81 Head Of Information Security Governance jobs in Qatar
Senior Information Security Engineer
Posted 6 days ago
Job Viewed
Job Description
Perform web application, API, and mobile application penetration testing using industry-leading methodologies (OWASP, PTES, etc.).
Conduct network penetration testing and infrastructure security assessments.
Execute Vulnerability Assessment and Penetration Testing (VAPT) engagements, document findings, and recommend remediations.
Integrate security into the Software Development Lifecycle (SDLC) and advise development teams on secure coding practices.
Develop, enhance, and maintain security testing frameworks and tools .
Review and validate security patches, mitigations, and fixes.
Stay updated on the latest attack techniques, exploits, and threat landscapes to enhance testing methodologies.
Collaborate with cross-functional teams to support security awareness and risk reduction efforts.
46 years of experience in Information Security, with a focus on application and network penetration testing .
Hands-on experience with tools like Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, and other manual testing tools .
Deep understanding of OWASP Top 10 , SANS Top 25 , and common exploitation techniques.
Experience in secure SDLC practices and working with development teams to resolve findings.
Strong knowledge of mobile application security (iOS and Android) and API testing methodologies .
Excellent report writing and communication skills for both technical and non-technical stakeholders.
OSCP (Offensive Security Certified Professional)
OSWE (Offensive Security Web Expert)
eWPT / eWPTX (eLearnSecurity Web Application Penetration Tester)
PNPT (Practical Network Penetration Tester)
HTB CPTS (Certified Penetration Testing Specialist)
Information Security Officer (ISO)
Posted 12 days ago
Job Viewed
Job Description
Role Purpose
The Information Security Officer (ISO) will be responsible for developing, implementing, and overseeing the bank’s information security strategy, policies, and controls. The role ensures that the bank’s data, systems, applications, and infrastructure are safeguarded against internal and external threats while meeting local regulatory requirements (QCB, QFCRA, NCSA-Q) and international standards (ISO 27001, NIST, GDPR, PCI-DSS as relevant).
Key ResponsibilitiesGovernance & Compliance
- Establish, maintain, and enforce the bank’s information security framework, aligned with QCB, QFCRA, and local cybersecurity regulations.
- Ensure compliance with international standards (ISO 27001, NIST CSF, COBIT, PCI-DSS) and conduct regular gap analyses.
- Prepare and present security risk assessments and reports to senior management, regulators, and the Board Risk Committee.
- Design, implement, and enforce security policies and procedures to safeguard the bank’s infrastructure and data.
Security Operations
- Oversee Security Operations Center (SOC) activities, incident response, and threat intelligence monitoring.
- Develop and maintain business continuity, disaster recovery, and incident response plans.
- Implement and monitor Data Loss Prevention (DLP), intrusion detection/prevention (IDS/IPS), endpoint protection, and other security tools.
- Lead investigations of security breaches, develop strategies for handling incidents, and ensure lessons learned are integrated into policies and processes.
- Stay current with the latest security systems, standards, and products to ensure optimal protection.
- Regularly evaluate the effectiveness of security measures and update them against emerging threats and industry best practices.
- Conduct regular staff training on security awareness, best practices, and incident procedures.
- Collaborate with IT and business management to continuously improve security controls and culture.
Risk Management
- Conduct enterprise-wide risk assessments on systems, applications, vendors, and third-party service providers.
- Identify vulnerabilities and ensure timely remediation through patch management and secure configurations.
- Work with IT and business units to integrate security into new product initiatives.
Vendor & Technology Oversight
- Evaluate and approve technology vendors, outsourcing partners, and cloud solutions for compliance with security standards.
- Manage penetration tests, vulnerability assessments, and external audits.
Requirements
- Bachelor’s degree in information security, Computer Science, or related field. Master’s degree preferred.
- Professional certifications: CISSP or CISM required; CISA and ISO 27001 Lead Implementer preferred.
