Job Description: Network & Security Operations Engineer
Location
On-site — Kingdom of Morocco
Role Type
Permanent / Long-term — Day 2 Operations (BAU)
Certification
NSE 5 minimum — NSE 7 / FCSS preferred
Clearance
Government site security clearance required
About the Platform
Project: Morocco Steady-State Operations
Environment: Government-grade, on-premises bare-metal infrastructure. Three security-zone Kubernetes clusters (DMZ, Core, Red Zone) underpinned by a Fortinet security fabric (FortiGate 901G HA pair, FortiSwitch, FortiManager, FortiPAM, FortiWeb WAF, FortiADC, FortiAnalyzer) and Dell PowerEdge R670 compute nodes with Ceph distributed storage. Backup is delivered via Dell PowerProtect.
Operations model: The platform has been deployed and accepted. These roles cover Day 2 steady-state operations — monitoring, incident response, change management, backup validation, and continuous improvement. No deployment or project delivery responsibilities.
Role Overview
The Network & Security Operations Engineer is the primary Day 2 owner of the entire Fortinet security fabric protecting the platform. You maintain service continuity, respond to security events and network incidents, manage configuration changes through the change control process, and ensure the logging and audit trail infrastructure is operational at all times — a compliance-critical requirement for this government platform.
You work alongside the Infrastructure & Platform Operations Engineer, who owns the compute, Kubernetes, and backup layer. Together, the two roles provide full-stack operational coverage with clear domain ownership.
Day-to-Day Responsibilities
Monitoring & Incident Response
Monitor FortiAnalyzer dashboards and alert feeds for security events, anomalous traffic, and policy violations across all zones.
Triage WAF alerts from FortiWeb: distinguish false positives from genuine threats, tune policies, and escalate confirmed incidents through the defined severity ladder.
Monitor FortiGate HA pair health: failover readiness, session table, CPU/memory baselines, and interface status.
Respond to FortiSwitch alerts: port flaps, uplink failures, spanning-tree events, and VLAN mismatches.
Own the first-response runbook for network and security incidents — document, contain, and escalate per the agreed SLA thresholds.
Change & Configuration Management
Process and implement firewall rule change requests through the change control board: validate business justification, implement on FortiManager, push to FortiGate, and produce evidence.
Manage VLAN and port changes on FortiSwitch: coordinate with the application and infrastructure teams to ensure correct zone placement.
Maintain FortiPAM user roster: onboard new privileged accounts, offboard leavers, enforce least-privilege RBAC, and produce monthly session audit reports.
Track and apply FortiOS, FortiSwitch, FortiWeb, and FortiManager firmware updates through the approved maintenance window process.
Renew and manage SSL/TLS certificates on FortiADC and FortiWeb ahead of expiry.
Compliance & Audit
Validate daily that log ingestion is functioning across all Fortinet components into FortiAnalyzer — any gap is a compliance incident.
Generate periodic access, session, and policy-change audit reports for security team consumption.
Conduct quarterly firewall rule reviews: identify stale, overly permissive, or undocumented rules and raise change requests for remediation.
Support any external security assessments or audits with evidence packs from FortiAnalyzer and FortiManager.
Documentation & Continuous Improvement
Maintain as-built accuracy: update network topology diagrams, VLAN registers, and IP plans after any change.
Update and improve operational runbooks based on incident learnings.
Identify recurring alert patterns and propose WAF tuning or firewall policy improvements to reduce noise.
Must-Have Requirements
FortiGate operations experience in a production environment: policy management, rule review, HA monitoring, firmware upgrades.
FortiManager operations: config push, managed-device monitoring, RBAC, audit trail review.
FortiAnalyzer or equivalent SIEM: log ingestion monitoring, security event investigation, report generation.
VLAN and switching operations: port changes, trunk management, VLAN troubleshooting.
NSE 5 minimum — NSE 7 / FCSS preferred. Certificate copy required at interview.
