وصف الوظيفة: يتحمل مهندس أمان السحابة مسؤولية تأمين البنية التحتية السحابية الأصلية لدى أفرِيوك، والتطبيقات، وأعباء العمل المستضافة في AWS وAzure. يصمم الدور ويفرض ضوابط أمان استباقية عبر كامل تكديس السحابة، ويراقب التهديدات ويستجيب لها، وي دمج الأمان في خطوط أنابيب CI/CD، ويدير جدران الحماية والد defenses المحيطية باستخدام أدوات أصلية من AWS وAzure وأدوات الطرف الثالث، مما يعزز وضع الأمان السحابي للمؤسسة بما يتماشى مع أفضل ممارسات الصناعة ومعايير الحوكمة المؤسسية
المسؤوليات الأساسية والمساءلة:تصميم وتنفيذ وإدارة معماريات سحابية آمنة عبر بيئات AWS وAzure، والالتزام بأفضل الممارسات الصناعية وإطارات الأمان ومعايير الحوكمة المؤسسية.• إدارة بيئات AWS Control Tower وLanding Zone Accelerator، بما في ذلك حوكمة الحساب، سياسات التحكم بالخدمات (SCPs)، Guardrails، قواعد AWS Config، وآليات الأمن لـ AWS Organizations.• تصميم وتنفيذ Azure Landing Zones، مجموعات الإدارة، Azure Policy، Azure Blueprints، وأطر الحوكمة المؤسسية.• تنفيذ وتكوين وإدارة خدمات أمان أصلية للسحابة، بما في ذلك:◦ AWS: Guard Duty، Security Hub، Inspector، Macie، IAM Access Analyzer، AWS Config، Cloud Trail، AWS WAF، Shield، Firewall Manager، KMS، وSecrets Manager.• Azure: Microsoft Defender for Cloud، Microsoft Sentinel، Azure Firewall، Azure DDoSProtection، Azure Key Vault، Azure Policy، Microsoft Entra ID (Azure AD)، وMicrosoft Defender for Identity.• تعريف وإدارة عمليات تشغيلية لرصد أمان السحابة، فرز التنبيهات، الاستجابة للحوادث، التذاكر، وإجراءات الإصلاح عبر منصات SIEM/SOAR مثل Microsoft Sentinel، Elastic SIEM، وMicrosoft Defender XDR، ومنصات ITSM بما في ذلك Jira وService Now.• توفير وإدارة بنية تحتية سحابية hands-on باستخدام Infrastructure as Code (IaC) مع Terraform، AWS Cloud Formation، Azure ARM Templates، أو Bicep.• تنفيذ ضوابط أمان IaC من خلال دمج فحص أمان تلقائي، والتحقق من السياسات، وفحوص الامتثال، وكشف تكوين البنية التحتية الخاطئ في خطوط أنابيب CI/CD باستخدام أدوات معيارية صناعيًا وأفضل الممارسات.• إجراء تحقيقات حوادث أمان السحابة، التحليل الجنائي، وتحليل السبب الجذري (RCA)، والعمل عن كثب مع فرق الهندسة لتنفيذ إجراءات تصحيح دائمة.• إجراء إدارة الثغرات عبر بنية السحابة التحتية، والآلات الافتراضية، والحاويات، ومجموعات Kubernetes، وأعباء العمل بدون خادم، وخدمات التخزين، وقواعد البيانات، وتطبيقات السحابة الأصلية.• تنفيذ أمان الهوية والوصول السحابي باستخدام AWS IAM، IAM Identity Center، Microsoft Entra ID، Privileged Identity Management (PIM)، الوصول القائم على الدور (RBAC)، الوصول المشروط، المصادقة متعددة العوامل (MFA)، ومبادئ الثقة الصفرية (Zero Trust).• تصميم وتأمين مكونات الشبكات السحابية بما في ذلك VPC/VNet، مجموعات الأمان، NSGs، NACLs، Transit Gateway، Azure Virtual WAN، Private Link، VPN، Direct Connect، Express Route، Application Load Balancers، وNetwork Load Balancers.• تطوير وصيانة لوحات أمان السحابة، مؤشرات الأداء الرئيسية/مؤشرات المخاطر الرئيسية، تشغيلية دليل الإجراءات، مخططات الهندسة المعمارية، تقارير الامتثال، وإجراءات التشغيل القياسية.
