وظائف مراقب كاميرات في الإمارات
٢٠٠١٥ وظائف شاغرة
<p>A reputable company is seeking a qualified MEP Officer to join our team.</p>
<p>Responsibilities:</p>
<p>Supervise Mechanical, Electrical, and Plumbing (MEP) works.<br />
Coordinate with contractors, engineers, and project teams.<br />
Ensure compliance with project specifications and safety standards.<br />
Monitor installation progress and prepare reports.<br />
Conduct inspections and resolve technical issues on-sit<br />
Applicants may send cv via email address hr.krissamp@gmail.com</p>
عن الوظيفة<br>وصف الشركة: تعتبر شركة بروبرتي شوب للاستثمار (PSI)، التي تأسست عام 2007 ومقرها في أبوظبي، واحدة من أكبر شركات العقارات الخاصة في دولة الإمارات العربية المتحدة. وقد بنت الشركة سمعة قوية وحائزة على جوائز في أسواق أبوظبي ودبي من خلال الأداء المستمر والشراكات مع كبار المطورين. تقدم PSI مجموعة واسعة من الخدمات العقارية، بما في ذلك الوساطة، والاستشارات التنموية، والتسويق، والاستشارات الاستثمارية، وتقييم العقارات، وإدارة العقارات والمرافق.<br>مع وجود مكاتب لها في أبوظبي ودبي وألمانيا وهولندا، توفر PSI تجربة عقارية شاملة وخالية من المتاعب للعملاء محلياً ودولياً. ينضم أعضاء الفريق إلى مؤسسة متنوعة وعالية الأداء تتمتع بتميز معترف به في المبيعات والخدمات.<br>ملخص الوظيفة<br>نحن نبحث عن مدير امتثال ذي خبرة للإشراف على إطار الامتثال للشركة وتعزيزه، مع تركيز قوي على مكافحة غسل الأموال وتمويل الإرهاب (AML/CFT)، والامتثال التنظيمي، وإدارة المخاطر، ومراقبة الامتثال.<br>سيتأكد هذا الدور من توافق أنشطة الأعمال مع لوائح دولة الإمارات العربية المتحدة المعمول بها والسياسات الداخلية، مع دعم الإدارة في تحديد وتقييم وتخفيف مخاطر الامتثال والمخاطر التنظيمية.<br>المسؤوليات الرئيسية: تطوير وتنفيذ والحفاظ على سياسات وإجراءات وضوابط الامتثال. قيادة إطار عمل الشركة لمكافحة غسل الأموال وتمويل الإرهاب، بما في ذلك اعرف عميلك (KYC)، والعناية الواجبة للعملاء (CDD)، والعناية الواجبة الموسعة (EDD)، والعقوبات، والأشخاص المعرضين سياسياً (PEP)، ومراقبة المعاملات. مراقبة التطورات التنظيمية وضمان التنفيذ في الوقت المناسب لمتطلبات دولة الإمارات التنظيمية المعمول بها. إجراء مراقبة الامتثال، وتقييمات المخاطر، والمراجعات الدورية للامتثال. تحديد فجوات الامتثال والمخالفات والمخاطر التنظيمية والتوصية بالإجراءات التصحيحية المناسبة. الحفاظ على سجل مخاطر الامتثال ومراقبة خطط تخفيف المخاطر. دعم التحقيقات في مخالفات الامتثال، والأنشطة المشبوهة، وسوء السلوك المحتمل. تنسيق التقارير التنظيمية والاستفسارات وعمليات التفتيش وطلبات المعلومات. تقديم التوجيه والدعم الاستشاري بشأن الامتثال للإدارة وأقسام الأعمال. تطوير وتقديم تدريب حول الوعي بالامتثال ومكافحة غسل الأموال. إعداد تقارير الامتثال الدورية وتحديثات المخاطر للإدارة العليا. تعزيز ثقافة قوية للامتثال والأخلاق والمساءلة والوعي التنظيمي.<br>المتطلبات: درجة البكالوريوس في القانون أو المالية أو المحاسبة أو الأعمال أو الامتثال أو إدارة المخاطر أو مجال ذي صلة. أكثر من 5 سنوات من الخبرة ذات الصلة في الامتثال، ومكافحة غسل الأموال، وإدارة المخاطر، أو الامتثال التنظيمي. أكثر من 3 سنوات من الخبرة في دور إداري أو إشرافي. معرفة قوية بمتطلبات دولة الإمارات العربية المتحدة لمكافحة غسل الأموال وتمويل الإرهاب والمتطلبات التنظيمية. خبرة عملية في اعرف عميلك (KYC)، والعناية الواجبة للعملاء (CDD)، والعناية الواجبة الموسعة (EDD)، وفحص العقوبات، والأشخاص المعرضين سياسياً (PEP)، ومراقبة الامتثال. يُفضل الحصول على خبرة في العقارات أو البنوك أو الخدمات المالية أو أي صناعة أخرى منظمة. تعتبر الشهادات المهنية مثل CAMS أو ICA أو ما يعادلها ميزة إضافية. مهارات تحليلية وتحقيقية وإعداد تقارير وتواصل قوية. مستوى عالٍ من النزاهة والسرية والحكم المهني.<br>ما نبحث عنه: متخصص امتثال عملي يمكنه إدارة وظيفة الامتثال بشكل مستقل، وتقديم توجيه تنظيمي عملي للشركة، وتحديد المخاطر قبل أن تصبح مشكلات، والعمل بثقة مع الإدارة العليا وأصحاب المصلحة التنظيميين.
We are looking for a Cloud Security Specialist to implement, manage, and improve security controls across Microsoft Azure environments. The role focuses on protecting cloud workloads, identities, endpoints, and data through Azure security services and cloud security best practices. The successful candidate will support cloud security operations, threat detection, security monitoring, and compliance activities across hybrid and cloud environments.<br>Key Responsibilities Implement and manage Azure security controls, policies, and security best practices across cloud environments. Configure and operate Microsoft security solutions including Microsoft Defender for Cloud, Defender XDR, Defender for Endpoint, Defender for Servers, and Microsoft Sentinel. Manage security monitoring, incident investigation, analytics rules, workbooks, and response activities within Microsoft Sentinel. Implement identity and access security controls using Entra ID, RBAC, Conditional Access, and related Azure security services. Manage endpoint and device security controls using Microsoft Intune. Configure data protection, governance, and compliance controls using Microsoft Purview. Perform cloud security assessments, security posture reviews, vulnerability analysis, and remediation activities. Integrate Azure security solutions with SOC operations, threat detection processes, and incident response workflows. Support security audits, compliance reviews, and maintain cloud security documentation.<br>Required Skills & Experience6+ years of experience in cloud security. Strong hands-on experience with Microsoft Azure security services and cloud security operations. Experience managing Microsoft security solutions including Defender XDR, Defender for Cloud, Microsoft Sentinel, Microsoft Intune, and Microsoft Purview. Strong understanding of Azure security architecture, shared responsibility model, Entra ID, RBAC, and Conditional Access. Experience with cloud threat detection, incident response, security monitoring, and security posture management. Knowledge of cloud security best practices and enterprise security controls. CCSP, AZ-500, or equivalent Azure security certification.<br>Preferred Skills Experience securing hybrid cloud environments integrating Azure with on-premise infrastructure. Knowledge of Azure security technologies including Azure Firewall, Network Security Groups, and Web Application Firewall. Experience with automation using Power Shell, Azure Functions, or Logic Apps. Familiarity with security frameworks such as ISO 27001, NIST, CIS, and SOC 2. Experience integrating SIEM/SOAR platforms with cloud environments. Strong analytical, troubleshooting, and documentation skills.
