Job description
Ce que nos collaborateurs aiment le plus chez nous ❤ : Pour consulter leurs avis certifiés
Company culture :
Sofrecom Maroc stands out for its strongly collaborative culture, where people, trust and employee well-being are central priorities. A close management approach promotes support, accountability and long-lasting teamwork. This collaborative foundation is complemented by a notable innovation dimension, encouraging initiative, agility and experimentation. Structured processes ensure reliability and operational efficiency, while performance-driven practices play a more supportive and balanced role.
Job :
Within the Security department, you will be responsible for the technical and operational management of the implementation of cybersecurity tools and solutions in the Middle East & Africa (MEA) subsidiaries, ensuring the quality of integration, security, compliance, and adoption by local teams.
Main activities
- Coordination & technical integration (responsibility of "technical project manager")
- Gather and consolidate requirements (technical, security, operational) from the internal program manager for strengthening the security posture of Middle East & Africa (MEA) subsidiaries and ensure their operational deployment in coordination with the IT and Network teams of the subsidiaries.
- Produce/validate technical deliverables: HLD/LLD, architecture documents, network flows, system requirements, sizing, prerequisites.
- Coordinate integration into local environments: AD/Azure AD, messaging, endpoints, network, proxies, firewalls...
- Ensure compliance with Orange standards: security, architecture, naming, logging, hardening, secrets management, certificates...
Deployment, testing, and go-live
- Define the deployment strategy (pilot, waves, rollback, change management).
- Prepare and execute technical and security testing: test plans, acceptance criteria, test reports.
- Supervise go-live: change windows, run coordination, incident recovery plan.
- Ensure transition to operations: documentation, runbooks, skills transfer.
Security, compliance, and risks
- Ensure compliance with Group policies and local requirements (e.g., data protection, country regulatory constraints).
- Monitor cyber risks related to deployment: configuration deviations, technical debt, exposure (ports/flows), obsolescence, third-party access.
- Contribute to security reviews: threat modeling (if applicable), configuration reviews, logging and retention requirements.
Partner management (publishers/integrators/managed service providers)
- Contribute to managing interactions with suppliers of various tools/solutions to be integrated, in coordination with the internal program manager for strengthening the security posture of Middle East & Africa (MEA) subsidiaries: planning, quality, deliverables, escalations, KPIs.
Subsidiary adoption & support
- Support local teams (IT, SecOps, network): workshops, training, support, best practices.
- Adapt deployments to on-site constraints (bandwidth, inventory, obsolescence, team availability, languages).
- Contribute to industrialization: models, templates, reusable standards, deployment playbooks.
الوصف الوظيفي
ما يحبه زملاؤنا في العمل أكثر عندنا ❤ : للاطلاع على آرائهم المعتمدة
ثقافة الشركة :
سوفريكم المغرب تبرز بـــثقافة تعاونية بشكل قوي، حيث الناس والثقة ورفاهية الموظف هي أولويات مركزية. نهج إداري قريب يشجع الدعم والمساءلة والعمل الجماعي طويل الأجل. هذه الأساس التعاوني يكمله بعد بعد ابتكاري ملحوظ، يشجع المبادرة والمرونة والتجريب. عمليات منظمة لضمان الاعتمادية والكفاءة التشغيلية، في حين أن الممارسات القائمة على الأداء تلعب دوراً أكثر دعمًا وتوازناً.
العمل :
ضمن قسم الأمن، ستتولى المسؤولية عن الإدارة التقنية والتشغيلية لتنفيذ أدوات وحلول الأمن السيبراني في فروع الشرق الأوسط وأفريقيا (MEA)، مع ضمان جودة التكامل والأمن والامتثال والتبني من قبل الفرق المحلية.
الأنشطة الرئيسية
- التنسيق والتكامل التقني (مسؤولية "المدير الفني للمشروع")
- جمْع وتوحيد المتطلبات (تقنية، أمان، تشغيلية) من مدير البرنامج الداخلي من أجل تعزيز موقف الأمن لفروع الشرق الأوسط وأفريقيا والتأكد من نشرها التشغيلي بالتنسيق مع فرق تكنولوجيا المعلومات والشبكة في الفروع.
- إنتاج/التحقق من التسليمات التقنية: HLD/LLD، وثائق الهندسة، تدفقات الشبكة، متطلبات النظام، التقدير، المتطلبات الأساسية.
- التنسيق للوحدة في البيئات المحلية: AD/Azure AD، الرسائل، النقاط النهائية، الشبكة، الوكاء، الجدران النارية...
- التأكد من الامتثال لمعايير Orange: الأمن، الهندسة، التسمية، التسجيل، التقوية، إدارة الأسرار، الشهادات...
النشر والاختبار والإطلاق
- تحديد استراتيجية النشر (تجريبي، دفعات، التراجع، إدارة التغيير).
- التحضير والتنفيذ لاختبارات تقنية وأمنية: خطط الاختبار، معايير القبول، تقارير الاختبارات.
- الإشراف على الإطلاق: فواصل التغيير، تنسيق التشغيل، خطة استعادة الحوادث.
- ضمان الانتقال إلى التشغيل: التوثيق، كتيبات التشغيل، نقل المهارات.
الأمن والالتزام والمخاطر
- التأكد من الامتثال لسياسات المجموعة والمتطلبات المحلية (مثلاً حماية البيانات، القيود التنظيمية البلدية).
- مراقبة المخاطر السيبرانية المرتبطة بالنشر: الانحرافات في التكوين، الدين التقني، التعرض (المنافذ/التدفقات)، التقادم، وصول الطرف الثالث.
- المساهمة في مراجعات الأمن: نمذجة التهديد (إن وُجد)، مراجعات التكوين، متطلبات التسجيل والاحتفاظ.
إدارة الشركاء (الناشرون/المتكاملون/مزودو الخدمة المدارة)
- المساهمة في إدارة التفاعلات مع مزودي الأدوات/الحلول المراد دمجها، بالتنسيق مع مدير البرنامج الداخلي من أجل تعزيز موقف الأمن لفروع الشرق الأوسط وأفريقيا: التخطيط، الجودة، المخرجات، التصعيدات، مؤشرات الأداء.
اعتماد الفرع والدعم
- دعم الفرق المحلية (تكنولوجيا المعلومات، SecOps، الشبكة): ورش عمل، تدريب، دعم، أفضل الممارسات.
- تكييف النُسخ مع القيود الميدانية (عرض النطاق الترددي، الجرد، التقادم، توفر الفريق، اللغات).
- المساهمة في التصنيع: النماذج، القوالب، المعايير القابلة لإعادة الاستخدام، كتيبات تشغيل النشر.