وصف الوظيفة
نحن نبحث عن مهندس أمان شبكات أول مع تخصص قوي في بوابة الويب الآمنة (SWG) وتقنيات البروكسي، لا سيما Blue Coat ProxySG (الآن جزء من Broadcom/Symantec).
يقع هذا الدور ضمن وظيفة أمان الشبكات الأوسع لدينا وهو مسؤول عن إدارة وتأمين وتحسين بنية وصول الويب/الإنترنت عبر المنظمة.
يجب أن يمتلك المرشحون خبرة عملية لا تقل عن سنتين إلى ثلاث سنوات في إدارة Blue Coat ProxySG / SGOS كجزء من مسار مهني أوسع في أمان الشبكات (عادةً 5+ سنوات إجمالاً).
وجود خبرة في البنوك والخدمات المالية يعتبر ميزة قوية، ولكنه ليس إلزامياً.
المسؤوليات الرئيسية إدارة Proxy وSecure Web Gateway إدارة وتكوين ودعم Blue Coat ProxySG (SGOS) و حلول بوابة الويب الآمنة/أمان الويب ذات الصلة.
تصميم وتنفيذ والمحافظة على فئات تصفية الويب وسياسات الاستخدام المقبول والتحكمات الآمنة للوصول إلى الإنترنت.
تكوين وإدارة اعتراض SSL/TLS (رؤية SSL)، ودمج المصادقة (AD/LDAP، Kerberos، SAML)، ودمج ICAP مع حلول DLP، وبرامج مكافحة الفيروسات، والصوامن.
مراقبة أداء البروكسي والتوافر والقدرة؛ إجراء ضبط وتحسين لضمان أقل زمن استجابة وأقصى زمن تشغيل.
استكشاف الأخطاء والاستجابة للحوادث استكشاف الحوادث المرتبطة بالبروكسي، ومشاكل الاتصال، والتعارضات السياسية، عبر طبقات الشبكة (TCP/IP، DNS، HTTP/HTTPS، التوجيه).
المشاركة في استجابة حوادث الأمان المتعلقة بتهديدات الويب، والحركة الضارة، وانتهاكات السياسات.
التعاون مع SOC، وفِرق الشبكة، وفرق الأمن السيبراني الأوسع لربط سجلات البروكسي مع منصات SIEM واستخبارات التهديدات.
دعم المشاريع والترحيل ودورة الحياة دعم الترقيات، والتصحيح، وإدارة دورة حياة أجهزة Blue Coat ProxySG ومكونات SWG ذات الصلة.
المساعدة في مشاريع الترحيل أو الدمج بين حلول البروكسي في المكان وعلى السحابة المنفذة SWG/SASE.
المساهمة في مبادرات الأتمتة والبرمجة لتسهيل نشر السياسات والتقارير والمهام الادارية الروتينية.
الحوكمة والتوثيق والامتثال إعداد وصيانة الوثائق الفنية، ومعايير التكوين، ودفاتر التشغيل التشغيلية.
دعم التدقيقات الداخلية والخارجية من خلال تقديم دلائل على التكوين الآمن، والتحكم في التغيير، وتطبيق السياسات.
ضمان التوافق مع سياسات أمن المعلومات والأطر التنظيمية ذات الصلة (مثل SAMA، NCA ECC، ISO/IEC 27001، PCI DSS) حيثما ينطبق.
درجة البكالوريوس في علوم الحاسوب، تكنولوجيا المعلومات، هندسة الشبكات، أو مجال ذي صلة (أو خبرة عملية معادلة).
5+ سنوات من الخبرة الإجمالية في هندسة الشبكات/الأمن السيبراني، بما في ذلك حد أدنى من سنتين إلى ثلاث سنوات من الخبرة العملية في إدارة Blue Coat ProxySG / SGOS.
بدلاً من ذلك، 5+ سنوات من الخبرة الإجمالية في الشبكات/الأمن السيبراني مع خبرة عملية قوية في منصات بوابة ويب آمنة أو بروكسي أخرى رائدة (مثلاً Symantec Web Security Service، Forcepoint، McAfee/Skyhigh Web Gateway، Cisco WSA/Umbrella، Zscaler، Fortinet FortiProxy)، مع قدرة وإرادة للتخصص في Blue Coat ProxySG.
