وصف الوظيفة
الأدوار والمسؤوليات
سياق وصف الوظيفة، كجزء من تقوية فريق الأمن السيبراني لمجموعة Scalian، نحن نوظف مهندس أمن سيبراني تشغيلي لدعم مدير الأمن السيبراني عبر نطاق واسع جداً (SOC، الحوادث، التدقيقات، اختبار الاختراق، الامتثال، إلخ). المنصب عملي للغاية، مع رؤية عالمية لأمن المعلومات للمجموعة (عدة دول). التبليغ إلى مدير بنية تحتية تكنولوجيا المعلومات للمجموعة، ضمن فريق بنية تحتية تكنولوجيا المعلومات للمجموعة. المسؤوليات الرئيسية: الأمان التشغيلي وSOC: مراقبة وإدارة SOC (مزوّد خارجي أو داخلي)؛ تحليل إشعارات الأمان؛ تأهيل/أولوية الحوادث؛ مراقبة إجراءات التصحيح؛ المشاركة النشطة في إدارة حوادث الأمان؛ التحقيق (SIEM، السجلات، النقاط الطرفية، الشبكات)؛ تحليل السبب الجذري (RCA)؛ الإسهام في الدروس المستفادة (REX)؛ الإسهام في تحسين مستمر لقواعد الكشف وعمليات SOC. اختبار الاختراق وإدارة الثغرات: مراقبة اختبارات الاختراق الخارجية (وإن وجدت الاختبارات الداخلية)؛ نطاق الاختبار (النطاق، الأهداف)؛ تحليل التقارير؛ تأهيل الثغرات؛ تنسيق خطط الإصلاح مع فرق تكنولوجيا المعلومات؛ المشاركة في إدارة الثغرات (الاستطلاع، الأولويات، الرصد). حوكمة عبر وظائف ومجالات وآمان: الإسهام في التطبيق والصيانة للمتطلبات. الأمن: أفضل الممارسات، تعزيز الحماية، الأدلة التقنية. المشاركة في تدقيقات الأمان (ISO 27001، TISAX، العملاء). دعم أمان لفِرَق تكنولوجيا المعلومات (الأنظمة، الشبكات، محطات العمل). رصد الأمان (التهديدات، الثغرات، أفضل الممارسات).
المرشح المثالي
ملف البحث
التكوين والخبرة
- درجة البكالوريوس (بكالريوس +3) أو ماجستير (بكالريوس +5) في الأمن السيبراني / علوم الحاسوب
- خبرة لا تقل عن 3 سنوات في الأمن التشغيلي (SOC)، استجابة للحوادث، أو أمان معلومات عام مع تركيز قوي على الأمن السيبراني
المهارات التقنية المتوقعة
- فهم جيد للبيئات: الأنظمة (Windows، Linux)، الشبكات (TCP/IP، جدار الحماية، الوكيل، VPN)، محطات العمل
- خبرة أو حساسية قوية: SOC / SIEM تحليل سجلات، إدارة حوادث الأمن، متطوعون واختبار الاختراق
- المهارات المطلوبة: أدوات EDR/XDR، منهجيات الهجوم (OWASP، MITRE ATT&CK)، معايير ISO 27001 / TISAX
المهارات الشخصية
- عقلية تحليلية ومنهجية
- القدرة على الحفاظ على رباطة الجأش في موقف الحادث
- مهارات التعامل بين الأشخاص (التعاون مع تكنولوجيا المعلومات، مزودي الخدمة، الإدارة)
- القدرة على تبسيط مواضيع الأمن
- الاستقلالية، الدقة، الحساسية بالأولويات
اللغات
- إنجليزية مهنية (في سياق دولي)
Job Description
Roles & Responsibilities
Job Description Context As part of strengthening the Scalian Group's Cybersecurity team, we are recruiting an Operational Cybersecurity Engineer to support the cybersecurity manager across a very broad scope (SOC, incidents, audits, penetration testing, compliance, etc.). The position is highly operational, with a global view of the group's IT security (multi-country). Reporting to the Group IT Infrastructure Manager, within the Group IT Infrastructure team. Main responsibilities: Operational Security & SOC: Monitoring and management of the SOC (external or internal provider); Analysis of security alerts; Qualification/prioritization of incidents; Monitoring of corrective actions; Active participation in security incident management; Investigation (SIEM, logs, endpoints, networks); Root cause analysis (RCA); Contribution to lessons learned (REX); Contribution to the continuous improvement of detection rules and SOC processes. Penetration Testing & Vulnerability Management: Monitoring of external penetration tests (and internal tests if applicable); Test scoping (scope, objectives); Analysis of reports; Vulnerability qualification; Coordination of remediation plans with IT teams; Participation in vulnerability management (scanning, prioritization, monitoring). Cross-functional Governance & Security: Contribution to the implementation and maintenance of requirements. Security: Best practices, hardening, technical guides. Participation in security audits (ISO 27001, TISAX, clients). Security support for IT teams (systems, networks, workstations). Security monitoring (threats, vulnerabilities, best practices).
Desired Candidate Profile
Search profile
Formation & exp rience
- Bachelor's degree (Bac+3) or Master's degree (Bac+5) in cybersecurity / computer science
- Minimum 3 years' experience in operational security (SOC), incident response, or general IT security with a strong cybersecurity focus
Expected technical skills
- Good understanding of environments: Systems (Windows, Linux), Networks (TCP/IP, firewall, proxy, VPN), Workstations
- Experience or strong sensitivity: SOC / SIEM Log analysis Security incident management Volunteers and intrusion testing
- Desired skills: EDR/XDR tools, attack methodologies (OWASP, MITRE ATT&CK), ISO 27001 / TISAX standards
Soft skills
- Analytical and methodical mind
- Ability to keep a cool head in an incident situation
- Good interpersonal skills (changes with IT, service providers, management)
- Ability to simplify security topics
- Autonomy, rigor, sense of priorities
LANGUAGES
- Professional English (international context)