- Cloud security certifications (e.g., CCSP, AWS Security) are a plus.
- 8–12 years in information security, with at least 5 years in the financial-services sector.
- Strong background in banking systems, digital channels, payment systems, and regulatory environments.
- Proven experience engaging with regulators (QCB, QFCRA, CMA, or equivalent).
- Proven experience in implementing SEIM Solutions, managing SOC Team.
- Expertise in cybersecurity frameworks, network security, cryptography, and identity & access management.
- Strong risk management and analytical skills.
- Excellent communication and stakeholder-management skills, capable of engaging effectively with regulators, auditors, and the Board.
- Ability to influence across departments, build a culture of security, and lead change initiatives without direct authority
Senior Information Security Manager
Posted today
Job Viewed
Job Description
Company Description Job Description
We are currently looking Senior Information Security Manager for our Qatar operations with the following terms & conditions.
Education & Experience Requirements:
- Bachelor's degree preferably in computer science, computer engineering or related subjects. Master's degree
- preferred.
- At least 8 years of relevant experience, preferably within a highly rated international bank or large corporate in an
- information security engineering capacity.
- Professional certification such as CISSP, CISM, CISA is mandatory
- Security engineering certifications and qualifications in Microsoft operating systems (such as Azure, MCSA,
- MCSE, et al) or Linux (such as RHCP, et al) are mandatory.
Required Special Skills:
- Excellent understanding of Information security technologies including firewalls, proxies, web application firewalls,
- IDS/IPS, ATP and sandbox solutions, EDR, vulnerability scanners, DLP, data classification tools, PAM, IAM,
Joining time frame: 2 weeks (maximum 1 month)
Additional Information
Terms and conditions:
Joining time frame: maximum 4 weeks
Senior Manager Information Security
Posted today
Job Viewed
Job Description
Nair Systems
is currently looking
Senior Manager, Security Technology Engineering
for our
Qatar
operations with the following terms & conditions.
Education & Experience Requirements:
· Bachelor's degree preferably in computer science, computer engineering or related subjects. Master's degree
· preferred.
· At least 8 years of relevant experience, preferably within a highly rated international bank or large corporate in an
· information security engineering capacity.
· Professional certification such as CISSP, CISM, CISA is mandatory
· Security engineering certifications and qualifications in Microsoft operating systems (such as Azure, MCSA, MCSE, et al) or Linux (such as RHCP, et al) are mandatory.
Required Special Skills:
· Excellent understanding of Information security technologies including firewalls, proxies, web application firewalls,
· IDS/IPS, ATP and sandbox solutions, EDR, vulnerability scanners, DLP, data classification tools, PAM, IAM,
· DDOS mitigation systems and more
· Good understanding of infrastructure and application security controls.
· Ability to communicate information security-related concepts to a broad spectrum of technical and non-technical staff.
· Risk Management skills (risk identification, risk assessment, risk mitigation)
· Maintain an understanding of all pertinent regulations as well as best practices pertaining to information security.
· Self-motivated, eye for detail.
· Ability to persuade others.
· Flexible team player and able to work and deliver under pressure.
· Ability to inspire and motivate others to gain commitment.
Should you be interested in this opportunity, please send your latest resume in MS Word format at the earliest
Information Security Manager - Banking
Posted today
Job Viewed
Job Description
Job Description
We are currently looking Information Security Manager for our Qatar operations with the following terms & conditions.
Education & Experience Requirements:
- Bachelor's degree preferably in computer science, computer engineering or related subjects. Master's degree
- preferred.
- At least 8 years of relevant experience, preferably within a highly rated international bank or large corporate in an
- information security engineering capacity.
- Professional certification such as CISSP, CISM, CISA is mandatory
- Security engineering certifications and qualifications in Microsoft operating systems (such as Azure, MCSA,
- MCSE, et al) or Linux (such as RHCP, et al) are mandatory.
