وصف الوظيفة
المهندس الأكبر في IAM مسؤول عن تصميم وتنفيذ وصيانة حلول IAM المؤسسية التي تضمن وصولاً آمناً وسلساً إلى الأنظمة والبيانات.
يتضمن هذا الدور قيادة المبادرات التقنية، وأتمتة عمليات دورة حياة الهوية، وتكامل التطبيقات، وتطبيق سياسات الأمان عبر المنظمة.
يتعاون المهندس مع فرق الأمان والبنية التحتية والتطبيق لضمان توافق IAM مع احتياجات العمل ومبادئ الأمن الصفري الثقة.
المسؤوليات 1.
هندسة IAM وتصميمها: تصميم وتنفيذ معماريات IAM، بما في ذلك: إدارة دورة حياة الهوية، نماذج المصادقة والتفويض، حوكمة الوصول والتحكم في الوصول القائم على الأدوار (RBAC/ABAC)، إدارة الوصول المميز (PAM)، تنفيذ ضوابط الهوية المتوافقة مع Zero-Trust.
تطوير تكامل النظام باستخدام APIs، SSO، الاتحاد (SAML، OAuth، OIDC)، وت provisioning SCIM.
2. دورة حياة الهوية والأتمتة: أتمتة سير العمل للانضمام/الانتقال/التغيب (JML).
بناء موصلات مخصصة، نصوص التزويد، وسلاسل أتمتة باستخدام PowerShell، وبرمجة Windows. تحسين تدفقات بيانات الهوية بين أنظمة الموارد البشرية، والأدلة، والتطبيقات.
3. الدليل وخدمات المصادقة: إدارة أدلة الهوية المؤسسية (مثل Active Directory، Entra ID، LDAP).
تنفيذ MFA، ومصادقة بدون كلمة مرور، وسياسات وصول تكيفية.
استكشاف مشكلات المصادقة عبر البروتوكولات: Kerberos، LDAP، SAML، OAuth 2.0، OIDC. 4. حوكمة الوصول والامتثال: ضمان الالتزام بسياسات الوصول والمتطلبات التنظيمية (ISO 27001، SOX، HIPAA، PCI، وغيرها). دعم شهادات الوصول/التصديق.
وضع وصيانة معايير IAM ونماذج وخطط تشغيل.
إجراء مراجعات وصول دورية وتحليل مخاطر.
5. إدارة الوصول المميز (PAM): إدارة منصات PAM مثل CyberArk، BeyondTrust، Delinea، وغيرها.
تنفيذ Vaulting وتدوير الاعتمادات ومراقبة الجلسات والوصول عند الطلب فقط.
تقليل الامتيازات القائمة وحسابات الإدارة القديمة.
6. تكامل التطبيقات: استيراد التطبيقات لميزة SSO والتزويد باستخدام SAML، OAuth، وSCIM. العمل مع المطورين وفرق المنتجات لتنفيذ أنماط هوية آمنة وحديثة.
7. الاستجابة للحوادث واستكشاف الأخطاء: التحقيق في أحداث أمان متعلقة بـ IAM وحلها.
دعم مركز العمليات الأمنية with كشف الهوية، والتنبيهات، والأدلة الجنائية.
إجراء تحليل سبب الجذر لفشل وصول الهوية.
المهارات التقنية: 6 إلى 8 سنوات خبرة في هندسة إدارة الهوية والوصول.
درجة البكالوريوس في علوم الحاسوب، أمن المعلومات، أو مجال ذي صلة.
خبرة قوية في: منصة IAM مثل: Okta، Azure AD/Entra ID، Ping، ForgeRock، SailPoint، وغيرها.
خدمات الدليل (Active Directory، LDAP) SSO/Federation (SAML، OIDC، OAuth) توفير SCIM التصميم والتنفيذ لعمارة IAM المؤسسية، بما في ذلك إدارة دورة حياة الهوية، ونماذج المصادقة والتفويض، وحوكمة الوصول، وإدارة الوصول المميز.
خبرة في أتمتة سير عمل JML وعمليات دورة حياة الهوية.
القدرة على بناء موصلات مخصصة، ونُسق التزويد، وسلاسل الأتمتة باستخدام PowerShell وبرمجة Windows.
خبرة مع تقنيات الوصول المميز، بما في ذلك إدارة منصات PAM مثل CyberArk، BeyondTrust، أو Delinea للتحكم في Vaulting وتدوير الاعتمادات ومراقبة الجلسات والوصول عند الطلب.
الإلمام بمبادئ Zero Trust.
فهم بمنصات السحابة: Azure، AWS، أو GCP.
خبرة في تنفيذ MFA، ومصادقة بدون كلمة مرور، وسياسات وصول شرطي/تكيفي.
خبرة في استكشاف مشكلات المصادقة عبر Kerberos، LDAP، SAML، OAuth 2.0.
0، وOIDC.
خبرة في دعم عمليات الحوكمة للوصول مثل مراجعات الوصول وشهادات/تصديقات الوصول.
