الوصف
المهندس الأمني المتخصص – حلول Fortinet مسؤول عن تصميم وتنفيذ وتحسين ودعم حلول الأمن السيبراني المعتمدة على Fortinet عبر مؤسسات كبرى ومزودي خدمات ومراكز بيانات. الدور يعمل كخبير فني في تقنيات Fortinet، مقدماً تصميم الهندسة، وقيادة النشر، واستكشاف الأخطاء، ودعم الهجرة، والتميز التشغيلي عبر بيئات العملاء.
العمل ضمن ممارسة الأمن السيبراني في ZainTECH، سيقود المهندس الأمني المتخصص تسليم حلول أمنية آمنة وقابلة للتوسع ومرنة تغطي أمان الشبكات، وSD-WAN، وSASE، وبنى Zero Trust، وإدارة الوصول المالك، وأمان تطبيقات الويب، ومنصات مراقبة الأمن. يتعاون الدور عن كثب مع العملاء وفرق ما قبل البيع وفِرق تسليم المشاريع وشركاء التكنولوجيا لضمان التنفيذ الناجح والتحسين المستمر لحلول Fortinet الأمنية.
المسؤوليات
هندسة الأمان وتصميم الحلول
- تصميم وتنفيذ بنى أمان للمؤسسات ومراكز البيانات باستخدام تقنيات Fortinet.
- تطوير حلول أمان آمنة وقابلة للتوسع وعالية التوفر تتوافق مع متطلبات عمل وأمن العميل.
- تصميم وهندسة نشرات عالية التوفر (HA)، وحلول SD-WAN المتقدمة، وبنى Secure Access Service Edge (SASE)، وبيئات Zero Trust Network Access (ZTNA)، واستراتيجيات تقسيم الشبكة والتقسيم الدقيق.
- إجراء تقييمات أمنية وتقديم توصيات متوافقة مع أفضل ممارسات الأمن السيبراني والمعايير الصناعية.
- تطوير التصاميم عالية المستوى (HLDs)، والتصاميم منخفضة المستوى (LLDs)، وخطط الهجرة والتنفيذ، ووثائق الهندسة التقنية.
نشر وتكامل حلول Fortinet
- قيادة التثبيت والتهيئة والهجرة وتحسين حلول Fortinet بما في ذلك:
- FortiGate
- FortiManager
- FortiAnalyzer
- FortiSwitch
- FortiAP
- FortiWeb
- FortiADC
- FortiPAM
- FortiProxy
- FortiDLP
- FortiSIEM
- FortiSASE
- FortiAppSec
- دمج منصات Fortinet مع:
- Active Directory
- LDAP
- RADIUS
- TACACS+
- مزودو الهوية IdPs
- منصات المصادقة متعددة العوامل MFA
- حلول SIEM وSyslog
- بيئات AWS وMicrosoft Azure
- حلول أمن من جهات خارجية
- ضمان نجاح الهجرة والتشغيل البيني بين البنى الأمنية القديمة والحديثة.
عمليات الأمن والدعم الفني
- تقديم دعم متقدم من المستوى L2 وL3 وخلال التصعيد للعملاء المؤسسيين.
- استكشاف أعطال معقدة:
- حوادث أمنية
- مشاكل الجدار الناري
- مشاكل التوجيه والاتصال
- مشاكل متعلقة بالشبكة الافتراضية الخاصة VPN
- التحديات في المصادقة والتحكم بالوصول
- إجراء تحليل السببالجذري وتقديم توصيات لمنع التكرار.
- مراقبة أداء الحل وضمان توفر الخدمة العالية.
- صيانة نسخ التكوين الاحتياطية وخطط التعافي من الكوارث ووثائق التشغيل.
- دعم العملاء خلال الحوادث الحرجة والانقطاعات الكبرى للخدمة.
أمان الشبكة وتقنيات الأمن المتقدمة
- إعداد وإدارة وتحسين:
- سياسات الأمان
- التحكم في التطبيقات
- أنظمة منع الاختراق (IPS)
- تصفية الويب
- خدمات مكافحة البرامج الضارة
- منع فقدان البيانات (DLP)
- خدمات الوكProxy
- إدارة الوصول المميز PAM
- مراقبة الأحداث الأمنية والترابط
- النشر والدعم:
- Psec VPN
- SSL VPN
- الوصول عن بُعد إلى الإنترنت (RIA)
- الوصول المباشر إلى الإنترنت (DIA)
- شبكات VPN بين المواقع Site-to-Site
- هياكل VPN محور-ثار
- تنفيذ نماذج أمان Zero Trust وSASE لتعزيز وضع الأمان لدى العملاء.
تسليم المشروع والتفاعل مع العملاء
- قيادة مشاريع التنفيذ والهجرة والترقية والتحسين.
