تشغيل الشبكات والاتصال
· إدارة ودعم شبكات LAN وWAN وSD-WAN والإنترنت والـ MPLS والاتصال بين المواقع عبر المكاتب والفروع والمستودعات ومراكز البيانات وبيئات العملاء.
· تكوين واستكشاف وتحسين محولاتCisco وHPE Aruba، والمفاتيح، وVLANs، وSTP، وLACP، والتوجيه، وQoS، وDHCP، وDNS، وNAT، وVPNs وتصاميم التوفر العالي.
· مراقبة السعة، والكمون، وفقدان الحزم، وحالة الواجهات والتوافر؛ إزالة عناصر الفشل المفردة وبطء الأداء المتكرر بشكل وقائي.
· التخطيط وتنفيذ تحديثات الأجهزة، وتحديثات البرامج الثابتة، وهجرات الفروع والتغييرات الشبكية مع تراجع مقيد وتأثير تشغيلي منخفض.
الأمن السيبراني، الجدار الناري وSASE
· إدارة جدران حماية Check Point وبوابات الأمان والمنصات الإدارية المرتبطة، بما في ذلك السياسة والكائنات وNAT وVPN ومنع التهديدات والسجلات والتحديثات والتوافر العالي.
· تصميم وتشغيل قدرات SASE التي تغطي الوصول الآمن إلى الويب والوصول عن بعد وربط الفروع، والوصول المعتمد على الهوية، والتحكم في تطبيقات السحابة وتنفيذ سياسات الأمان.
· دعم منتجات أمان نقطة النهاية مثل EDR/EPP، ومكافحة البرامج الخبيثة، وجدار حماية المضيف، والتحكم في الأجهزة، وتشفير القرص، والحماية عبر الويب وفرض الوضع الأمني.
· مراجعة التنبيهات وسجلات الجدار الناري والأحداث الأمنية؛ التحقيق في التهديدات المشتبه بها وتنسيق الاحتواء والمعالجة وجمع الأدلة والتصعيد مع SOC أو شركاء الأمن.
· إجراء مراجعات دورية لقاعدة القواعد ومراجعات وصول وتخفيف الثغرات وتقوية الأمان بما يتماشى مع الحد الأدنى من الامتيازات ومعايير أمان المؤسسة.
البنية التحتية اللاسلكية
· تصميم ونشر ودعم شبكات الواي فاي المؤسسية باستخدام نقاط وصول HPE Aruba ووحدات التحكم اللاسلكي، بما في ذلك SSIDs وملامح التردد والقنوات والتنقل والوصول للضيف والمصادقة والتقسيم.
· إجراء مسوحات لاسلكية واستكشاف التداخل والتغطية الضعيفة والازدحام، وفشل المصادقة ومشاكل وحدة التحكم/النقطة اللاسلكية.
· تكامل الخدمات اللاسلكية المؤسسية والضيوف مع RADIUS/NAC وخدمات الدليل والشهادات وسياسات الأمن.
التكامل الهوية والسحاب والتطبيقات كخدمة
· دعم تكاملات الشبكة والأمن مع Active Directory وMicrosoft Entra ID، بما في ذلك الوصول بالهوية والمجموعات وRADIUS/NPS وSSO وMFA والتبعيات للوصول المشروط.
· دعم الاتصال الآمن بـAzure أو بيئات سحابية أخرى باستخدام VPN واتصال خاص وتوجيه وDNS والتحكمات الأمنية للشبكة ومبادئ الهندسة المختلطة.
· تمكين وتأمين خدمات SaaS من خلال SSO وسياسات الوصول وبوابات الويب الآمنة/CASB والتحقق من السجلات ومتطلبات تكامل البائع.
· التعاون مع فرق الخادم والسحاب والتطبيق والأمن في التغييرات التي تؤثر على المصادقة والشهادات وواجهات برمجة التطبيقات وSAP/ERP وأحمال العمل السحابية والخدمات الأساسية للأعمال.
تشغيل الخدمة وإدارة الحوادث
· تقديم دعم L3 للحوادث المعقدة وطلبات الخدمة؛ استعادة الخدمات ضمن اتفاقية مستوى الخدمة وإبقاء أصحاب المصلحة على اطلاع أثناء الانقطاعات عالية التأثير.
