وظيفة قائد هندسة أمن السحابة لدى جامعة الملك عبدالله للعلوم والتقنية في ثول
تفاصيل الوظيفة
جامعة الملك عبدالله للعلوم والتقنية (KAUST) تعلن عن وظيفة قائد هندسة أمن السحاب (Cloud Security Engineering Lead) في مكة ثول، السعودية. يتولى هذا الدور مسؤولية تصميم وتنفيذ وضمان بيئات سحابية وهجينة آمنة عبر بيئات متعددة السحابات، مع التركيز على تطبيق مبادئ الثقة الصفرية (Zero Trust) وتعزيز الوضع الأمني.
نبذة عن الوظيفة
- قيادة أنشطة هندسة وأمن السحاب ضمن برنامج التحول في الأمن السيبراني بالجامعة، بدءًا من التصميم وحتى التنفيذ والتسليم التشغيلي.
- تقييم بيئات Azure و Microsoft 365 والبيئات الهجينة والمتعددة السحابات لتحديد الثغرات الأمنية والتبعيات التقنية.
- تصميم وتنفيذ بنى سحابية آمنة تتماشى مع مبادئ الأمن ومتطلبات التشغيل وأهداف الثقة الصفرية (Zero Trust).
- تقديم خبرات عملية في مجالات مثل Entra ID وConditional Access وPrivileged Identity Management وDefender XDR وMicrosoft Sentinel وغيرها.
- تطوير تكاملات بين منصات السحاب وعمليات الأمن (SIEM/SOAR) والتحليلات والأتمتة.
- قيادة التصميم الفني ومراجعة التكوينات واختبار المفهوم واستكشاف الأخطاء وإصلاحها للمبادرات الأمنية.
المهام والمسؤوليات
- تملك مسؤولية بنية وأمن السحاب عبر المبادرات الموكلة ضمن برنامج التحول، بما في ذلك التصميم والتنفيذ والتثبيت والتسليم التشغيلي.
- تقييم بيئات Azure و Microsoft 365 والبيئات الهجينة والمتعددة السحابات لتحديد الثغرات الأمنية والتبعيات التقنية وفرص تحسين الضوابط.
- تصميم وتنفيذ بنى سحابية آمنة تتوافق مع مبادئ أمن KAUST ومبادئ الثقة الصفرية.
- تقديم خبرات عملية في Microsoft Entra ID وConditional Access وPrivileged Identity Management وIdentity Protection وMFA وضوابط بدون كلمة مرور وIntune وDefender XDR وDefender for Cloud وMicrosoft Sentinel وMicrosoft Purify.
- هندسة وتحسين وضع أمن السحاب وحماية أعباء العمل وتقليل مسارات الهجوم والتسجيل والمراقبة والتكوين عبر IaaS وPaaS وSaaS ونقاط النهاية والهوية.
- تصميم وتنفيذ تكاملات بين منصات السحاب وعمليات الأمن، بما في ذلك SIEM/SOAR وحالات الكشف وتحليلات KQL وأتمتة الحوادث وذكاء التهديدات.
- تطبيق مبادئ الثقة الصفرية عبر الهوية والوصول المميز ونقاط النهاية والتطبيقات ووصول الشبكة والتعاون والبيانات، وضمان تشغيل الضوابط بشكل متسق عبر التبعيات السحابية والهجينة.
- تطوير أنماط اتصال ووصول آمنة للبيئات السحابية والهجينة، والعمل مع فرق أمن الشبكات على التقسيم والجدران النارية والوصول عن بُعد والاتصال الخاص وDNS.
- قيادة قرارات التصميم الفني ومراجعة التكوينات وأنشطة إثبات المفهوم والاختبار واستكشاف الأخطاء وإصلاحها للمبادرات الأمنية الموكلة.
- مراجعة وتحدي التصاميم المقدمة من Microsoft ومزودي السحابة وشركاء التسليم؛ ضمان استيفاء المقترحات الفنية لمعايير KAUST الأمنية والمعمارية والمرونة والتسجيل والتشغيل.
- قيادة أو دعم أنشطة الترحيل والتحديث من منصات الأمن القديمة إلى قدرات أصلية في السحابة، وضمان معالجة التسلسل والتعايش والاسترجاع واستمرارية التشغيل.
- إدارة التبعيات التقنية مع إدارة الهوية المؤسسية (IAM) وSaviynt IGA وأمن الشبكات والتقسيم وتقليل التعرض السيبراني وعمليات الأمن وإدارة نقاط النهاية والبنية التحتية والتطبيقات.
- المساهمة في القيادة التقنية لمشروع Microsoft 365 A5، بما في ذلك البنية والتكوين الأمني وDefender وEntra وIntune وPurview وتكامل عمليات الأمن وضوابط أمان Copilot والاختبار والجاهزية التجريبية والتسليم الفني.
