مهندس أمن معلومات — بغداد
الراتب يُحدد أثناء المقابلة
بغداد
- جهة العمل
- taawon.iq
- الشروط المطلوبة
- بكالوريوس في الأمن السيبراني أو علوم الحاسوب، خبرة 3-5 سنوات، معرفة قوية بالشبكات والتطبيقات، مهارات تحليلية
Job Vacancy: Information Security Engineer Department: IT Location: Headquarters – Baghdad, Iraq Reports To: IT Manager
Job Summary:
We are looking for an experienced Information Security Engineer to join our IT Department. The successful candidate will be responsible for identifying and mitigating cybersecurity risks across our branch networks, POS systems, e-commerce platforms, web and mobile applications, APIs, and enterprise systems.
Key Responsibilities:
Conduct penetration testing and vulnerability assessments across networks, systems, POS infrastructure, websites, APIs, and mobile applications.
Identify, analyze, and document security vulnerabilities and provide practical remediation recommendations.
Perform security assessments of branch networks, firewalls, VPNs, wireless networks, Active Directory, and enterprise systems.
Conduct web and application security testing based on OWASP standards and best practices.
Assess the security of ERP integrations, APIs, databases, and backend systems.
Prepare technical security reports, risk assessments, and remediation plans.
Work with IT, network, system administration, and development teams to resolve identified vulnerabilities.
Conduct re-testing to verify that security issues have been properly remediated.
Support PCI-DSS compliance and security assessments for POS and cardholder data environments.
Monitor emerging cybersecurity threats and support the investigation and response to security incidents.
Requirements:
Bachelor’s degree in Cybersecurity, Computer Science, or a related field.
3–5 years of hands-on experience in cybersecurity, penetration testing, vulnerability assessment, or security operations.
Strong knowledge of network, application, and information security.
Practical experience with penetration testing and vulnerability assessment tools.
Good understanding of OWASP, PCI-DSS, NIST CSF, and ISO/IEC 27001.
Knowledge of FortiGate, MikroTik, VPNs, wireless networks, and Active Directory.
Programming/scripting skills in Python, Bash, or PowerShell.
Strong analytical, problem-solving, and technical reporting skills.
Experience in retail, financial services, logistics, or multi-branch environments is highly preferred.
Preferred Certifications:
OSCP – Highly Preferred GPEN / GWAPT CEH / CEH Practical eJPT
How to Apply: Interested candidates are invited to send their CV to ((البريد مخفي — اضغط لإظهاره)) and mention the job title in the email subject line.