Job description
Company Description
The Company:
Sucafina is the leading sustainable Farm to Roaster coffee company, with a family tradition in commodities that stretches back to 1905. Today, with more than 1,400 employees in 34 countries, we help stakeholders worldwide to find the perfect coffee solutions. We embed technology, innovation, and sustainability throughout the supply chain, creating shared value for all by Investing in Farmers, Caring for People, and Protecting Our Planet. For more information, visit www.sucafina.com.
What are we looking for:
We are looking for entrepreneurs, techies, passionate, eager to learn, humble, with a positive attitude and a high level of integrity People. Flexible and willing to take challenges, work and live in coffee-producing countries, People who want to build expertise and a career in the coffee business and are ready to go the extra mile.
What we offer:
We offer within our pleasant family environment, great opportunities to learn and grow, we offer challenges and exposure to multicultural environments, on-merit base compensation, and free coffee around the clock!
Job Description
Role Overview:
Senior technical owner of the company’s cybersecurity controls, with particular responsibility for application security and for security audit and compliance.
Key Responsibilities:
- Application security: embed security into the SDLC, threat modelling, secure code review and remediation follow-up.
- Penetration testing: scope and manage internal and third-party application and infrastructure tests, and drive findings to closure.
- Security audit: lead internal and external audits, customer assessments and certification cycles; prepare evidence and close findings.
- Compliance and frameworks: maintain controls, policies and standards against ISO 27001, NIST CSF / CIS Controls and applicable regulation.
- Risk management: identify, assess and report information security risks and track treatment plans.
- Vulnerability management: run the scanning and patching cycle with risk-based prioritization and SLAs.
- SIEM and monitoring: maintain log coverage, correlation rules and alert tuning; ensure critical systems are monitored.
- EDR / endpoint security: administer and tune the EDR/XDR platform, maintain coverage and perform threat hunting.
- Network and perimeter security: manage Fortinet FortiGate firewall policies, IPS and web filtering, SSL inspection, VPN and rule recertification.
- Identity and access management: govern authentication, MFA, SSO, privileged access and periodic access reviews.
- Cloud security: define and verify hardening baselines and configuration for Azure.
- Data protection: set standards for encryption, key management, data classification and DLP.
- Incident response: act as senior responder; maintain and exercise playbooks and lead post-incident reviews.
- Third-party security: assess vendors and SaaS providers and set contractual security requirements.
- Awareness and reporting: deliver security training and phishing simulations; report metrics to management.
Qualifications
Qualifications and Experience:
- Degree in Computer Science, Information Security or Engineering, or equivalent experience.
- 6–8+ years in cybersecurity, including a senior or lead role.
- Hands-on application security experience: secure SDLC, threat modelling, SAST/DAST/SCA, secure code review, OWASP Top 10 / ASVS.
- Proven experience leading security audits and compliance work (ISO 27001, NIST CSF, CIS or SOC 2).
- Solid command of cybersecurity essentials: risk, IAM, network, cloud, endpoint, cryptography, vulnerability management and incident response.
- Hands-on SIEM experience (e.g. Forti SIEM) log onboarding, use cases, alert tuning.
- Hands-on EDR/XDR experience (e.g. Defender for Endpoint, CrowdStrike).
- Hands-on Fortinet FortiGate firewall administration (policies, IPS, VPN, FortiManager / FortiAnalyzer).
- Experience with at least one major cloud platform and modern CI/CD toolchains.
- Ability to read code in at least one mainstream language and engage credibly with developers.
- Preferred certifications: CISSP, CISM, CISA, CSSLP, ISO 27001 Lead Auditor, Fortinet NSE 4+, OSCP or SC-200.
Additional Information
Soft skills:
- Excellent organizational skills (ability to prioritize, plan tasks, and respect deadlines).
- Good interpersonal skills.
- Teamwork skills/team spirit.
- Ability to work under stress and respond to tight deadlines.