- تحديد معايير القبول الفني وأدلة التحقق وخطوط الأساس الأمنية ومعايير التنفيذ ومتطلبات الجاهزية الإنتاجية للمبادرات الموكلة.
- تحديد مخاطر البنية والتكوينات الخاطئة والفجوات الأمنية ومعوقات التنفيذ والتبعيات البائعة مسبقًا ودفعها للحل مع ملكية وتصعيد واضحين.
- إنتاج تصاميم عالية الجودة (as-built) ومعايير تكوين ووثائق هندسية وأدلة تشغيلية (runbooks) وإجراءات تشغيلية ومواد نقل المعرفة.
- تطوير مهارات الفرق التقنية الداخلية من خلال الاقتران والجلسات الفنية ومراجعة التصاميم واستكشاف الأخطاء وإصلاحها ونقل المعرفة المنظم لضمان استدامة تشغيل القدرات المنفذة من قبل KAUST.
الشروط والمتطلبات
- درجة البكالوريوس في علوم الحاسب أو الأمن السيبراني أو أمن المعلومات أو تكنولوجيا المعلومات أو الهندسة أو مجال ذي صلة؛ الخبرة المهنية المكافئة قد تُعتبر بديلاً.
- شهادات Microsoft متقدمة في بنية Azure أو الأمن أو الهوية أو أمن Microsoft 365 أو عمليات الأمن مفضلة بشدة.
- الشهادات ذات الصلة في السحاب أو الأمن السيبراني مثل CISSP أو CCSP أو GIAC Cloud Security أو شهادات أمن Microsoft أو شهادات أمن Google/AWS تعتبر ميزة.
- يجب أن تدعم الشهادات الخبرة العملية الملموسة في هندسة أمن السحاب المؤسسي، وليست بديلاً عنها.
المهارات المطلوبة
- خبرة عملية عميقة في هندسة أمن السحاب عبر Microsoft Azure وMicrosoft 365، مع القدرة على التنقل بين البنية والتكوين والتكامل واستكشاف الأخطاء والتشغيل.
- معرفة قوية بتقنيات أمن Microsoft بما في ذلك Entra ID وConditional Access وPIM وIdentity Protection وDefender XDR وDefender for Cloud وIntune وMicrosoft Sentinel وMicrosoft Purify.
- فهم قوي لبنية أمن السحاب عبر الهوية والشبكة ونقاط النهاية وأعباء العمل والتطبيقات والبيانات والتسجيل والمراقبة وعمليات الأمن.
- خبرة عملية في تصميم وتنفيذ بنى الثقة الصفرية (Zero Trust) وضوابط الأمن المرتكزة على الهوية في بيئات مؤسسية.
- فهم قوي لـ SIEM/SOAR وهندسة الكشف وKQL أو لغات استعلام مماثلة وإدخال بيانات التتبع وأتمتة الحوادث وتكامل SOC.
- خبرة في إدارة وضع أمن السحاب وتقوية أعباء العمل وتحليل مسارات الهجوم وخطوط الأساس الآمنة للتكوين والإصلاح عبر IaaS وPaaS وSaaS.
- القدرة على تصميم أنماط اتصال وهجينة آمنة (حسب الحاجة) وضمان التكامل مع الشبكات والأمن المؤسسي.
عرض النص الأصلي للإعلان
About the Role
KAUST is undertaking a Cybersecurity Transformation Program focused on secure cloud and hybrid environments across its multi-cloud environments. The organization emphasizes modern security architectures, Zero Trust, and sustainable operational handover, working closely with internal teams and delivery partners to modernize security operations, cloud security posture, identity, and network security.
Kaust is seeking a hands-on cloud security engineering role responsible for designing, implementing, and assuring secure cloud and hybrid environments across KAUST's multi-cloud environments. The role combines solution architecture with direct technical execution across cloud security, identity, endpoint, security operations, Zero Trust, and modern workplace security. The incumbent will translate security requirements into deployable technical controls, lead complex implementation activities, resolve cross-platform dependencies, and ensure solutions are operationally supportable and measurable. The role will work across multiple portfolio initiatives rather than a single technology program. As a start, Microsoft 365 A5 is one major project within the portfolio, alongside other initiatives such as Enterprise IAM, cloud security posture improvement, security operations integration, network security and segmentation, cyber exposure reduction, and related security modernization efforts. The engineer is expected to remain personally hands-on in design, configuration, integration, troubleshooting, testing, remediation, and knowledge transfer while providing technical direction to partners and internal teams.
Responsibilities
- Own cloud security architecture and engineering activities across assigned initiatives within the Cybersecurity Transformation Program, from design through implementation, stabilization, and operational handover.
