امتلك هندسة الحلول الشاملة لنظام Daitics AI CDP: منصة بيانات العملاء السيادية المخصصة محلياً لشركات الاتصالات، مبنية على بنية تدفقية، ومُنفَّذة على بنية تحتية نُشغّلها بأنفسنا (Kubernetes، Helm)، وليست خدمات سحابية مُدارة. تعالج المنصة مئات الآلاف من الأحداث في الثانية عبر أكثر من ثلاثين مصدر نظام وتقدم ملفات تعريف عملاء موحدة للأشخاص B2C والمنظمات B2B، والحسابات، والمواقع، والخطوط، والأجهزة وجهات الاتصال. ستتولى الهندسة المعمارية عبر العناوين الخمسة (التأليف، والتحكم، والبيانات، والتفعيل، والمراقبة) وعلى الطبقات الخمس (الأحداث الذرية، وبُنى البلاطات، وقيم السمات، فلاتر الإشارات، وأحداث الإشارات)، وتبقي الخط في مبادئ الهندسة المعمارية عبر حدود المحركات، وتترجمها إلى تصاميم يمكن لفرق الهندسة بناؤها وفقها.
المتطلبات
12+ سنة في هندسة البرمجيات والبيانات، مع خبرة لا تقل عن 5 سنوات في امتلاك هندسة الحلول أو منصة لهياكلDistributed systems على نطاق واسع
إثبات امتلاك هندسة شاملة من النهاية للنهاية لمنصة تدفق بيانات على بنية تحتية مُدارة ذاتياً (محلياً أو سحابة خاصة) - الطوبولوجيا، موضع الحالة، مجالات الفشل، الانتقال والقدرة الاستيعابية
فهم معماري عميق وتطبيقي لـ Apache Flink كبيئة تشغيل تدفقية ذات حالة - DataStream وSQL، الحالة المفهرسة على RocksDB، حالة البث، I/O غير متزامن، الانقطاعات والانحدار وفقاً لقواعد التوقف والتوفير (متطلب أساسي)
القدرة المثبتة على تصميم هياكل زمن وصول من طبقتين: مسار حار بملي ثانية مقابل مسار بارد دائم بمقياس دقيقة مع ميزان زمن استلام شامل
خبرة في تصميم هياكل Kafka لمشقّات منصة متعددة المستأجرين - تصنيف المواضيع، اختيار وحجم مفتاح التقسيم، تدفقات تحكم مضغوطة، فئات الاحتفاظ وأسماء معايير
خبرة في هندسة حوكمة المخططات عبر المنتجين والمستهلكين - Avro أو ما يعادله من خلال سجل مخطط، أوضاع التوافق وترقيات مدروسة للتغييرات المكسورة
خبرة عملية في هندسة هياكل جدولة lakehouse (Apache Paimon، Iceberg، Delta Lake أو Hudi) على تخزين كائنات متوافق مع S3 - تصميم المفتاح الأساسي وجداول LSM، التقسيم، الدمج وتلاشي اللقطات
خبرة في استخدام ذاكرات موزعة (Apache Ignite، Hazelcast، Redis أو ما شابه) - جداول مقسمة مقابل متكررة، اقتران التماثل، وصول عميل رقيق وإبطال الاستهلاك المتبادل
قدرة على تعريف وتطبيق إطار قرار وضع الحالة: حالة البث مقابل الحالة المفهرسة مقابل التخزين الخارجي مقابل التحميل من أول مرة
خبرة في هندسة حل التعرف على الهوية على نطاق واسع - المطابقة الحتمية والاحتمالية، نمذجة مخطط الهوية، علاقات B2B تاريخية، عمليات الدمج والانفصال وتخييط مجهول إلى معروف
خبرة في الهندسة المعمارية لإنفاذ الموافقات وحوكمة البيانات - أوضاع إنفاذ قابلة للتكوين، وسم البيانات المستخدمة، توزيع السياسات على وقت التشغيل وتصاميم تتجنب نداء خدمة متزامن لكل حدث
خبرة في هندسة التشفير، التجزئة، الإخفاء والتشفير لمعرِّفات حساسة - ترقيم وتدوير المفاتيح (HashiCorp Vault Transit أو ما يعادله) وتدقيق فك التشفير عند الطلب
خبرة في تصميم خط سير كامل وتحليل تأثير التحرير في وقت التعديل، تفعيل القطع المميّز للإصدار وترحيل عبر حدود المحرك مع نافذة نعمة وإمكانية التراجع
خبرة في تصميم عزل متعدد المستأجرين على Kubernetes، اتحاد هوية المؤسسة IdP (OIDC، Keycloak أو ما يعادله)، ABAC، NetworkPolicies، خدمة-شبكة mTLS وإدارة الأسرار
خبرة في تحديد مجالات الفشل وSLOs وRPO وRTO لأطر البث وتصميم مسارات الإعادة والتعبئة والتسوية التي لا تعيد تشغيل إجراءات خارجية
خبرة عملية مع Spring Boot على Java لخدمات التحكم الدقيقة، PostgreSQL كمخزن تعريف، وتنسيق سير العمل (Temporal، Argo Workflows أو ما يعادله)
خبرة مع أكوام المراقبة (OpenTelemetry، Prometheus، Grafana، التتبع الموزع)؛ خبرة في الاتصالات الصناعية مع TM Forum SID و TMF620 ميزة قوية
معرفة باستخدام أدوات الذكاء الاصطناعي في التصميم والتطوير وتصحيح الأخطاء (Claude، Cursor، Codex)