We are looking for a Cloud Security Specialist to implement, manage, and improve security controls across Microsoft Azure environments. The role focuses on protecting cloud workloads, identities, endpoints, and data through Azure security services and cloud security best practices. The successful candidate will support cloud security operations, threat detection, security monitoring, and compliance activities across hybrid and cloud environments.<br>Key Responsibilities Implement and manage Azure security controls, policies, and security best practices across cloud environments. Configure and operate Microsoft security solutions including Microsoft Defender for Cloud, Defender XDR, Defender for Endpoint, Defender for Servers, and Microsoft Sentinel. Manage security monitoring, incident investigation, analytics rules, workbooks, and response activities within Microsoft Sentinel. Implement identity and access security controls using Entra ID, RBAC, Conditional Access, and related Azure security services. Manage endpoint and device security controls using Microsoft Intune. Configure data protection, governance, and compliance controls using Microsoft Purview. Perform cloud security assessments, security posture reviews, vulnerability analysis, and remediation activities. Integrate Azure security solutions with SOC operations, threat detection processes, and incident response workflows. Support security audits, compliance reviews, and maintain cloud security documentation.<br>Required Skills & Experience6+ years of experience in cloud security. Strong hands-on experience with Microsoft Azure security services and cloud security operations. Experience managing Microsoft security solutions including Defender XDR, Defender for Cloud, Microsoft Sentinel, Microsoft Intune, and Microsoft Purview. Strong understanding of Azure security architecture, shared responsibility model, Entra ID, RBAC, and Conditional Access. Experience with cloud threat detection, incident response, security monitoring, and security posture management. Knowledge of cloud security best practices and enterprise security controls. CCSP, AZ-500, or equivalent Azure security certification.<br>Preferred Skills Experience securing hybrid cloud environments integrating Azure with on-premise infrastructure. Knowledge of Azure security technologies including Azure Firewall, Network Security Groups, and Web Application Firewall. Experience with automation using Power Shell, Azure Functions, or Logic Apps. Familiarity with security frameworks such as ISO 27001, NIST, CIS, and SOC 2. Experience integrating SIEM/SOAR platforms with cloud environments. Strong analytical, troubleshooting, and documentation skills.
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<strong>Senior Security Engineer</strong>
<strong>Role Overview</strong>
<p>We are seeking an experienced <strong>Senior Security Engineer</strong> to strengthen and evolve enterprise security practices across application, infrastructure, and cloud environments within a highly regulated financial services environment.</p><br><br>
<p>This role will be responsible for driving secure-by-design principles across the software development lifecycle, implementing DevSecOps best practices, conducting security assessments, and enhancing the organization's overall security posture. The successful candidate will work closely with Development, DevOps, Infrastructure, Architecture, and Product teams to ensure security controls are embedded throughout the technology landscape.</p><br><br>
<p>The ideal candidate will possess deep technical expertise across application security, cloud security, penetration testing, threat modelling, and security architecture, combined with strong stakeholder management and communication skills.</p><br><br>
<strong>Key Responsibilities</strong>
<ul>
<li>Conduct web, mobile, and API penetration testing and vulnerability assessments. </li><li>Perform secure code reviews and identify application and infrastructure security weaknesses. </li><li>Manage and optimize security tooling including: <ul>
<li>SAST </li><li>DAST </li><li>SCA </li><li>Infrastructure as Code (IaC) Security </li><li>Container Security Solutions </li></ul>
</li><li>Drive DevSecOps initiatives and integrate security controls into CI/CD pipelines. </li><li>Perform threat modelling, security risk assessments, and architecture reviews. </li><li>Design and review secure solutions across cloud, container, Kubernetes, and enterprise platforms. </li><li>Lead vulnerability management activities, including remediation planning and tracking. </li><li>Support security incident investigations, root cause analysis, and remediation efforts. </li><li>Deliver security awareness sessions and secure coding training to engineering teams. </li><li>Collaborate with development, DevOps, infrastructure, and product teams to ensure secure implementation of solutions. </li><li>Support continuous improvement of security standards, processes, and governance frameworks. </li><li>Participate in security reviews and compliance initiatives across enterprise projects.
</li></ul>
<strong>Required Skills & Qualifications</strong>
<ul>
<li>8–15 years of experience in Information Security, Cyber Security, or Security Engineering roles. </li><li>Strong hands-on expertise in: <ul>
<li>Application Security </li><li>Infrastructure Security </li><li>Cloud Security </li><li>Security Architecture </li></ul>
</li><li>Deep experience performing: <ul>
<li>Web Application Penetration Testing </li><li>API Security Testing </li><li>Mobile Security Testing </li><li>Vulnerability Assessments </li></ul>
</li><li>Strong understanding of: <ul>
<li>OWASP Top 10 </li><li>OWASP API Security Top 10 </li><li>Secure Development Practices </li></ul>
</li><li>Experience implementing and managing DevSecOps programmes. </li><li>Strong expertise with CI/CD security integration and security automation. </li><li>Experience conducting: <ul>
<li>Threat Modelling </li><li>Risk Assessments </li><li>Security Architecture Reviews </li><li>Secure Design Assessments </li></ul>
</li><li>Hands-on experience securing: <ul>
<li>Kubernetes Environments </li><li>Docker Containers </li><li>Microservices Architectures </li><li>Cloud-Native Applications </li></ul>
</li><li>Strong knowledge of: <ul>
<li>AWS Security </li><li>Azure Security </li><li>Identity & Access Management </li><li>Secrets Management </li><li>Network Security </li></ul>
</li><li>Experience supporting security incident response and remediation activities. </li><li>Strong stakeholder management, presentation, and communication skills. </li><li>Experience with scripting and automation using: <ul>
<li>Python </li><li>Bash </li><li>PowerShell </li></ul>
</li></ul>
<strong>Preferred Skills & Experience</strong>
<ul>
<li>Banking or Financial Services industry experience. </li><li>Strong understanding of PCI-DSS compliance requirements. </li><li>Experience working with governance and compliance frameworks including: <ul>
<li>ISO 27001 </li><li>SOC 2 </li><li>NIST </li><li>CIS </li></ul>
</li><li>Familiarity with GDPR and privacy regulations. </li><li>Experience establishing or supporting Security Champion programmes. </li><li>Exposure to Security Operations and Incident Response functions. </li><li>Relevant security certifications such as: <ul>
<li>CISSP </li><li>CSSLP </li><li>OSCP </li><li>CEH </li><li>AWS Security Specialty </li><li>Azure Security Engineer Associate </li></ul>
</li></ul>
<strong>Halian Group</strong>
<p>With over 28 years of experience, we have come to understand that innovation is the only way to provide agile, practical solutions that transform businesses and careers. Our resourcing and smart services help you to realise tomorrow's potential. Discover the amazing things possible when you bring the right people and the right technologies together.</p><br><br>
<p>At Halian, we recognise that diversity, equity, and inclusion (DEI) are essential to building high-performing teams for our clients. We are committed to connecting organisations with top talent from all backgrounds, ensuring that every individual feels valued, respected, and empowered to contribute their unique perspectives.</p><br><br>
<p>We encourage applications from all qualified candidates, regardless of race, gender, disability, or any other characteristic that makes them unique.</p><br><br>
<p><strong>#LI-CC1</strong></p><br><br>
<br><br> </div>
Director – Security<br>Role Overview:We are seeking an experienced Director – Security to lead and oversee enterprise-wide security operations, governance, risk management, investigations, and crisis response across business operations, assets, communities, and corporate functions. The role will be responsible for developing a proactive security culture, safeguarding organizational assets and reputation, and ensuring effective security controls across all functions.<br>Key Responsibilities:<br>Security Leadership & Governance Develop and implement organization-wide security strategies, policies, and procedures. Establish a strong culture of security awareness and accountability. Advise senior leadership on security risks and mitigation measures. Corporate & Operational Security Oversee security operations across offices, facilities, projects, and communities. Manage security service providers and on-site security teams. Conduct security audits, inspections, and vulnerability assessments. Risk Management & Investigations Support fraud prevention, security investigations, and risk mitigation initiatives. Coordinate with internal stakeholders on security-related incidents and investigations. Implement confidential reporting mechanisms for security concerns and misconduct. Incident & Crisis Management Lead security response during emergencies and critical incidents. Develop and maintain crisis management and business continuity plans. Ensure emergency preparedness protocols are regularly tested and updated. Stakeholder Management Collaborate with internal departments to ensure compliance with security standards. Liaise with government authorities, law enforcement agencies, and external security partners when required.<br>Qualifications & Experience:Bachelor's Degree in Security Management, Risk Management, Criminal Justice, Business Administration, or a related field. Professional certifications in Security, Investigations, Risk Management, or Fraud Prevention are preferred.10–15 years of experience in corporate security, investigations, enterprise risk, or security leadership roles. Experience in Real Estate, Property Development, Hospitality, Large Communities, or diversified business groups is highly preferred. Strong knowledge of security operations, investigations, crisis management, and risk governance. Excellent leadership, stakeholder management, analytical, and decision-making skills. High level of integrity, professionalism, and confidentiality.