- High level of autonomy/self-discipline.
- Proactiveness.
- Curious keen to learn and ready for new challenges.
- Ability to work independently.
Languages:
- Excellent verbal and written communication skills in English
- Knowledge of any other language is a plus (French)
الوصف الوظيفي
وصف الشركة
الشركة:
سوكافينا هي الشركة الرائدة في مجال القهوة المستدامة من المزرعة إلى المحمصة، مع تقاليد عائلية في السلع الأساسية تمتد إلى عام 1905. اليوم، مع أكثر من 1400 موظف في 34 دولة، نساعد أصحاب المصلحة في جميع أنحاء العالم في العثور على حلول القهوة المثالية. نحن ندمج التكنولوجيا والابتكار والاستدامة في جميع أنحاء سلسلة التوريد، مما يخلق قيمة مشتركة للجميع من خلال الاستثمار في المزارعين، والرعاية بالبشر، وحماية كوكبنا. لمزيد من المعلومات، يرجى زيارة www.sucafina.com.
عما نبحث:
نحن نبحث عن أشخاص رواد أعمال، محبين للتكنولوجيا، شغوفين، حريصين على التعلم، متواضعين، يتمتعون بسلوك إيجابي ومستوى عالٍ من النزاهة. أشخاص مرنين ولديهم الاستعداد لمواجهة التحديات، والعمل والعيش في الدول المنتجة للقهوة، وأشخاص يرغبون في بناء خبراتهم ومسيرتهم المهنية في مجال القهوة ومستعدون لبذل أقصى جهد.
ما نقدمه:
نقدم في بيئتنا العائلية اللطيفة فرصاً رائعة للتعلم والنمو، ونوفر التحديات والتعرض لبيئات متعددة الثقافات، ومكافآت قائمة على الاستحقاق، وقهوة مجانية على مدار الساعة!
الوصف الوظيفي
نظرة عامة على الدور:
المسؤول الفني الأول عن عناصر التحكم في الأمن السيبراني للشركة، مع مسؤولية خاصة عن أمن التطبيقات والتدقيق الأمني والامتثال.
المسؤوليات الرئيسية:
- أمن التطبيقات: دمج الأمن في دورة حياة تطوير البرمجيات (SDLC)، ونمذجة التهديدات، ومراجعة الكود الآمن ومتابعة المعالجة.
- اختبار الاختراق: تحديد نطاق وإدارة اختبارات التطبيقات والبنية التحتية الداخلية والتابعة لأطراف خارجية، ومعالجة النتائج حتى إغلاقها.
- التدقيق الأمني: قيادة عمليات التدقيق الداخلي والخارجي، وتقييمات العملاء ودورات الحصول على الشهادات؛ وإعداد الأدلة وإغلاق الملاحظات.
- الامتثال والأطر: الحفاظ على الضوابط والسياسات والمعايير وفقاً لمعايير ISO 27001، وNIST CSF / ضوابط CIS واللوائح المعمول بها.
- إدارة المخاطر: تحديد وتقييم والإبلاغ عن مخاطر أمن المعلومات ومتابعة خطط المعالجة.
- إدارة الثغرات الأمنية: تشغيل دورة الفحص والتصحيح مع ترتيب الأولويات بناءً على المخاطر واتفاقيات مستوى الخدمة (SLAs).
- نظام SIEM والمراقبة: الحفاظ على تغطية السجلات، وقواعد الربط وضبط التنبيهات؛ وضمان مراقبة الأنظمة الحساسة.
- أمن الأجهزة الطرفية / EDR: إدارة وضبط منصة EDR/XDR، والحفاظ على التغطية وإجراء البحث عن التهديدات.
- أمن الشبكات والحيط الأمني: إدارة سياسات جدار الحماية Fortinet FortiGate، ونظام منع الاختراق (IPS)، وتصفية الويب، وفحص SSL، والشبكة الافتراضية الخاصة (VPN)، وإعادة اعتماد القواعد.
