وصف الوظيفة
ما يحبه موظفونا فينا أكثر شيء ❤ : للاطلاع على آرائهم المعتمدة
ثقافة الشركة :
Sofrecom Maroc تبرز بكونها ثقافة تعاونية بشكل قوي، حيث الناس، الثقة ورفاهية الموظف هي أولويات مركزية. أسلوب إدارة قريب يعزز الدعم، المساءلة والعمل الجماعي الدائم. هذه الأساس التعاوني يكملها بُعد ابتكاري ملحوظ، يشجع المبادرة، والرشاقة والتجربة. عمليات منظمة تضمن الاعتماد والكفاءة التشغيلية، بينما تمارس الممارسات القائمة على الأداء دوراً أكثر دعمًا وتوازناً.
الوظيفة :
سياق المهمة:
سينضم الفريق متعدد التخصصات العامل بنمط أجايل. مهمتك الرئيسية هي تعزيز مجال أمان خدمات السحابة (COSMOS Security) من خلال المساهمة في التصميم، التطوير، الأتمتة، والتشغيل لحلول الأمان عبر وظائف متعددة.
ستعمل في بيئة تقنية مبتكرة، في الغالب مفتوحة المصدر، وستتعاون عن كثب مع العديد من أصحاب المصالح الداخليين لضمان توفر خدمات آمنة وعالية الأداء وموثوقة.
المهام الرئيسية
دورك سيدور حول محاور THINK، BUILD، RUN الاستراتيجية، مع نطاق تدخل يغطي عدة مشاريع رئيسية.
1. تصميم وتنفيذ خدمات الأمان (BUILD)
المشاركة في بناء وتطوير خدمة WAF (Web Application Firewall) القائمة على حل F5 NAP، من هيكلها إلى نشرها.
المساهمة في إثراء أداة أمان داخلية تجمع وظائف كشف الثغرات، والتحكم بالامتثال (CIS)، وتحليل المتانة (مثلاً Vulso، John the Ripper).
تعريف وتنفيذ هندسة هذه الخدمات في بيئة حاويات (Docker) ومُدارة (Kubernetes).
2. الدعم والمساعدة (BUILD & RUN)
مساعدة فرق العملاء في دمج خدمة WAF: المساعدة في التحقيق في الحظر، تكوين القواعد، وبناء الخبرة.
تقديم الدعم الفني لفرق التطوير من أجل التكامل المستمر (CI/CD) لتطبيقاتهم على منصاتنا.
3. الدراسات والمراقبة التكنولوجية (THINK)
إجراء دراسات تقنية لتقييم ودمج حلول جديدة تتعلق باستراتيجية أمان المجال.
ضمان أن تكون الدراسات قابلة لإعادة الإنتاج من خلال توثيق صارم ونقل النتائج بفعالية.
4. الأتمتة والتكامل المستمر (BUILD)
تطوير وصيانة خطوط تكامل ونشر مستمر (GitLab-CI) لخدمات الأمان.
كتابة إجراءات التكامل والتشغيل المرتبطة.
5. الصيانة في ظروف تشغيلية والتحسين المستمر (RUN)
التعامل مع حوادث المستوى 2 و3 وتقديم خبرتك لحلها.
مراقبة الأداء والتوفر وتجربة المستخدم للخدمات.
إدارة مراقبة سعة المنصة وتحسين الموارد.
المشاركة في تدوير الفريق لضمان استمرارية الخدمة (إدارة التذاكر، الاتصال، والتناوب عند الاستدعاء).
Job description
Ce que nos collaborateurs aiment le plus chez nous ❤ : Pour consulter leurs avis certifiés
Company culture :
Sofrecom Maroc stands out for its strongly collaborative culture, where people, trust and employee well-being are central priorities. A close management approach promotes support, accountability and long-lasting teamwork. This collaborative foundation is complemented by a notable innovation dimension, encouraging initiative, agility and experimentation. Structured processes ensure reliability and operational efficiency, while performance-driven practices play a more supportive and balanced role.
Job :
Mission Context:
You will join a multidisciplinary team working in agile mode. Your main mission will be to strengthen the Cloud services security domain (COSMOS Security) by contributing to the design, development, automation, and operation of cross-functional security solutions.
You will work in an innovative technical environment, mostly Open Source, and collaborate closely with many internal stakeholders to ensure the availability of secure, high-performance, and reliable services.
Main Missions
Your role will revolve around the strategic THINK, BUILD, and RUN axes, with an intervention scope covering several key projects.
1. Design and implementation of security services (BUILD)
Participate in the construction and evolution of a WAF (Web Application Firewall) service based on the F5 NAP solution, from its architecture to its deployment.
Contribute to the enrichment of an internal security tool that aggregates vulnerability detection, compliance control (CIS), and robustness analysis functionalities (e.g., Vulso, John the Ripper).
Define and implement the architecture of these services in a containerized (Docker) and orchestrated (Kubernetes) environment.
2. Support and assistance (BUILD & RUN)
Assist client teams in integrating the WAF service: help investigate blocks, configure rules, and build expertise.
Provide technical support to development teams for the continuous integration (CI/CD) of their applications on our platforms.
3. Studies and technological watch (THINK)
Conduct technical studies to evaluate and integrate new solutions related to the domain's security strategy.
Ensure studies are reproducible through rigorous documentation and effectively communicate results.
4. Automation and continuous integration (BUILD)
Develop and maintain continuous integration and deployment pipelines (GitLab-CI) for security services.
Write associated integration and operational procedures.
5. Maintenance in Operational Conditions and continuous improvement (RUN)
Handle Level 2 and 3 incidents and provide your expertise for their resolution.
Monitor the performance, availability, and user experience of services.
Manage platform capacity monitoring and optimize resources.
Participate in team rotations to ensure service continuity (ticket management, communication, on-call duty).