وصف الوظيفة
ثقافة الشركة :
Aba Technology شركة تقودها الابتكار، حيث ي şekكل الإبداع، والتجربة، والتفكير الطموح العمل اليومي. تدعم هذه العقلية الريادية بنية قوية وانضباط عملياتي، مما يضمن الكفاءة وجودة متسقة. الفرق تزدهر في بيئة تعاونية ومهتمة تقدر الثقة والدعم والعمل الجماعي الوثيق. بينما يلعب الأداء والمنافسة دوراً أخف، يظل التركيز على الرشاقة، الاتساق الجماعي، والابتكار المؤثر.
الوظيفة :
CI/CD والتح automation
• تصميم وتنفيذ وصيانة خطوط CI/CD (GitLab CI، GitHub Actions، Azure DevOps).
• أتمتة البناء، الاختبار، النشر، والتراجع عبر بيئات مختلفة (تطوير، التهيئة، الإنتاج).
• تعميم تجهيز البنية التحتية عبر البنية التحتية ككود (IaC).
الأمن المتكامل (Sec)
• دمج أدوات تحليل الأمان في خطوط الأنابيب: SAST (SonarQube)، DAST (OWASP ZAP، Burp)، SCA (Snyk، Dependency-Track، Trivy).
• تنفيذ إدارة الأسرار.
• تعزيز أمان صور الحاويات وتكويناتها (معايير CIS، فحص الصور، توقيع القطع).
• تحديد وتطبيق سياسات أمان Kubernetes (RBAC، سياسات الشبكة، OPA/Gatekeeper، Kyverno).
• المشاركة في إدارة الثغرات: الكشف، التصنيف (CVSS/EPSS)، الإصلاح، والمتابعة.
البنية التحتية والسحابة
• إدارة وتحسين بيئات السحابة وعوارض Kubernetes.
• ضمان توافر عالي ومرونة وخطط استمرارية الأعمال/التعافي من الكوارث (BCP/DRP).
• تحسين تكاليف السحابة (FinOps).
المراقبة والعمليات
• تنفيذ الرصد، التسجيل، والتنبيه (Prometheus، Grafana، ELK/OpenSearch، Datadog).
• المشاركة في إدارة الحوادث في الإنتاج وما بعد الحدث.
• المساهمة في الاستجابة لحوادث الأمن بالتنسيق مع فريق الأمن السيبراني (SOC/CSIRT).
الثقافة والدعم
• نشر ثقافة DevSecOps بين فرق التطوير (التدريب، الإرشادات، أبطال الأمان).
• كتابة والحفاظ على الوثائق الفنية (تشغيل دفاتر العمل، الهندسات، الإجراءات).
• إجراء متابعة تقنية وأمنية مستمرة.
ملف تعريف مطلوبة :
المهارات الصلبة:
• التعليم: درجة ماجستير (مدرسة هندسية أو ماجستير) في علوم الحاسوب، الأنظمة/الشبكات، أو الأمن.
• الخبرة: من 3 إلى 5 سنوات كحد أدنى في DevOps/SRE مع عنصر أمني قوي، أو في الأمن التشغيلي مع خبرة في الأتمتة.
• الشهادات المميزة: CKA/CKS، AWS/Azure Security Specialty، Terraform Associate، DevSecOps Foundation، CompTIA Security+.
المهارات الناعمة:
• الصرامة والقدرة على توقع المخاطر.
• عقلية الأتمتة (
Job description
Company culture :
Aba Technology is a company driven by innovation, where creativity, experimentation, and bold thinking shape everyday work. This entrepreneurial mindset is supported by strong structure and process discipline, ensuring efficiency and consistent quality. Teams thrive in a collaborative and caring environment that values trust, support, and close teamwork. While performance and competition play a lighter role, the focus remains on agility, collective alignment, and impactful innovation.
Job :
CI/CD and Automation
• Design, implement, and maintain CI/CD pipelines (GitLab CI, GitHub Actions, Azure DevOps).
• Automate builds, tests, deployments, and rollbacks across different environments (dev, staging, production).
• Industrialize infrastructure provisioning through Infrastructure as Code.
Integrated Security (Sec)
• Integrate security analysis tools into pipelines: SAST (SonarQube), DAST (OWASP ZAP, Burp), SCA (Snyk, Dependency-Track, Trivy).
• Implement secret management.
• Harden container images and configurations (CIS Benchmarks, image scanning, artifact signing).
• Define and apply Kubernetes security policies (RBAC, Network Policies, OPA/Gatekeeper, Kyverno).
• Participate in vulnerability management: detection, prioritization (CVSS/EPSS), remediation, and tracking.
Infrastructure and Cloud
• Administer and optimize cloud environments and Kubernetes clusters.
• Ensure high availability, resilience, and business continuity/disaster recovery plans (BCP/DRP).
• Optimize cloud costs (FinOps).
Observability and Operations
• Implement monitoring, logging, and alerting (Prometheus, Grafana, ELK/OpenSearch, Datadog).
• Participate in production incident management and post-mortems.
• Contribute to security incident response in coordination with the cybersecurity team (SOC/CSIRT).
Culture and Support
• Disseminate the DevSecOps culture among development teams (training, guidelines, security champions).
• Write and maintain technical documentation (runbooks, architectures, procedures).
• Conduct continuous technological and security watch.
Required profile :
Hard Skills:
• Education: Master's degree (engineering school or Master's) in computer science, systems/networks, or security.
• Experience: 3 to 5 years minimum in DevOps/SRE with a strong security component, or in operational security with automation experience.
• Valued Certifications: CKA/CKS, AWS/Azure Security Specialty, Terraform Associate, DevSecOps Foundation, CompTIA Security+.
Soft Skills:
• Rigor and ability to anticipate risks.
• Automation mindset ("automate everything").
• Teaching ability and capacity to evangelize best practices.
• Autonomy, responsiveness in incident management, teamwork in multidisciplinary teams.