وظيفة موظف أول توصيل شاغرة لدى العليان في الرياض
تفاصيل الوظيفة
تعلن شركة العليان عن توفر وظيفة Senior Officer, Delivery في مدينة الرياض، حيث ستعمل على تصميم ونشر وتشغيل وتأمين وتحسين بيئات الشبكات المؤسسية والأمن السيبراني عبر البنية التحتية المحلية والخاصة والعامة والهجينة، مع تقديم الدعم التقني المباشر وخدمات الإدارة لأمن الشبكات والشبكات السحابية وأمن نقاط النهاية وحماية البيانات والتشفير والتحكم في الهوية والمراقبة والاستجابة للحوادث.
المهام والمسؤوليات
- إدارة عمليات أمن الشبكات: إدارة جدران الحماية المؤسسية، بوابات الأمان، والوصول الآمن عن بُعد عبر مراكز البيانات والفروع والبيئات السحابية. تكوين ومراقبة أنظمة كشف التسلل (IDS/IPS)، منع التهديدات، تصفية الويب، التحكم في التطبيقات، وحماية الشبكة من البرامج الضارة. تصميم التقسيم والتقسيم الدقيق باستخدام VLANs وVRFs والشبكات الفرعية ومناطق الأمان ومجموعات الأمان وسياسات التحكم في الوصول. دعم التوجيه والتبديل وDNS وDHCP وموازنة التحميل والشبكات اللاسلكية وSD-WAN وVPN من موقع إلى موقع وVPN العميل والاتصال الخاص. مراقبة التوفر والسعة والأحداث الأمنية، واستكشاف المشكلات المعقدة وإجراء تحليل السبب الجذري.
- هندسة الشبكات السحابية والهجينة: تصميم وإدارة الشبكات الافتراضية عبر منصات السحابة العامة والخاصة المدعومة، بما في ذلك الشبكات الفرعية ومناطق الأمان المعتمدة. تكوين مجموعات الأمان، ضوابط جدار الحماية السحابي، جداول التوجيه، البوابات، نقاط النهاية الخاصة، وخدمات الاتصال بالمنصة. إدارة عناوين IP وDNS وواجهات الشبكة ونشر الموارد السحابية في الشرائح الشبكية المعتمدة. تكوين التوصيل البيني السحابي والاتصال الهجين الآمن عبر VPN والدوائر المخصصة وخدمات التوصيل البيني وبوابات التوجيه. الحفاظ على رسومات الشبكات السحابية وخطط IP وخرائط التبعية وخطوط الأساس للتكوين ودفاتر التشغيل.
- أمن نقاط النهاية وتعزيز الحماية: إدارة EDR/XDR ومكافحة البرامج الضارة وجدار الحماية المضيف والتحكم في التطبيقات والتحكم في الأجهزة وسياسات الكشف عن نقاط النهاية. تنفيذ تعزيز الخوادم ونقاط النهاية، وخطوط الأساس الأمنية، وضوابط التصحيح، ومعالجة الثغرات الأمنية، وسياسات الامتثال. التحقيق في التنبيهات، وعزل الأجهزة المتأثرة عند التفويض، وتنسيق الاحتواء والاسترداد، وتوثيق النتائج. دعم إدارة الأجهزة المحمولة وإدارة نقاط النهاية الموحدة وضوابط الوصول الآمنة.
- حماية البيانات ومنع فقدانها (DLP) والتصنيف: تنفيذ سياسات DLP عبر نقاط النهاية والبريد الإلكتروني ومنصات التعاون والخدمات السحابية والتطبيقات المدعومة. فرض ضوابط التصنيف ووضع العلامات الحساسة والتعامل والاحتفاظ والمشاركة الآمنة للمعلومات. تكوين التشفير للبيانات الساكنة والمنقولة عبر الأقراص والملفات وقواعد البيانات والتخزين والنسخ الاحتياطي والاتصالات. دعم الاكتشاف وضبط السياسات والاستثناءات والتحقيق في التنبيهات وجمع أدلة الامتثال.
