81 Head Of Information Security Governance jobs in Qatar

Senior Information Security Engineer

Doha, Doha PPL Dynamics

Posted 6 days ago

Job Viewed

Tap Again To Close

Job Description

Key Responsibilities:

  • Perform web application, API, and mobile application penetration testing using industry-leading methodologies (OWASP, PTES, etc.).


  • Conduct network penetration testing and infrastructure security assessments.


  • Execute Vulnerability Assessment and Penetration Testing (VAPT) engagements, document findings, and recommend remediations.


  • Integrate security into the Software Development Lifecycle (SDLC) and advise development teams on secure coding practices.


  • Develop, enhance, and maintain security testing frameworks and tools .


  • Review and validate security patches, mitigations, and fixes.


  • Stay updated on the latest attack techniques, exploits, and threat landscapes to enhance testing methodologies.


  • Collaborate with cross-functional teams to support security awareness and risk reduction efforts.



Required Skills & Qualifications:

  • 46 years of experience in Information Security, with a focus on application and network penetration testing .


  • Hands-on experience with tools like Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, and other manual testing tools .


  • Deep understanding of OWASP Top 10 , SANS Top 25 , and common exploitation techniques.


  • Experience in secure SDLC practices and working with development teams to resolve findings.


  • Strong knowledge of mobile application security (iOS and Android) and API testing methodologies .


  • Excellent report writing and communication skills for both technical and non-technical stakeholders.



Preferred Certifications (1 or more):

  • OSCP (Offensive Security Certified Professional)


  • OSWE (Offensive Security Web Expert)


  • eWPT / eWPTX (eLearnSecurity Web Application Penetration Tester)


  • PNPT (Practical Network Penetration Tester)


  • HTB CPTS (Certified Penetration Testing Specialist)


#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information Security Officer (ISO)

Doha, Doha Lesha Bank

Posted 12 days ago

Job Viewed

Tap Again To Close

Job Description

Role Purpose

The Information Security Officer (ISO) will be responsible for developing, implementing, and overseeing the bank’s information security strategy, policies, and controls. The role ensures that the bank’s data, systems, applications, and infrastructure are safeguarded against internal and external threats while meeting local regulatory requirements (QCB, QFCRA, NCSA-Q) and international standards (ISO 27001, NIST, GDPR, PCI-DSS as relevant).

Key Responsibilities

Governance & Compliance

  • Establish, maintain, and enforce the bank’s information security framework, aligned with QCB, QFCRA, and local cybersecurity regulations.
  • Ensure compliance with international standards (ISO 27001, NIST CSF, COBIT, PCI-DSS) and conduct regular gap analyses.
  • Prepare and present security risk assessments and reports to senior management, regulators, and the Board Risk Committee.
  • Design, implement, and enforce security policies and procedures to safeguard the bank’s infrastructure and data.

Security Operations

  • Oversee Security Operations Center (SOC) activities, incident response, and threat intelligence monitoring.
  • Develop and maintain business continuity, disaster recovery, and incident response plans.
  • Implement and monitor Data Loss Prevention (DLP), intrusion detection/prevention (IDS/IPS), endpoint protection, and other security tools.
  • Lead investigations of security breaches, develop strategies for handling incidents, and ensure lessons learned are integrated into policies and processes.
  • Stay current with the latest security systems, standards, and products to ensure optimal protection.
  • Regularly evaluate the effectiveness of security measures and update them against emerging threats and industry best practices.
  • Conduct regular staff training on security awareness, best practices, and incident procedures.
  • Collaborate with IT and business management to continuously improve security controls and culture.

Risk Management

  • Conduct enterprise-wide risk assessments on systems, applications, vendors, and third-party service providers.
  • Identify vulnerabilities and ensure timely remediation through patch management and secure configurations.
  • Work with IT and business units to integrate security into new product initiatives.

Vendor & Technology Oversight

  • Evaluate and approve technology vendors, outsourcing partners, and cloud solutions for compliance with security standards.
  • Manage penetration tests, vulnerability assessments, and external audits.