· قيادة استكشاف الأخطاء التقني، ودعم الحوادث الكبرى، وتحليل السبب الجذري والإجراءات التصحيحية/الوقائية لفشل الشبكة والأمن.
· الحفاظ على المراقبة الاستباقية، وعُتبات التنبيه، ونسخ احتياطية للتكوين، ولوحات التوفر، وفحوصات الصحة التشغيلية لجميع الأصول الحيوية.
· توجيه مهندسي L1/L2، ومراجعة التصعيدات وتقوية قدرة الفريق من خلال نقل المعرفة، وكتابة Runbooks وتوجيه فني.
المشروعات والعمارة والتغيير
· ترجمة متطلبات العمل إلى معماريات شبكية/أمنية آمنة وقابلة للتوسع ومستدامة وكميات قابلة للتنفيذ ومعايير قبول.
· قيادة المشاريع البنية التحتية المعينة وتنسيق أصحاب المصلحة الداخليين والعملاء ومقدمي الخدمات وموردي المعدات والتعاون في التنفيذ.
· تحديد المخاطر التقنية ومخاطر المشروع مبكرًا وتوثيق التدابير، وإدارة الاعتماديات والتصعيد في حالة تأخر التسليم أو التعرض التشغيلي.
· اتباع ضوابط إدارة التغيير، وإكمال تقييم التأثير/المخاطر، والحصول على الموافقات، والتحقق من التنفيذ والحفاظ على خطط التراجع المختبرة.
حوكمة البائعين وSLA والتكاليف والامتثال
· إدارة أداء البائع مقابل SLA وعقود الدعم ومعالم المشروع؛ إجراء مراجعات الخدمة وتحريك حلول سريعة للتصعيد.
· متابعة التجديدات والتراخيص والضمانات وتغطية الدعم؛ تقييم المقترحات وتقديم خيارات تجارية أو هندسية تعزز القيمة وتقلل CAPEX/OPEX.
· الحفاظ على معايير الشبكة والأمان، وسجلات الأصول/التكوين، والرسوم البيانية، وSOPs، ووثائق البناء وتوثيق تسليم المشروع.
· تسجيل ومراجعة مخاطر البنية التحتية بشكل دوري؛ دعم التدقيقات الداخلية/الخارجية والالتزام بمتطلبات تكنولوجيا المعلومات، وأمن المعلومات، والتنظيم وحماية البيانات.
· التخطيط والتحقق من الصيانة الوقائية، واستعداد استرداد الكوارث، واستعادة التكوين وخطط الاستمرارية للبنية التحتية الحرجة.
*** خبرة في إدارة شبكاتEnterprise كبيرة وأمن يتعلق بها.
ملف المرشح المرغوب
الكفاءة التقنية
التبديل المؤسسي (VLAN، STP، LACP، OSPF/BGP)
الإنترنت اللاسلكي المؤسسي (Aruba/Cisco، RF، 802.1X، التنقل)
الجدار الناري (Check Point/Fortinet، NAT، IPS، تحكم التطبيقات)
VPN (IPSec، SSL VPN، Site-to-Site، الوصول عن بُعد)
SASE / Zero Trust (ZTNA، SWG، CASB، FWaaS)
Microsoft Entra ID والتحقق المشروط للوصول
Microsoft Intune وإدارة النقاط الطرفية
Active Directory، DNS، DHCP، PKI وNPS/RADIUS
أمان الشبكة (التقسيم، NAC، MFA، التقسيم المصغر)
شبكات السحابة (Azure/AWS، VNet، VPN)
موازن التحميل / WAF / الوكيل العكسي
المراقبة، SIEM وتحليل الحزم
التوفر العالي واسترداد الكوارث
التشخيص العملي الفعّال وتحليل الأسباب
Network & Connectivity Operations
· Administer and support enterprise LAN, WAN, SD-WAN, internet, MPLS and site-to-site connectivity across offices, branches, warehouses, data centres and customer environments.
· Configure, troubleshoot and optimize Cisco and HPE Aruba switches, routers, VLANs, STP, LACP, routing, QoS, DHCP, DNS, NAT, VPNs and high-availability designs.
· Monitor capacity, latency, packet loss, interface health and availability; proactively remove single points of failure and recurring performance bottlenecks.
· Plan and execute hardware refreshes, firmware upgrades, branch migrations and network changes with controlled rollback and minimal production impact.