- إدارة المفاتيح والخزائن والشهادات والأسرار: إدارة خزائن المؤسسات أو السحابة ومخازن المفاتيح وتكامل HSM وخدمات إدارة الأسرار. إنشاء أو استيراد المواد التشفيرية بشكل آمن وإدارة دورة حياة المفاتيح (التدوير والإبطال والأرشفة والتقاعد). إدارة الأسرار وبيانات اعتماد الخدمة والرموز والشهادات، بما في ذلك الأذونات وتواريخ الانتهاء والتجديد وسجلات التدقيق. تعيين مفاتيح التشفير لموارد التخزين وقواعد البيانات والنسخ الاحتياطي والأقراص الافتراضية والتطبيقات المدعومة.
- حوكمة الهوية والوصول وأمن السحابة: تكوين ومراجعة مستخدمي IAM والأدوار والمجموعات وهويات الخدمة والسياسات والوصول المميز باستخدام مبدأ الامتياز الأقل والفصل بين المهام. تطبيق المصادقة متعددة العوامل (MFA) والوصول المشروط والوصول الإداري الآمن عند الدعم. تطبيق ضوابط وضع أمن السحابة وحماية عبء العمل والتسجيل والمراقبة والتكوين والامتثال. المشاركة في مراجعات الهندسة وتقييمات المخاطر والثغرات وتخطيط المعالجة.
- مراقبة الأمن والاستجابة للحوادث: دمج الشبكة والسحابة ونقاط النهاية والهوية والمنصات الأمنية مع المراقبة المركزية ونظام إدارة المعلومات الأمنية والأحداث (SIEM) ومركز العمليات الأمنية (SOC) وخدمات الكشف المُدارة. مراقبة التنبيهات والسجلات، وفرز الحوادث، وجمع الأدلة، وتنسيق التصعيد والاحتواء والاسترداد والإجراءات ما بعد الحادث. الحفاظ على حالات الاستخدام وقواعد التنبيه ولوحات المعلومات وفحوصات الصحة والتقارير التشغيلية. إجراء تحليل السبب الجذري والتوصية بالتحسينات الوقائية.
- النشر والخدمات المُدارة والتوثيق: تنفيذ مشاريع النشر والترحيل والتكوين والاختبار والتسليم والدعم المستمر للشبكات السحابية والمحلية. إعداد وثائق التصميم عالي المستوى ومنخفض المستوى (HLD/LLD) وبيانات الأسلوب وخطط التنفيذ والاختبار والتراجع وسجلات التشغيل. تنفيذ الحوادث والطلبات والتغييرات والمشكلات ضمن اتفاقيات مستوى الخدمة (SLAs) وإجراءات إدارة التغيير المتفق عليها. التنسيق مع العملاء والفرق الداخلية ومصنعي المعدات الأصلية (OEMs) ومزودي السحابة وشركات الاتصالات وشركاء الأمن. تقديم ورش العمل ونقل المعرفة والاكتشاف التقني والتقدير وقوائم المواد ودعم ما قبل البيع عند الحاجة.
الشروط والمتطلبات
- خبرة عملية لا تقل عن 7 سنوات في أدوار هندسة الشبكات أو الأمن أو البنية التحتية أو السحابة.
- خبرة في دعم بيئات المؤسسات أو الخدمات المدارة عبر البنية التحتية السحابية والمحلية.
- خبرة عملية في التنفيذ واستكشاف الأخطاء لجدران الحماية والتوجيه والتبديل وVPN والتقسيم وحماية نقاط النهاية وضوابط الأمان.
- خبرة عملية في منصة سحابة عامة رئيسية واحدة على الأقل والقدرة على العمل عبر منصات إضافية.
- خبرة في إنتاج وثائق التنفيذ ودفاتر التشغيل والتقارير الفنية الموجهة للعملاء.