Requirements

  • Bachelor’s degree in information security, Computer Science, or related field. Master’s degree preferred.
  • Professional certifications: CISSP or CISM required; CISA and ISO 27001 Lead Implementer preferred.
  • Cloud security certifications (e.g., CCSP, AWS Security) are a plus.
  • 8–12 years in information security, with at least 5 years in the financial-services sector.
  • Strong background in banking systems, digital channels, payment systems, and regulatory environments.
  • Proven experience engaging with regulators (QCB, QFCRA, CMA, or equivalent).
  • Proven experience in implementing SEIM Solutions, managing SOC Team.
  • Expertise in cybersecurity frameworks, network security, cryptography, and identity & access management.
  • Strong risk management and analytical skills.
  • Excellent communication and stakeholder-management skills, capable of engaging effectively with regulators, auditors, and the Board.
  • Ability to influence across departments, build a culture of security, and lead change initiatives without direct authority

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Senior Information Security Manager

QAR90000 - QAR120000 Y VAM SYSTEMS

Posted today

Job Viewed

Tap Again To Close

Job Description

Company Description Job Description

We are currently looking Senior Information Security Manager for our Qatar operations with the following terms & conditions.

Education & Experience Requirements:

  • Bachelor's degree preferably in computer science, computer engineering or related subjects. Master's degree
  • preferred.
  • At least 8 years of relevant experience, preferably within a highly rated international bank or large corporate in an
  • information security engineering capacity.
  • Professional certification such as CISSP, CISM, CISA is mandatory
  • Security engineering certifications and qualifications in Microsoft operating systems (such as Azure, MCSA,
  • MCSE, et al) or Linux (such as RHCP, et al) are mandatory.

Required Special Skills:

  • Excellent understanding of Information security technologies including firewalls, proxies, web application firewalls,
  • IDS/IPS, ATP and sandbox solutions, EDR, vulnerability scanners, DLP, data classification tools, PAM, IAM,

Joining time frame: 2 weeks (maximum 1 month)

Additional Information

Terms and conditions:

Joining time frame: maximum 4 weeks

This advertiser has chosen not to accept applicants from your region.

Senior Manager Information Security

QAR90000 - QAR120000 Y Nair Systems LLC

Posted today

Job Viewed

Tap Again To Close

Job Description

Nair Systems
is currently looking
Senior Manager, Security Technology Engineering
for our
Qatar
operations with the following terms & conditions.

Education & Experience Requirements:

·   Bachelor's degree preferably in computer science, computer engineering or related subjects. Master's degree

·   preferred.

·   At least 8 years of relevant experience, preferably within a highly rated international bank or large corporate in an

·   information security engineering capacity.

·   Professional certification such as CISSP, CISM, CISA is mandatory

·   Security engineering certifications and qualifications in Microsoft operating systems (such as Azure, MCSA, MCSE, et al) or Linux (such as RHCP, et al) are mandatory.

Required Special Skills:

·   Excellent understanding of Information security technologies including firewalls, proxies, web application firewalls,

·   IDS/IPS, ATP and sandbox solutions, EDR, vulnerability scanners, DLP, data classification tools, PAM, IAM,

·   DDOS mitigation systems and more

·   Good understanding of infrastructure and application security controls.

·   Ability to communicate information security-related concepts to a broad spectrum of technical and non-technical staff.

·   Risk Management skills (risk identification, risk assessment, risk mitigation)

·   Maintain an understanding of all pertinent regulations as well as best practices pertaining to information security.

·   Self-motivated, eye for detail.

·   Ability to persuade others.

·   Flexible team player and able to work and deliver under pressure.

·   Ability to inspire and motivate others to gain commitment.

Should you be interested in this opportunity, please send your latest resume in MS Word format at the earliest

This advertiser has chosen not to accept applicants from your region.

Information Security Manager - Banking

QAR104000 - QAR130878 Y VAM SYSTEMS

Posted today

Job Viewed

Tap Again To Close

Job Description

Job Description

We are currently looking Information Security Manager for our Qatar operations with the following terms & conditions.

Education & Experience Requirements:

  • Bachelor's degree preferably in computer science, computer engineering or related subjects. Master's degree
  • preferred.
  • At least 8 years of relevant experience, preferably within a highly rated international bank or large corporate in an
  • information security engineering capacity.
  • Professional certification such as CISSP, CISM, CISA is mandatory
  • Security engineering certifications and qualifications in Microsoft operating systems (such as Azure, MCSA,
  • MCSE, et al) or Linux (such as RHCP, et al) are mandatory.