Experience operating network/security infrastructure in a government, critical infrastructure, or regulated environment.
Familiarity with PAM platforms: session monitoring, privileged account lifecycle.
On-site availability in Morocco on a permanent or long-term basis.
Desired Candidate Profile
Good-to-Have
FortiWeb WAF operations: signature updates, alert tuning, false-positive management.
FortiPAM-specific experience (or CyberArk / BeyondTrust in a comparable role).
FortiADC or equivalent ADC/load-balancer operations (F5 LTM, Citrix NetScaler).
SSL certificate lifecycle management across multiple services.
Familiarity with API/PNR data classification requirements or aviation/border security data handling.
French or Arabic language capability.
وصف الوظيفة: مهندس تشغيل الشبكات والأمن
الموقع
موقع فعلي — المملكة المغربية
نوع الدور
دائم / طويل الأجل — عمليات الساعة 2 (BAU)
الاعتماد
لا يقل عن NSE 5 — يفضل NSE 7 / FCSS
التصريح الأمني
مطلوب تصريح أمني حكومي
حول المنصة
المشروع: عمليات الوضع الثابت في المغرب
البيئة: بنية تحتية مادية في الموقع من مستوى حكومي. ثلاث عنConfigurations من Kubernetes zones للمناطق الأمنية (DMZ، Core، Red Zone) مدعومة بنسيج أمني Fortinet (زوج FortiGate 901G HA، FortiSwitch، FortiManager، FortiPAM، FortiWeb WAF، FortiADC، FortiAnalyzer) وعُقد حوسبة Dell PowerEdge R670 مع تخزين Ceph الموزع. النسخ الاحتياطي يتم عبر Dell PowerProtect.
نمـوذج التشغيل: تم نشر المنصة وقبولها. تغطي هذه الأدوار عمليات الساعة 2 الثابتة — المراقبة، الاستجابة للحوادث، إدارة التغيير، التحقق من النسخ الاحتياطي، والتحسين المستمر. لا توجد مسؤوليات النشر أو تقديم المشروع.
نظرة عامة على الدور
مهندس تشغيل الشبكات والأمن هو المالك الأساسي للساعة 2 لكامل نسيج Fortinet الأمني الذي يحمي المنصة. تحافظ على استمرارية الخدمة، وتستجيب للأحداث الأمنية وحوادث الشبكة، وتدير تغييرات التكوين من خلال عملية التحكم في التغيير، وتضمن أن تكون بنية التسجيل والتدقيق قيد التشغيل في جميع الأوقات — وهو متطلب امتثال حاسم لهذه المنصة الحكومية.
تعمل جنباً إلى جنب مع مهندس تشغيل البنية التحتية والمنصة، الذي يمتلك طبقة الحوسبة وKubernetes والنسخ الاحتياطي. معاً، يوفر الاثنان تغطية تشغيلية كاملة بالنطاقات الواضحة.
المسؤوليات اليومية
المراقبة والاستجابة للحوادث
مراقبة لوحات FortiAnalyzer وتغذيات الإنذار لأحداث الأمن، وحركة مرور غير عادية، وانتهاكات السياسات عبر جميع المناطق.
تصنيف إنذارات WAF من FortiWeb: التمييز بين الإيجابيات الكاذبة والتهديدات الحقيقية، ضبط السياسات، وتصعيد الحوادث المؤكدة عبر سلم شدة محدد.
مراقبة صحة زوج FortiGate HA: جاهزية التحويل التلقائي، جداول الجلسات، المقاييس الأساسية للـCPU/الذاكرة، وحالة الواجهات.
الاستجابة لإنذارات FortiSwitch: تقلبات المنافذ، فشل الربط، أحداث spanning-tree، وت mismatches في VLAN.
امتلاك دليل الاستجابة الأولي للحوادث الشبكية والأمنية — توثيق، احتواء، وتصعيد وفقاً لع thresholds SLA المتفق عليها.