- إدارة الهوية والوصول: حوكمة المصادقة، والمصادقة متعددة العوامل (MFA)، وتسجيل الدخول الموحد (SSO)، والوصول المتميز، والمراجعات الدورية للوصول.
- أمن السحابة: تحديد والتحقق من خطوط الأساس للتحصين والتكوين لبيئة Azure.
- حماية البيانات: وضع معايير التشفير وإدارة المفاتيح وتصنيف البيانات ومنع تسرب البيانات (DLP).
- الاستجابة للحوادث: العمل كمنسق استجابة أول؛ والحفاظ على أدلة الإجراءات وتدريبها وقيادة مراجعات ما بعد الحوادث.
- أمن الأطراف الخارجية: تقييم الموردين ومزودي خدمات SaaS وضع متطلبات الأمن التعاقدية.
- التوعية وإعداد التقارير: تقديم التدريب الأمني ومحاكاة التصيد الاحتيالي؛ تقديم المقاييس إلى الإدارة.
المؤهلات
المؤهلات والخبرة:
- درجة بكالوريوس في علوم الحاسوب، أو أمن المعلومات، أو الهندسة، أو خبرة معادلة.
- خبرة من 6 إلى 8+ سنوات في مجال الأمن السيبراني، بما في ذلك دور قيادي أو متقدم.
- خبرة عملية في أمن التطبيقات: دورة حياة تطوير البرمجيات الآمنة (SDLC)، ونمذجة التهديدات، وSAST/DAST/SCA، ومراجعة الكود الآمن، وOWASP Top 10 / ASVS.
- خبرة مثبتة في قيادة أعمال التدقيق الأمني والامتثال (ISO 27001، أو NIST CSF، أو CIS، أو SOC 2).
- إتقان تام لأساسيات الأمن السيبراني: المخاطر، وإدارة الهوية والوصول (IAM)، والشبكات، والسحابة، والأجهزة الطرفية، والتشفير، وإدارة الثغرات الأمنية، والاستجابة للحوادث.
- خبرة عملية في أنظمة SIEM (مثل Forti SIEM) ودمج السجلات، وحالات الاستخدام، وضبط التنبيهات.
- خبرة عملية في أنظمة EDR/XDR (مثل Defender for Endpoint، وCrowdStrike).
- خبرة عملية في إدارة جدران حماية Fortinet FortiGate (السياسات، وIPS، وVPN، وFortiManager / FortiAnalyzer).
- خبرة في منصة سحابية رئيسية واحدة على الأقل وسلاسل أدوات CI/CD الحديثة.
- القدرة على قراءة الكود في لغة برمجية رئيسية واحدة على الأقل والتواصل بشكل موثوق مع المطورين.
- الشهادات المفضل الحصول عليها: CISSP، أو CISM، أو CISA، أو CSSLP، أو ISO 27001 Lead Auditor، أو Fortinet NSE 4+، أو OSCP، أو SC-200.
معلومات إضافية
المهارات الشخصية:
- مهارات تنظيمية ممتازة (القدرة على تحديد الأولويات، وتخطيط المهام، والالتزام بالمواعيد النهائية).
- مهارات ممتازة في التعامل مع الآخرين.
- مهارات العمل الجماعي / روح الفريق.
- القدرة على العمل تحت الضغط والاستجابة للمواعيد النهائية الضيقة.
- مستوى عالٍ من الاستقلالية / الانضباط الذاتي.
- المبادرة والنهج الاستباقي.
- الفضول والرغبة الشديدة في التعلم والاستعداد للتحديات الجديدة.
- القدرة على العمل بشكل مستقل.
اللغات:
- مهارات تواصل شفهية وكتابية ممتازة باللغة الإنجليزية
- معرفة أي لغة أخرى تعد ميزة إضافية (الفرنسية)