تفاصيل الوظيفة
شركة Jobgether تعلن نيابة عن شريكها عن وظيفة Ubuntu Security Engineer في السعودية. انضم إلى فريق أمني موزع عالميًا مكرس لحماية المستخدمين وتعزيز أمان البرمجيات مفتوحة المصدر، حيث ستستقصي الثغرات الناشئة في نظام Ubuntu البيئي، وتتعاون مع فرق هندسية داخلية ومطورين من المصادر المفتوحة.
المهام والمسؤوليات
- تحليل واستقصاء وإصلاح واختبار الثغرات التي تؤثر على الحزم مفتوحة المصدر ضمن نظام Ubuntu البيئي.
- مراقبة وتتبع الثغرات عند اكتشافها والبحث عنها وتصحيحها وإصدارها باستخدام أدوات وعمليات أمنية داخلية.
- التعاون مع فرق هندسية داخلية ومطوري المصادر المفتوحة والمجتمع الأوسع لتطوير وتبادل والتحقق من تصحيحات أمنية فعالة.
- تدقيق الكود المصدري والمكونات البرمجية لتحديد نقاط الضعف الأمنية والثغرات المحتملة.
- تقييم المخاطر الأمنية والمساهمة في تحديد أولويات جهود المعالجة بناءً على الأثر والإلحاح.
- تصميم وتطوير ميزات وأتمتة وأدوات داخلية تساعد الفرق الهندسية على تحسين أمان منتجاتها وبنيتها التحتية.
- توثيق النتائج الأمنية وأنشطة المعالجة والمعلومات التقنية ذات الصلة بوضوح ودقة.
- المساهمة في مبادرات أمنية عبر النظام البيئي للمصادر المفتوحة والتفاعل مع مجتمعات الصناعة عند الاقتضاء.
الشروط والمتطلبات
- فهم قوي لثغرات أمن البرمجيات الشائعة وتقنيات الهجوم وأساليب تحديدها وإصلاحها.
- خبرة أو إلمام بممارسات الإفصاح المنسق عن الثغرات والتواصل الأمني المسؤول.
- إلمام بأدوات تطوير المصادر المفتوحة وسير العمل والمنهجيات.
- إتقان لغة برمجة واحدة على الأقل ذات صلة مثل C أو Python أو Go أو Rust أو Java أو Ruby أو PHP أو JavaScript أو TypeScript.
- خبرة مع لينكس، ويفضل بيئات Ubuntu أو Debian.
- قدرات تحليلية واستدلال منطقي قوية، ومهارات في حل المشكلات واتخاذ القرارات.
- مهارات تواصل ممتازة مع القدرة على شرح القضايا الأمنية التقنية بوضوح للفرق الهندسية ومساهمي المصادر المفتوحة.
- مهارات تواصل وتعاون قوية مع القدرة على العمل بفعالية عبر الثقافات والبلدان والفرق الموزعة.
- الفضول والقدرة على التكيف والمساءلة والاهتمام الحقيقي بتعلم التهديدات والتقنيات الأمنية الناشئة.
- نهج ذاتي التحفيز ومدروس للعمل مع القدرة على إدارة الأولويات والوفاء بالالتزامات بشكل مستقل.
- درجة البكالوريوس أو خلفية معادلة في علوم الحاسب أو STEM أو مجال تقني ذي صلة مفضلة، ولكن يُشجع المرشحون ذوو الخلفيات البديلة المقنعة على التقديم.
- يمكن النظر في المرشحين عبر مستويات خبرة متعددة، من الخريجين إلى كبار مهندسي الأمن، بناءً على قدراتهم التقنية وإنجازاتهم وخبراتهم الأمنية ذات الصلة.
المزايا
- تعويض تنافسي بناءً على الموقع الجغرافي والخبرة والأداء.
- مكافأة سنوية أو عمولة تعتمد على الأداء، حسب الدور والموقع.
- مراجعة سنوية للتعويض.
- ميزانية تعلم وتطوير شخصي بقيمة 2,000 دولار أمريكي سنويًا.
- برامج تقدير ومكافآت.
- إجازة سنوية.
- إجازة أمومة وأبوة.
- برنامج مساعدة أعضاء الفريق ومنصة العافية.
- بيئة عمل عن بعد بالكامل وموزعة.
