Security Solutions Specialist
I. Job Summary The Security Solutions Specialist is responsible for investigating and responding to security incidents, conducting threat hunting and forensic analysis, and supporting the integration, configuration, and optimization of cybersecurity solutions within customer environments. The role combines SOC operations with security solutions integration, acting as a technical interface between the SOC and specialized security functions.
II. Duties & Responsibilities1. Incident Investigation & Response Investigate and analyze security incidents escalated by Tier 1 SOC Team Leaders. Analyze logs, network traffic, endpoint data, and security alerts to determine impact and root cause. Lead containment, eradication, and recovery activities for confirmed incidents. Prepare incident reports and escalate complex incidents to Tier 3 when required.2. Threat Hunting & Forensics Conduct proactive threat hunting to identify advanced and emerging threats. Perform digital forensic analysis to understand attack paths and collect relevant evidence. Develop and improve detection rules and security use cases.3. Security Solutions Integration Integrate, configure, and maintain security solutions within customer environments. Work with SIEM and SOAR platforms, including log onboarding, correlation rules, dashboards, alerts, playbooks, and automation workflows. Integrate security technologies using APIs, connectors, agents, and log-forwarding mechanisms. Configure and support Fortinet solutions, particularly Forti Gate, and ensure proper security event monitoring. Troubleshoot security integration, log collection, alerting, and automation issues.· Create and maintain implementation guides, runbooks, and architecture diagrams.· Develop HLD that define target architecture, data flows, security controls, and integration points across customer environments.· Produce LLD with device‑level configurations, policies, parsing/normalization rules, playbooks, and API mappings for accurate, repeatable deployments.
III. Position Expectations Strong understanding of cybersecurity, SOC operations, incident response, and network security. Hands-on knowledge of SIEM, SOAR, Forti Gate, and Fortinet security solutions. Understanding of security integrations, APIs, log management, event correlation, and automation. Strong analytical, troubleshooting, communication, and reporting skills. Ability to collaborate effectively with SOC, IT, security teams, and customers. Proactive approach to threat detection, security improvement, and continuous learning. Provide technical guidance to junior team members while contributing to SOC procedures, training, knowledge sharing, and continuously improving processes, detection capabilities, automation, and security integrations.
IV. Qualifications Bachelor’s degree in computer engineering or a related field.4 years of experience in SOC, cybersecurity, incident response, security engineering, or a related role. Hands-on experience with SIEM and SOAR platforms. Practical knowledge of Forti Gate and Fortinet security solutions. Knowledge of networking concepts, firewalls, VPNs, IDS/IPS, authentication, and security protocols. Experience with security integrations, APIs, log collection, and automation is highly preferred. Relevant certifications such as Fortinet NSE/FCP, Security+, CySA+, CEH, or equivalent are an advantage. Good English communication and technical documentation skills. Strong analytical, problem-solving, and troubleshooting abilities.
أخصائي حلول أمنية
I. ملخص الوظيفة: يتولى أخصائي الحلول الأمنية مسؤولية التحقيق في الحوادث الأمنية والاستجابة لها، وإجراء عمليات البحث عن التهديدات والتحليل الجنائي، ودعم دمج وتكوين وتحسين حلول الأمن السيبراني داخل بيئات العملاء. يجمع هذا الدور بين عمليات مركز العمليات الأمنية (SOC) ودمج الحلول الأمنية، ليكون بمثابة واجهة تقنية بين مركز العمليات الأمنية والوظائف الأمنية المتخصصة.
