الوصف الوظيفي
بصفتك مهندس أمن سحابي من المستوى الثاني/الثالث (L2/L3)، ستتولى إدارة العمليات الأمنية اليومية، والحوادث، والتغييرات عبر بيئتنا متعددة السحابات (Azure و OCI و GCP). هذا دور هندسي يركز على التنفيذ: ستعمل على معالجة طلبات الهوية والوصول، والاستجابة للحوادث والتنبيهات الأمنية وحلها، وتنفيذ التغييرات المعتمدة، وإجراء المهام التشغيلية الروتينية عبر Microsoft Entra ID و Microsoft Defender و Intune وأتمتة Logic Apps وإدارة الشهادات/المفاتيح (GCP PKI و Azure Key Vault).
ستعمل كجزء من فريق العمليات، حيث ستستلم التذاكر والطلبات من قائمة الانتظار، واستكشاف المشكلات وإصلاحها، وتنفيذ التغييرات وفقًا لطلبات التغيير المعتمدة،
المسؤوليات
إدارة الهوية والوصول (Entra ID / Azure)
- إدارة الهويات المميزة (PIM): معالجة طلبات تعيين الأدوار ورفع صلاحيات الوصول، واتخاذ الإجراءات بشأن موافقات الوصول المميز المحدد بوقت، وإجراء مراجعات الوصول المجدولة عبر المجموعات المُمكّنة بـ PIM.
- تسجيلات التطبيقات: إنشاء وإدارة تسجيلات التطبيقات ومعرفات الخدمة الرئيسية (Service Principals) — بما في ذلك تدوير المعتمدات/الأسرار، وتحديد نطاق أذونات API، وإجراءات الموافقة — وفقًا للطلبات المعتمدة.
- الهويات المدارة: توفير الهويات المدارة المعينة من قبل النظام والمعينة من قبل المستخدم بناءً على طلب فرق التطبيقات والمنصات.
- الوصول المشروط والمصادقة متعددة العوامل (MFA): تنفيذ وتحديث سياسات الوصول المشروط وإعدادات المصادقة متعددة العوامل (MFA) وفقًا لطلبات التغيير المعتمدة؛ واستكشاف مشكلات المصادقة والوصول التي يثيرها المستخدمون أو أنظمة المراقبة وإصلاحها.
- تسجيل الدخول الأحادي / الاتحاد (SSO / Federation): تكوين واستكشاف مشكلات تسجيل الدخول الأحادي والاتحاد لتطبيقات المنصة وإصلاحها.
الأتمتة الأمنية
- أتمتة Logic Apps: بناء وصيانة واستكشاف أخطاء أتمتة أمن Logic Apps وإصلاحها (حظر مؤشرات الاختراق IOC، وفحوصات صحة الوكلاء، والتنبيه بتغييرات DNS)، والاستجابة لإخفاقات الأتمتة.
عمليات الأمن السحابي
- سياسة Azure Policy: تطبيق وتحديث تعيينات Azure Policy وفقًا للقواعد الأساسية المعتمدة؛ وتحديد الموارد غير المتوافقة التي حددتها السياسة ومعالجتها.
- Defender for Cloud: مراقبة درجة الأمان (Secure Score) والتوصيات الأمنية يوميًا؛ واتخاذ إجراءات بشأن مهام المعالجة ومتابعة حل المشكلات المحددة.
- Defender for Servers and Containers: مراقبة التنبيهات بالتهديدات والاستجابة لها على أعباء عمل الخوادم والحاويات، بما في ذلك AKS؛ والتحقيق في الأنشطة المشبوهة، ومعالجة طلبات الوصول في الوقت المناسب (JIT)، وتطبيق تغييرات التكوين الآمنة.
- أمن الأجهزة الطرفية وإدارة الأجهزة: إجراء الإدارة اليومية لـ Microsoft Defender للأجهزة الطرفية و Intune، بما في ذلك إعداد الأجهزة، ونشر التطبيقات والشهادات، واستكشاف مشكلات توافق الأجهزة وإصلاحها.
البنية التحتية للمفاتيح العامة (PKI) وإدارة الشهادات
- عمليات الشهادات: إجراء التشغيل اليومي لسلطات الشهادات الداخلية (CAs)، بما في ذلك سلطات الشهادات الخاصة المستضافة في GCP.
- دورة حياة الشهادة: معالجة طلبات إصدار الشهادات وتجديدها وإلغائها بما يتوافق مع سياسة ومعايير PKI الحالية.
- إدارة المفاتيح: إدارة المفاتيح والأسرار في Azure Key Vault، بما في ذلك التدوير وتحديثات سياسة الوصول وفقًا للطلبات المعتمدة.
- المخزون والمراقبة: الحفاظ على سجلات مخزون الشهادات والمفاتيح ومراقبة الانتهاء القادم أو التكوينات الخاطئة المحددة.
المؤهلات
- التعليم: درجة البكالوريوس / شهادة جامعية في علوم الحاسوب، أو تكنولوجيا المعلومات، أو مجال ذي صلة.
