Information Security Engineer

Doha, Doha BAE Systems Strategic Aerospace Services WLL

Posted 3 days ago

Job Viewed

Tap Again To Close

Job Description

BAE Systems Strategic Aerospace Services WLL | Full time

The Information Security Engineer willfocus on ensuring the organization's applications and data is secure and builtaccording to best security standards. This role will be the subject matterexpert on building secure code, application security, vulnerability testing,and providing security validation to the organization's environments.

  • Performscheduled penetration testing of the company's applications
  • Performwhite, gray and black box security assessments.
  • Supportthe organization, JVs and Subsidiaries in implementing Secure Softwaredevelopment lifecycle.
  • PerformMobile Services security Assessments.
  • Supportthe organizations’ environment monitoring by using available tools or helpbuild internal tools to enable advanced threat detection and response.
  • ConductSecurity Vulnerability Assessments and impact assessment on company’s electronicassets.
  • PerformSecurity Assessments on ERP and other on-premise solutions.


Requirements

Skills,Knowledge and Behaviors:

  • Ability to lead directand indirect resources
  • Ability to communicatetechnical challenges to non-technical audiences
  • Ability to quantify riskand impact vectors
  • Certified Ethical Hacker
  • OCSP level of technicalexpertise
  • Strong Scriptingcapability
  • Strong Applicationsecurity background
  • Strong Infrastructuresecurity Background
  • Strong experience in open source security tools
Qualifications & Experience:
  • SecurityCertification focusing on offensive or defensive practices
  • Bachelor’s degreein Information Security or Computer Engineering
  • 10 + years incybersecurity field
  • System, networkand/or application background
#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information Security Engineer

Doha, Doha BAE Systems Strategic Aerospace Services WLL

Posted 3 days ago

Job Viewed

Tap Again To Close

Job Description

BAE Systems Strategic Aerospace Services WLL | Full time The Information Security Engineer willfocus on ensuring the organization's applications and data is secure and builtaccording to best security standards. This role will be the subject matterexpert on building secure code, application security, vulnerability testing,and providing security validation to the organization's environments.

Performscheduled penetration testing of the company's applications

Performwhite, gray and black box security assessments.

Supportthe organization, JVs and Subsidiaries in implementing Secure Softwaredevelopment lifecycle.

PerformMobile Services security Assessments.

Supportthe organizations’ environment monitoring by using available tools or helpbuild internal tools to enable advanced threat detection and response.

ConductSecurity Vulnerability Assessments and impact assessment on company’s electronicassets.

PerformSecurity Assessments on ERP and other on-premise solutions.

Requirements

Skills,Knowledge and Behaviors:

Ability to lead directand indirect resources

Ability to communicatetechnical challenges to non-technical audiences

Ability to quantify riskand impact vectors

Certified Ethical Hacker

OCSP level of technicalexpertise

Strong Scriptingcapability

Strong Applicationsecurity background

Strong Infrastructuresecurity Background

Strong experience in open source security tools

Qualifications & Experience: SecurityCertification focusing on offensive or defensive practices

Bachelor’s degreein Information Security or Computer Engineering

10 + years incybersecurity field

System, networkand/or application background

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information Security Officer