II. المهام والمسؤوليات: 1. التحقيق في الحوادث والاستجابة لها: التحقيق في الحوادث الأمنية التي يتم تصعيدها من قبل قادة فرق المستوى الأول في مركز العمليات الأمنية وتحليلها. تحليل السجلات وحركة مرور الشبكة وبيانات نقاط النهاية والتنبيهات الأمنية لتحديد التأثير والسبب الجذري. قيادة أنشطة الاحتواء والمعالجة والتعافي للحوادث المؤكدة. إعداد تقارير الحوادث وتصعيد الحوادث المعقدة إلى المستوى الثالث عند الحاجة. 2. البحث عن التهديدات والتحليل الجنائي: إجراء بحث استباقي عن التهديدات لتحديد التهديدات المتقدمة والناشئة. إجراء التحليل الجنائي الرقمي لفهم مسارات الهجوم وجمع الأدلة ذات الصلة. تطوير وتحسين قواعد الكشف وحالات الاستخدام الأمني. 3. دمج الحلول الأمنية: دمج وتكوين وصيانة الحلول الأمنية داخل بيئات العملاء. العمل مع منصات SIEM و SOAR، بما في ذلك إلحاق السجلات، وقواعد الارتباط، ولوحات المعلومات، والتنبيهات، وكتيبات التشغيل (playbooks)، وسير عمل الأتمتة. دمج التقنيات الأمنية باستخدام واجهات برمجة التطبيقات (APIs)، والموصلات، والوكلاء، وآليات إعادة توجيه السجلات. تكوين ودعم حلول Fortinet، وخاصة FortiGate، وضمان المراقبة الصحيحة للأحداث الأمنية. استكشاف مشكلات الدمج الأمني وجمع السجلات والتنبيهات والأتمتة وإصلاحها. · إنشاء وصيانة أدلة التنفيذ وكتيبات التشغيل ومخططات البنية التحتية. · تطوير التصاميم عالية المستوى (HLD) التي تحدد البنية التحتية المستهدفة، وتدفقات البيانات، وعناصر التحكم الأمنية، ونقاط الدمج عبر بيئات العملاء. · إعداد التصاميم منخفضة المستوى (LLD) مع تكوينات على مستوى الجهاز، والسياسات، وقواعد التحليل/التطبيع، وكتيبات التشغيل، وتعيينات واجهة برمجة التطبيقات لضمان عمليات نشر دقيقة وقابلة للتكرار.
III. توقعات المنصب: فهم قوي للأمن السيبراني وعمليات مركز العمليات الأمنية (SOC) والاستجابة للحوادث وأمن الشبكات. معرفة عملية بمنصات SIEM و SOAR وحلول FortiGate و Fortinet الأمنية. فهم عمليات الدمج الأمني، وواجهات برمجة التطبيقات (APIs)، وإدارة السجلات، وربط الأحداث، والأتمتة. مهارات تحليلية وقدرة قوية على استكشاف الأخطاء وإصلاحها والتواصل وإعداد التقارير. القدرة على التعاون بفعالية مع مركز العمليات الأمنية، وتكنولوجيا المعلومات، وفرق الأمن، والعملاء. نهج استباقي للكشف عن التهديدات والتحسين الأمني والتعلم المستمر. تقديم التوجيه الفني لأعضاء الفريق المبتدئين مع المساهمة في إجراءات مركز العمليات الأمنية والتدريب وتبادل المعرفة والتحسين المستمر للعمليات وقدرات الكشف والأتمتة وعمليات الدمج الأمني.
IV. المؤهلات: درجة البكالوريوس في هندسة الحاسوب أو مجال ذي صلة. خبرة 4 سنوات في مركز العمليات الأمنية (SOC)، أو الأمن السيبراني، أو الاستجابة للحوادث، أو الهندسة الأمنية، أو دور ذي صلة. خبرة عملية مع منصات SIEM و SOAR. معرفة عملية بحلول FortiGate و Fortinet الأمنية. معرفة بمفاهيم الشبكات، وجدران الحماية، و VPNs، و IDS/IPS، والمصادقة، والبروتوكولات الأمنية. يفضل بشدة الحصول على خبرة في عمليات الدمج الأمني، وواجهات برمجة التطبيقات (APIs)، وجمع السجلات، والأتمتة. تعد الشهادات ذات الصلة مثل Fortinet NSE/FCP، أو Security+، أو CySA+، أو CEH، أو ما يعادلها ميزة إضافية. مهارات جيدة في التواصل باللغة الإنجليزية والتوثيق الفني. قدرات قوية في التحليل وحل المشكلات واستكشاف الأخطاء وإصلاحها.