- درجة البكالوريوس في علوم الحاسب أو تقنية المعلومات أو الأمن السيبراني أو هندسة الشبكات أو نظم المعلومات أو مجال ذي صلة؛ يمكن النظر في الخبرة المعتمدة المكافئة.
- يفضل: شهادة معترف بها في هندسة السحابة أو أمن السحابة أو شبكات السحابة.
- يفضل: CCNP Enterprise/Security أو Fortinet أو Palo Alto Networks أو Check Point أو شهادة أمان شبكات معادلة.
- يفضل: CISSP أو CISM أو Security+ أو CySA+ أو شهادة أمن سيبراني معادلة.
- شهادة في نقاط النهاية أو الهوية أو حماية المعلومات أو SIEM أو عمليات الأمن أو ITIL تعتبر ميزة إضافية.
- المهارات التقنية المطلوبة: TCP/IP، IPv4/IPv6، VLAN، VRF، BGP، OSPF، DNS، DHCP، VPN، SD-WAN، موازنة التحميل، الشبكات اللاسلكية، والاتصال الهجين. جدران الحماية من الجيل التالي، IDS/IPS، التقسيم، الثقة الصفرية، الوصول عن بُعد، وحوكمة قواعد الأمان. الشبكات الافتراضية السحابية، الحوسبة، التخزين، قواعد البيانات، IAM، التسجيل، المراقبة، الخزائن، وإدارة المفاتيح. EDR/XDR، تعزيز نقاط النهاية، معالجة الثغرات، التصحيح، والامتثال. DLP، التصنيف، وضع العلامات، التشفير، PKI، الشهادات، دورة حياة المفاتيح، وإدارة الأسرار.
عرض النص الأصلي للإعلان
Role Purpose:
Design, deploy, secure, operate and continuously improve enterprise network and cybersecurity environments across on-premises, private-cloud, public-cloud and hybrid infrastructures. Provide hands-on technical delivery and managed-services support for network security, cloud networking, endpoint security, data protection, encryption, identity controls, monitoring and incident response. Translate business and security requirements into resilient, scalable and compliant solutions while maintaining documentation and agreed service levels.
|
Key Accountabilities |
Key Activities |
|
Network Security Operations |
• Manage enterprise firewalls, security gateways and secure remote access across data centers, branches and cloud environments. • Configure and monitor IDS/IPS, threat prevention, web filtering, application control and network malware protection. • Design segmentation and micro-segmentation using VLANs, VRFs, subnets, security zones, security groups and access-control policies. • Support routing, switching, DNS, DHCP, load balancing, wireless, SD-WAN, site-to-site VPN, client VPN and private connectivity. • Monitor availability, capacity and security events; troubleshoot complex issues and perform root-cause analysis. |
|
Cloud & Hybrid Network Engineering |
• Design and manage virtual networks across supported public and private cloud platforms, including approved subnets and security zones. • Configure security groups, cloud firewall controls, route tables, gateways, private endpoints and platform connectivity services. • Manage IP addressing, DNS, network interfaces and deployment of cloud resources into approved network segments. • Configure cloud peering and secure hybrid connectivity through VPN, dedicated circuits, interconnect services and routing gateways. • Maintain cloud-network diagrams, IP plans, dependency maps, configuration baselines and runbooks. |
|
Endpoint Security & Hardening |
• Administer EDR/XDR, anti-malware, host firewall, application control, device control and endpoint-detection policies. • Implement server and endpoint hardening, security baselines, patching controls, vulnerability remediation and compliance policies. • Investigate alerts, isolate affected devices when authorized, coordinate containment and recovery, and document findings. • Support mobile-device management, unified endpoint management and secure access controls. |
|
Data Protection, DLP & Classification |
• Implement DLP policies across endpoints, email, collaboration platforms, cloud services and supported applications. • Enforce classification, sensitivity labeling, handling, retention and secure information-sharing controls. • Configure encryption for data at rest and in transit across disks, files, databases, storage, backup and communications. • Support discovery, policy tuning, exceptions, alert investigation and compliance evidence collection. |
|
Key, Vault, Certificate & Secrets Management |
• Manage enterprise or cloud vaults, key stores, HSM integrations and secrets-management services. • Generate or securely import cryptographic material and manage key lifecycle, rotation, revocation, archival and retirement. • Manage secrets, service credentials, tokens and certificates, including permissions, expiry, renewal and audit logs. • Assign encryption keys to supported storage, database, backup, virtual-disk and application resources. |