إدارة التغيير والتكوين
عملية وتنفيذ طلبات تغيير قواعد الجدار الناري من خلال مجلس التحكم في التغيير: التحقق من جدوى العمل، التنفيذ على FortiManager، الدفع إلى FortiGate، وتقديم الأدلة.
إدارة تغييرات VLAN والمنافذ على FortiSwitch: التنسيق مع فرق التطبيق والبنية التحتية لضمان وضع المنطقة الصحيح.
الحفاظ على قائمة مستخدمي FortiPAM: إدراج حسابات مميزة جديدة، إنهاء وصول عند المغادرة، فرض أقل امتياز RBAC، وإنتاج تقارير تدقيق جلسات شهرية.
تتبع وتطبيق تحديثات firmware لـ FortiOS، FortiSwitch، FortiWeb، و FortiManager من خلال نافذة الصيانة المعتمدة.
تجديد وإدارة شهادات SSL/TLS على FortiADC و FortiWeb قبل انتهاء الصلاحية.
الامتثال والتدقيق
التحقق يومياً من أن إدخال السجلات يعمل عبر جميع مكونات Fortinet إلى FortiAnalyzer — أي فجوة تعتبر حادث امتثال.
إنتاج تقارير مراجعة وصول وجلسة وتغيير السياسات بشكل دوري للاستخدام من قبل فريق الأمن.
إجراء مراجعات قواعد الجدار الناري ربع السنوية: تحديد القواعد العتيقة أو المفرطة الإذن أو غير الموثقة ورفع طلبات تعديل للإصلاح.
دعم أي تقييمات أمنية خارجية أو تدقيقات مع حزم أدلة من FortiAnalyzer و FortiManager.
التوثيق والتحسين المستمر
الحفاظ على دقة كما-بُني: تحديث مخططات بنية الشبكة، سجلات VLAN، وخطط IP بعد أي تغيير.
تحديث وتحسين أدلة التشغيل بناءً على دروس الحوادث.
تحديد أنماط الإنذارات المتكررة واقتراح ضبط WAF أو تحسين سياسة الجدار الناري لتقليل الضوضاء.
المتطلبات الأساسية
خبرة تشغيل FortiGate في بيئة إنتاج: إدارة السياسات، مراجعة القواعد، مراقبة HA، ترقية firmware.
تشغيل FortiManager: دفع التكوين، مراقبة الأجهزة المدارة، RBAC، مراجعة سجل التدقيق.
FortiAnalyzer أو SIEM مكافئ: مراقبة إدخال السجلات، التحقيق في أحداث الأمن، إنشاء التقارير.
تشغيل VLAN والتبديل: تغييرات المنافذ، إدارة الروابط، استكشاف أخطاء VLAN.
NSE 5 كحد أدنى — يفضل NSE 7 / FCSS. مطلوب نسخة الشهادة عند المقابلة.
خبرة في تشغيل بنية الشبكة/الأمن في بيئة حكومية، بنية تحتية حيوية، أو بيئة منظمة.
ألم بـ منصات PAM: رصد الجلسات، دورة حياة الحساب المميز.
التواجد في المغرب بشكل دائم أو على المدى الطويل.
الملف المرشح المرغوب
مطلوب
عمليات FortiWeb WAF: تحديث التوقيعات، ضبط الإنذارات، إدارة الإيجابيات الكاذبة.
خبرة محددة بـ FortiPAM (أو CyberArk / BeyondTrust في دور مماثل).
FortiADC أو منافذ ADC/تحميل-الموازنات المكافئ (F5 LTM، Citrix NetScaler).
إدارة دورة حياة شهادات SSL عبر خدمات متعددة.
الاطلاع على متطلبات تصنيف بيانات API/PNR أو بيانات الأمن الجوي/الحدودي.
كفاءة في الفرنسية أو العربية.