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>Job Title: Lead Infrastructure & Cloud Security Engineer</p><p>Location: Abu Dhabi, UAE</p><p>Job Purpose:</p><p>The Lead Infrastructure & Cloud Security Engineer is responsible for designing, implementing, securing, and</p><p>managing the organization's IT infrastructure, cloud platforms, network security, and cybersecurity operations.</p><p>The role ensures the availability, integrity, confidentiality, and resilience of enterprise systems while supporting</p><p>business objectives through secure and scalable technology solutions.</p><p>Key Responsibilities:</p><p>Infrastructure & Cloud Management:</p><ul><li><p>Lead the design, implementation, and maintenance of on-premises and cloud infrastructure</p></li></ul><p>environments.</p><ul><li><p>Manage hybrid infrastructure, including servers, virtualization platforms, storage, backup, and disaster</p></li></ul><p>recovery solutions.</p><ul><li><p>Ensure high availability, performance, scalability, and security of enterprise systems.</p></li><li><p>Support cloud adoption, migration, and optimization initiatives.</p></li></ul><p>Cyber Security & Security Operations:</p><ul><li><p>Develop and implement cybersecurity controls, standards, and best practices.</p></li><li><p>Monitor and respond to security incidents, threats, and vulnerabilities.</p></li><li><p>Conduct security assessments, risk analysis, and remediation activities.</p></li><li><p>Manage endpoint protection, threat detection, SIEM, and security monitoring solutions.</p></li><li><p>Lead incident response and security investigations.</p></li></ul><p>Network Security:</p><ul><li><p>Design and maintain secure network architectures.</p></li><li><p>Manage firewalls, VPNs, network segmentation, and remote access solutions.</p></li><li><p>Ensure secure connectivity across on-premises and cloud environments.</p></li><li><p>Implement security hardening and network security best practices.</p></li></ul><p>Identity & Access Management:</p><ul><li><p>Manage Active Directory, Entra ID (Azure AD), and Identity & Access Management solutions.</p></li><li><p>Implement access controls, privileged access management, MFA, and conditional access policies.</p></li><li><p>Ensure compliance with security and access governance requirements.</p></li></ul><p>Governance, Risk & Compliance:</p><ul><li><p>Support compliance initiatives aligned with ISO 27001, NIST, CIS Controls, and industry standards.</p></li><li><p>Conduct security audits, vulnerability assessments, and risk management activities.</p></li><li><p>Develop and maintain security policies, procedures, and documentation.</p></li></ul><p>Leadership & Stakeholder Management</p><ul><li><p>Provide technical leadership and guidance to infrastructure and security teams.</p></li><li><p>Collaborate with internal stakeholders, vendors, and business units.</p></li><li><p>Lead infrastructure and security-related projects and initiatives.</p></li><li><p>Prepare technical reports, recommendations, and executive updates.</p></li></ul><br></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><p>Required Qualifications:</p><ul><li><p>Bachelor's Degree in Computer Science, Information Technology, Cyber Security, or a related field.</p></li><li><p>8+ years of experience in Infrastructure, Cloud, Network Security, and Cyber Security.</p></li><li><p>3+ years of experience in a Lead or Senior Engineer role.</p></li><li><p>Strong experience with hybrid infrastructure environments (On-Premises and Cloud).</p></li><li><p>Hands-on experience with Azure, AWS, or GCP and cloud security best practices.</p></li><li><p>Strong knowledge of Network Security, Firewalls, VPNs, Routing, Switching, and Security Architecture.</p></li><li><p>Experience with enterprise security technologies such as Palo Alto, Fortinet, Cisco, Microsoft Defender,</p></li></ul><p>CrowdStrike, SentinelOne, Splunk, or Microsoft Sentinel.</p><ul><li><p>Strong experience with Active Directory, Entra ID (Azure AD), Microsoft 365, VMware/Hyper-V, and</p></li></ul><p>Identity & Access Management.</p><ul><li><p>Experience in Security Operations, Incident Response, Vulnerability Management, and Risk Assessment.</p></li><li><p>Knowledge of ISO 27001, NIST, CIS Controls, and security compliance frameworks.</p></li><li><p>Excellent leadership, stakeholder management, troubleshooting, and communication skills.</p></li></ul><p>Preferred Certifications:</p><ul><li><p>CISSP, CCSP, CISM, CEH</p></li><li><p>Azure Security Engineer (AZ-500)</p></li><li><p>AWS Security Specialty</p></li><li><p>CCNP Security / PCNSE / Fortinet NSE</p></li></ul><p>Key Competencies:</p><ul><li><p>Infrastructure & Cloud Architecture</p></li><li><p>Cyber Security Operations</p></li><li><p>Network Security</p></li><li><p>Security Risk Management</p></li><li><p>Identity & Access Management</p></li><li><p>Incident Response</p></li><li><p>Leadership & Team Management</p></li><li><p>Vendor & Stakeholder Management</p></li><li><p>Problem Solving & Decision Making</p></li><li><p>Communication & Presentation Skills</p></li></ul><p></p></section>
???? Security Architect with SAP RISE | SAP experience (MUST HAVE)<br><br>???? Contract: 12 months, renewable contract<br>???? Shape the future of security within one of the Middle East's largest digital transformation programmes. We're partnering with one of the Middle East's leading luxury retail groups to appoint an experienced Security Architect who will play a pivotal role in designing and embedding enterprise security across a large-scale SAP Transformation Programme. This is a high-impact opportunity to influence security strategy, architecture, governance, and secure-by-design principles across a complex enterprise environment.<br>What We're Looking For (Must-Haves)✅ 8+ years' experience in Security Architecture or Enterprise Security Architecture✅ MUST HAVE SAP experience (SAP S/4HANA and SAP RISE are essential)✅ Solid understanding of ISO 27001 Controls, Security Governance and Risk Management✅ Experience designing security architecture for large-scale ERP or Digital Transformation ✅ Knowledge of IAM, PAM, GRC, Cloud Security and Enterprise Security Frameworks✅ Excellent stakeholder engagement skills, with the ability to influence technical and business teams<br>What You'll Be Doing???? Design & own enterprise security architecture across a major SAP transformation programme???? Define security standards, frameworks and architectural best practices???? Embed Security by Design across SAP solutions and programme delivery???? Lead architecture reviews, security assessments and risk mitigation initiatives???? Ensure compliance with ISO 27001 controls and enterprise security standards???? Partner with Information Security, Enterprise Architecture, SAP Delivery Teams, PMO and senior business stakeholders<br>Why Join?✨ Join one of the largest luxury retail organisations in the Middle East✨ Work on a flagship enterprise SAP transformation with high executive visibility✨ Influence the security strategy of a business investing heavily in technology and innovation✨ Collaborate with senior leaders and highly skilled technology teams on business-critical initiatives✨ Long-term programme with exciting career growth and exposure to cutting-edge enterprise technologies<br>???? Location: Dubai, UAE (Hybrid)???? Contract: 12 months, renewable contract If you're passionate about Enterprise Security Architecture, SAP Security, and delivering security across complex transformation programmes, I'd love to hear from you.<br>#Security Architect #Cyber Security #Information Security #SAPSecurity #SAPRISE #S4HANA #SAP #Enterprise Architecture #Cyber Security Jobs #ISO27001 #IAM #PAM #Cloud Security #GRC #Dubai Jobs #UAEJobs #Tech Jobs #Digital Transformation #Hiring Now
