هذا ليس دور تحليل الحوادث العادي الذي تفكر فيه؛ فنحن نقضي نسبة كبيرة من وقتنا في العمل على المشاريع، مع الموازنة مع واجباتنا التشغيلية مثل هندسة الكشف والاستجابة للحوادث. إذا كنت مستعداً لإحداث تأثير ملموس ودفع مشاريع أمنية مبتكرة، تقدم الآن للانضمام إلى فريقنا العالمي والمساعدة في تشكيل مستقبل الأمن في الملصفِر Almosafer. نحن نبحث عن مهندسي نظم وبرمجيات يحبون حل المشكلات الأمنية المعقدة من الأساس على مبادئ أولية.
الملف المرغوب للمرشح
- درجة بكالوريوس في علوم الحاسب أو الهندسة أو نظم المعلومات أو ما يعادلها من سنوات الخبرة في مجال تقني ذو صلة
- 3+ سنوات من الخبرة في مجال الاستجابة للحوادث أو هندسة الكشف أو تخصصات أمنية ذات صلة
- مهارات برمجة قوية بلغة بايثون، راست، و/أو جو
- خبرة عملية في نماذج أمان BeyondCorp أو Zero Trust. خبرة مثبتة في واحد أو أكثر من مجالات الكشف والاستجابة:
- التحليل الجنائي الرقمي (المعالم، الاستحواذ على الأقراص/السحابة، أدوات مثل GRR، Timesketch)
- تحليل البرمجيات الخبيثة (ثابتة ومتحركة، IDA Pro، Ghidra)
- إدارة الاستجابة للحوادث (فعاليات على نطاق واسع وتعدد الأطراف)
- كشف التسلل على الجهاز/الشبكة (تحليل سجلات/أنظمة كبيرة وغير مألوفة)
- تيلم الشبكة (التدفقات، PCAPs، Zeek)
- ذكاء التهديدات (نمذجة الجهات وتدابير وتقنيات الهجوم)
- صيد التهديدات (إيجاد مؤشرات الاختراق عبر بحيرات البيانات)
- تفاصيل نظام التشغيل عبر اثنين أو أكثر من macOS أو Windows أو Linux تغطي هياكل الملفات/الأقراص، التحري الرقمي، ضوابط الأمن، التقوية، البرمجة النصية، وتحليل الثنائيات.
- معرفة متقدمة بالسحابة قادرة على البناء والنشر والتحقيق في أحداث الأمن عبر اثنين أو أكثر من AWS، Kubernetes، أو GCP.
This is not your typical IR or analyst role, we spend large percentages of our time on project work, balancing this with our operational duties such as detection engineering and incident response. If you're ready to make a tangible impact and drive innovative security projects, apply now to join our global team and help shape the future of security at Almosafer.We are looking for systems & software engineers who love to solve complex security problems fundamentally from first principles.
Desired Candidate Profile
- Bachelor of Science in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field
- 3+ years of experience in the field of incident response, detection engineering or related security disciplines
- Strong programming skills in Python, Rust, and/or Go.
- Practical experience with BeyondCorp or Zero Trust security models.Proven expertise in one or more detection & response areas:
- Digital forensics (artefacts, disk/cloud acquisition, tools like GRR, Timesketch)
- Malware analysis (static & dynamic, IDA Pro, Ghidra)
- Incident management & response (large-scale, multi-stakeholder events
- Host/network intrusion detection (parsing large, unfamiliar logs/systems)
- Network telemetry (flows, PCAPs, Zeek)
- Threat intelligence (modelling actors and TTPs)
- Threat hunting (finding IOCs across data lakes)
- OS internals across two or more of macOS, Windows, or Linux covering file/disk structures, forensics, security controls, hardening, scripting, and binary analysis.
- Advanced cloud knowledge able to build, deploy, and investigate security events across two or more of AWS, Kubernetes, or GCP.