Doha, Doha Management Solutions International MSI

Posted 6 days ago

Job Viewed

Tap Again To Close

Job Description

Primary responsible for planning, coordinating, and organizing Information Security activities. Enforce and monitor the implementation and compliance with IT Information Security Policy. Develop and manage the implementation of Information Security Policies and Procedures. Ensure Risk Assessments are conducted on all information systems such as people, process, technology, and information processing facilities. Ensure implementation of all Information Security controls, as set forth in the Risk Treatment Plan, to ensure adequate security for the respective system. Conduct Information Security communications and outreach by leveraging the Information Security Management System (ISMS) committee. Establish appropriate measures to assess operational capabilities and determine compliance and effectiveness levels with Information Security Policy. Supervise other related assurance functions, as necessary. Ensure the compliance of Information Security Policies in the organization. Develop and ensure implementation of Information Security procedures. Develop and ensure implementation of incident handling and reporting. Follow-up, escalate, and report the resolution of Information Security issues identified during security assessments, penetration tests, and audits. Develop, implement, and maintain Disaster Recovery (DR) procedures and infrastructure in relation to the Business Continuity Plan (BCP) / IT Service Contingency Plan. Conduct and coordinate Information Security awareness and orientation programs. Responsible for conducting Committee meetings. Security Incident Management Establish a formal procedure for internally reporting and tracking security incidents. Ensure incident response and escalation procedures are followed, and inform all employees, contractors, and third-party users of their responsibility to report security incidents. Incident Handling : Participate and / or oversee the investigation and management of information security events and policy violations and track them to conclusion. Incident Notification and Reporting : Follow policy for the notification and reporting of incidents immediately upon discovery. Corrective / Preventive Actions : Develop and document corrective action plans and implement preventive actions to mitigate recurrence. Analyze a security incident to detect an underlying problem that exists or is likely to exist. Categorize and prioritize the problem based on the frequency, severity, and impact of the incident. Investigate and diagnose the root cause of the problem. Test and apply temporary workarounds. Document the known error record. Create a formal process to address risk through the coordination and control of activities regarding each risk. Conduct formal vulnerability assessments of the environment on a regular basis. Create a formal process to mitigate vulnerabilities and more. Qualifications Experience 8+ years in IT work experience 5+ years in a similar role Education Bachelor of Engineering Or Bachelor of IT Or Bachelor of Computer Science Certifications CRISC – Certified in Risk and Information Systems Control Or ISO / IEC 27001 Lead Implementer or Lead Auditor Or CISSP – Certified Information Systems Security Professional Required Skillset Expertise in implementation of security frameworks such as NIST , ISO / IEC 27001 , and other local regulations and frameworks. Expertise in compliance requirements like GDPR , HIPAA , PCI DSS , SOX , and other relevant laws and regulations. Expertise in conducting risk assessments , identifying security risks, evaluating impact, and implementing mitigation strategies. Expertise in developing policies , procedures , and processes . Expertise in creating and managing security awareness and training programs to educate employees on cybersecurity threats and best practices. Information Security Officer • Doha, ad-Dawhah, Qatar

#J-18808-Ljbffr
This advertiser has chosen not to accept applicants from your region.

Information Security (ISMS) Consultants

Doha, Doha Premium Solutions Consultancy

Posted 4 days ago

Job Viewed

Tap Again To Close

Job Description

Urgent Requirement

A well-known IT Consultancy in Qatar is looking for suitable candidates to furnish the below position local with NOC,

JOB Title : Information Security (ISMS) Consultants

Nationality : Indian / Pakistan / Filipino

Notice Period : Immediately

Job Location : Qatar

Job Description

  • Own and successfully drive projects for ISO 27001, ISO 22301
  • Successfully handle GRC (Governance, Risk and Compliance) assignments totally independently.
  • Establish risk management framework for the client to address the client specific requirements.
  • Conducting risk based IS Audits
  • Review and enhance project level ISMS documentation and get the client sign-off.
  • Support and guide ISMS consultants
  • Interaction with certification auditors and non-conformities closure within the stipulated time.
  • Data privacy engagements
  • Effective interaction with key stakeholders in relation to ongoing security improvements
  • Keep up to date with the latest news and threats in the security industry.

Requirements

Required Qualification, Skills & Experience :

  • Intensive understanding of security methodologies and industry standards (e.g. ISO 27001,, Business Continuity Standards, IT Governance)
  • Excellent Communication and Presentation Skills
  • Experience : 3 to 5 years preferably with Consultancy Background in ISMS.
  • Bachelor’s degree in science / computer applications.
  • Relevant Certification from authorized training body (CISA / CISM / CISSP) is essential.
  • ISO 27001 : 2013 Lead Auditor / Lead Implementer
  • ISO 22301 : 2013 Lead Implementer
  • Benefits

    Gross Salary : 10K – 15K (QAR)

    #J-18808-Ljbffr
    This advertiser has chosen not to accept applicants from your region.

    Senior Information Security Engineer

    Doha, Doha PPL Dynamics

    Posted 6 days ago

    Job Viewed

    Tap Again To Close

    Job Description

    Key Responsibilities:

    • Perform web application, API, and mobile application penetration testing using industry-leading methodologies (OWASP, PTES, etc.).


    • Conduct network penetration testing and infrastructure security assessments.