<h2 class="h5">الوصف الوظيفي</h2>
<div class="t-break" data-jb-field="description">
<p>تبحث أمازون عن موظف صحة وسلامة في مكان العمل (WHS) ليضاف إلى الفريق: <br> <br> عامًا بعد عام، مع استمرارنا في النمو، نحتاج أن نعمل بذكاء قدر الإمكان للحفاظ على سلامة جميع أعضاء فريقنا وتحقيقهم ووجودهم المحفَّز وتمكينهم. لمساعدتنا في تحقيق ذلك، نحن نبحث عن موظف EHS لديه دافع. بفضل ميلك إلى العمل، سنحتاجك للتدخل والمساعدة في دفع الصحة والسلامة عبر مركز التوزيع لدينا في الرياض <br> <br> في هذا المنصب الحاسم لـ WHS، ستبلغ المدير WHS. <br>- قيادة تقييم مخاطر الموقع للأنشطة الحالية والجديدة. <br>- إنشاء مصفوفة تدريب WHS للموقع. <br>- قيادة تطبيق معايير وتوجيهات WHS الخاصة بالموقع.<br>- قيادة تنفيذ أهداف وبرامج WHS الخاصة بالموقع.<br>- تعزيز ثقافة السلامة بين الموظفين من خلال تقديم محتوى WHS يوميًا إلى إحاطة الشيفت.<br>- إجراء عمليات تدقيق سلامة الموقع بشكل متكرر لتحديد جميع المعدات والعمليات غير المتوافقة في الموقع. <br>- العمل مع فريق العمليات لتنفيذ الحلول للقضاء على التعرض لهذه المخاطر ومنع الإصابات.<br>- حضور الحوادث وحالات الإصابات المهنية في الموقع.<br>- توجيه ومساعدة مديري المناطق في تحقيقات الحوادث، وكتابة Gensuite وتواصل الدروس المستفادة.<br>- مساعدة فريق العمليات في ورقة متابعة Gensuite وإنشاء CAPA. <br>- تدقيق ممارسات حفظ السجلات وضمان اتساق إدخالات Gensuite مع معايير WHS العالمية والأنظمة المحلية.<br>- ضمان وجود مخزون PPE في الموقع والتنسيق مع الشراء لطلبات الشراء.<br>- مهمة تدقيق متطلبات السلامة الأساسية (KSR) أسبوعيًا، المراقبة والدعم.<br>- ضمان إتمام تدريبي مكافحة الحرائق الأساسي وتدريب الإسعافات الأولية. المتطلبات.<br>- فحص يومي لأدوات العمل الصناعية الميكانيكية المجهزة وفتح المرفأ الرأسي والتواصلات.<br>- مراقبة يومية لنظام تتبع الإجراءات والدعم.<br>- المشاركة في جولة سلامة إدارة الموقع، وتقديم رؤى حول الأعمال والظروف غير الآمنة للإدارة.<br>- تقديم تحديث يومي لمدير WHS في البلد حول تقدم الأهداف والحوادث وKSR وATS والأعمال الشبكية، إلخ).<br>- إعداد أجندة اجتماع لجنة WHS وكتابة MOM وخلق ATS.<br>- مراجعة يومية لتصريح العمل والتوقيع عليه.<br>- القيادة في المشتريات المتعلقة بـ WHS والمتابعة.<br>- إعداد خطط الاستجابة للطوارئ.<br>- إدارة وتنفيذ تدريبات الطوارئ.<br>- إدارة إعداد وتدريب تدريبات الطوارئ، إعداد السجلات.<br>- وضع مؤشر الحرارة، الرصد والدعم.<br>- تقديم الدعم للطلبات الخاصة بالموقع، والأحداث والأنشطة غير المخطط لها.<br>- إجراء تدقيق WHS يوميًا وأسبوعيًا، مثل فحص غرفة النفايات الخطرة، فحص مجموعة التسرب، غرفة الإسعافات الأولية، إلخ.<br>- الخبرة في الكهرباء/الميكانيكا/الإلكترونيات والاتصالات والأجهزة والتحكمات<br>- الخبرة في تحليل البيانات، مع القدرة على تفسير البيانات واستخلاص الرؤى لاتخاذ القرارات<br>- الخبرة في Microsoft Word وExcel وPowerPoint<br>ثقافتنا الشمولية تمكن أمازون من تقديم أفضل النتائج لعملائنا. إذا كنت تعاني من إعاقة وتحتاج إلى تسهيل أو تعديل في مكان العمل أثناء عملية التقديم والتوظيف، بما في ذلك الدعم للمقابلة أو عملية الانضمام، يرجى زيارة https://amazon.jobs/content/en/how-we-hire/accommodations لمزيد من المعلومات. إذا لم يكن البلد/المنطقة التي تقدّم فيها مدرجة، يرجى التواصل مع شريك التوظيف الخاص بك.</p><br> </div>
<section><p class="heading jdMain">الوصف الوظيفي</p><p class="heading">الأدوار والمسؤوليات</p><div class="paragraph"><ul><li><p>الحفاظ على المستندات الخاصة بالمشتريات والعقود والرقابة عليها في الأنظمة الورقية والإلكترونية للتقييم والتسجيل.</p></li><li><p>التأكد من تسجيل وتحديث جميع العقود وأوامر الشراء والتعديلات والمراسلات والمستندات الداعمة بشكل صحيح.</p></li><li><p>تتبع حالة الوثائق والتعديلات والموافقات والتوزيع وفقًا لإجراءات الشركة.</p></li><li><p>التنسيق مع فرق المشتريات والقانون والمالية والجودة والمشروعات لجمع المستندات المطلوبة والحفظ.</p></li><li><p>ضمان التحكم في الإصدارات والسرية للمستندات الحساسة.</p></li><li><p>إعداد إرسال المستندات والسجلات وأجهزة التتبع والتقارير.</p></li><li><p>مراقبة تواريخ انتهاء العقد والتجديد وشهادات التأمين والضمانات البنكية وغيرها من وثائق الامتثال.</p></li><li><p>دعم أنشطة المناقصات والتوريد من خلال الحفاظ على وثائق RFQ/RFP وسجلات الموردين.</p></li><li><p>التأكد من أن جميع مستندات المشتريات والعقود تتوافق مع سياسات الشركة ومتطلبات التدقيق.</p></li><li><p>المساعدة في توثيق إدخال الموردين وتحديثات سجل البائعين الرئيسى.</p></li><li><p>أرشفة العقود المكتملة وملفات المشتريات للرجوع المستقبلي والتدقيق.</p></li><li><p>دعم التدقيقات الداخلية والخارجية من خلال توفير السجلات المطلوبة للمشتريات والعقود.</p></li><li><p>الحفاظ على سجلات دقيقة للوثائق الواردة والصادرة.</p></li><li><p>المتابعة مع أصحاب المصلحة الداخليين والموردين للحصول على المستندات والموافقات المعلقة.</p></li></ul></div></section><section><p class="heading">الملف المرغوب فيه للمرشح</p><p class="paragraph"></p><p>مسؤولية مراقب المستندات للمشتريات والعقود هي إدارة وتنظيم وتتبّع والحفاظ على المستندات المرتبطة بالمشتريات والعقود لضمان الدقة والامتثال وإمكانية الوصول والاحتفاظ بالسجلات بشكل صحيح. الدور يدعم فرق المشتريات والعقود من خلال ضمان تحكم صحيح بكل المستندات طوال دورة حياة العقد.</p><ul><li><p>مهارات تنظيم عالية وإدارة مستندات فعالة.</p></li><li><p>الاهتمام بالتفاصيل والدقة.</p></li><li><p>مهارات اتصال وتنسيق جيدة.</p></li><li><p>الإتقان في تطبيقات ميكروسوفت أوفيس.</p></li><li><p>القدرة على إدارة المعلومات السرية بمهنية.</p></li><li><p>معرفة عمليات المشتريات والعقود.</p></li><li><p>القدرة على العمل تحت الضغط والالتزام بالمواعيد النهائية.</p></li></ul><br><p>الكفاءات الأساسية</p><ul><li><p>تحكم المستندات</p></li><li><p>تنسيق المشتريات</p></li><li><p>دعم إدارة العقود</p></li><li><p>إدارة السجلات</p></li><li><p>مراقبة الامتثال</p></li><li><p>إدارة الوقت</p></li><li><p>تنسيق الفريق</p></li><li><p>حل المشكلات</p></li></ul><p></p></section>
<br><p>مهندس الأمان:</p><br><ul><li><p>وصف الدور: سيكون مهندس الأمان مسؤولاً عن تنفيذ وإدارة ضوابط الأمان لحماية بيانات وأنظمة المؤسسة. سيقوم هذا الدور بتهيئة أجهزة الأمان وصيانتها، وإجراء تقييمات الثغرات، والرد على الحوادث الأمنية.</p></li></ul><p>المسؤوليات الرئيسية: تهيئة وإدارة أجهزة الأمان (الجدران النارية، IDS/IPS، SIEM، إلخ).</p><p>إجراء تقييمات الثغرات واختبار الاختراق.</p><p>الرد على الحوادث الأمنية وإجراء التحقيقات الجنائية الرقمية.</p><p>تنفيذ سياسات وإجراءات الأمان.</p><p>مراقبة سجلات الأمان والتنبيهات.</p><p>تهيئة أدوات أمان السحابة.</p><p><strong>الملف الشخصي المرغوب فيه للمرشح</strong></p><p>حد أدنى 10 سنوات من الخبرة في هندسة الأمن</p>