Required Special Skills:
- Excellent understanding of Information security technologies including firewalls, proxies, web application firewalls,
- IDS/IPS, ATP and sandbox solutions, EDR, vulnerability scanners, DLP, data classification tools, PAM, IAM,
- DDOS mitigation systems and more
- Good understanding of infrastructure and application security controls.
- Ability to communicate information security-related concepts to a broad spectrum of technical and non-technical staff.
- Risk Management skills (risk identification, risk assessment, risk mitigation)
- Maintain an understanding of all pertinent regulations as well as best practices pertaining to information security.
- Self-motivated, eye for detail.
- Ability to persuade others.
- Flexible team player and able to work and deliver under pressure.
- Ability to inspire and motivate others to gain commitment.
Joining time frame: 2 weeks (maximum 1 month)
Information Security (ISMS) Consultants
Posted 4 days ago
Job Viewed
Job Description
Information Security (ISMS) Consultants Nationality :
Indian / Pakistan / Filipino Notice Period :
Immediately Job Location :
Qatar Job Description Own and successfully drive projects for ISO 27001, ISO 22301 Successfully handle GRC (Governance, Risk and Compliance) assignments totally independently. Establish risk management framework for the client to address the client specific requirements. Conducting risk based IS Audits Review and enhance project level ISMS documentation and get the client sign-off. Support and guide ISMS consultants Interaction with certification auditors and non-conformities closure within the stipulated time. Data privacy engagements Effective interaction with key stakeholders in relation to ongoing security improvements Keep up to date with the latest news and threats in the security industry. Requirements Required Qualification, Skills & Experience : Intensive understanding of security methodologies and industry standards (e.g. ISO 27001,, Business Continuity Standards, IT Governance) Excellent Communication and Presentation Skills Experience : 3 to 5 years preferably with Consultancy Background in ISMS. Bachelor’s degree in science / computer applications. Relevant Certification from authorized training body (CISA / CISM / CISSP) is essential. ISO 27001 : 2013 Lead Auditor / Lead Implementer ISO 22301 : 2013 Lead Implementer Benefits Gross Salary :
10K – 15K (QAR)
#J-18808-Ljbffr
Senior Information Security Engineer
Posted 6 days ago
Job Viewed
Job Description
Perform
web application, API, and mobile application penetration testing
using industry-leading methodologies (OWASP, PTES, etc.).
Conduct
network penetration testing
and infrastructure security assessments.
Execute
Vulnerability Assessment and Penetration Testing (VAPT)
engagements, document findings, and recommend remediations.
Integrate security into the
Software Development Lifecycle (SDLC)
and advise development teams on secure coding practices.
Develop, enhance, and maintain
security testing frameworks and tools .
Review and validate security patches, mitigations, and fixes.
Stay updated on the latest
attack techniques, exploits, and threat landscapes
to enhance testing methodologies.
Collaborate with cross-functional teams to support security awareness and risk reduction efforts.
Required Skills & Qualifications:
46 years of experience
in Information Security, with a focus on
application and network penetration testing .
Hands-on experience with tools like
Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, and other manual testing tools .
Deep understanding of
OWASP Top 10 ,
SANS Top 25 , and common exploitation techniques.
Experience in
secure SDLC
practices and working with development teams to resolve findings.
Strong knowledge of
mobile application security
(iOS and Android) and
API testing methodologies .
Excellent report writing and communication skills for both technical and non-technical stakeholders.
Preferred Certifications (1 or more):
OSCP (Offensive Security Certified Professional)
OSWE (Offensive Security Web Expert)
eWPT / eWPTX (eLearnSecurity Web Application Penetration Tester)
PNPT (Practical Network Penetration Tester)
HTB CPTS (Certified Penetration Testing Specialist)
#J-18808-Ljbffr
Be The First To Know
About the latest Head of information security governance Jobs in Qatar !