Required Special Skills:

  • Excellent understanding of Information security technologies including firewalls, proxies, web application firewalls,
  • IDS/IPS, ATP and sandbox solutions, EDR, vulnerability scanners, DLP, data classification tools, PAM, IAM,
  • DDOS mitigation systems and more
  • Good understanding of infrastructure and application security controls.
  • Ability to communicate information security-related concepts to a broad spectrum of technical and non-technical staff.
  • Risk Management skills (risk identification, risk assessment, risk mitigation)
  • Maintain an understanding of all pertinent regulations as well as best practices pertaining to information security.
  • Self-motivated, eye for detail.
  • Ability to persuade others.
  • Flexible team player and able to work and deliver under pressure.
  • Ability to inspire and motivate others to gain commitment.

Joining time frame: 2 weeks (maximum 1 month)

This advertiser has chosen not to accept applicants from your region.

Information Security (ISMS) Consultants

Doha, Doha Premium Solutions Consultancy

Posted 4 days ago

Job Viewed

Tap Again To Close

Job Description

Urgent Requirement A well-known IT Consultancy in Qatar is looking for suitable candidates to furnish the below position local with NOC, JOB Title :

Information Security (ISMS) Consultants Nationality :

Indian / Pakistan / Filipino Notice Period :

Immediately Job Location :

Qatar Job Description Own and successfully drive projects for ISO 27001, ISO 22301 Successfully handle GRC (Governance, Risk and Compliance) assignments totally independently. Establish risk management framework for the client to address the client specific requirements. Conducting risk based IS Audits Review and enhance project level ISMS documentation and get the client sign-off. Support and guide ISMS consultants Interaction with certification auditors and non-conformities closure within the stipulated time. Data privacy engagements Effective interaction with key stakeholders in relation to ongoing security improvements Keep up to date with the latest news and threats in the security industry. Requirements Required Qualification, Skills & Experience : Intensive understanding of security methodologies and industry standards (e.g. ISO 27001,, Business Continuity Standards, IT Governance) Excellent Communication and Presentation Skills Experience : 3 to 5 years preferably with Consultancy Background in ISMS. Bachelor’s degree in science / computer applications. Relevant Certification from authorized training body (CISA / CISM / CISSP) is essential. ISO 27001 : 2013 Lead Auditor / Lead Implementer ISO 22301 : 2013 Lead Implementer Benefits Gross Salary :

10K – 15K (QAR)

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Senior Information Security Engineer

Doha, Doha PPL Dynamics

Posted 6 days ago

Job Viewed

Tap Again To Close

Job Description

Key Responsibilities:

Perform

web application, API, and mobile application penetration testing

using industry-leading methodologies (OWASP, PTES, etc.).

Conduct

network penetration testing

and infrastructure security assessments.

Execute

Vulnerability Assessment and Penetration Testing (VAPT)

engagements, document findings, and recommend remediations.

Integrate security into the

Software Development Lifecycle (SDLC)

and advise development teams on secure coding practices.

Develop, enhance, and maintain

security testing frameworks and tools .

Review and validate security patches, mitigations, and fixes.

Stay updated on the latest

attack techniques, exploits, and threat landscapes

to enhance testing methodologies.

Collaborate with cross-functional teams to support security awareness and risk reduction efforts.

Required Skills & Qualifications:

46 years of experience

in Information Security, with a focus on

application and network penetration testing .

Hands-on experience with tools like

Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, and other manual testing tools .

Deep understanding of

OWASP Top 10 ,

SANS Top 25 , and common exploitation techniques.

Experience in

secure SDLC

practices and working with development teams to resolve findings.

Strong knowledge of

mobile application security

(iOS and Android) and

API testing methodologies .

Excellent report writing and communication skills for both technical and non-technical stakeholders.

Preferred Certifications (1 or more):

OSCP (Offensive Security Certified Professional)

OSWE (Offensive Security Web Expert)

eWPT / eWPTX (eLearnSecurity Web Application Penetration Tester)

PNPT (Practical Network Penetration Tester)

HTB CPTS (Certified Penetration Testing Specialist)

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.
Be The First To Know

About the latest Head of information security governance Jobs in Qatar !