Responsibilities:Provide L3 engineering and deep troubleshooting support for complex security infrastructure issues, incidents, and escalations. Design, configure, harden, review, and optimize enterprise security solutions and security policies. Support security architecture reviews, solution design, technology upgrades, migrations, and implementation activities. Perform root-cause analysis and resolution of complex security and connectivity issues across multiple security platforms. Provide technical support for Disaster Recovery (DR) exercises, resilience testing, failover, and recovery activities. Review existing security configurations and policies and recommend improvements based on security best practices and operational requirements. Work closely with infrastructure, network, application, SOC, and other technical teams to resolve security-related issues. Manage incidents, service requests, problems, and changes in accordance with established ITSM processes.<br>Key Technology Areas:Strong hands-on experience across several of the following technologies is required:Firewalls: Checkpoint and/or Palo Alto Secure Web Gateway / Proxy: Proxy solutions and Zscaler Web Application Firewall: F5 WAFNetwork Security: IPS/IDS and DDoS protection Security Network Design and Architecture Endpoint Security: Trellix / McAfee, EDR and DLPIdentity & Access Security: MFA, VPN and token-based authentication solutions ITSM / Incident, Problem and Change Management
An experienced security professional responsible for assessing, testing, and strengthening the security posture of complex web applications, APIs, authentication systems, and digital services. The role focuses on identifying vulnerabilities, validating security controls, and driving remediation efforts to protect critical business workflows and sensitive data from emerging threats.<br>Key Responsibilities Web Application & API Security Testing Perform comprehensive manual and automated penetration testing of web applications, APIs, microservices, and internet-facing services. Identify vulnerabilities related to authentication, authorization, session management, input validation, and API security. Assess applications against recognized security frameworks and industry best practices. File & Document Security Assessment Evaluate security controls governing file uploads, downloads, storage, and processing workflows. Identify risks associated with malicious file handling, content validation, storage isolation, and data exposure. Access Control & Authorization Review Validate role-based and attribute-based access controls across multiple user types and permission levels. Identify authorization weaknesses, including Insecure Direct Object References (IDOR), privilege escalation, and unauthorized data access. Assess segregation and isolation controls within shared application environments. Identity & Authentication Security Review authentication and authorization mechanisms, including OAuth 2.0, Open ID Connect (OIDC), SAML, and JWT implementations. Test token validation, session handling, replay protection, and identity federation controls. Identify weaknesses in identity lifecycle management and access governance. Business Logic Security Analysis Assess critical user journeys and application workflows for logic flaws and abuse cases. Identify race conditions, workflow bypasses, automation weaknesses, and inadequate rate-limiting controls. Evaluate protections against fraud, abuse, and unauthorized transaction manipulation. Security Advisory & Remediation Support Produce clear, risk-based security assessment reports with prioritized remediation recommendations. Collaborate with stakeholders to validate fixes and perform security re-testing. Support secure development practices throughout the software delivery lifecycle.<br>Required Skills & Experience Security Assessment Expertise Minimum 5 years of hands-on experience conducting web application and API penetration testing. Strong understanding of modern attack techniques and security testing methodologies. Security Frameworks & Methodologies Expert knowledge of:OWASP Top 10OWASP API Security Top 10OWASP Web Security Testing Guide (WSTG) Threat modeling and risk-based assessment approaches Security Tools Advanced proficiency with:Burp Suite Professional Postman Web application and API testing tools Identity & Access Management Security Proven experience identifying and exploiting weaknesses in:OAuth 2.0Open ID Connect (OIDC) JWTSAML 2.0Secure File Handling Strong understanding of secure file processing, archive parsing, storage isolation, and content validation. Experience assessing file management controls and secure object storage implementations.<br>Preferred Qualifications Experience assessing file-scanning, malware-detection, or Content Disarm and Reconstruction (CDR) solutions. Familiarity with security automation and vulnerability assessment tools such as:Nuclei Semgrep OWASP ZAPKnowledge of cloud security controls across AWS, Microsoft Azure, and Google Cloud Platform (GCP). Understanding of secure architecture principles for internet-facing applications and distributed environments.<br>Preferred Certifications Offensive Security OSCP (Offensive Security Certified Professional) OSWE (Offensive Security Web Expert) Port Swigger BSCP (Burp Suite Certified Practitioner) Other relevant application security, penetration testing, or cloud security certifications are advantageous. Senior Web App Security Engineer in Abu Dhabi, United Arab Emirates
An experienced security professional responsible for assessing, testing, and strengthening the security posture of complex web applications, APIs, authentication systems, and digital services. The role focuses on identifying vulnerabilities, validating security controls, and driving remediation efforts to protect critical business workflows and sensitive data from emerging threats.<br>Key Responsibilities Web Application & API Security Testing Perform comprehensive manual and automated penetration testing of web applications, APIs, microservices, and internet-facing services. Identify vulnerabilities related to authentication, authorization, session management, input validation, and API security. Assess applications against recognized security frameworks and industry best practices. File & Document Security Assessment Evaluate security controls governing file uploads, downloads, storage, and processing workflows. Identify risks associated with malicious file handling, content validation, storage isolation, and data exposure. Access Control & Authorization Review Validate role-based and attribute-based access controls across multiple user types and permission levels. Identify authorization weaknesses, including Insecure Direct Object References (IDOR), privilege escalation, and unauthorized data access. Assess segregation and isolation controls within shared application environments. Identity & Authentication Security Review authentication and authorization mechanisms, including OAuth 2.0, Open ID Connect (OIDC), SAML, and JWT implementations. Test token validation, session handling, replay protection, and identity federation controls. Identify weaknesses in identity lifecycle management and access governance. Business Logic Security Analysis Assess critical user journeys and application workflows for logic flaws and abuse cases. Identify race conditions, workflow bypasses, automation weaknesses, and inadequate rate-limiting controls. Evaluate protections against fraud, abuse, and unauthorized transaction manipulation. Security Advisory & Remediation Support Produce clear, risk-based security assessment reports with prioritized remediation recommendations. Collaborate with stakeholders to validate fixes and perform security re-testing. Support secure development practices throughout the software delivery lifecycle.