- Assess Azure, Microsoft 365, hybrid, and where relevant multicloud environments to identify security gaps, technical dependencies, and opportunities for control improvement.
- Design and implement secure cloud architectures aligned with KAUST security principles, enterprise architecture standards, operational requirements, and Zero Trust objectives.
- Provide hands-on engineering across Microsoft Entra ID, Conditional Access, Privileged Identity Management, Identity Protection, MFA and passwordless controls, Intune, Defender XDR, Defender for Cloud, Microsoft Sentinel, Microsoft Purview, and related Microsoft security capabilities.
- Engineer and improve cloud security posture management, workload protection, attack-path reduction, logging, monitoring, and security configuration across IaaS, PaaS, SaaS, endpoint, and identity environments.
- Design and implement integrations between cloud platforms and Security Operations, including SIEM/SOAR telemetry, detection use cases, KQL analytics, incident automation, threat intelligence, and operational monitoring requirements.
- Apply Zero Trust principles across identity, privileged access, endpoints, applications, network access, collaboration, and data, ensuring controls operate coherently across cloud and hybrid dependencies.
- Develop secure connectivity and access patterns for cloud and hybrid environments, working with network security teams on segmentation, firewalling, secure remote access, private connectivity, DNS, and related controls where required.
- Lead technical design decisions, configuration reviews, proof-of-concept activities, testing, troubleshooting, and remediation for assigned cloud security initiatives.
- Review and challenge designs proposed by Microsoft, cloud providers, and delivery partners; ensure technical proposals meet KAUST security, architecture, resilience, logging, and operational standards.
- Lead or support migration and modernization activities from legacy security platforms to cloud-native capabilities, ensuring sequencing, coexistence, rollback, and operational continuity are addressed.
- Manage technical dependencies with Enterprise IAM, Saviynt IGA, Network Security and Segmentation, Cyber Exposure Reduction, Security Operations, endpoint management, infrastructure, and application teams.
- Contribute technical leadership to the Microsoft 365 A5 project, including architecture, security configuration, Defender, Entra, Intune, Purview, Security Operations integration, Copilot security controls, testing, pilot readiness, and technical handover as assigned.
- Define technical acceptance criteria, validation evidence, security baselines, implementation standards, and production-readiness requirements for assigned initiatives.
- Proactively identify architecture risks, misconfigurations, security gaps, implementation blockers, and vendor dependencies, and drive them to resolution with clear ownership and escalation.
- Produce high-quality as-built designs, configuration standards, engineering documentation, runbooks, operational procedures, and knowledge-transfer materials.
- Upskill internal technical teams through pairing, technical walkthroughs, design reviews, troubleshooting, and structured knowledge transfer so implemented capabilities can be sustainably operated by KAUST.
Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Technology, Engineering, or a closely related discipline; substantial equivalent professional experience may be considered.
- Advanced Microsoft certifications in Azure architecture, security, identity, Microsoft 365 security, or security operations are strongly preferred.
- Relevant cloud or cybersecurity certifications such as CISSP, CCSP, GIAC cloud security, Microsoft Security certifications, Google/AWS security certifications, or equivalent are advantageous.
- Certifications should support, not substitute for, demonstrable hands-on enterprise cloud security engineering and implementation experience.
Required Skills
- Deep hands-on cloud security engineering expertise across Microsoft Azure and Microsoft 365, with the ability to move comfortably between architecture, configuration, integration, troubleshooting, and operationalization.
- Strong knowledge of Microsoft security technologies including Entra ID, Conditional Access, PIM, Identity Protection, Defender XDR, Defender for Cloud, Intune, Microsoft Sentinel, and Microsoft Purview.
- Strong understanding of cloud security architecture across identity, network, endpoint, workloads, applications, data, logging, monitoring, and security operations.
- Practical experience designing and implementing Zero Trust architectures and identity-centric security controls in enterprise environments.
- Strong understanding of SIEM/SOAR, detection engineering, KQL or comparable query languages, security telemetry onboarding, incident automation, and SOC integration.
- Experience with cloud security posture management, workload hardening, attack-path analysis, secure configuration baselines, and remediation across IaaS, PaaS, and SaaS.
- Ability to design secure hybrid and, where relevant, multicloud integrations, including federation, SSO, network connectivity, logging, and security control alignment.
- Strong technical governance and engineering judgment, including the ability to challenge vendor designs and translate security requirements into practical implementation decisions.
- Ability to lead multidisciplinary technical teams and delivery partners without losing hands-on engagement in critical technical work.
- Strong written and verbal communication, including the ability to explain technical risks, architecture decisions, and delivery implications to both technical and senior stakeholders.
- Evidence-led and outcome-oriented approach, with emphasis
رقم الإعلان لدى المصدر: 4475544089