Information Security Officer (ISO)

Doha, Doha Lesha Bank

Posted 12 days ago

Job Viewed

Tap Again To Close

Job Description

Role Purpose

The Information Security Officer (ISO) will be responsible for developing, implementing, and overseeing the bank’s information security strategy, policies, and controls. The role ensures that the bank’s data, systems, applications, and infrastructure are safeguarded against internal and external threats while meeting local regulatory requirements (QCB, QFCRA, NCSA-Q) and international standards (ISO 27001, NIST, GDPR, PCI-DSS as relevant). Key Responsibilities

Governance & Compliance Establish, maintain, and enforce the bank’s information security framework, aligned with QCB, QFCRA, and local cybersecurity regulations. Ensure compliance with international standards (ISO 27001, NIST CSF, COBIT, PCI-DSS) and conduct regular gap analyses. Prepare and present security risk assessments and reports to senior management, regulators, and the Board Risk Committee. Design, implement, and enforce security policies and procedures to safeguard the bank’s infrastructure and data. Security Operations Oversee Security Operations Center (SOC) activities, incident response, and threat intelligence monitoring. Develop and maintain business continuity, disaster recovery, and incident response plans. Implement and monitor Data Loss Prevention (DLP), intrusion detection/prevention (IDS/IPS), endpoint protection, and other security tools. Lead investigations of security breaches, develop strategies for handling incidents, and ensure lessons learned are integrated into policies and processes. Stay current with the latest security systems, standards, and products to ensure optimal protection. Regularly evaluate the effectiveness of security measures and update them against emerging threats and industry best practices. Conduct regular staff training on security awareness, best practices, and incident procedures. Collaborate with IT and business management to continuously improve security controls and culture. Risk Management Conduct enterprise-wide risk assessments on systems, applications, vendors, and third-party service providers. Identify vulnerabilities and ensure timely remediation through patch management and secure configurations. Work with IT and business units to integrate security into new product initiatives. Vendor & Technology Oversight Evaluate and approve technology vendors, outsourcing partners, and cloud solutions for compliance with security standards. Manage penetration tests, vulnerability assessments, and external audits. Requirements Bachelor’s degree in information security, Computer Science, or related field. Master’s degree preferred. Professional certifications: CISSP or CISM required; CISA and ISO 27001 Lead Implementer preferred. Cloud security certifications (e.g., CCSP, AWS Security) are a plus. 8–12 years in information security, with at least 5 years in the financial-services sector. Strong background in banking systems, digital channels, payment systems, and regulatory environments. Proven experience engaging with regulators (QCB, QFCRA, CMA, or equivalent). Proven experience in implementing SEIM Solutions, managing SOC Team. Expertise in cybersecurity frameworks, network security, cryptography, and identity & access management. Strong risk management and analytical skills. Excellent communication and stakeholder-management skills, capable of engaging effectively with regulators, auditors, and the Board. Ability to influence across departments, build a culture of security, and lead change initiatives without direct authority

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Senior Information Security Specialist

Civil Service and Government Development Bureau

Posted 26 days ago

Job Viewed

Tap Again To Close

Job Description

The Role
Perform a set of specialized tasks requiring experience and mastery of principles and fundamentals in the field of identifying security issues related to data, information, and applications, securing them against viruses, and protecting them from hacking and data theft.

Requirements
• Education: Bachelor's Degree in Computer Science or Information System • Years of Experience: 8 - 13 years

About the company
The Civil Service and Government Development Bureau was established on October 19, 2021. The role of the Bureau is to strengthen the workforce capabilities and capacity, and promote transformation of the Government of Qatar.
This advertiser has chosen not to accept applicants from your region.

Senior Information Security Expert

Civil Service and Government Development Bureau

Posted 26 days ago

Job Viewed

Tap Again To Close

Job Description

The Role
Executing a set of specialized tasks that require in-depth and diverse knowledge of the principles, fundamentals, and regulations governing work in the field of identifying security issues related to data, information, and applications, and securing them against viruses, hacking, and data theft.

Requirements
• Education: Bachelor's Degree in Computer Science or Information System • Years of Experience: 16 - 21 years

About the company
The Civil Service and Government Development Bureau was established on October 19, 2021. The role of the Bureau is to strengthen the workforce capabilities and capacity, and promote transformation of the Government of Qatar.
This advertiser has chosen not to accept applicants from your region.

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Head Of Information Security Governance Jobs