<br>Required Skills & Experience Security Assessment Expertise Minimum 5 years of hands-on experience conducting web application and API penetration testing. Strong understanding of modern attack techniques and security testing methodologies. Security Frameworks & Methodologies Expert knowledge of:OWASP Top 10OWASP API Security Top 10OWASP Web Security Testing Guide (WSTG) Threat modeling and risk-based assessment approaches Security Tools Advanced proficiency with:Burp Suite Professional Postman Web application and API testing tools Identity & Access Management Security Proven experience identifying and exploiting weaknesses in:OAuth 2.0Open ID Connect (OIDC) JWTSAML 2.0Secure File Handling Strong understanding of secure file processing, archive parsing, storage isolation, and content validation. Experience assessing file management controls and secure object storage implementations.<br>Preferred Qualifications Experience assessing file-scanning, malware-detection, or Content Disarm and Reconstruction (CDR) solutions. Familiarity with security automation and vulnerability assessment tools such as:Nuclei Semgrep OWASP ZAPKnowledge of cloud security controls across AWS, Microsoft Azure, and Google Cloud Platform (GCP). Understanding of secure architecture principles for internet-facing applications and distributed environments.<br>Preferred Certifications Offensive Security OSCP (Offensive Security Certified Professional) OSWE (Offensive Security Web Expert) Port Swigger BSCP (Burp Suite Certified Practitioner) Other relevant application security, penetration testing, or cloud security certifications are advantageous. Senior Web App Security Engineer in Abu Dhabi, United Arab Emirates
About The Role<br><br>Engage in the client Software Development Lifecycle to collaboratively ensure new products, platforms, and technologies meet or exceed security engineering requirements;<br><br>Create formal threat models to enumerate and mitigate potential security risks in proposed architecture and designs;<br><br>Partner with Information Security GRC counterparts to author security requirements and standards;<br><br>Brief executive leaders on potential emergent threats and ongoing efforts to proactively address potential cyber security risks;<br><br>Work with platform and security engineering leadership to interactively improve<br><br>Enhance and mature the security engineering training curriculum in partnership with Security Awareness and Training owners;<br><br>Act as domain specialist across Peloton’s security solutions and technology stack;<br><br>Identify strategic investments and initiatives that lower the transactional cost of designing and implementing secure platform solutions and reduce the likelihood of potential cyber security attacks;<br><br>Influence the security strategy by improving the collective strength of the security team and articulating the capabilities needed to optimally manage cyber-attack risk;<br><br>Requirements<br><br>10+ years of hands-on experience in working with engineering teams on design and implementation of security best practices in architecture and code.<br><br>10+ years of experience working with product security teams to drive engineering remediation to externally identified threats and vulnerabilities.<br><br>7+ years of experience with creating threat models and working with teams to identify and remediate potential security gaps related to authentication, authorization, network segmentation, encryption, container configuration, bastion host setup, etc.<br><br>Extensive experience and strong understanding of cloud security controls including but not limited to such as IAM, KMS, VPC, Security Groups, AWS Inspector, Guard Duty and SCPs.<br><br>Knowledge and Hands on Skills with Docker, ECS, Kubernetes, and Container Security.<br><br>Extensive understanding MITRE ATT&CK, NIST CSF, CVSS and CWE criteria, enumeration and scoring.<br><br>Broad security-related domain knowledge with authentication and authorization, identity and access management, data protection, OAuth/Open ID connect, Web security.<br><br>Extensive experience with embedded software development and architectures, security protocols, applied cryptography and security standards<br><br>Deep understanding of the TCP/IP protocol stack and major protocols.<br><br>Working knowledge of one or more general purpose programming/script languages including but not limited to: Java, C/C++, C#, Python, Java Script, Power Shell.<br><br>Excellent relationship building skills across diverse cross-functional teams.<br><br>Exceptional written/oral communication skills.<br><br>Good cryptography knowledge and implementation expertise with hands on experience in PKI – SSL, TLS certificate management<br><br>Exceptional bias for action and ownership.<br><br>Humble, hardworking, forward-thinking and embodies a “hands on” leadership mindset.<br><br>Job Category: Architect<br><br>Requirements<br><br>The Principal Security Architect will work with external technology providers and security vendors. They will evaluate and assess the applicability of various solutions to determine their capability to mitigate potential security risks. They will work closely with partner teams to integrate solutions that are determined necessary.<br><br>The role plays a critical function in constantly evolving clients security development lifecycle. It owns the development of security engineering requirements and secure design and architecture review consultation. In coordination with Security Response Engineering, the Principal Platform Security Architect drives the root cause analysis to ensure critical security risks and design flaws discovered post release never manifest in future iterations of Peloton’s products and services.<br><br>The ideal candidate is a proven engineering leader that has both exemplary engineering and communication skills. They have extensive experience collaborating with internal engineering partners and briefing Executive Leadership. They are a proven security technology and methodology expert that scales through enabling other engineering partners to make the right security design decisions and trade-offs.<br><br>About The Company<br><br>At AMD, we are dedicated to safeguarding our client against cyber threats. We recognize the distinct requirements and vulnerabilities of each enterprise, which is why we offer tailor-made solutions to shield your data and assets effectively.<br><br>Our collaborative approach involves working closely with clients to devise a holistic cybersecurity strategy that harmonizes with their specific business objectives.
