وصف الوظيفة
الأدوار والمسؤوليات
في شركة المل specimens? Almosafer Travel & Tourism Co، لسنا مجرد جزء من صناعة السفر، بل نساعد في تشكيل مستقبلها. كأكبر شركة سفر في المملكة العربية السعودية، نخدم ملايين الناس عبر كل قطاع من منظومة السفر والسياحة. متجذرين في اسمنا Almosafer، الذي يعني المسافر، نسعى لجعل كل رحلة سلسة وشخصية وهادفة. منصاتنا وخدماتنا المتنوعة مصممة لتقديم تجارب enrich ذات صدى يعكس روح المملكة العربية السعودية والمنطقة الأوسع. نتحد برؤية جريئة: أن نكون القائد الذي لا شك فيه في خدمات السفر، ونبني روابط دائمة ونضع معايير جديدة للتميز في المملكة وما بعدها. فريقنا عبر المملكة العربية السعودية والمنطقة الأوسع يمزج فهماً عميقاً للثقافة مع ابتكار مستقبلي، ليشكل معياراً جديداً للسفر في المنطقة.
هذا ليس دور تقليدي لـ IR أو محلل، فنحن نقضي نسباً كبيرة من وقتنا في أعمال المشروع، مع موازنة ذلك مع واجباتنا التشغيلية مثل هندسة الكشف والاستجابة للحوادث. إذا كنت مستعداً لإحداث تأثير ملموس وقيادة مشاريع أمنية مبتكرة، قدّم الآن للانضمام إلى فريقنا العالمي والمساعدة في تشكيل مستقبل الأمن في Almosafer. نحن نبحث عن مهندسين أنظمة وبرمجيات يحبون حل مشكلات الأمن المعقدة بشكل أساسي من المبادئ الأولى.
المسؤوليات:
- بناء ونشر وصيانة أنظمة أمان واسعة النطاق عبر منظومتنا البيئية.
- البحث والابتكار وتحسين قدرات الأمن لدينا من خلال أدوات جديدة ومحسّنة.
- تطوير استراتيجيات أتمتة ذكية لتقليل الحاجة إلى فرز التنبيهات يدويًا.
- إجراء هندسة الكشف لزيادة التغطية، مع تحديد الأنشطة الخبيثة عبر نقاط نهاية Almosafer والبُنى التحتية والشبكات وبيئات السحابة.
- تحقيق في التنبيهات والحوادث المحتملة من البداية إلى النهاية، بما في ذلك التحليل الرقمي والتحقيق في البرمجيات الخبيثة ومعلومات التهديد عند الحاجة.
- قيادة جهود الاستجابة للحوادث والرد على محاولات الاختراق والأنشطة المشبوهة، بالتنسيق مع فرق متعددة في Almosafer.
- المشاركة في تمارين فريق حمراء ومحاكاة التهديدات من أجل تحديد الثغرات وتحسين الكفاءات وتوسيع معرفة الفريق.
المرشح المرغوب فيه
بكالوريوس في علوم الحاسب الآلي، الهندسة، أنظمة المعلومات، أو ما يعادلها من سنوات الخبرة في مجال تقني ذو صلة
أكثر من 5 سنوات خبرة في مجال استجابة الحوادث، هندسة الكشف أو تخصصات أمنية ذات صلة
مهارات برمجة قوية في بايثون، روست، و/أو غو.
خبرة عملية مع نماذج أمن BeyondCorp أو Zero Trust. خبرة مثبتة في واحد أو أكثر من مجالات الكشف والاستجابة:
- التحقيق الجنائي الرقمي (الأدلة، اقتناء القرص/السحابة، أدوات مثل GRR، Timesketch)
- تحليل البرمجيات الخبيثة (ثابتة وديناميكية، IDA Pro، Ghidra)
- إدارة الاستجابة للحوادث وقيادتها (أحداث كُبرى متعددة الأطراف)
- كشف التطفل على الأجهزة/الشبكات (تحليل سجلات/أنظمة كبيرة وغير معروفة)
- التليمتري الشبكي (التدفقات، PCAPs، Zeek)
- معلومات التهديدات (نمذجة الجهات الفاعلة والتقنيات والتكتيكات والطرق)
- صيد التهديدات (العثور على IO Cs عبر بحيرات البيانات)
أنظمة تشغيل داخلية تغطي اثنين أو أكثر من macOS، Windows، أو Linux مع تغطية تراكيب الملفات/الأقراص، الطب الشرعي، ضوابط الأمن، التقوية، البرمجة النصية، وتحليل الثنائيات.
معرفة سحابية متقدمة قادرة على البناء والنشر والتحقيق في أحداث الأمن عبر اثنين أو أكثر من AWS، Kubernetes، أو GCP.
Job Description
Roles & Responsibilities
At Almosafer Travel & Tourism Co, we re not just part of the travel industry, we re helping shape its future. As Saudi Arabia s leading travel company, we serve millions across every segment of the travel and tourism ecosystem. Rooted in our name Almosafer, meaning the traveler, we strive to make every journey seamless, personal, and purposeful. Our diverse platforms and services are built to deliver enriching experiences that reflect the spirit of Saudi Arabia and the wider region. We re united by a bold vision:To be the undisputed leader in travel services, fostering lasting connections and setting new benchmarks for excellence in the Kingdom and beyond.Our team across Saudi Arabia and the wider region blends deep cultural understanding with forward-thinking innovation, shaping a new standard for travel in the region.
This is not your typical IR or analyst role, we spend large percentages of our time on project work, balancing this with our operational duties such as detection engineering and incident response. If you're ready to make a tangible impact and drive innovative security projects, apply now to join our global team and help shape the future of security at Almosafer.We are looking for systems & software engineers who love to solve complex security problems fundamentally from first principles.
Responsibilities:
- Build, deploy and maintain large scale security systems across our ecosystem.
- Research, innovate and improve our security capabilities through new and enhanced tooling.
- Develop smart automation strategies to reduce the need for manual alert triage.
- Conduct detection engineering to increase coverage, identifying malicious activities across Almosafer s endpoints, infrastructure, networks, and cloud environments.
- Investigate alerts and potential incidents end-to-end, including digital forensics, malware analysis and threat intelligence as needed.
- Lead incident response efforts and respond to intrusion attempts and suspicious activities, collaborating with multiple Almosafer teams.
- Participate in red team exercises and threat simulations in order to identify gaps, improve competencies and expand the team s knowledge.
Desired Candidate Profile
Bachelor of Science in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field
5+ years of experience in the field of incident response, detection engineering or related security disciplines
Strong programming skills in Python, Rust, and/or Go.
Practical experience with BeyondCorp or Zero Trust security models.Proven expertise in one or more detection & response areas:
- Digital forensics (artefacts, disk/cloud acquisition, tools like GRR, Timesketch)
- Malware analysis (static & dynamic, IDA Pro, Ghidra)
- Incident management & response (large-scale, multi-stakeholder events
- Host/network intrusion detection (parsing large, unfamiliar logs/systems)
- Network telemetry (flows, PCAPs, Zeek)
- Threat intelligence (modelling actors and TTPs)
- Threat hunting (finding IOCs across data lakes)
OS internals across two or more of macOS, Windows, or Linux covering file/disk structures, forensics, security controls, hardening, scripting, and binary analysis.
Advanced cloud knowledge able to build, deploy, and investigate security events across two or more of AWS, Kubernetes, or GCP.