|
Identity, Access & Cloud Security Governance |
• Configure and review IAM users, roles, groups, service identities, policies and privileged access using least privilege and segregation of duties. • Implement MFA, conditional access and secure administrative access where supported. • Apply cloud-security posture, workload protection, logging, monitoring, configuration and compliance controls. • Participate in architecture reviews, risk and vulnerability assessments, and remediation planning. |
|
Security Monitoring & Incident Response |
• Integrate network, cloud, endpoint, identity and security platforms with centralized monitoring, SIEM, SOC and managed-detection services. • Monitor alerts and logs, triage incidents, collect evidence and coordinate escalation, containment, recovery and post-incident actions. • Maintain use cases, alert rules, dashboards, health checks and operational reports. • Perform root-cause analysis and recommend preventive improvements. |
|
Deployment, Managed Services & Documentation |
• Deliver implementation, migration, configuration, testing, handover and ongoing support for cloud and on-premises network-security projects. • Prepare HLD/LLD, method statements, implementation, test and rollback plans, as-built records and operational runbooks. • Execute incidents, requests, changes and problems within agreed SLAs and change-management procedures. • Coordinate with customers, internal teams, OEMs, cloud providers, carriers and security partners. • Provide workshops, knowledge transfer, technical discovery, estimation, bills of materials and pre-sales support when required. |
|
JOB SPECIFICATIONS |
|
|
Industry / Domain |
Enterprise networking, cloud and hybrid infrastructure, cybersecurity, managed services, network operations, security operations and technical consulting. |
|
Necessary Knowledge and Experience |
• Minimum 7 years of hands-on experience in network, security, infrastructure or cloud engineering roles. • Experience supporting enterprise or managed-services environments across cloud and on-premises infrastructure. • Hands-on implementation and troubleshooting of firewalls, routing, switching, VPNs, segmentation, endpoint protection and security controls. • Practical experience with at least one major public-cloud platform and ability to work across additional platforms. • Experience producing implementation documents, operational runbooks and customer-facing technical reports. |
|
Education and Certification Requirements |
• Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, Information Systems or a related discipline; equivalent certified experience may be considered. • Preferred: recognized cloud architecture, cloud security or cloud networking certification. • Preferred: CCNP Enterprise/Security, Fortinet, Palo Alto Networks, Check Point or equivalent network-security certification. • Preferred: CISSP, CISM, Security+, CySA+ or equivalent cybersecurity certification. • Endpoint, identity, information-protection, SIEM, security-operations or ITIL certification is advantageous. |
|
Job Specific Technical Skills |
• TCP/IP, IPv4/IPv6, VLAN, VRF, BGP, OSPF, DNS, DHCP, VPN, SD-WAN, load balancing, wireless and hybrid connectivity. • Next-generation firewalls, IDS/IPS, segmentation, Zero Trust, remote access and security-rule governance. • Cloud virtual networking, compute, storage, databases, IAM, logging, monitoring, vaults and key management. • EDR/XDR, endpoint hardening, vulnerability remediation, patching and compliance. • DLP, classification, labeling, encryption, PKI, certificates, key lifecycle, secrets management and secure data handling. • SIEM/SOC integration, incident response, problem and change management, capacity, availability and DR awareness. • Scripting and Infrastructure as Code using PowerShell, Python, Terraform or equivalent is preferred. • Architecture diagrams, HLD/LLD, as-built configurations, implementation plans, test evidence and operational reports. |
رقم الإعلان لدى المصدر: 1368462323