An experienced security professional responsible for assessing, testing, and strengthening the security posture of complex web applications, APIs, authentication systems, and digital services. The role focuses on identifying vulnerabilities, validating security controls, and driving remediation efforts to protect critical business workflows and sensitive data from emerging threats.<br><br>Key Responsibilities<br><br>Web Application & API Security Testing<br><br>Perform comprehensive manual and automated penetration testing of web applications, APIs, microservices, and internet-facing services. Identify vulnerabilities related to authentication, authorization, session management, input validation, and API security. Assess applications against recognized security frameworks and industry best practices. <br><br>File & Document Security Assessment<br><br>Evaluate security controls governing file uploads, downloads, storage, and processing workflows. Identify risks associated with malicious file handling, content validation, storage isolation, and data exposure. <br><br>Access Control & Authorization Review<br><br>Validate role-based and attribute-based access controls across multiple user types and permission levels. Identify authorization weaknesses, including Insecure Direct Object References (IDOR), privilege escalation, and unauthorized data access. Assess segregation and isolation controls within shared application environments. <br><br>Identity & Authentication Security<br><br>Review authentication and authorization mechanisms, including OAuth 2.0, Open ID Connect (OIDC), SAML, and JWT implementations. Test token validation, session handling, replay protection, and identity federation controls. Identify weaknesses in identity lifecycle management and access governance. <br><br>Business Logic Security Analysis<br><br>Assess critical user journeys and application workflows for logic flaws and abuse cases. Identify race conditions, workflow bypasses, automation weaknesses, and inadequate rate-limiting controls. Evaluate protections against fraud, abuse, and unauthorized transaction manipulation. <br><br>Security Advisory & Remediation Support<br><br>Produce clear, risk-based security assessment reports with prioritized remediation recommendations. Collaborate with stakeholders to validate fixes and perform security re-testing. Support secure development practices throughout the software delivery lifecycle. <br><br>Required Skills & Experience<br><br>Security Assessment Expertise<br><br>Minimum 5 years of hands-on experience conducting web application and API penetration testing. Strong understanding of modern attack techniques and security testing methodologies. <br><br>Security Frameworks & Methodologies <br><br>Expert knowledge of:OWASP Top 10 OWASP API Security Top 10 OWASP Web Security Testing Guide (WSTG) Threat modeling and risk-based assessment approaches <br>Security Tools <br><br>Advanced proficiency with:Burp Suite Professional Postman Web application and API testing tools <br>Identity & Access Management Security <br><br>Proven experience identifying and exploiting weaknesses in:OAuth 2.0 Open ID Connect (OIDC) JWT SAML 2.0 <br>Secure File Handling<br><br>Strong understanding of secure file processing, archive parsing, storage isolation, and content validation. Experience assessing file management controls and secure object storage implementations. <br><br>Preferred Qualifications <br><br>Experience assessing file-scanning, malware-detection, or Content Disarm and Reconstruction (CDR) solutions. Familiarity with security automation and vulnerability assessment tools such as:Nuclei Semgrep OWASP ZAP Knowledge of cloud security controls across AWS, Microsoft Azure, and Google Cloud Platform (GCP). Understanding of secure architecture principles for internet-facing applications and distributed environments. <br><br>Preferred Certifications <br><br>Offensive Security OSCP (Offensive Security Certified Professional) OSWE (Offensive Security Web Expert) Port Swigger BSCP (Burp Suite Certified Practitioner) Other relevant application security, penetration testing, or cloud security certifications are advantageous. <br><br>Senior Web App Security Engineer in Abu Dhabi, United Arab Emirates
We are looking for an experienced Network Security Lead to design, implement, and govern enterprise network security solutions across hybrid environments. The role requires strong technical expertise in firewall architecture, VPN technologies, network segmentation, and security operations. The successful candidate will lead network security initiatives, ensure secure network connectivity, and provide technical guidance for enterprise security platforms.<br>Key Responsibilities Lead network security architecture, design, implementation, and operational governance activities. Manage and maintain enterprise firewall platforms including Fortinet, Palo Alto Networks, and Cisco ASA. Design and support secure VPN solutions including SSL VPN and IPSec VPN environments. Define and enforce firewall security standards, policies, and rule management processes. Perform firewall rule reviews, optimisation, segmentation improvements, and security configuration assessments. Support security incident investigation, troubleshooting, root cause analysis, and remediation activities. Manage firewall upgrades, migrations, lifecycle activities, and vendor coordination. Provide technical leadership and guidance to network and security operations teams. Ensure network security controls align with security policies, compliance requirements, and industry best practices.<br>Required Skills & Experience10–12 years of experience in enterprise network security. Strong hands-on experience with firewall technologies including Fortinet Forti Gate, Forti Manager, Forti Analyzer, Palo Alto Networks PAN-OS, Panorama, and Cisco ASA. Strong understanding of firewall policies, NAT, routing, VPN technologies, and network segmentation. Experience designing and managing SSL VPN and IPSec VPN solutions. Experience with high availability (HA), clustering, and disaster recovery configurations. Strong knowledge of IDS/IPS, URL filtering, malware protection, and network security monitoring. Experience handling complex security incidents and technical escalations. Relevant vendor certifications such as Fortinet certifications, PCNSA/PCNSE, or CCIE Security.<br>Preferred Skills Experience with cloud network security solutions across Azure, AWS, or GCP. Knowledge of automation tools such as Python or Ansible. Familiarity with security frameworks including ISO 27001, NIST, SOC 2, and PCI-DSS. Strong leadership, communication, and stakeholder management skills.
