Information Security Engineer-مهندس أمن معلومات

Information Security Engineer

Trans-Sahara IT & Communications — Tripoli, Libya

About the role

Trans-Sahara IT & Communications is looking for an Information Security Engineer to protect our data-centre and cloud platforms and to support the security and compliance commitments we make to our clients in the banking and financial sector. This is a hands-on engineering role, not a purely advisory one: you will identify weaknesses, implement the fix, and be able to prove it was effective. You will also work directly with clients on security assessments and certification readiness.

Key responsibilities

Infrastructure security operations

  • Administer perimeter and internal firewalls: policy review, rule hygiene, signature and software currency, and high-availability configuration.
  • Harden servers, virtualization hosts, storage and network equipment against a documented baseline, and verify the result.
  • Own identity and access security: directory and single sign-on integration, multi-factor authentication, privileged account separation and access reviews.
  • Run the vulnerability management cycle — scan, prioritise, drive remediation to closure, and report on it.
  • Monitor security events through the SIEM platform, investigate alerts and lead incident response.
  • Manage certificate and credential lifecycle, including rotation and expiry monitoring.

Governance, risk and compliance

  • Maintain and operate the ISO/IEC 27001:2022 information security management system and drive it towards certification.
  • Assess and close gaps against the national NISSA information-security requirements.
  • Maintain the risk register, security policies and procedures, and the evidence required for audit.
  • Support PCI DSS scope maintenance on client environments, working within strict segmentation boundaries.
  • Complete client security questionnaires and due-diligence requests.
  • Deliver security awareness training to staff.

Client-facing security delivery

  • Perform security assessments and hardening reviews for clients, and write the reports that accompany them.
  • Support pre-sales work on security and compliance services with technical scoping and solution input.
  • Advise clients on remediation, and verify that agreed fixes have been applied.

Required qualifications and experience

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity or a related field — or equivalent proven practical experience.
  • Minimum 3 years in information security, or in a systems or network administration role with substantial security responsibility.
  • Hands-on firewall administration — Huawei USG, Fortinet, Palo Alto, Cisco or comparable — including policy design and review.
  • Practical knowledge of identity and access management: LDAP or Active Directory, RADIUS, single sign-on and multi-factor authentication.
  • Experience running vulnerability assessments and, critically, seeing remediation through to closure.
  • Working familiarity with ISO/IEC 27001 and at least one of PCI DSS, NIST or the Libyan NISSA framework.
  • Linux administration and networking knowledge strong enough to implement and verify a fix independently, not only to report a finding.
  • Clear technical writing in English — assessment reports and client documentation are produced in English. Arabic for daily work.

Desirable

  • SIEM operation: Wazuh, Splunk, IBM QRadar or equivalent.
  • Penetration testing or offensive security experience.
  • Certification: ISO 27001 Lead Implementer or Lead Auditor, CISSP, CISM, CEH, OSCP or CompTIA Security+.
  • Experience in a bank, financial institution, telecommunications operator or managed service provider.
  • Cloud platform security — OpenStack, or a major public cloud.
  • Scripting for security automation: Python, Bash or PowerShell.

Working conditions

  • On-site position based in Tripoli, working across the company head office and the Trans-Sahara Data Center.
  • Occasional travel to client sites within Libya for assessments and remediation work.
  • Availability for incident response outside normal working hours.
  • The role requires security screening and the signature of a confidentiality agreement; it carries privileged access to client environments.

How to apply

Please send your CV to recruitment@transahara.com, stating the job title.

Closing date: 31/08/2026.

مهندس أمن معلومات

عابر الصحراء لتقنية المعلومات والاتصالات — طرابلس، ليبيا

نبذة عن الوظيفة

تبحث شركة عابر الصحراء لتقنية المعلومات والاتصالات عن مهندس أمن معلومات لحماية منصاتها في مركز البيانات والحوسبة السحابية، ودعم التزامات الشركة الأمنية والامتثالية تجاه عملائها في القطاع المصرفي والمالي. هذه وظيفة هندسية تطبيقية، وليست استشارية بحتة: ستتولى تحديد نقاط الضعف، وتنفيذ الحلول، والقدرة على إثبات فعاليتها. كما ستعمل مباشرة مع العملاء في التقييمات الأمنية والاستعداد لشهادات الاعتماد.

المهام الرئيسية

عمليات أمن البنية التحتية

إدارة جدران الحماية المحيطية والداخلية: مراجعة السياسات، تنظيم القواعد، تحديث التوقيعات والبرمجيات، وإعداد التوفر العالي (HA).

تحصين الخوادم ومنصات الافتراضية والتخزين ومعدات الشبكة وفق معايير موثقة، والتحقق من فعالية ذلك.