    • Execute Vulnerability Assessment and Penetration Testing (VAPT) engagements, document findings, and recommend remediations.


    • Integrate security into the Software Development Lifecycle (SDLC) and advise development teams on secure coding practices.


    • Develop, enhance, and maintain security testing frameworks and tools .


    • Review and validate security patches, mitigations, and fixes.


    • Stay updated on the latest attack techniques, exploits, and threat landscapes to enhance testing methodologies.


    • Collaborate with cross-functional teams to support security awareness and risk reduction efforts.



    Required Skills & Qualifications:

    • 46 years of experience in Information Security, with a focus on application and network penetration testing .


    • Hands-on experience with tools like Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, and other manual testing tools .


    • Deep understanding of OWASP Top 10 , SANS Top 25 , and common exploitation techniques.


    • Experience in secure SDLC practices and working with development teams to resolve findings.


    • Strong knowledge of mobile application security (iOS and Android) and API testing methodologies .


    • Excellent report writing and communication skills for both technical and non-technical stakeholders.



    Preferred Certifications (1 or more):

    • OSCP (Offensive Security Certified Professional)


    • OSWE (Offensive Security Web Expert)


    • eWPT / eWPTX (eLearnSecurity Web Application Penetration Tester)


    • PNPT (Practical Network Penetration Tester)


    • HTB CPTS (Certified Penetration Testing Specialist)


    #J-18808-Ljbffr
    This advertiser has chosen not to accept applicants from your region.

    Information Security Officer (ISO)

    Doha, Doha Lesha Bank

    Posted 12 days ago

    Job Viewed

    Tap Again To Close

    Job Description

    Role Purpose

    The Information Security Officer (ISO) will be responsible for developing, implementing, and overseeing the bank’s information security strategy, policies, and controls. The role ensures that the bank’s data, systems, applications, and infrastructure are safeguarded against internal and external threats while meeting local regulatory requirements (QCB, QFCRA, NCSA-Q) and international standards (ISO 27001, NIST, GDPR, PCI-DSS as relevant).

    Key Responsibilities

    Governance & Compliance

    • Establish, maintain, and enforce the bank’s information security framework, aligned with QCB, QFCRA, and local cybersecurity regulations.
    • Ensure compliance with international standards (ISO 27001, NIST CSF, COBIT, PCI-DSS) and conduct regular gap analyses.
    • Prepare and present security risk assessments and reports to senior management, regulators, and the Board Risk Committee.
    • Design, implement, and enforce security policies and procedures to safeguard the bank’s infrastructure and data.

    Security Operations

    • Oversee Security Operations Center (SOC) activities, incident response, and threat intelligence monitoring.
    • Develop and maintain business continuity, disaster recovery, and incident response plans.
    • Implement and monitor Data Loss Prevention (DLP), intrusion detection/prevention (IDS/IPS), endpoint protection, and other security tools.
    • Lead investigations of security breaches, develop strategies for handling incidents, and ensure lessons learned are integrated into policies and processes.
    • Stay current with the latest security systems, standards, and products to ensure optimal protection.
    • Regularly evaluate the effectiveness of security measures and update them against emerging threats and industry best practices.
    • Conduct regular staff training on security awareness, best practices, and incident procedures.
    • Collaborate with IT and business management to continuously improve security controls and culture.

    Risk Management

    • Conduct enterprise-wide risk assessments on systems, applications, vendors, and third-party service providers.
    • Identify vulnerabilities and ensure timely remediation through patch management and secure configurations.
    • Work with IT and business units to integrate security into new product initiatives.

    Vendor & Technology Oversight

    • Evaluate and approve technology vendors, outsourcing partners, and cloud solutions for compliance with security standards.
    • Manage penetration tests, vulnerability assessments, and external audits.

    Requirements

    • Bachelor’s degree in information security, Computer Science, or related field. Master’s degree preferred.
    • Professional certifications: CISSP or CISM required; CISA and ISO 27001 Lead Implementer preferred.
    • Cloud security certifications (e.g., CCSP, AWS Security) are a plus.
    • 8–12 years in information security, with at least 5 years in the financial-services sector.
    • Strong background in banking systems, digital channels, payment systems, and regulatory environments.
    • Proven experience engaging with regulators (QCB, QFCRA, CMA, or equivalent).
    • Proven experience in implementing SEIM Solutions, managing SOC Team.
    • Expertise in cybersecurity frameworks, network security, cryptography, and identity & access management.
    • Strong risk management and analytical skills.
    • Excellent communication and stakeholder-management skills, capable of engaging effectively with regulators, auditors, and the Board.
    • Ability to influence across departments, build a culture of security, and lead change initiatives without direct authority

    #J-18808-Ljbffr
    This advertiser has chosen not to accept applicants from your region.

