Responsibilities
Develop, implement, and maintain the organization’s Information Security strategy, policies, procedures, and controls.
Establish and continuously improve the Information Security Management System (ISMS) in accordance with ISO/IEC 27001.
Ensure compliance with QCB regulations, NCSA requirements, NIST Cybersecurity Framework, PCI DSS, and other applicable regulatory standards.
Identify, assess, and manage information security and cybersecurity risks and maintain the Information Security Risk Register.
Conduct and oversee security risk assessments, vulnerability assessments, penetration testing, and control reviews.
Lead and manage information security incidents, including investigation, response, reporting, and post-incident corrective actions.
Oversee security monitoring, logging, and cybersecurity controls, including SIEM, EDR/XDR, IAM/PAM, DLP, firewalls, IDS/IPS, and WAF.
Develop and maintain information security policies, standards, procedures, and security KPIs.
Manage third-party and vendor security risks, including security assessments and compliance reviews.
Coordinate internal and external security audits and regulatory examinations.
Provide regular information security reports, risk updates, KPIs, and recommendations to senior management and the Board.
Develop and deliver information security awareness and training programs across the organization.
Ensure information security requirements are incorporated into Business Continuity and Disaster Recovery plans.
Stay updated on emerging cybersecurity threats, regulatory requirements, and industry best practices.
Qualifications
Bachelor’s degree in information security, Cybersecurity, Computer Science, Information Technology, or a related field, master’s degree is preferred.
10–15 years of experience in IT and Information Security, with 5–7 years in a senior or leadership security role.
Experience working within financial institutions, banking, or other highly regulated environments.
Strong knowledge and practical experience with QCB regulations, NCSA requirements, ISO/IEC 27001, PCI DSS, and NIST.
CISSP certification is mandatory or strongly preferred.
Additional certifications such as CISM, CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor, or PCI DSS certifications are an advantage.
Strong understanding of cybersecurity governance, risk management, compliance, and security controls.
Hands-on knowledge of enterprise security technologies, including SIEM, EDR/XDR, IAM/PAM, DLP, firewalls, IDS/IPS, and WAF.
Experience managing security incidents, audits, penetration testing, vulnerability assessments, and third-party security risks.
Strong leadership, communication, stakeholder management, and presentation skills.
Ability to communicate effectively with senior management and Board-level stakeholders.
High level of integrity, independence, analytical thinking, and professional judgment.
تفاصيل الوظيفة
الموقع الدوحة - قطر
القطاع
تكنولوجيا المعلومات والاتصالات
نوع الوظيفة دوام كامل
الدرجة العلمية بكالوريوس
الخبرات 10-15
الجنسية
غير محدد
سجلي الدخول للتقدم