فهم قوي لمفاهيم الشبكات الأساسية: TCP/IP، DNS، HTTP/HTTPS، التوجيه، وتقسيم الشبكة.
خبرة عملية في تصنيف عناوين الويب، وتقاطعات SSL/TLS، وفِقرات فحص المحتوى.
خبرة في دمج منصات البروكسي/SWG مع DLP، والصوامن، واستخبارات التهديدات، أو حلول SIEM قيمة للغاية.
مهارات استكشاف أخطاء ممتازة، وتحليلية، والتواصل، مع القدرة على العمل عبر وظائف الشبكة والأمن والبنية التحتية.
وجود خبرة في البنوك، والخدمات المالية، أو قطاعات منظمة أخرى مفضلة لكن غير مطلوبة.
Job description
We are looking for a Senior Network Security Engineer with a strong specialization in Secure Web Gateway (SWG) and proxy technologies, particularly Blue Coat ProxySG (now part of Broadcom/Symantec).
This role sits within our broader network security function and is responsible for administering, securing, and optimizing web/internet access infrastructure across the organization.
Candidates should bring at least 2–3 years of hands-on Blue Coat ProxySG / SGOS administration experience as part of a broader network security career (typically 5+ years overall).
Experience in banking and financial services is a strong plus, but not mandatory.
Key Responsibilities Proxy & Secure Web Gateway Administration Administer, configure, and support Blue Coat ProxySG (SGOS) and related secure web gateway/web security solutions.
Design, implement, and maintain web filtering categories, acceptable use policies, and secure internet access controls.
Configure and manage SSL/TLS interception (SSL Visibility), authentication integration (AD/LDAP, Kerberos, SAML), and ICAP integration with DLP, antivirus, and sandboxing solutions.
Monitor proxy performance, availability, and capacity; conduct tuning and optimization to ensure minimal latency and maximum uptime.
Troubleshooting & Incident Response Troubleshoot proxy-related incidents, connectivity issues, and policy conflicts, working across network layers (TCP/IP, DNS, HTTP/HTTPS, routing).
Participate in security incident response related to web-based threats, malicious traffic, and policy violations.
Collaborate with SOC, network, and broader cybersecurity teams to correlate proxy logs with SIEM and threat intelligence platforms.
Project, Migration & Lifecycle Support Support upgrades, patching, and lifecycle management of Blue Coat ProxySG appliances and related SWG components.
Assist with migration or integration projects between on-premise proxy solutions and cloud-delivered SWG/SASE platforms.
Contribute to automation and scripting initiatives to streamline policy deployment, reporting, and routine administration tasks.
Governance, Documentation & Compliance Prepare and maintain technical documentation, configuration standards, and operational runbooks.
Support internal and external audits by providing evidence of secure configuration, change control, and policy enforcement.
Ensure alignment with information security policies and relevant regulatory frameworks (e.
g., SAMA, NCA ECC, ISO/IEC 27001, PCI DSS) where applicable.
Bachelor's degree in Computer Science, Information Technology, Network Engineering, or a related field (or equivalent practical experience).
5+ years of overall network/cybersecurity engineering experience, including a minimum of 2–3 years of hands-on Blue Coat ProxySG / SGOS administration.
Alternatively, 5+ years of overall network/cybersecurity experience with strong hands-on exposure to other leading secure web gateway or proxy platforms (e.
g., Symantec Web Security Service, Forcepoint, McAfee/Skyhigh Web Gateway, Cisco WSA/Umbrella, Zscaler, Fortinet FortiProxy), with demonstrated ability and willingness to specialize in Blue Coat ProxySG.
Strong understanding of core networking concepts: TCP/IP, DNS, HTTP/HTTPS, routing, and network segmentation.
Hands-on experience with web filtering, URL categorization, SSL/TLS interception, and content inspection policies.
Experience integrating proxy/SWG platforms with DLP, sandboxing, threat intelligence, or SIEM solutions is highly valued.
Excellent troubleshooting, analytical, and communication skills, with the ability to work cross-functionally with network, security, and infrastructure teams.
Experience in banking, financial services, or other regulated sectors is preferred but not required.