    Information Security (ISMS) Consultants

    Doha, Doha Premium Solutions Consultancy

    Posted 4 days ago

    Job Viewed

    Tap Again To Close

    Job Description

    Urgent Requirement A well-known IT Consultancy in Qatar is looking for suitable candidates to furnish the below position local with NOC, JOB Title :

    Information Security (ISMS) Consultants Nationality :

    Indian / Pakistan / Filipino Notice Period :

    Immediately Job Location :

    Qatar Job Description Own and successfully drive projects for ISO 27001, ISO 22301 Successfully handle GRC (Governance, Risk and Compliance) assignments totally independently. Establish risk management framework for the client to address the client specific requirements. Conducting risk based IS Audits Review and enhance project level ISMS documentation and get the client sign-off. Support and guide ISMS consultants Interaction with certification auditors and non-conformities closure within the stipulated time. Data privacy engagements Effective interaction with key stakeholders in relation to ongoing security improvements Keep up to date with the latest news and threats in the security industry. Requirements Required Qualification, Skills & Experience : Intensive understanding of security methodologies and industry standards (e.g. ISO 27001,, Business Continuity Standards, IT Governance) Excellent Communication and Presentation Skills Experience : 3 to 5 years preferably with Consultancy Background in ISMS. Bachelor’s degree in science / computer applications. Relevant Certification from authorized training body (CISA / CISM / CISSP) is essential. ISO 27001 : 2013 Lead Auditor / Lead Implementer ISO 22301 : 2013 Lead Implementer Benefits Gross Salary :

    10K – 15K (QAR)

    #J-18808-Ljbffr
    This advertiser has chosen not to accept applicants from your region.
    Be The First To Know

    About the latest Sr security consultant identity presales Jobs in Doha !

    Senior Information Security Engineer

    Doha, Doha PPL Dynamics

    Posted 6 days ago

    Job Viewed

    Tap Again To Close

    Job Description

    Key Responsibilities:

    Perform

    web application, API, and mobile application penetration testing

    using industry-leading methodologies (OWASP, PTES, etc.).

    Conduct

    network penetration testing

    and infrastructure security assessments.

    Execute

    Vulnerability Assessment and Penetration Testing (VAPT)

    engagements, document findings, and recommend remediations.

    Integrate security into the

    Software Development Lifecycle (SDLC)

    and advise development teams on secure coding practices.

    Develop, enhance, and maintain

    security testing frameworks and tools .

    Review and validate security patches, mitigations, and fixes.

    Stay updated on the latest

    attack techniques, exploits, and threat landscapes

    to enhance testing methodologies.

    Collaborate with cross-functional teams to support security awareness and risk reduction efforts.

    Required Skills & Qualifications:

    46 years of experience

    in Information Security, with a focus on

    application and network penetration testing .

    Hands-on experience with tools like

    Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, and other manual testing tools .

    Deep understanding of

    OWASP Top 10 ,

    SANS Top 25 , and common exploitation techniques.

    Experience in

    secure SDLC

    practices and working with development teams to resolve findings.

    Strong knowledge of

    mobile application security

    (iOS and Android) and

    API testing methodologies .

    Excellent report writing and communication skills for both technical and non-technical stakeholders.

    Preferred Certifications (1 or more):

    OSCP (Offensive Security Certified Professional)

    OSWE (Offensive Security Web Expert)

    eWPT / eWPTX (eLearnSecurity Web Application Penetration Tester)

    PNPT (Practical Network Penetration Tester)

    HTB CPTS (Certified Penetration Testing Specialist)

    #J-18808-Ljbffr
    This advertiser has chosen not to accept applicants from your region.

