وصف الوظيفة
Ce que nos collaborateurs aiment le plus chez nous ❤ : Pour consulter leurs avis certifiés
Company culture :
Sofrecom Maroc تبرز بثقافتها التعاونية القوية، حيث الناس، الثقة ورفاهية الموظف في صدارة الأولويات. يروّج نهج الإدارة القريب للدعم، المساءلة والعمل الجماعي الطويل الأمد. تؤكد هذه الأساس التعاوني بُعداً مزدوجاً من الابتكار الملحوظ، يشجع المبادرة والمرونة والتجريب. عمليات منظمة تضمن الاعتمادية والكفاءة التشغيلية، فيما تمارس ممارسات مركزة على الأداء دوراً داعماً ومتوازناً أكثر.
الوظيفة :
سياق المهمة:
ستنضم إلى فريق متعدد التخصصات يعمل بنمط أجايل. مهمتك الأساسية ستكون تعزيز مجال أمان خدمات السحابة (COSMOS Security) من خلال المساهمة في تصميم وتطوير وأتمتة وتشغيل حلول أمان عابرة للوظائف.
ستعمل في بيئة فنية مبتكرة، في الغالب مفتوحة المصدر، وتتعاون عن كثب مع العديد من أصحاب المصلحة الداخليين لضمان توفر خدمات آمنة وعالية الأداء وموثوقة.
المهام الرئيسية
سيتركز دورك حول محاور THINK وBUILD وRUN الاستراتيجية، مع نطاق تدخل يغطي عدداً من المشاريع الرئيسية.
1. تصميم وتنفيذ خدمات الأمان (BUILD)
المشاركة في إنشاء وتطور خدمة WAF (Web Application Firewall) استناداً إلى حل F5 NAP، من هيكلها المعماري إلى نشرها.
المساهمة في إثراء أداة أمان داخلية تجمع اكتشاف الثغرات والضبط الامتثاثي (CIS) وتحليلات الصلابة (مثلاً Vulso، John the Ripper).
تعريف وتنفيذ هندسة هذه الخدمات في بيئة حاويات (Docker) ومنظّمة (Kubernetes).
2. الدعم والمساندة (BUILD & RUN)
مساعدة فرق العملاء في دمج خدمة WAF: المساعدة في التحقيق في حالات الحظر، إعداد القواعد، وبناء الخبرة.
توفير الدعم الفني لفرق التطوير بهدف الدمج المستمر (CI/CD) لتطبيقاتهم على منصاتنا.
3. الدراسات والمراقبة التقنية (THINK)
إجراء دراسات تقنية لتقييم ودمج حلول جديدة تتعلق باستراتيجية أمان النطاق.
ضمان أن تكون الدراسات قابلة لإعادة الإنتاج من خلال توثيق صارم وتوصيل النتائج بشكل فعال.
4. الأتمتة والتكامل المستمر (BUILD)
تطوير وصيانة خطوط أنابيب الدمج والنشر المستمر (GitLab-CI) لخدمات الأمان.
كتابة إجراءات الدمج والتشغيل المرتبطة بها.
5. الصيانة في ظروف التشغيل والتحسين المستمر (RUN)
التعامل مع حوادث المستوى 2 و3 وتقديم خبرتك لحلها.
مراقبة الأداء والتوافر وتجربة المستخدم للخدمات.
إدارة مراقبة سعة المنصة وتحسين الموارد.
المشاركة في جولات الفريق لضمان استمرارية الخدمة (إدارة التذاكر، التواصل، والواجب العارض).
Job description
Ce que nos collaborateurs aiment le plus chez nous ❤ : Pour consulter leurs avis certifiés
Company culture :
Sofrecom Maroc stands out for its strongly collaborative culture, where people, trust and employee well-being are central priorities. A close management approach promotes support, accountability and long-lasting teamwork. This collaborative foundation is complemented by a notable innovation dimension, encouraging initiative, agility and experimentation. Structured processes ensure reliability and operational efficiency, while performance-driven practices play a more supportive and balanced role.
Job :
Mission Context:
You will join a multidisciplinary team working in agile mode. Your main mission will be to strengthen the Cloud services security domain (COSMOS Security) by contributing to the design, development, automation, and operation of cross-functional security solutions.
You will work in an innovative technical environment, mostly Open Source, and collaborate closely with many internal stakeholders to ensure the availability of secure, high-performance, and reliable services.
Main Missions
Your role will revolve around the strategic THINK, BUILD, and RUN axes, with an intervention scope covering several key projects.
1. Design and implementation of security services (BUILD)
Participate in the construction and evolution of a WAF (Web Application Firewall) service based on the F5 NAP solution, from its architecture to its deployment.
Contribute to the enrichment of an internal security tool that aggregates vulnerability detection, compliance control (CIS), and robustness analysis functionalities (e.g., Vulso, John the Ripper).
Define and implement the architecture of these services in a containerized (Docker) and orchestrated (Kubernetes) environment.
2. Support and assistance (BUILD & RUN)
Assist client teams in integrating the WAF service: help investigate blocks, configure rules, and build expertise.
Provide technical support to development teams for the continuous integration (CI/CD) of their applications on our platforms.
3. Studies and technological watch (THINK)
Conduct technical studies to evaluate and integrate new solutions related to the domain's security strategy.
Ensure studies are reproducible through rigorous documentation and effectively communicate results.
4. Automation and continuous integration (BUILD)
Develop and maintain continuous integration and deployment pipelines (GitLab-CI) for security services.
Write associated integration and operational procedures.
5. Maintenance in Operational Conditions and continuous improvement (RUN)
Handle Level 2 and 3 incidents and provide your expertise for their resolution.
Monitor the performance, availability, and user experience of services.
Manage platform capacity monitoring and optimize resources.
Participate in team rotations to ensure service continuity (ticket management, communication, on-call duty).