Information Security Officer (ISO)
Posted 12 days ago
Job Viewed
Job Description
The Information Security Officer (ISO) will be responsible for developing, implementing, and overseeing the bank’s information security strategy, policies, and controls. The role ensures that the bank’s data, systems, applications, and infrastructure are safeguarded against internal and external threats while meeting local regulatory requirements (QCB, QFCRA, NCSA-Q) and international standards (ISO 27001, NIST, GDPR, PCI-DSS as relevant). Key Responsibilities
Governance & Compliance Establish, maintain, and enforce the bank’s information security framework, aligned with QCB, QFCRA, and local cybersecurity regulations. Ensure compliance with international standards (ISO 27001, NIST CSF, COBIT, PCI-DSS) and conduct regular gap analyses. Prepare and present security risk assessments and reports to senior management, regulators, and the Board Risk Committee. Design, implement, and enforce security policies and procedures to safeguard the bank’s infrastructure and data. Security Operations Oversee Security Operations Center (SOC) activities, incident response, and threat intelligence monitoring. Develop and maintain business continuity, disaster recovery, and incident response plans. Implement and monitor Data Loss Prevention (DLP), intrusion detection/prevention (IDS/IPS), endpoint protection, and other security tools. Lead investigations of security breaches, develop strategies for handling incidents, and ensure lessons learned are integrated into policies and processes. Stay current with the latest security systems, standards, and products to ensure optimal protection. Regularly evaluate the effectiveness of security measures and update them against emerging threats and industry best practices. Conduct regular staff training on security awareness, best practices, and incident procedures. Collaborate with IT and business management to continuously improve security controls and culture. Risk Management Conduct enterprise-wide risk assessments on systems, applications, vendors, and third-party service providers. Identify vulnerabilities and ensure timely remediation through patch management and secure configurations. Work with IT and business units to integrate security into new product initiatives. Vendor & Technology Oversight Evaluate and approve technology vendors, outsourcing partners, and cloud solutions for compliance with security standards. Manage penetration tests, vulnerability assessments, and external audits. Requirements Bachelor’s degree in information security, Computer Science, or related field. Master’s degree preferred. Professional certifications: CISSP or CISM required; CISA and ISO 27001 Lead Implementer preferred. Cloud security certifications (e.g., CCSP, AWS Security) are a plus. 8–12 years in information security, with at least 5 years in the financial-services sector. Strong background in banking systems, digital channels, payment systems, and regulatory environments. Proven experience engaging with regulators (QCB, QFCRA, CMA, or equivalent). Proven experience in implementing SEIM Solutions, managing SOC Team. Expertise in cybersecurity frameworks, network security, cryptography, and identity & access management. Strong risk management and analytical skills. Excellent communication and stakeholder-management skills, capable of engaging effectively with regulators, auditors, and the Board. Ability to influence across departments, build a culture of security, and lead change initiatives without direct authority
#J-18808-Ljbffr
Senior Information Security Specialist
Posted 26 days ago
Job Viewed
Job Description
Perform a set of specialized tasks requiring experience and mastery of principles and fundamentals in the field of identifying security issues related to data, information, and applications, securing them against viruses, and protecting them from hacking and data theft.
Requirements
• Education: Bachelor's Degree in Computer Science or Information System • Years of Experience: 8 - 13 years
About the company
The Civil Service and Government Development Bureau was established on October 19, 2021. The role of the Bureau is to strengthen the workforce capabilities and capacity, and promote transformation of the Government of Qatar.
Senior Information Security Expert
Posted 26 days ago
Job Viewed
Job Description
Executing a set of specialized tasks that require in-depth and diverse knowledge of the principles, fundamentals, and regulations governing work in the field of identifying security issues related to data, information, and applications, and securing them against viruses, hacking, and data theft.
Requirements
• Education: Bachelor's Degree in Computer Science or Information System • Years of Experience: 16 - 21 years
About the company
The Civil Service and Government Development Bureau was established on October 19, 2021. The role of the Bureau is to strengthen the workforce capabilities and capacity, and promote transformation of the Government of Qatar.