environments. The ideal candidate has deep expertise in Keycloak administration, a strong understanding of security protocols like OAuth2, OIDC, and SAML, and the ability to troubleshoot complex issues in high-availability setups
Requirements
Keycloak Administration and Configuration: Install, configure, and maintain Keycloak servers, including realm management, user federation (e.g., LDAP/AD integration), and custom theme/UI development for login, registration, and admin consoles.
IAM Solution Design and Implementation: Design and deploy secure authentication/authorization solutions using Keycloak, supporting protocols such as OIDC, OAuth2, and SAML; integrate with internal/external applications, APIs, and third-party services for identity federation.
Infrastructure Management: Manage Keycloak clustering, high-availability setups, performance tuning, and monitoring; handle upgrades, backups, and disaster recovery to ensure 99.9% uptime.
Security and Compliance: Implement role-based access control (RBAC), fine-grained permissions, and policies; conduct security audits, vulnerability assessments, and ensure compliance with standards like GDPR, HIPAA, or SOC 2.
Troubleshooting and Optimization: Diagnose and resolve incidents related to authentication failures, token issues, or integration problems; optimize Keycloak for scalability in cloud (e.g., AWS, Azure) or hybrid environments.
Collaboration and Documentation: Work with development, DevOps, and security teams to provide guidance on best practices; maintain comprehensive documentation for configurations, processes, and troubleshooting guides
Custom Development (as needed): Develop and maintain custom Keycloak extensions, providers, or scripts using Java or REST APIs for tailored functionality.
Required Qualifications
• Experience: 5+ years in IAM administration, with at least 3 years focused on Keycloak; proven track record in enterprise deployments.
• Technical Skills:
◦ Expert-level proficiency in Keycloak features (realms, clients, roles, users, events, and Admin REST API).
◦ Strong knowledge of identity protocols (OAuth2, OIDC, SAML, JWT) and related tools (e.g., LDAP, Kerberos).
◦ Experience with containerization (Docker, Kubernetes) and cloud platforms (AWS, Azure).
◦ Familiarity with databases (PostgreSQL, MySQL) for Keycloak persistence and monitoring tools (Prometheus, Grafana).
Benefits
رقم الإعلان لدى المصدر: 416C64CD44