- تنسيق الأنشطة مع العملاء والبائعين ومديري المشاريع وفرق التسليم الداخلية.
- إنتاج وثائق التنفيذ الفنية وتقارير القبول ووثائق كما-بُني وتوثيق التسليم التشغيلي.
- عقد جلسات نقل المعرفة للعملاء وورش عمل تقنية.
- دعم فرق ما قبل البيع خلال عروض الحلول والمناقشات التقنية وأنشطة إثبات المفهوم.
التحسين المستمر والقيادة التقنية
- البقاء مطلعاً على التهديدات السيبرانية الناشئة وتطوير منتجات Fortinet وأفضل الممارسات الصناعية.
- المشاركة في تمكين تقني ومبادرات تبادل المعرفة.
- دعم تطوير المعايير التقنية ومنهجيات التنفيذ وإجراءات التشغيل.
- المساهمة في مبادرات تحسين الخدمة عبر ممارسة الأمن السيبراني.
ثقافتنا ومدونة السلوك
في ZainTECH، نفخر بثقافة مبنية على التعاون والابتكار والنزاهة دون تنازل. نحن نبحث عن أفراد يشاركون هذه القيم وملتزمون بتركيز العميل والتميز الأخلاقي. من المتوقع أن يحافظ جميع الموظفين على مدونة السلوك لدينا كإطار توجيهي للسلوك المسؤول في كل ما نقوم به — من كيفية العمل مع بعضنا البعض إلى كيفية التعامل مع العملاء والشركاء عالميًا.
المتطلبات
- درجة البكالوريوس في هندسة الحاسبات، علوم الحاسوب، أمن المعلومات، تقنية المعلومات، أو مجال ذي صلة، مع خبرة لا تقل عن 5 سنوات في الأمن السيبراني وهندسة أمان الشبكات.
- خبرة عملية مثبتة في تصميم وتنفيذ ودعم حلول Fortinet الأمنية، بما في ذلك FortiGate وFortiManager وFortiAnalyzer وSD-WAN وSASE وFortiWeb وFortiADC وFortiPAM وFortiProxy وFortiDLP وFortiSIEM.
- معرفة قوية بهندسة أمان الشبكات وتصميم البنية التحتية، مع خبرة في TCP/IP والتوجيه والتبديل وBGP وOSPF وVLAN وNAT وتشكيل حركة البيانات والتوجيه المستند إلى السياسات.
- مهارات متقدمة في استكشاف الأخطاء وتحليلها وحل المشكلات، مع خبرة في دعم بيئات مؤسسية معقدة أو خدمات مدارة أو مقدمي خدمات.
- مهارات تواصل متميزة أمام العملاء وعرض وتقديم واستشارات تقنية، مع القدرة على التفاعل بفاعلية مع أصحاب المصلحة على جميع المستويات.
- قيادة تقنية مثبتة، قدرات توجيه وإرشاد، وخبرة في إدارة تسليم المشروع مع التنسيق مع عدة أصحاب مصلحة.
- فهم قوي لعمليات الأمن وعمليات الاستجابة للحوادث وخدمات الأمن المدارة، بما في ذلك التعرض لبنية Zero Trust وسحابة الأمن.
- خبرة في العمل مع منصات الإفتراضية والسحابة مثل VMware ESXi وHyper-V وAWS وMicrosoft Azure، ويفضل ضمن بيئات مؤسسية كبيرة أو متعددة المواقع.
- مهارات توثيق وتقارير وحوكمة تشغيلية قوية، مع القدرة على العمل بفاعلية في بيئات عالية الضغط والمشاركة في نشاطات الاستجابة للحوادث عند الحاجة.
- شهادات ذات صلة مثل FCP وFCSS وNSE 4/5/6/7 وCCNA وCCNP Security وFortiSASE وشهادات أمان AWS/Azure، مع الالتزام بالتعلم المستمر والتطوير المهني.
Description
The Specialist Security Engineer – Fortinet Solutions is responsible for designing, implementing, optimizing, and supporting advanced Fortinet-based cybersecurity solutions across enterprise, service provider, and data center environments. The role serves as a technical subject matter expert for Fortinet technologies, providing architecture design, deployment leadership, troubleshooting, migration support, and operational excellence across customer environments.
Working within ZainTECH’s Cybersecurity Practice, the Specialist Security Engineer will lead the delivery of secure, scalable, and resilient security solutions covering network security, SD-WAN, SASE, Zero Trust architectures, privileged access management, web application security, and security monitoring platforms. The role collaborates closely with customers, presales teams, project delivery teams, and technology partners to ensure successful implementation and ongoing optimization of Fortinet security solutions.
Responsibilities
Security architecture & solution design
- Design and implement enterprise and data center security architectures utilizing Fortinet technologies.
- Develop secure, scalable, and highly available security solutions aligned with customer business and security requirements.