نحن نبحث عن مهندس أمن سيبراني ذو خبرة لتحديد ومراجعة وحوكمة بنية الأمن المؤسسي عبر تطبيقات الأعمال، والبنية التحتية، ومنصات السحابة، والمبادرات التقنية. يركز هذا الدور على دمج الأمن في تصميم الحلول، وإجراء تقييمات البنية التحتية، وتحديد معايير الأمن، وضمان توافق ضوابط الأمن مع أهداف العمل ومتطلبات المخاطر وأفضل الممارسات في القطاع.<br>سيقدم المرشح الناجح توجيهات حول بنية الأمن عبر بيئات السحابة الهجينة والمتعددة، وسيعمل عن كثب مع فرق التكنولوجيا وأصحاب المصلحة في الأعمال والفرق القيادية.<br>المسؤوليات الرئيسية: تحديد وصيانة أطر عمل بنية الأمن المؤسسي، والمعايير، وبنيات المرجع، ومبادئ تصميم الأمن باستخدام منهجيات TOGAF/SABSA. مراجعة واعتماد تصميمات الأمن، والتصميمات عالية المستوى (HLDs)، والتصميمات منخفضة المستوى (LLDs)، وهندسة الحلول، والمقترحات الفنية، ووثائق البنية التحتية. ضمان تطبيق مبادئ "الأمن بالتصميم" و"الأمن الافتراضي" عبر المبادرات التقنية الجديدة. إجراء مراجعات لبنية الأمن، ونمذجة التهديدات، وتقييمات المخاطر، وتقييمات التصميم لحلول المؤسسة. تقييم وتحسين المنصات والتطبيقات والبنية التحتية وضوابط الأمن الحالية بناءً على معايير الأمن وأفضل الممارسات. تصميم ومراجعة بنى الأمن عبر منصات إدارة الهوية والوصول (IAM)، وأمن الشبكات، وأمن السحابة، وأمن نقاط النهاية، وأمن البريد الإلكتروني، ومنصات SIEM/SOAR. تقييم بيئات Microsoft Azure، والسحابة الهجينة، والسحابة المتعددة، وبيئات VMware لضمان تنفيذ بنية آمنة. تحديد الثغرات الأمنية، وتقديم توصيات المعالجة، ودعم مبادرات تحسين الأمن. دعم عمليات التدقيق الداخلية والخارجية من خلال ضمان الحفاظ على وثائق بنية الأمن والضوابط والأدلة. تقديم التوجيه الفني للمهندسين وفرق العمل وأصحاب المصلحة في الأعمال بشأن قرارات التكنولوجيا الآمنة.<br>المهارات والخبرات المطلوبة: خبرة تتراوح بين 10-12 سنة في بنية الأمن السيبراني، أو تصميم أمن المؤسسات، أو استشارات الأمن. شهادة TOGAF و/أو SABSA. فهم قوي لمبادئ بنية الأمن المؤسسي، ونهج "الثقة الصفرية" (Zero Trust)، وأساليب "الأمن بالتصميم". خبرة في تصميم ومراجعة حلول الأمن عبر: منصات IAM بما في ذلك Sail Point، وIBM IAM، وImprivata، وSSO، وMFA، وPAM، وحوكمة الوصول. منصات أمن الشبكات بما في ذلك Fortinet، وPalo Alto Networks، وCisco ASA، وتقنيات VPN، وتجزئة الشبكات. منصات أمن السحابة بما في ذلك Microsoft Defender for Cloud، وMicrosoft Sentinel، وMicrosoft Intune، وMicrosoft Purview، وDefender XDR. حلول أمن نقاط النهاية والبريد الإلكتروني بما في ذلك Microsoft Defender for Endpoint، وProofpoint، وTrend Micro، وMicrosoft Exchange Online Protection. خبرة في إعداد HLDs، وLLDs، ورسوم بنية الأمن، والتصميمات الفنية، وتوصيات الأمن. معرفة قوية بنمذجة التهديدات، ومنهجيات تقييم المخاطر، وضوابط الأمن، وحوكمة البنية التحتية. خبرة في تقييم حلول الأمن عبر بيئات السحابة الهجينة والمتعددة.<br>المهارات المفضلة: شهادة CISSP، أو CCSP، أو Azure Security. خبرة في بنية أمن VMware. معرفة بأطر عمل الأمن بما في ذلك ISO 27001، وNIST، وSOC 2، وPCI-DSS. خبرة في تكامل SIEM/SOAR وعمليات الأمن التشغيلية. التعرض لممارسات DevSecOps ودورة حياة تطوير البرمجيات الآمنة. مهارات قوية في التواصل، والتوثيق، والعروض التقديمية، وإدارة أصحاب المصلحة.
Minimum 10-15 years overall experience in IT starting with the hands-on engineering positions5 years’ experience doing practical design or architecture within the specialization (solutions, infrastructure, network, security, etc.) Act as a technical focal point for complex network and security design/solution Act as a technical SME during the product/solution evalution and implementation for network & security tools Must have experience around Enterprise Security Architecture Security, Security Strategy and Compliance Consulting Experience creating and audit of security best practices and implementation of security principles across the organization , to meet business goals along with customer and regulatory requirements,Understanding of compliance regulatory requirements like ISO,PCI DSS, NESA etc.,Must have experience around design of security controls and product best fit analysis to ensure end to end security covering different areas of security architecture : Layered Security Zoning Integration aspects API Security Endpoint Security Data Security Compliance and regulations Threat Intelligence Threat Exposure & Incident Management aspects Must Possess strong presentation , written and verbal communication skills Industry Security Certifications like CCIE,CISSP, CISA, CISM, CSRIC, TOGAF,SABSA etc., are preferred Good Understanding & Must have experience in implementing Cloud Security Controls Good Understanding of Cloud Platforms like Azure, Oracle, Google,AWS etc.,Good Understanding of Dockers, Containers and Kubernetes Good Understanding of SDN technologies like ACI. Good Understanding of REST, SOAP Protocols, Web services etc.,Good Understanding of Symmetric and Asymmetric Cryptography algorithms. Hands on Experience on Multi-vendor firewalls and other security technologies ( Firewalls, Web Proxy, Email Gate, Endpoint Security etc..) Knowledge and experience in requirements traceability throughout the design phase, including functional and non-functional requirements Ability and experience in translating functional and non-functional requirements into solution/feature/component design and service architecture Understands how the business structures and functions in FAB relate to the nature of the service Can create a high-level and low-level design (functional and non-functional) of a single or a small collection of components or a small end-to-end service Conducts / participates in code reviews, identifies bug root causes, and finds a workable solution Participates in Communities Proactively addresses issues discovered in the software components, infrastructure and scripts in the various environments
About The Role<br><br>What you will be doing:<br><br>Work directly with product teams in building a security by design and by default mindset by defining a structured approach to security in line with the Application Security Program mandates<br><br>Develop design patterns, and code guidelines that meet business security and system requirements in line with the risk assessments, policies, and procedures<br><br>Be a thought leader and help the wider organization drive security solutions implementation in-alignment with other stakeholders<br><br>Drive feature implementations in line with the architecture via designs, coding, reviews and tests. Perform Proof of Concept (POC) activities as necessary<br><br>Lead Dev Sec Ops implementation through technology, process and human upskilling including SAST, DAST, SCA, and penetration test results in collaboration with the developers.<br><br>Review current software security control measures and implement security enhancements for multiple cloud-based products<br><br>Participate in vulnerability investigations and become an extended arm to the Security Operation team<br><br>What You Have<br><br>Master’s degree in computer science or cyber security, a related field or equivalent demonstrated experience and knowledge<br><br>Minimum 7+ years of experience in engineering or software development or related fields.<br><br>Minimum 5 years hands-on product security role either as an architect, penetration tester or security engineer in cloud and application<br><br>Strong working knowledge of<br><br>software technologies such as C/C++, Java, . Net, python, etc.<br><br>Experience analyzing, using SAST, DAST, SCA and penetration tests.<br><br>Azure cloud<br><br>IOT and Operating system hardening using DISA STIGS and CIS benchmark<br><br>Experience ins secure software development or at least knowledge in secure coding practices and application security test report interpretation for various coding languages and multiple cloud services<br><br>Strong knowledge of secure software development lifecycle and practices including Agile methodologies for software development<br><br>Understanding of security by design principles and architecture level security concepts<br><br>Sound understanding and experience in implementing security public key Infrastructure (PKI)),<br><br>Experience implementing OWASP Top10 application security guidelines in cloud-based web applications<br><br>Experienced in generating, defining, and reviewing penetration test results through knowledge of standard methodologies and tools including environmental configuration definition, security analysis, threat modeling, and system security audits<br><br>Knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities<br><br>Exposure to international privacy requirements & cross-industry trends<br><br>Requirements<br><br>We are looking for a Principal Product Security Engineer whom his primary responsibility will be to for design, build, test and implementing secure SDLC across the product development lifecycle.<br><br>This role requires deep knowledge of building product security program from scratch which includes writing SOP, SWI, designing training for developers and gaining the trust of the product teams through hands-on engagement. A deep understanding of web-based secure code principles, and IOT security is a pre-requisite. Candidates should have experience in FDA and EU MDR submission process.<br><br>About The Company<br><br>At AMD, we are dedicated to safeguarding our client against cyber threats. We recognize the distinct requirements and vulnerabilities of each enterprise, which is why we offer tailor-made solutions to shield your data and assets effectively.<br><br>Our collaborative approach involves working closely with clients to devise a holistic cybersecurity strategy that harmonizes with their specific business objectives.