Job Title: Security Engineer - Netskope & SASE
Location: UAE/Onsite
Role Type - FTE
Job Summary:
We are seeking a highly skilled L3 Information Security Engineer to design, implement, and maintain our enterprise security infrastructure. Your primary responsibility is driving our Secure Access Service Edge (SASE) strategy using Netskope. You will also lead a specialized technical team managing core endpoint, email, and vulnerability management platforms. Additionally, you will provide secondary engineering support for firewall assurance and cloud security posture management.
Key Responsibilities:
Primary Technical Engineering (SASE & Core Security):
- SASE Architecture: Own the deployment, configuration, and continuous optimization of Netskope (CASB, SWG, ZTNA).
- Policy Management: Design and enforce data loss prevention (DLP) and threat protection policies across cloud and web traffic.
- L3 Escalation Support: Serve as the highest technical escalation point for complex SASE infrastructure issues.
Team Leadership & Platform Management:
- Team Leadership: Lead and mentor a team of security engineers handling daily operations for endpoint, email, and vulnerability platforms.
- Endpoint Protection (EPP/EDR): Oversee administration and incident response across Trend Micro Deep Security Manager (DSM), Symantec Endpoint Security, and CrowdStrike Falcon.
- Vulnerability Management: Drive the enterprise vulnerability lifecycle utilizing Qualys, ensuring accurate scanning, prioritization, and reporting.
- Email Security: Manage inbound/outbound threat protection, mail routing, and phishing mitigation strategies using Proofpoint.
Secondary Technical Responsibilities:
- Firewall Assurance: Support network security auditing, compliance tracking, and policy optimization using AlgoSec.
- Cloud Security (CNAPP/CSPM): Assist in securing multi-cloud environments by monitoring alerts and compliance postures via Palo Alto Prisma Cloud.
Job Requirements:
Experience & Education
- Experience: Minimum 7–9 years in cybersecurity engineering, with at least 2–3 years in an L3 or team leadership role.
- Education: Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or equivalent practical experience.
Technical Skills:
- SASE: Deep technical expertise in Netskope implementation and traffic steering.
- EDR/EPP: Hands-on mastery of CrowdStrike, Trend Micro DSM, and Symantec.
- Vulnerability & Email: Proven experience with Qualys VMDR and Proofpoint Enterprise.
- Network & Cloud Security: Solid foundational knowledge of AlgoSec and Palo Alto Prisma Cloud.
- Core Networking: Strong understanding of TCP/IP, DNS, routing, SSL/TLS decryption, and API integrations.
Soft Skills:
- Leadership: Proven ability to guide, train, and distribute workload among junior to mid-level engineers.
- Communication: Ability to translate complex technical risks into clear business language for stakeholders.
Preferred Certifications:
- Netskope Certified Cloud Security Administrator (NCCSA) / Integrator (NCCSI)
- CrowdStrike Certified Falcon Administrator (CCFA) or Analyst (CCFA)
- Qualys Certified Specialist
- CISSP, CISM, or CEH
المسمى الوظيفي: مهندس أمن - Netskope & SASE
الموقع: الإمارات العربية المتحدة/في الموقع
نوع الدور - دوام كامل (FTE)
ملخص الوظيفة:
نحن نبحث عن مهندس أمن معلومات للمستوى الثالث (L3) ذو مهارات عالية لتصميم وتطوير وصيانة البنية التحتية لأمن المؤسسة. المسؤولية الرئيسية الموكلة إليك هي قيادة استراتيجية خدمة الوصول الآمن إلى الحافة (SASE) باستخدام Netskope. كما ستتولى قيادة فريق تقني متخصص يدير المنصات الأساسية لحماية النقاط النهائية والبريد الإلكتروني وإدارة الثغرات الأمنية. بالإضافة إلى ذلك، ستوفر دعمًا هندسيًا ثانوياً لضمان الجدران النارية وإدارة وضع الأمن السحابي.
المسؤوليات الرئيسية:
الهندسة التقنية الأساسية (SASE والأمن الأساسي):
- بنية SASE: تولي مسؤولية نشر وتكوين والتحسين المستمر لمنصة Netskope (CASB, SWG, ZTNA).
- إدارة السياسات: تصميم وتطبيق سياسات منع تسريب البيانات (DLP) والحماية من التهديدات عبر حركة مرور السحاب والويب.
- دعم التصعيد للمستوى L3: العمل كأعلى نقطة تصعيد تقنية لمشكلات البنية التحتية المعقدة لـ SASE.
قيادة الفريق وإدارة المنصات:
- قيادة الفريق: قيادة وتوجيه فريق من مهندسي الأمن الذين يتعاملون مع العمليات اليومية لمنصات النقاط النهائية والبريد الإلكتروني والثغرات الأمنية.
- حماية النقاط النهائية (EPP/EDR): الإشراف على الإدارة والاستجابة للحوادث عبر Trend Micro Deep Security Manager (DSM) و Symantec Endpoint Security و CrowdStrike Falcon.
- إدارة الثغرات الأمنية: قيادة دورة حياة الثغرات الأمنية للمؤسسة باستخدام Qualys، مع ضمان الفحص الدقيق وتحديد الأولويات وإعداد التقارير.
- أمن البريد الإلكتروني: إدارة الحماية من التهديدات الواردة/الصادرة وتوجيه البريد واستراتيجيات الحد من التصيد الاحتيالي باستخدام Proofpoint.
المسؤوليات التقنية الثانوية:
- ضمان الجدران النارية: دعم تدقيق أمن الشبكة، وتتبع الامتثال، وتحسين السياسات باستخدام AlgoSec.
- الأمن السحابي (CNAPP/CSPM): المساعدة في تأمين البيئات السحابية المتعددة من خلال مراقبة التنبيهات وأوضاع الامتثال عبر Palo Alto Prisma Cloud.
متطلبات الوظيفة:
الخبرة والتعليم
- الخبرة: ما لا يقل عن 7–9 سنوات في هندسة الأمن السيبراني، مع سنتين إلى 3 سنوات على الأقل في دور L3 أو دور قيادي للفريق.
- التعليم: درجة البكالوريوس في علوم الحاسوب، أو الأمن السيبراني، أو تكنولوجيا المعلومات، أو خبرة عملية معادلة.
المهارات التقنية:
- SASE: خبرة تقنية عميقة في تطبيق Netskope وتوجيه حركة المرور.
- EDR/EPP: إتقان عملي لـ CrowdStrike و Trend Micro DSM و Symantec.
- الثغرات الأمنية والبريد الإلكتروني: خبرة مثبتة مع Qualys VMDR و Proofpoint Enterprise.
- أمن الشبكات والسحاب: معرفة تأسيسية قوية بـ AlgoSec و Palo Alto Prisma Cloud.
- الشبكات الأساسية: فهم قوي لـ TCP/IP و DNS والتوجيه وفك تشفير SSL/TLS وتكاملات API.
المهارات الشخصية:
- القيادة: قدرة مثبتة على توجيه وتدريب وتوزيع حجم العمل بين المهندسين المبتدئين والمتوسطين.
- التواصل: القدرة على ترجمة المخاطر التقنية المعقدة إلى لغة أعمال واضحة لأصحاب المصلحة.
الشهادات المفضلة:
- Netskope Certified Cloud Security Administrator (NCCSA) / Integrator (NCCSI)
- CrowdStrike Certified Falcon Administrator (CCFA) أو Analyst (CCFA)
- Qualys Certified Specialist
- CISSP, CISM, أو CEH