Information Security Officer

منذ 2 أيام

Doha, Doha, قطر Qatar Stock Exchange دوام كامل ‏٢٥٠٬٠٠٠ ر.ق.‏ - ‏٤٥٠٬٠٠٠ ر.ق.‏ عقد

About Qatar Stock Exchange

Qatar Stock Exchange (QSE) is the principal securities market of the State of Qatar. QSE gives local and international investors direct access to an advanced, well-regulated capital market covering equities, ETFs, sukuk, bonds, and Treasury bills. QSE serves as an effective platform for listed companies to raise capital, broaden their investor base, and support their growth plans in line with Qatar National Vision 2030 and the Third Financial Sector Strategy.

Job Summary

The Information Security Officer is responsible for identifying and assessing information security risks and for developing the policies, procedures, and technical standards that protect QSE's information assets. Reporting to the Director of Risk Management, the role designs, plans, and implements internal controls with a particular focus on technical security and maintains a corporate-wide information security management program aligned to regulatory and industry standards.

Roles And Responsibilities

Security Strategy, Policy and Governance

  • Establish and maintain a corporate-wide information security management programme ensuring information assets are adequately protected.
  • Design, implement, and monitor a comprehensive enterprise information security strategy and IT risk management programme.
  • Develop and maintain security policies, procedures, and technical standards.
  • Drive security decisions based on government and industry regulations and risk management findings.
  • Lead auditing and compliance initiatives.

Risk Assessment and Controls

  • Identify and assess IT security risks and technical standards.
  • Carry out information security risk assessments and test data processing systems.
  • Design, plan, and implement internal controls, particularly those related to technical security.
  • Assess systems for security gaps, design effective solutions, and report to management and executive staff.
  • Regulate access to information, ensuring only authorized users can reach restricted data and systems.

Technical Security Operations

  • Design, maintain, and review IT security architecture and firewalls.
  • Plan and implement security measures across all information systems and networks.
  • Plan regular penetration tests, evaluate results, and oversee closure of identified gaps.
  • Manage and execute regular vulnerability assessments and oversee patch management systems.
  • Conduct real-time analysis of immediate threats and triage incidents as they arise.

Incident Response and Continuity

  • Investigate and report on security incidents.
  • Plan and test responses to security breaches, including tabletop exercises.
  • Support IT disaster recovery plans and strategies, addressing intrusions quickly and effectively.
  • Test backup and recovery procedures.

Awareness and Stakeholder Engagement

  • Train staff on the proper use of information systems.
  • Partner with business stakeholders across the company to raise awareness of information risk management.
  • Coordinate, supervise, manage, and train others.
  • Stay current with security legislation, regulations, alerts, and emerging threats.

Requirements

  • Bachelor's degree, preferably in Information Technology or Computer Science (CISSP or CISM certification desirable).
  • Over 5 years of relevant information security experience.
  • In-depth knowledge of information security standards including ISO 27001, ITIL, COBIT, NIA, and the National Cyber Security Framework.
  • Strong technical skills across Active Directory, proxy, antivirus, network security, encryption, vulnerability assessment and penetration testing, and web services security.
  • Strong analytical, reasoning, and reporting skills.