- الخبرة: خبرة عملية من 8 إلى 10 سنوات في عمليات الأمن السحابي (L2/L3)، مع خبرة مثبتة في إدارة Microsoft Entra ID (RBAC و PIM وتسجيلات التطبيقات والهويات المدارة والوصول المشروط)، وتشغيل Microsoft Defender عبر أعباء عمل السحابة والخوادم والحاويات والأجهزة الطرفية، والتعامل مع عمليات PKI / الشهادات. يُشترط وجود خبرة في العمل ضمن عملية إدارة الحوادث والتغيير (ITSM). تُعد الخبرة متعددة السحابات عبر Azure و OCI و/أو GCP ميزة إضافية.
- الشهادات: الشهادات المهنية ذات الصلة مرغوبة بشدة. وقد تشمل على سبيل المثال لا الحصر:
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- Microsoft Certified: Endpoint Administrator Associate (MD-102)
- Google Cloud Certified: Professional Cloud Security Engineer
- شهادات الأمان المستقلة عن بائعي التكنولوجيا (CISSP و CCSP و CSA CCSK و GIAC وما إلى ذلك)
- المعرفة: معرفة عملية بمفاهيم الهوية والوصول المميز، وأساسيات PKI (دورة حياة الشهادة، إدارة المفاتيح، سلاسل الثقة)، وحماية أعباء العمل السحابية، وحدث التذاكر الموجهة للحوادث/التغيير. القدرة على اتباع كتب التشغيل (runbooks) وإجراءات التشغيل القياسية بدقة تحت ضغط الوقت.
Job Description
As a L2/L3 Cloud Security Engineer, you shall handle day-to-day security operations, incidents, and changes across our multi-cloud estate (Azure, OCI, and GCP). This is an execution-focused engineering role: you will process identity and access requests, respond to and resolve security incidents and alerts, implement approved changes, and carry out routine operational tasks across Microsoft Entra ID, Microsoft Defender, Intune, Logic Apps automation, and certificate/key management (GCP PKI, Azure Key Vault).
You will work as part of the operations team, picking up tickets and requests from the queue, troubleshooting issues, executing changes per approved change requests,
Responsibilities
Identity and Access Management (Entra ID / Azure)
- Privileged Identity Management (PIM): Process role-assignment and access-elevation requests, action time-bound privileged access approvals, and carry out scheduled access reviews across PIM-enabled groups.
- App Registrations: Create and manage app registrations and service principals — including credential/secret rotation, API permission scoping, and consent actions — per approved requests.
- Managed Identities: Provision system-assigned and user-assigned managed identities as requested by application and platform teams.
- Conditional Access and MFA: Implement and update Conditional Access policies and MFA settings per approved change requests; troubleshoot authentication and access issues raised by users or monitoring.
- SSO / Federation: Configure and troubleshoot single sign-on and federation for platform applications.
Security Automation
- Logic Apps Automation: Build, maintain, and troubleshoot Logic Apps security automations (IOC blocking, agent health checks, DNS change alerting), and respond to automation failures.
Cloud Security Operations
- Azure Policy: Apply and update Azure Policy assignments per approved baselines; identify and remediate non-compliant resources flagged by policy.
- Defender for Cloud: Monitor secure score and security recommendations daily; action remediation tasks and track resolution of flagged issues.
- Defender for Servers and Containers: Monitor and respond to threat alerts on server and container workloads, including AKS; investigate suspicious activity, process just-in-time (JIT) access requests, and apply secure configuration changes.
- Endpoint Security and Device Management: Perform day-to-day administration of Microsoft Defender for endpoints and Intune, including device onboarding, application and certificate deployment, and troubleshooting of device compliance issues.
PKI and Certificate Management
- Certificate Operations: Perform day-to-day operation of internal Certificate Authorities (CAs), including private CAs hosted in GCP.
- Certificate Lifecycle: Process certificate issuance, renewal, and revocation requests in line with existing PKI policy and standards.
- Key Management: Manage keys and secrets in Azure Key Vault, including rotation and access-policy updates per approved requests.
- Inventory and Monitoring: Maintain certificate and key inventory records and monitor for upcoming expiries or flagged misconfigurations.
Qualifications
- Education: Bachelor's / college degree in Computer Science, Information Technology, or a related field.
- Experience: 8-10 years of hands-on experience in cloud security operations (L2/L3), with demonstrable experience administering Microsoft Entra ID (RBAC, PIM, App Registrations, Managed Identities, Conditional Access), operating Microsoft Defender across cloud, server, container, and endpoint workloads, and handling PKI / certificate operations. Experience working within an incident and change management process (ITSM) is required. Multi-cloud experience across Azure, OCI, and/or GCP is a plus.
- Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- Microsoft Certified: Endpoint Administrator Associate (MD-102)
- Google Cloud Certified: Professional Cloud Security Engineer
- Vendor-agnostic security certifications (CISSP, CCSP, CSA CCSK, GIAC, etc.)
- Knowledge: Working knowledge of identity and privileged access concepts, PKI fundamentals (certificate lifecycle, key management, trust chains), cloud workload protection, and ticket-driven incident/change processes. Ability to follow runbooks and standard operating procedures accurately under time pressure.