Cybersecurity, Firewall & SASE
· Administer Check Point firewalls, security gateways and related management platforms, including policy, objects, NAT, VPN, threat prevention, logs, upgrades, backups and high availability.
· Design and operate SASE capabilities covering secure web access, remote access, branch connectivity, identity-aware access, cloud application control and security policy enforcement.
· Support endpoint security products such as EDR/EPP, anti-malware, host firewall, device control, disk encryption, web protection and security posture enforcement.
· Review alerts, firewall logs and security events; investigate suspected threats and coordinate containment, remediation, evidence collection and escalation with SOC or security partners.
· Conduct periodic rule-base reviews, access reviews, vulnerability remediation and security hardening in line with least privilege and organizational security standards.
Wireless Infrastructure
· Design, deploy and support enterprise Wi‑Fi using HPE Aruba access points and wireless controllers, including SSIDs, RF profiles, channels, roaming, guest access, authentication and segmentation.
· Perform wireless surveys and troubleshoot interference, weak coverage, congestion, authentication failures and controller/AP issues.
· Integrate corporate and guest wireless services with RADIUS/NAC, directory services, certificates and security policies.
Identity, Cloud & SaaS Integration
· Support network and security integrations with Active Directory and Microsoft Entra ID, including identity-based access, groups, RADIUS/NPS, SSO, MFA and conditional access dependencies.
· Support secure connectivity to Azure or other cloud environments using VPN, private connectivity, routing, DNS, network security controls and hybrid architecture principles.
· Enable and secure SaaS services through SSO, access policies, secure web gateway/CASB controls, logging and vendor integration requirements.
· Collaborate with server, cloud, application and security teams on changes affecting authentication, certificates, APIs, SAP/ERP, cloud workloads and business-critical services.
Service Operations & Incident Management
· Provide L3 support for complex incidents and service requests; restore services within agreed SLA and keep stakeholders informed during high-impact outages.
· Lead technical troubleshooting, major incident support, root-cause analysis and corrective/preventive actions for network and security failures.
· Maintain proactive monitoring, alert thresholds, configuration backups, availability dashboards and operational health checks for all critical assets.
· Guide L1/L2 engineers, review escalations and strengthen team capability through knowledge transfer, runbooks and technical coaching.
Projects, Architecture & Change
· Translate business requirements into secure, scalable and supportable network/security architectures, bills of quantity, implementation plans and acceptance criteria.
· Lead assigned infrastructure projects and coordinate internal stakeholders, customers, service providers, OEMs and implementation partners.
· Identify technical and project risks early, document mitigations, manage dependencies and escalate delivery delays or operational exposure.
· Follow change-management controls, complete impact/risk assessment, obtain approvals, validate implementation and maintain tested rollback plans.
Vendor, SLA, Cost & Compliance Governance
· Manage vendor performance against SLA, support contracts and project milestones; run service reviews and drive timely resolution of escalations.
· Track renewals, licenses, warranties and support coverage; evaluate proposals and recommend commercial or architectural options that improve value and reduce CAPEX/OPEX.
· Maintain network and security standards, asset/configuration records, diagrams, SOPs, build documents, support procedures and project handover packs.
· Register and periodically review infrastructure risks; support internal/external audits and comply with IT, information security, regulatory and data-protection requirements.
· Plan and verify preventive maintenance, disaster recovery readiness, configuration recovery and continuity measures for critical infrastructure.
*** Experienced in handling large Enterprise networks and security .
Desired Candidate Profile
Technical Competency
Enterprise Switching (VLAN, STP, LACP, OSPF/BGP)
Enterprise Wireless (Aruba/Cisco, RF, 802.1X, Roaming)
Firewall (Check Point/Fortinet, NAT, IPS, App Control)
VPN (IPSec, SSL VPN, Site-to-Site, Remote Access)
SASE / Zero Trust (ZTNA, SWG, CASB, FWaaS)
Microsoft Entra ID & Conditional Access
Microsoft Intune & Endpoint Management
Active Directory, DNS, DHCP, PKI & NPS/RADIUS
Network Security (Segmentation, NAC, MFA, Micro-segmentation)
Cloud Networking (Azure/AWS, VNet, VPN)
Load Balancer / WAF / Reverse Proxy
Monitoring, SIEM & Packet Analysis
High Availability & Disaster Recovery
Practical hands on Troubleshooting & RCA