خبرة في العمل بمواقع مطابقة لـ ISO 27001؛ وجود SOX، HIPAA، أو PCI يعتبر إضافة.
المهارات اللينة: تفكير تحليلي وحل مشكلات قوي.
القدرة على التواصل مع أصحاب المصلحة التقنيين وغير التقنيين.
خبرة في قيادة مشاريع تقنية وتقديم حلول بمستوى مؤسسي.
تجربة بالشراكة مع SOC وفرق الأمان والبنية التحتية والتطبيق لتوفير تكاملات IAM وحل الحوادث.
خبرة في التحقيق وحل حوادث أمان متعلقة بـ IAM وإجراء تحليل سبب الجذر.
الأهلية للعمل في المملكة العربية السعودية.
مرشح مفضل
سنوات الخبرة
لا خبرة مطلوبة
المؤهل الدراسي
درجة البكالوريوس / دبلوم عالي
Job description
The IAM Senior Engineer is responsible for designing, implementing, and maintaining enterprise IAM solutions that ensure secure and seamless access to systems and data.
This role involves leading technical initiatives, automating identity lifecycle processes, integrating applications, and enforcing security policies across the organization.
The engineer collaborates with security, infrastructure, and application teams to ensure IAM aligns with business needs and zero‑trust security principles.
Responsibilities 1.
IAM Architecture & Engineering Design and implement IAM architectures, including: Identity lifecycle management Authentication and authorization models Access governance and role-based access control (RBAC/ABAC) Privileged access management (PAM) Implement Zero-Trust aligned identity controls.
Develop system integrations using APIs, SSO, federation (SAML, OAuth, OIDC), and SCIM provisioning.
2. Identity Lifecycle & Automation Automate joiner/mover/leaver (JML) workflows.
Build custom connectors, provisioning scripts, and automation pipelines using PowerShell, Windows Script Optimize identity data flows between HR systems, directories, and applications.
3. Directory & Authentication Services Manage enterprise identity directories (e.
g., Active Directory, Entra ID, LDAP).
Implement MFA, passwordless authentication, and adaptive access policies.
Troubleshoot authentication issues across protocols: Kerberos, LDAP, SAML, OAuth 2.
0, OIDC. 4. Access Governance & Compliance Ensure adherence to access policies and regulatory requirements (ISO 27001, SOX, HIPAA, PCI, etc.
). Support access certifications/attestations.
Develop and maintain IAM standards, patterns, and playbooks.
Conduct periodic access reviews and risk analysis.
5. Privileged Access Management (PAM) Administer PAM platforms (CyberArk, BeyondTrust, Delinea, etc.
). Implement vaulting, credential rotation, session monitoring, and just‑in‑time access.
Reduce standing privileges and legacy admin accounts.
6. Application Integration Onboard applications for SSO and provisioning using SAML, OAuth, and SCIM Work with developers and product teams to implement secure, modern identity patterns.
7. Incident Response & Troubleshooting Investigate and resolve IAM‑related security incidents.
Support SOC with identity‑specific detection, alerts, and forensics.
Perform root-cause analysis for identity access failures.
Technical Skills 6 to 8 years of experience in identity and access management (IAM) engineering.
Bachelor’s degree in computer science, information security, or a related field.
Strong expertise in: IAM platform(s): Okta, Azure AD/Entra ID, Ping, ForgeRock, SailPoint, etc.
Directory services (Active Directory, LDAP) SSO/Federation (SAML, OIDC, OAuth) SCIM provisioning Experience designing and implementing enterprise IAM architectures, including identity lifecycle management, authentication and authorization models, access governance, and privileged access management.
Experience automating joiner/mover/leaver (JML) workflows and identity lifecycle processes.
Ability to build custom connectors, provisioning scripts, and automation pipelines using PowerShell and Windows scripting.
Experience with privileged access technologies, including administering PAM platforms such as CyberArk, BeyondTrust, or Delinea for vaulting, credential rotation, session monitoring, and just-in-time access.
Familiarity with Zero Trust principles.
Understanding of cloud platforms: Azure, AWS, or GCP.
Experience implementing MFA, passwordless authentication, and conditional/adaptive access policies.
Experience troubleshooting authentication issues across Kerberos, LDAP, SAML, OAuth 2.
0, and OIDC.
Experience supporting access governance processes such as access reviews and access certifications/attestations.
Experience working in environments aligned with ISO 27001; experience with SOX, HIPAA, or PCI is a plus.
Soft Skills Strong problem-solving and analytical mindset.
Ability to communicate with both technical and non‑technical stakeholders.
Experience leading technical projects and delivering enterprise‑grade solutions.
Experience partnering with SOC, security, infrastructure, and application teams to deliver IAM integrations and resolve incidents.
Experience investigating and resolving IAM-related security incidents and performing root-cause analysis.
Eligibility to work in Saudi Arabia.
Preferred candidate
Years of experience
No experience required
Degree
Bachelor's degree / higher diploma