- فرص لقاء الزملاء شخصيًا مرتين سنويًا عبر سباقات الفريق.
- فرص السفر دوليًا والتعاون مع الزملاء في مواقع جديدة.
- بطاقة أولوية الدخول وتحديثات السفر المؤهلة لمناسبات الشركة الطويلة.
- فرص المساهمة في مشاريع أمنية مفتوحة المصدر والمشاركة في أحداث الصناعة والمنشورات والمبادرات التقنية.
- بيئة عمل شاملة ومتعددة الثقافات تقدر وجهات النظر والخبرات المتنوعة.
عرض النص الأصلي للإعلان
Join a globally distributed security engineering team dedicated to protecting users and strengthening the security of open source software.
You’ll investigate emerging vulnerabilities across the Ubuntu ecosystem, helping identify, assess, remediate, and document security issues.
The role combines hands-on security engineering with software development, code auditing, vulnerability research, and security tooling.
You’ll collaborate with internal engineering teams, upstream developers, and members of the broader open source community to deliver robust security fixes.
Your work will directly contribute to improving the resilience and security of widely used Linux technologies and open source projects.
The environment is highly technical, collaborative, and international, with opportunities to share knowledge through open source contributions, publications, and industry events.
This opportunity is open to candidates across experience levels, from graduates through senior security engineers, with strong technical potential and a passion for security.
Accountabilities
- Analyse, investigate, fix, and test vulnerabilities affecting open source packages within the Ubuntu ecosystem.
- Monitor and track vulnerabilities as they are discovered, researched, patched, and released, using internal security tools and processes.
- Collaborate with internal engineering teams, upstream developers, and the wider open source community to develop, exchange, and validate effective security patches.
- Audit source code and software components to identify security weaknesses and potential vulnerabilities.
- Assess security risks and contribute to prioritising remediation efforts based on impact and urgency.
- Design and develop features, automation, and internal tools that help engineering teams improve the security of their products and infrastructure.
- Document security findings, remediation activities, and relevant technical information clearly and accurately.
- Contribute to security initiatives across the broader open source ecosystem and engage with industry communities where appropriate.
- Work effectively within a globally distributed team, taking ownership of projects and maintaining consistent progress with a high degree of autonomy.
- Strong understanding of common software security vulnerabilities, attack techniques, and approaches to identifying and fixing them.
- Experience or familiarity with coordinated vulnerability disclosure practices and responsible security communication.
- Familiarity with open source development tools, workflows, and methodologies.
- Proficiency in at least one relevant programming language, such as C, Python, Go, Rust, Java, Ruby, PHP, JavaScript, or TypeScript.
- Experience with Linux, ideally Ubuntu or Debian-based environments.
- Strong analytical, logical reasoning, troubleshooting, and decision-making abilities.
- Excellent communication skills, with the ability to explain technical security issues clearly to engineering teams and open source contributors.
- Strong interpersonal and collaboration skills, with the ability to work effectively across cultures, countries, and distributed teams.
- Curiosity, adaptability, accountability, and a genuine interest in learning about emerging security threats and technologies.
- A self-motivated and thoughtful approach to work, with the ability to manage priorities and deliver against commitments independently.
- A bachelor’s degree or equivalent background in Computer Science, STEM, or a related technical discipline is preferred, although candidates with compelling alternative backgrounds are encouraged to apply.
- Candidates may be considered across multiple experience levels, from graduate to senior, depending on their technical capabilities, achievements, and relevant security experience.
- Competitive compensation based on geographical location, experience, and performance.
- Performance-driven annual bonus or commission, depending on role and location.
- Annual compensation review.
- Personal learning and development budget of USD 2,000 per year.
- Recognition and rewards programs.
- Annual holiday leave.
- Maternity and paternity leave.
- Team Member Assistance Program and Wellness Platform.
- Fully distributed and remote working environment.
- Twice-yearly opportunities to meet colleagues in person through team sprints.
- Opportunities to travel internationally and collaborate with colleagues in new locations.
- Priority Pass and travel upgrades for eligible long-haul company events.
- Opportunities to contribute to open source security projects and participate in industry events, publications, and technical initiatives.
- Inclusive, multicultural working environment that values diverse perspectives and experiences.
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
رقم الإعلان لدى المصدر: 4461949429