وصف الوظيفة
نحن نبحث عن مهندس أمني شبكي أول مع تخصص قوي في Secure Web Gateway (SWG) وتقنيات البروكسي، خاصة Blue Coat ProxySG (الذي أصبح جزءًا من Broadcom/Symantec).
يأتي هذا الدور ضمن وظيفة أمان الشبكة الأوسع لدينا وهو مسؤول عن إدارة وتأمين وتحسين بنية وصول الإنترنت/الويب عبر المؤسسة.
يجب أن يجلب المرشحون خبرة عملية لا تقل عن 2–3 سنوات في إدارة Blue Coat ProxySG / SGOS كجزء من مسيرة أمان شبكي أوسع (عادةً 5+ سنوات بشكل عام).
الخبرة في القطاع المصرفي والخدمات المالية تعتبر إضافة قوية، لكنها ليست إلزامية.
المسؤوليات الرئيسية: إدارة Proxy & Secure Web Gateway إدارة Blue Coat ProxySG (SGOS) والحلول المرتبطة بالبوابة الآمنة للويب/أمان الويب، وتكوينها ودعمها.
تصميم وتنفيذ والحفاظ على فئات فلاتر الويب، سياسات الاستخدام المقبول، والتحكم في وصول الإنترنت الآمن.
تكوين وإدارة الاعتراض SSL/TLS (رؤية SSL)، الدمج في المصادقة (AD/LDAP، Kerberos، SAML)، والتكامل ICAP مع حلول DLP، مضاد الفيروسات، والتحصين في البيئات الآمنة.
مراقبة أداء البروكسي، والتوافر، والقدرة؛ إجراء التحسينات لضمان أقل زمن استجابة وأقصى زمن تشغيل.
استكشاف الأخطاء والاستجابة للحوادث troubleshoot للمشكلات المرتبطة بالبروكسي، ومشاكل الاتصال، وتضارب السياسات، عبر طبقات الشبكة (TCP/IP، DNS، HTTP/HTTPS، التوجيه).
المشاركة في استجابة الحوادث الأمنية المتعلقة بالتهديدات الويب، الحركة الخبيثة، وانتهاكات السياسات.
التعاون مع فرق SOC والشبكة وأقسام الأمن السيبراني الأوسع لربط سجلات البروكسي بمنصات SIEM وThreat Intelligence.
الدعم في المشاريع المتعلقة بالترحيل ودعم عمر النظام بحيث يتم صيانة Blue Coat ProxySG وأجزاء SWG المرتبطة.
المساعدة في مشاريع الترحيل أو الدمج بين حلول البروكسي في الموقع ومنصات SWG/SASE المقدمة سحابيًا.
المساهمة في مبادرات الأتمتة والبرمجة لتسهيل تطبيق السياسات والتقارير والمهام الإدارية الروتينية.
الحوكمة والتوثيق والامتثال تحضير وصيانة الوثائق الفنية، ومعايير التكوين، ودلائل التشغيل.
دعم التدقيقات الداخلية والخارجية من خلال توفير أدلة على التكوين الآمن، وسيطرة التغيير، وفرض السياسة.
ضمان التوافق مع سياسات أمن المعلومات والأطر التنظيمية ذات الصلة (مثل SAMA، NCA ECC، ISO/IEC 27001، PCI DSS حيثما كان ذلك applicable).
درجة البكالوريوس في علوم الحاسوب، تكنولوجيا المعلومات، هندسة الشبكات، أو مجال ذي صلة (أو خبرة عملية مكافئة).
5+ سنوات من خبرة الهندسة الشبكية/الأمن السيبراني بشكل عام، بما في ذلك الحد الأدنى من 2–3 سنوات من الخبرة العملية في إدارة Blue Coat ProxySG / SGOS.
بدلاً من ذلك، 5+ سنوات من الخبرة الشبكية/الأمن السيبراني بشكل عام مع خبرة عملية قوية تجاه منصات بوابة ويب آمنة أو بروكسي أخرى رائدة (مثلاً، Symantec Web Security Service، Forcepoint، McAfee/Skyhigh Web Gateway، Cisco WSA/Umbrella، Zscaler، Fortinet FortiProxy)، مع قدرة و رغبة مثبتة في التخصص في Blue Coat ProxySG.
فهم قوي لمفاهيم الشبكات الأساسية: TCP/IP، DNS، HTTP/HTTPS، التوجيه، وتقسيم الشبكات.
خبرة عملية في فلاتر الويب، فئات URL، الاعتراض SSL/TLS، وسياسات فحص المحتوى.
الخبرة في دمج منصات البروكسي/SWG مع DLP، الحماية في البيئات المعزّزة، استخبارات التهديدات، أو حلول SIEM تعتبر ذات قيمة عالية.
مهارات استثنائية في الاستكشاف والتحليل والتواصل، مع القدرة على العمل عبر وظائف الشبكة والأمن والبنية التحتية.
الخبرة في القطاعات المصرفية أو الخدمات المالية أو القطاعات المنظمة الأخرى مفضلة لكنها ليست مطلوبة.
Job description
We are looking for a Senior Network Security Engineer with a strong specialization in Secure Web Gateway (SWG) and proxy technologies, particularly Blue Coat ProxySG (now part of Broadcom/Symantec).
This role sits within our broader network security function and is responsible for administering, securing, and optimizing web/internet access infrastructure across the organization.
Candidates should bring at least 2–3 years of hands-on Blue Coat ProxySG / SGOS administration experience as part of a broader network security career (typically 5+ years overall).
Experience in banking and financial services is a strong plus, but not mandatory.
Key Responsibilities Proxy & Secure Web Gateway Administration Administer, configure, and support Blue Coat ProxySG (SGOS) and related secure web gateway/web security solutions.
Design, implement, and maintain web filtering categories, acceptable use policies, and secure internet access controls.
Configure and manage SSL/TLS interception (SSL Visibility), authentication integration (AD/LDAP, Kerberos, SAML), and ICAP integration with DLP, antivirus, and sandboxing solutions.
Monitor proxy performance, availability, and capacity; conduct tuning and optimization to ensure minimal latency and maximum uptime.
Troubleshooting & Incident Response Troubleshoot proxy-related incidents, connectivity issues, and policy conflicts, working across network layers (TCP/IP, DNS, HTTP/HTTPS, routing).
Participate in security incident response related to web-based threats, malicious traffic, and policy violations.
Collaborate with SOC, network, and broader cybersecurity teams to correlate proxy logs with SIEM and threat intelligence platforms.
Project, Migration & Lifecycle Support Support upgrades, patching, and lifecycle management of Blue Coat ProxySG appliances and related SWG components.
Assist with migration or integration projects between on-premise proxy solutions and cloud-delivered SWG/SASE platforms.
Contribute to automation and scripting initiatives to streamline policy deployment, reporting, and routine administration tasks.
Governance, Documentation & Compliance Prepare and maintain technical documentation, configuration standards, and operational runbooks.
Support internal and external audits by providing evidence of secure configuration, change control, and policy enforcement.
Ensure alignment with information security policies and relevant regulatory frameworks (e.
g., SAMA, NCA ECC, ISO/IEC 27001, PCI DSS) where applicable.
Bachelor's degree in Computer Science, Information Technology, Network Engineering, or a related field (or equivalent practical experience).
5+ years of overall network/cybersecurity engineering experience, including a minimum of 2–3 years of hands-on Blue Coat ProxySG / SGOS administration.
Alternatively, 5+ years of overall network/cybersecurity experience with strong hands-on exposure to other leading secure web gateway or proxy platforms (e.
g., Symantec Web Security Service, Forcepoint, McAfee/Skyhigh Web Gateway, Cisco WSA/Umbrella, Zscaler, Fortinet FortiProxy), with demonstrated ability and willingness to specialize in Blue Coat ProxySG.
Strong understanding of core networking concepts: TCP/IP, DNS, HTTP/HTTPS, routing, and network segmentation.
Hands-on experience with web filtering, URL categorization, SSL/TLS interception, and content inspection policies.
Experience integrating proxy/SWG platforms with DLP, sandboxing, threat intelligence, or SIEM solutions is highly valued.
Excellent troubleshooting, analytical, and communication skills, with the ability to work cross-functionally with network, security, and infrastructure teams.
Experience in banking, financial services, or other regulated sectors is preferred but not required.