Own the end-to-end solution architecture of the Daitics AI CDP: a sovereign, on-prem, telco-native Customer Data Platform built on a streaming architecture, deployed on infrastructure we run ourselves (Kubernetes, Helm), not managed cloud services. The platform processes hundreds of thousands of events per second across thirty or more source systems and delivers unified customer profiles for B2C persons and B2B organizations, accounts, sites, lines, devices and contacts. You will own the architecture across the five planes (Authoring, Control, Data, Activation, Observability) and the five layers (atomic events, tile primitives, trait values, signal filters, signal events), hold the line on architectural principles across engine boundaries, and translate them into designs engineering teams can build against.
Requirements
12+ years in software and data engineering, with at least 5 years owning solution or platform architecture for large-scale distributed systems
Demonstrated ownership of end-to-end architecture for a streaming data platform on self-managed infrastructure (on-prem or private cloud) - topology, state placement, failure domains, cutover and capacity
Deep, hands-on architectural command of Apache Flink as a stateful streaming runtime - DataStream and SQL, keyed state on RocksDB, broadcast state, Async I/O, checkpoint and savepoint discipline (core requirement)
Proven ability to design two-tier latency architectures: a millisecond-level hot path against a minute-level durable cold path with an explicit end-to-end latency budget
Experience designing Kafka topologies for multi-tenant platforms - topic taxonomy, partition-key selection and sizing, compacted control streams, retention classes and naming conventions
Experience architecting schema governance across producers and consumers - Avro or equivalent through a schema registry, compatibility modes and coordinated promotion of breaking changes
Hands-on architecture experience with lakehouse table formats (Apache Paimon, Iceberg, Delta Lake or Hudi) on S3-compatible object storage - primary-key and LSM table design, partitioning, compaction and snapshot expiry
Experience with distributed in-memory caches (Apache Ignite, Hazelcast, Redis or similar) - partitioned versus replicated tables, affinity colocation, thin-client access and cross-consumer invalidation
Ability to define and enforce a state-placement decision framework: broadcast state versus keyed state versus external cache versus first-seen load
Experience architecting identity resolution at scale - deterministic and probabilistic matching, identity graph modeling, effective-dated B2B relationships, merge and split workflows and anonymous-to-known stitching
Architecture experience with consent enforcement and data governance - configurable enforcement modes, data usage labeling, policy distribution to the runtime and designs that avoid a synchronous service call per event
Experience architecting tokenization, hashing, masking and encryption for sensitive identifiers - key versioning and rotation (HashiCorp Vault Transit or equivalent) and audited just-in-time detokenization
Experience designing end-to-end lineage and edit-time impact analysis, versioned artifact activation and cutover across engine boundaries with grace windows and rollback
Experience designing multi-tenant isolation on Kubernetes, enterprise IdP federation (OIDC, Keycloak or equivalent), ABAC, NetworkPolicies, service-mesh mTLS and secrets management
Experience defining failure domains, SLOs, RPO and RTO targets for streaming platforms, and designing replay, backfill and reconciliation paths that do not re-trigger external actions
Practical experience with Spring Boot on Java for control-plane microservices, PostgreSQL as a definition store, and workflow orchestration (Temporal, Argo Workflows or equivalent)
Experience with observability stacks (OpenTelemetry, Prometheus, Grafana, distributed tracing); telco experience with TM Forum SID and TMF620 is a strong advantage
Familiarity using AI tools for design, development and debugging (Claude, Cursor, Codex)