- Design and architect High Availability (HA) deployments, advanced SD-WAN solutions, Secure Access Service Edge (SASE) architectures, Zero Trust Network Access (ZTNA) environments, network segmentation and micro-segmentation strategies.
- Conduct security assessments and provide recommendations aligned with cybersecurity best practices and industry standards.
- Develop High-Level Designs (HLDs), Low-Level Designs (LLDs), migration and implementation plans, technical architecture documentation.
Fortinet solution deployment & integration
- Lead the installation, configuration, migration, and optimization of Fortinet solutions including:
- FortiGate
- FortiManager
- FortiAnalyzer
- FortiSwitch
- FortiAP
- FortiWeb
- FortiADC
- FortiPAM
- FortiProxy
- FortiDLP
- FortiSIEM
- FortiSASE
- FortiAppSec
- Integrate Fortinet platforms with:
- Active Directory
- LDAP
- RADIUS
- TACACS+
- Identity Providers (IdPs)
- Multi-Factor Authentication (MFA) platforms
- SIEM and Syslog solutions
- AWS and Microsoft Azure environments
- Third-party security solutions
- Ensure successful migration and interoperability between legacy and modern security infrastructures.
Security operations & technical support
- Provide advanced L2, L3, and escalation support for enterprise customers.
- Troubleshoot complex:
- Security incidents
- Firewall issues
- Routing and connectivity problems
- VPN-related issues
- Authentication and access control challenges
- Conduct root cause analysis and provide recommendations to prevent recurrence.
- Monitor solution performance and ensure high service availability.
- Maintain configuration backups, disaster recovery plans, and operational documentation.
- Support customers during critical incidents and major service disruptions.
Network security & advanced security technologies
- Configure, manage, and optimize:
- Security policies
- Application control
- Intrusion Prevention Systems (IPS)
- Web filtering
- Anti-malware services
- Data Loss Prevention (DLP)
- Proxy services
- Privileged Access Management (PAM)
- Security event monitoring and correlation
- Deploy and support:
- Psec VPN
- SSL VPN
- Remote Internet Access (RIA)
- Direct Internet Access (DIA)
- Site-to-Site VPNs
- Hub-and-Spoke VPN architectures
- Implement Zero Trust and SASE security models to enhance customer security posture.
Project delivery & customer engagement
- Lead implementation, migration, upgrade, and optimization projects.
- Coordinate activities with customers, vendors, project managers, internal delivery teams.
- Produce technical implementation documentation, acceptance reports, as-built documentation, operational handover documentation.
- Conduct customer knowledge transfer sessions and technical workshops.
- Support presales teams during solution presentations, technical discussions, and proof-of-concept activities.
Continuous improvement & technical leadership
- Stay current with emerging cybersecurity threats, Fortinet product developments, and industry best practices.
- Participate in technical enablement and knowledge-sharing initiatives.
- Support the development of technical standards, implementation methodologies, and operational procedures.
- Contribute to service improvement initiatives across the Cybersecurity Practice.
Our culture & code of conduct
At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our Code of Conduct, which serves as a guiding framework for responsible behaviour across everything we do — from how we work with each other to how we engage with clients and partners globally.
Requirements
- Bachelor's degree in Computer Engineering, Computer Science, Information Security, Information Technology, or a related field, with a minimum of 5 years of experience in cybersecurity and network security engineering.
- Proven hands-on expertise in designing, implementing, and supporting Fortinet security solutions, including FortiGate, FortiManager, FortiAnalyzer, SD-WAN, SASE, FortiWeb, FortiADC, FortiPAM, FortiProxy, FortiDLP, and FortiSIEM.
- Strong knowledge of network security architecture and infrastructure design, with expertise in TCP/IP, Routing & Switching, BGP, OSPF, VLANs, NAT, Traffic Shaping, and Policy-Based Routing.
- Advanced troubleshooting, analytical, and problem-solving skills, with experience supporting complex enterprise, managed services, or service provider environments.
- Strong customer-facing communication, presentation, consulting, and technical advisory skills, with the ability to engage effectively with stakeholders across all levels.
- Demonstrated technical leadership, mentoring capabilities, and experience managing project delivery while coordinating with multiple stakeholders.
- Solid understanding of security operations, incident response processes, and managed security services, including exposure to Zero Trust and cloud security architectures.
- Experience working with virtualization and cloud platforms such as VMware ESXi, Hyper-V, AWS, and Microsoft Azure, preferably within large-scale enterprise or multi-site environments.
- Strong documentation, reporting, and operational governance skills, with the ability to perform effectively in high-pressure environments and participate in critical incident response activities when required.
- Relevant certifications such as FCP, FCSS, NSE 4/5/6/7, CCNA, CCNP Security, FortiSASE, and AWS/Azure Security certifications, along with a commitment to continuous learning and professional development.