تولي مسؤولية أمن الهوية والوصول: تكامل الدليل وتسجيل الدخول الموحد (SSO)، المصادقة متعددة العوامل، فصل الحسابات المميزة، ومراجعات الوصول.

تشغيل دورة إدارة الثغرات — الفحص، تحديد الأولويات، متابعة المعالجة حتى الإغلاق، وإعداد التقارير.

مراقبة الأحداث الأمنية عبر منصة SIEM، والتحقيق في التنبيهات وقيادة الاستجابة للحوادث.

إدارة دورة حياة الشهادات الرقمية وبيانات الاعتماد، بما يشمل التجديد ومراقبة الانتهاء.

الحوكمة والمخاطر والامتثال

صيانة وتشغيل نظام إدارة أمن المعلومات وفق معيار ISO/IEC 27001:2022، والعمل على تحقيق الاعتماد.

تقييم وسد الفجوات مقابل متطلبات أمن المعلومات الوطنية (NISSA).

صيانة سجل المخاطر والسياسات والإجراءات الأمنية، والأدلة المطلوبة للتدقيق.

دعم الحفاظ على نطاق PCI DSS في بيئات العملاء، ضمن حدود تجزئة صارمة.

استكمال استبيانات الأمان وطلبات العناية الواجبة الخاصة بالعملاء.

تقديم تدريب توعوي أمني للموظفين.

تقديم الخدمات الأمنية للعملاء

إجراء تقييمات أمنية ومراجعات تحصين للعملاء، وكتابة التقارير المرافقة لها.

دعم أعمال ما قبل البيع في خدمات الأمن والامتثال من خلال التحديد الفني ومدخلات الحلول.

تقديم المشورة للعملاء بشأن المعالجة، والتحقق من تطبيق الحلول المتفق عليها.

المؤهلات والخبرات المطلوبة

درجة البكالوريوس في علوم الحاسوب أو تقنية المعلومات أو الأمن السيبراني أو مجال ذي صلة — أو خبرة عملية مثبتة معادلة.

3 سنوات على الأقل في أمن المعلومات، أو في دور إدارة أنظمة أو شبكات يتضمن مسؤولية أمنية جوهرية.

خبرة عملية في إدارة جدران الحماية — Huawei USG، Fortinet، Palo Alto، Cisco أو ما يعادلها — بما في ذلك تصميم السياسات ومراجعتها.

معرفة عملية بإدارة الهوية والوصول: LDAP أو Active Directory، RADIUS، تسجيل الدخول الموحد والمصادقة متعددة العوامل.

خبرة في إجراء تقييمات الثغرات، والأهم من ذلك، متابعة المعالجة حتى إغلاقها فعليًا.

إلمام عملي بمعيار ISO/IEC 27001، وبواحد على الأقل من: PCI DSS، أو NIST، أو الإطار الليبي NISSA.

معرفة قوية بإدارة أنظمة لينكس والشبكات تكفي لتنفيذ الحل والتحقق منه بشكل مستقل، لا الاكتفاء بالإبلاغ عن الثغرة فقط.

كتابة فنية واضحة باللغة الإنجليزية — تُعد تقارير التقييم ووثائق العملاء باللغة الإنجليزية، مع العربية للعمل اليومي.

مؤهلات إضافية مفضّلة

تشغيل منصات SIEM: Wazuh أو Splunk أو IBM QRadar أو ما يعادلها.

خبرة في اختبار الاختراق أو الأمن الهجومي.

شهادات مهنية: ISO 27001 Lead Implementer أو Lead Auditor، أو CISSP، أو CISM، أو CEH، أو OSCP، أو CompTIA Security+.

خبرة سابقة في بنك أو مؤسسة مالية أو شركة اتصالات أو مزود خدمات مُدارة.

أمن المنصات السحابية — OpenStack أو إحدى المنصات السحابية العامة الكبرى.

برمجة نصية للأتمتة الأمنية: Python أو Bash أو PowerShell.

ظروف العمل

وظيفة حضورية في طرابلس، موزعة بين المقر الرئيسي للشركة ومركز عابر الصحراء للبيانات.

سفر عرضي إلى مواقع العملاء داخل ليبيا لأغراض التقييم والمعالجة.

التوفر للاستجابة للحوادث خارج أوقات الدوام الاعتيادية.

تتطلب الوظيفة فحصًا أمنيًا وتوقيع اتفاقية سرية، وتمنح صلاحية وصول مميزة لبيئات العملاء.

طريقة التقديم

يُرجى إرسال السيرة الذاتية إلى [recruitment@transahara.com]، مع كتابة اسم الوظيفة.

آخر موعد للتقديم: [31 / 08 / 2026].

Location: Tripoli_/_طرابلس | Type: Contract_-_عقد_عمل | Category: Information_Security-أمن_المعلومات

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *