Senior Information Security Officer

4 weeks ago


Doha, Qatar Talent Pal Full time

Job Summary and Purpose


Drive a strong and robust Information Security Management System (ISMS) in the organization through threat/vulnerability detection security scanning penetration testing security monitoring vulnerability mitigations threat mitigations identifying IT/OT security risks and other related information security activities.



Ensure adherence to the various information security standards and standards and provide technical consultation on Information Security issues.

Accountabilities

Key Accountabilities:

Information Security Management:

1. Identify information security vulnerabilities and threats in the company IT/OT technology network and infrastructure using various techniques e.g. penetration testing and vulnerability assessment.
2. Collate information from the conducted assessments and recommend appropriate remedial steps.
3. Develop review improve and update information security policies procedures guidelines and other related documents.
4. Provide support to build the organization wide information security awareness and training programs. Contribute and provide content for awareness activities.
5. Monitor evaluate and ensure the segregation of duties on all systems to mitigate the risk of unintentional and/or deliberate system misuse.
6. Ensure compliance with the applicable internal and international information security standards (e.g. NIA ISO27001).
7. Monitor changes or updates in any applicable law regulation or accreditation standards pertaining to Information Security and ensure compliance as required.
8. Ensure appropriate administrative and technical safeguards are in place to protect information assets from internal and external threats. Coordinate physical safeguards for those assets in coordination with the General Services department.
9. Liaise and maintain contact with governmental authorities regulatory bodies security groups and industry forums in the field of Information Security.
10. Prepare security baselines and safeguard applications operating systems and infrastructure devices by adopting the latest standards.
11. Resolve information security issues and improve the Information Security performance by providing technical consultation in system development acquisition procurement implementation change management operation/support and architectural and other adhoc projects.
12. Assist all organizational units in areas related to Information Security and follow the related processes to provide support.

Accountabilities 2

13. Work with the concerned parties on the Information Security incidents and vulnerability management processes from design to implementation and beyond.
14. Review technical information in the requirements statements feasibility analysis operating procedure manuals and other documents produced in the process of system development.
15. Monitor and assess IT systems security system audit trails/logs and the validity of system configurations whenever required.
16. Assist in vulnerability mitigation e.g. through software/system patching through the IT department.
17. Assist in performing ongoing security monitoring of information systems including assessing information security risk conducting functional and gap analyses to determine the extent to which key business areas and infrastructure comply with statutory and regulatory requirements.
18. Evaluate and recommend new information security technologies and countermeasures against threats to information or privacy and develop security reports and dashboards.
19. Ensure identification recording reporting and resolving any Information Security violations.
20. Support and assist the other activities linked with Enterprise Risk and Business Continuity Management such as Risk Assessments and Business Impact Analysis.
21. Support the development of the organizations disaster recovery and business continuity plans for information security and tests readiness.

Generic Accountabilities:

Quality Health Safety & Environment (QHSE):
22. Adhere to all relevant QHSE policies procedures instructions and controls so that NAKILAT provides a safe world class secure and environmentally responsible service to customers the public and its own people.

Policies Systems Processes & Procedures:
23. Implement approved policies processes and procedures and provide instructions to subordinates to ensure their proper implementation.

Others:
24. Carry out any other duties as directed by the immediate supervisor.

Accountabilities 3Accountabilities 4Competencies Interactive Communication Collaboration & Teamwork Drive Vision Solution Oriented Customer Centricity Achievement Oriented Empower & Nurture Talent Key Result Areas
  • Contribute to the development and management of policies and procedures for the Information Security Management System.
  • Develop coordinate and conduct organization wide information security awareness programs and trainings.
  • Prepare Information Security related risk assessments reports and other relevant documentation.
  • Conduct the required activities to identify threats and vulnerabilities for IT and OT infrastructure.
  • Monitor various Information Security systems.
  • Drive the vulnerability patching.
Interactions and Working Relations


Internal: Interaction with all staff on information security activities such as data classification access review threats/vulnerabilities identification and mitigation support and contribution to information security initiatives and projects.
External: Interface with vendors and external auditors and organizations for information security related matters

Financial Authorities

As per TOFA.

Qualifications Experience and Job Skills

Qualifications:

  • Bachelors Degree in Computer Science or any other equivalent field.
  • Certified Information Systems Security Professional (CISSP) Certified Ethical Hacker (CEH) and Certified ISO27001 Lead implementer are preferred.
  • Globally recognized credential certification is preferred in Information Security domain for example CISM ISO27001LA.


Experience:
  • Minimum of 4 years of Information Security experience.
  • IT background is preferred.


Job Specific Skills:
  • Ability to manage pressure prioritize needs requirements and positively interact with the company users and external parties.
  • Ability to trouble shoot and investigate information security incidents.
  • Knowledge of Information Security Management System (ISO 27001) and other Information Security framework (NIST).
  • Security related qualifications (e.g. CISSP CISM CEH ISO 27001 LI/LA).

Job Specific Competencies:
ii. Technical

8) Business /Industry Knowledge
9) Enterprise Risk Management
10) Business Risk
11) Risk Project Management
12) Business Continuity Management
13) Governance
14) Risk Management Methodology/Process
15) Risk Identification and Assessment
16) Business Impact Analysis
17) Risk Response & Reporting
18) Risk Mitigation & Control
19) Information Security Management

Senior Information Security Officer Department: Business Support Services City: Ras Laffan


Job Segment: Information Security Information Systems Testing Change Management Computer Science Technology Management

This job has been sourced from an external job board.
More jobs on

  • Doha, Qatar Talent Pal Full time

    JobSummary andPurposeDrivea strong and robust Information Security Management System (ISMS)in the organization through threat/vulnerability detection securityscanning penetration testing security monitoring vulnerabilitymitigations threat mitigations identifying IT/OT security risks andother related information securityactivities. Ensure adherenceto the...


  • Doha, Qatar Talent Pal Full time

    **Job Summary and Purpose**: Drive a strong and robust Information Security Management System (ISMS) in the organization through threat/vulnerability detection, security scanning, penetration testing, security monitoring, vulnerability mitigations, threat mitigations, identifying IT/OT security risks and other related information security activities. Ensure...


  • Doha, Qatar Carnegie Mellon University Full time

    The Senior Information Security Engineer (SISE) is responsible security tool implementation and administration and for monitoring, investigation, response and support tasks related to the operation of the University's information security program with a primary focus on compliance areas by: - Monitoring and responding to network intrusion, system log, and...


  • Doha, Qatar Injazat Information Technology Full time

    Responsibilities: Collaboratingwith department managers to determine securityneeds. Planning and implementing comprehensivesecurity strategies. Controlling the securityoperations budget, monitoring expenses, and documentingprocesses. Supervising, recruiting, andtraining security personnel. Gathering securityintelligence and implementing preventativemeasures....


  • Doha, Baladīyat ad Dawḩah, Qatar Qatar Petroleum Full time

    Job SummaryLead Information Security projects and report regularly on their progress. Coordinate and provide expert technical support by integrating Cyber & Information Security requirements into ICT projects, OT and Infrastructure projects, and review and validate the effective implementation of Cyber & Information Securityrequirements into project...


  • Doha, Qatar Qatar Petroleum Full time

    Job SummaryLead Information Security projects and report regularly on their progress. Coordinate and provide expert technical support by integrating Cyber & Information Security requirements into ICT projects, OT and Infrastructure projects, and review and validate the effective implementation of Cyber & Information Securityrequirements into project...


  • Doha, Qatar qatar petroleum doha Full time

    Responsiblity:Monitor computer networks for security issues.Investigate security breaches and other cybersecurity incidents.Install security measures and operate software to protect systems and information infrastructure, including firewalls and data encryption programs.Document security breaches and assess the damage they cause.Work with the security team...


  • Doha, Qatar Robert Walters Full time

    Requirements For The Role✔ 7+ years of experience in Information Security✔ Develop and monitor a strategic, comprehensive enterprise information /cyber security risk management program to ensure protection of digital anddata assets✔ Implement and lead the strategy for managing and reporting securityincidents and oversee investigations of reported...


  • Doha, Qatar Injazat Information Technology Full time

    Responsibilities: Collaboratingwithdepartment managers to determine securityneeds. Planning andimplementing comprehensivesecurity strategies. Controlling thesecurityoperations budget, monitoring expenses, anddocumentingprocesses. Supervising, recruiting, andtraining securitypersonnel. Gathering securityintelligence and implementingpreventativemeasures....


  • Doha, Qatar Robert Walters Full time

    Requirements For TheRole✔ 7+ years of experiencein Information Security✔ Develop and monitora strategic, comprehensive enterprise information/cyber security risk management program toensure protection of digital anddataassets✔ Implement and lead the strategy formanaging and reporting securityincidents andoversee investigations of reported...


  • Doha, Qatar qatar petroleum doha Full time

    Responsiblity:Monitorcomputer networks for securityissues.Investigate security breaches and othercybersecurity incidents.Install securitymeasures and operate software to protect systems and informationinfrastructure, including firewalls and data encryptionprograms.Document security breaches and assessthe damage they cause.Work with the securityteam to...


  • Doha, Qatar Robert Walters Full time

    Information Security Architect– Duties AndExperienceDomainArchitect Responsible forcurrent and target security architecture forgroupWork with group stakeholders, technicalteams, external vendors and partnersDevSecOpsWork with technical teams to embedDevSecOps cultureWork across group technologyand data functionsMentorLeading team members or...


  • Doha, Qatar Robert Walters Full time

    Information Security Architect – Duties And ExperienceDomain Architect Responsible for current and target security architecture for groupWork with group stakeholders, technical teams, external vendors and partners DevSecOps Work with technical teams to embed DevSecOps cultureWork across group technology and data functions Mentor Leading team members or...


  • Doha, Baladīyat ad Dawḩah, Qatar Qatar Petroleum Full time

    Job SummaryInformation Security Monitoring Analyst is an alert management analyst, responsible for monitoring, analysing and responding to information and operational security alerts triggered by Security Information and Event Management (SIEM) and Threat intelligence feeds. Primary responsibilities detect anomaly and potential security threats, filtering...


  • Doha, Qatar Raytheon Full time

    Qualifications We Value: Experience working in DoD classified operating and/or laboratory environmentsExperience with various information system security tools that address vulnerability analysis and mitigation. These may include Splunk, Forcepoint, Ivanti, Tenable, ACAS, HBSS, etc.Familiarity with implementation of Government directives and policies derived...


  • Doha, Qatar Al Nasr star security services Full time

    Job Title: Security Supervisor Location: Doha, Qatar (Local Hiring) **Position Overview**: **Qualifications**: Minimum of 5-7 years of experience in security management, with at least 3 years in a supervisory role. Age between 30 to 40 years. Proven experience in security management. High school diploma or equivalent; additional certifications in...


  • Doha, Baladīyat ad Dawḩah, Qatar Bay Avenue Tours Full time

    Job SummaryIn this role you will provide security operational support, coordination and management across the Passenger Terminal Complex and associated landside and airside facilities reporting into The Airport Security Operations Center Duty Manager.You will need to liase and direct effectively with all other airport stakeholders to ensure passenger, staff...


  • Doha, Qatar Bay Avenue Tours Full time

    Job SummaryIn this role you will provide security operational support, coordination and management across the Passenger Terminal Complex and associated landside and airside facilities reporting into The Airport Security Operations Center Duty Manager.You will need to liase and direct effectively with all other airport stakeholders to ensure passenger, staff...


  • Doha, Qatar Hamad International Airport Full time

    Job SummaryIn this role, you need to have a bachelor degree or equivalent with essential of qualified security area. Minimum of 4 years operation experience in Aviation Security Supervision with knowledge of emergency plans and AVSEC security principles. You must have good knowledge of computer literacy of MS Office applications and great command of English...


  • Doha, Baladīyat ad Dawḩah, Qatar Hamad International Airport Full time

    Job SummaryIn this role, you need to have a bachelor degree or equivalent with essential of qualified security area. Minimum of 4 years operation experience in Aviation Security Supervision with knowledge of emergency plans and AVSEC security principles. You must have good knowledge of computer literacy of MS Office applications and great command of English...