الشهادات (مفضلة)• AWS Certified Security — Specialty• Microsoft Certified: Azure Security Engineer Associate (AZ-500)• Certified Cloud Security Professional (CCSP)• GIAC Cloud Security Automation (GCSA)• Certified Kubernetes Security Specialist (CKS) أو Certified Kubernetes Administrator (CKA)• CISSP أو شهادات أمان سحابية ذات صلة
Job Description:The Cloud Security Engineer is responsible for securing Avrioc's cloud-native infrastructure,applications, and workloads hosted in AWS and Azure. The role designs and enforces proactivesecurity controls across the full cloud stack, monitors and responds to threats, integratessecurity into CI/CD pipelines, and manages firewall and perimeter defenses using AWS and Azure native and third-party tooling, strengthening the organization's cloud security posture inline with industry best practice and enterprise governance standards
Key Responsibilities & Accountabilities:Design, implement, and manage secure cloud architectures across AWS and Azureenvironments, adhering to industry best practices, security frameworks, and enterprisegovernance standards.• Manage AWS Control Tower and Landing Zone Accelerator environments, including accountgovernance, Service Control Policies (SCPs), Guardrails, AWS Config Rules, and AWSOrganizations security controls.• Design and implement Azure Landing Zones, Management Groups, Azure Policy, Azure Blueprints, and enterprise governance frameworks.• Implement, configure, and manage cloud-native security services, including:◦ AWS: Guard Duty, Security Hub, Inspector, Macie, IAM Access Analyzer, AWS Config,Cloud Trail, AWS WAF, Shield, Firewall Manager, KMS, and Secrets Manager.◦ Azure: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Firewall, Azure DDoSProtection, Azure Key Vault, Azure Policy, Microsoft Entra ID (Azure AD), and Microsoft Defender for Identity.• Define and manage operational processes for cloud security monitoring, alert triage,incident response, ticketing, and remediation through SIEM/SOAR platforms such as Microsoft Sentinel, Elastic SIEM, and Microsoft Defender XDR, and ITSM platformsincluding Jira and Service Now.• Provision and manage cloud infrastructure hands-on using Infrastructure as Code (IaC) with Terraform, AWS Cloud Formation, Azure ARM Templates, or Bicep.• Implement IaC security controls by integrating automated security scanning, policyvalidation, compliance checks, and infrastructure misconfiguration detection into CI/CDpipelines using industry-standard tools and best practices.• Conduct cloud security incident investigations, forensic analysis, and Root Cause Analysis(RCA), working closely with engineering teams to implement permanent corrective actions.• Perform vulnerability management across cloud infrastructure, virtual machines,containers, Kubernetes clusters, serverless workloads, storage services, databases, andcloud-native applications.• Implement cloud identity and access security using AWS IAM, IAM Identity Center,Microsoft Entra ID, Privileged Identity Management (PIM), Role-Based Access Control(RBAC), Conditional Access, Multi-Factor Authentication (MFA), and Zero Trust securityprinciples.• Design and secure cloud networking components including VPC/VNet, Security Groups,NSGs, NACLs, Transit Gateway, Azure Virtual WAN, Private Link, VPN, Direct Connect,Express Route, Application Load Balancers, and Network Load Balancers.• Develop and maintain cloud security dashboards, KPIs/KRIs, operational runbooks,architecture diagrams, compliance reports, and standard operating procedures.
Certifications (preferred)• AWS Certified Security — Specialty• Microsoft Certified: Azure Security Engineer Associate (AZ-500)• Certified Cloud Security Professional (CCSP)• GIAC Cloud Security Automation (GCSA)• Certified Kubernetes Security Specialist (CKS) or Certified Kubernetes Administrator (CKA)• CISSP or other relevant cloud security certifications