عن الدور الوظيفي
كل عملية تسجيل دخول، وكل توثيق لهوية عميل، وكل طلب وصول بزيادة الصلاحيات يمر عبر المعمارية التي تصممها من الصفر. أنت تبني جانبي إدارة الهوية في وقت واحد: تجربة العملاء التي يجب أن تكون سلسة وآمنة في الوقت نفسه، وعناصر التحكم الخاصة بالقوى العاملة التي تحافظ على تأمين البنية التحتية الحيوية للبنك. عندما تنجح في ذلك، تصبح إدارة الهوية أمرًا لا يفكر فيه أحد لأنه يعمل بفاعلية وأمان في كل مرة.
ما ستفعله
- تصميم وبناء إطار عمل إدارة الهوية والوصول للمؤسسات (IAM) وإدارة هوية العملاء والوصول (CIAM) بالكامل من الصفر، وتحديد مسارات عمل دورة حياة الهوية الحديثة، ومعايير التوثيق، ونماذج التفويض
- الشراكة مع فريق المنتجات لتصميم تجارب توثيق مستهلك آمنة وعالية التوافر وقليلة الاحتكاك، بما في ذلك التوثيق متعدد العوامل، والربط بالبيانات الحيوية (البصمة)، وخيارات الدخول بدون كلمة مرور، والموازنة بين الأمان المصرفي الصارم وتجربة المصرفية الرقمية السلسة
- تطبيق ضوابط قوية لهوية القوى العاملة، وتسجيل الدخول الأحادي (SSO)، وخدمات دليل المؤسسة، ومسارات عمل إدارة الوصول ذي الصلاحيات (PAM) المؤتمتة لحماية البنية التحتية الحيوية وبيئات السحابة
- الشراكة مع أمن السحابة وهندسة الشبكات لفرض التحقق المستمر من الهوية، والوصول بأقل الصلاحيات، وسياسات الوصول المشروط عبر الخدمات المصغرة السحابية الأصلية
- أتمتة عملية منح وإلغاء صلاحيات المستخدمين، والتحكم في الوصول القائم على الأدوار (RBAC) للقضاء على تشتت الهويات وتسهيل مسارات العمل الداخلية من الموارد البشرية إلى تقنية المعلومات
- إنشاء حملات منتظمة لإعادة إقرار الصلاحيات، وسجلات التدقيق، وآليات إعداد التقارير لتلبية المراجعات الداخلية وفحوصات البنك المركزي المصري التنظيمية
الملف الشخصي للمرشح المطلوب
ما نبحث عنه- أكثر من 10 سنوات من الخبرة التراكمية في تقنية المعلومات وأمن المعلومات، بما في ذلك 4 إلى 5 سنوات من التخصص في معمارية وقيادة IAM وCIAM وPAM ضمن قطاعات البنوك، أو الخدمات المالية، أو بيئات التكنولوجيا المالية (Fintech) المتقدمة
- خبرة عملية في بروتوكولات الهوية الحديثة (OIDC وOAuth 2.0 وSAML)، ومزودي خدمات الهوية السحابية (مثل Azure AD/Entra ID وOkta وPing Identity)، ومعماريات CIAM الحديثة
- فهم قوي لدوريات الأمن السيبراني الصادرة عن البنك المركزي المصري (CBE)، ومتطلبات التوثيق، وإرشادات خصوصية البيانات
- يُفضل بقوة الحصول على شهادات مهنية مثل CISSP أو مدير هوية ووصول معتمد (CIAM) أو الشهادات التخصصية المعتمدة من الشركات المصنعة
- عقلية البناء والابتكار، والقدرة على الازدهار في بيئة سريعة الوتيرة وتبدأ من الصفر، مع القدرة على الموازنة بين الصرامة الأمنية القصوى للبيانات المالية والتسليم السريع للمنتجات بأسلوب مرن
- مهارات ممتازة في التعاون بين الوظائف المختلفة، والجسر بين هندسة المنتجات، وعمليات الأمن، وأصحاب المصلحة التنفيذيين
ستزدهر معنا إذا كنت- تفضل تصميم هندسة الهوية من المبادئ الأولى بدلاً من الترقيع في فوضى موروثة من الأدلة والصلاحيات
- تعتقد أن تسجيل الدخول يجب أن يبدو سهلاً للعميل وأن يكون صارماً وغير قابل للمساومة في خلفيته
- تتعامل مع الوصول بأقل الصلاحيات كأصل افتراضي، وليس كاستثناء تلتفت إليه عندما يتوفر الوقت
- تستطيع ترجمة قرار معمارية الهوية إلى شيء يفهمه كل من الجهات التنظيمية وفريق المنتجات
- تريد بناء الطبقة التي تثق بها كل الأنظمة الأخرى في البنك في النهاية
THE ROLE
Every login, every customer authentication, every privileged access request runs through the architecture you design, from a blank page. You're building both sides of identity at once, the customer-facing experience that has to feel invisible and secure at the same time, and the workforce controls that keep the bank's critical infrastructure locked down. Get it right, and identity becomes the thing nobody thinks about because it just works, safely, every time.
WHAT YOU LL DO
- Design and build the enterprise IAM and CIAM framework entirely from scratch, defining modern identity lifecycle workflows, authentication standards, and authorization models
- Partner with the Product team to architect secure, high-availability, low-friction consumer authentication experiences, including multi-factor authentication, biometric integration, and passwordless options, balancing rigorous bank security with a seamless digital banking experience
- Implement robust workforce identity controls, Single Sign-On (SSO), Enterprise Directory services, and automated Privileged Access Management (PAM) workflows to protect critical infrastructure and cloud environments
- Partner with cloud security and network engineering to enforce continuous identity verification, least-privilege access, and conditional access policies across cloud-native microservices
- Automate user provisioning, de-provisioning, and role-based access control (RBAC) to eliminate identity sprawl and streamline internal HR-to-IT workflows
- Establish regular access recertification campaigns, audit logging, and reporting mechanisms to satisfy internal reviews and CBE regulatory examinations
Desired Candidate Profile
WHAT WE RE LOOKING FOR- 10+ years of cumulative IT and information security experience, including 4 to 5 years specializing in IAM, CIAM, and PAM architecture and leadership within banking, financial services, or advanced fintech environments
- Hands-on expertise with modern identity protocols (OIDC, OAuth 2.0, SAML), cloud identity providers (e.g., Azure AD/Entra ID, Okta, Ping Identity), and modern CIAM architectures
- Solid understanding of Central Bank of Egypt (CBE) cybersecurity circulars, authentication requirements, and data privacy guidelines
- Professional credentials such as CISSP, Certified Identity and Access Manager (CIAM), or vendor-specific expert certifications are strongly preferred
- A builder mindset, thriving in a fast-paced, from-scratch environment, able to balance extreme security rigor for financial data with rapid, agile product delivery
- Excellent cross-functional collaboration skills, bridging product engineering, security operations, and executive stakeholders
YOU LL THRIVE HERE IF YOU- You'd rather architect identity from first principles than patch together an inherited mess of directories and permissions
- You believe a login should feel effortless to the customer and be uncompromising underneath
- You treat least-privilege access as a default, not an exception you get to when there's time
- You can translate an identity architecture decision into something both a regulator and a product team understand
- You want to build the layer that every other system in the bank ultimately trusts