    Information Security Officer (ISO)

    Doha, Doha Lesha Bank

    Posted 12 days ago

    Job Viewed

    Tap Again To Close

    Job Description

    Role Purpose

    The Information Security Officer (ISO) will be responsible for developing, implementing, and overseeing the bank’s information security strategy, policies, and controls. The role ensures that the bank’s data, systems, applications, and infrastructure are safeguarded against internal and external threats while meeting local regulatory requirements (QCB, QFCRA, NCSA-Q) and international standards (ISO 27001, NIST, GDPR, PCI-DSS as relevant). Key Responsibilities

    Governance & Compliance Establish, maintain, and enforce the bank’s information security framework, aligned with QCB, QFCRA, and local cybersecurity regulations. Ensure compliance with international standards (ISO 27001, NIST CSF, COBIT, PCI-DSS) and conduct regular gap analyses. Prepare and present security risk assessments and reports to senior management, regulators, and the Board Risk Committee. Design, implement, and enforce security policies and procedures to safeguard the bank’s infrastructure and data. Security Operations Oversee Security Operations Center (SOC) activities, incident response, and threat intelligence monitoring. Develop and maintain business continuity, disaster recovery, and incident response plans. Implement and monitor Data Loss Prevention (DLP), intrusion detection/prevention (IDS/IPS), endpoint protection, and other security tools. Lead investigations of security breaches, develop strategies for handling incidents, and ensure lessons learned are integrated into policies and processes. Stay current with the latest security systems, standards, and products to ensure optimal protection. Regularly evaluate the effectiveness of security measures and update them against emerging threats and industry best practices. Conduct regular staff training on security awareness, best practices, and incident procedures. Collaborate with IT and business management to continuously improve security controls and culture. Risk Management Conduct enterprise-wide risk assessments on systems, applications, vendors, and third-party service providers. Identify vulnerabilities and ensure timely remediation through patch management and secure configurations. Work with IT and business units to integrate security into new product initiatives. Vendor & Technology Oversight Evaluate and approve technology vendors, outsourcing partners, and cloud solutions for compliance with security standards. Manage penetration tests, vulnerability assessments, and external audits. Requirements Bachelor’s degree in information security, Computer Science, or related field. Master’s degree preferred. Professional certifications: CISSP or CISM required; CISA and ISO 27001 Lead Implementer preferred. Cloud security certifications (e.g., CCSP, AWS Security) are a plus. 8–12 years in information security, with at least 5 years in the financial-services sector. Strong background in banking systems, digital channels, payment systems, and regulatory environments. Proven experience engaging with regulators (QCB, QFCRA, CMA, or equivalent). Proven experience in implementing SEIM Solutions, managing SOC Team. Expertise in cybersecurity frameworks, network security, cryptography, and identity & access management. Strong risk management and analytical skills. Excellent communication and stakeholder-management skills, capable of engaging effectively with regulators, auditors, and the Board. Ability to influence across departments, build a culture of security, and lead change initiatives without direct authority

    #J-18808-Ljbffr
    This advertiser has chosen not to accept applicants from your region.

    Service Design Architect – Information Security

    Doha, Doha MEEZA QSTP

    Posted 4 days ago

    Job Viewed

    Tap Again To Close

    Job Description

    Service Design Architect – Information Security

    • Design and develop complex service design security solutions, ensuring they align with client requirements, business objectives, and industry best practices.
    • Collaborate with cross-functional teams to define and implement service design methodologies, frameworks, and standards.
    • Conduct in-depth analysis of client needs, business processes, and technical requirements to design innovative and efficient service solutions.
    • Conduct user research, interviews, surveys, and analyze data to identify opportunities that can improve the services provided.
    • Contribute to maintaining quality standards for the services provided by MEEZA by following metrics and KPIs for measuring service performance, participating in audits and reviews, and implementing corrective actions to improve service quality.
    • Provide technical expertise and guidance to service design teams, ensuring the successful execution and delivery of service design projects.
    • Stay abreast of emerging technologies and industry trends, incorporating them into service design strategies to drive innovation and enhance service offerings.
    • Support the implementation of tools that allow for effective monitoring and trending of IT infrastructure, software and IT components performance and resource utilization.
    • Establish and maintain comprehensive capacity management planning processes at the enterprise, system, and IT component level.
    • Collaborate closely with Security Operations and Compliance to ensure that security reviews regarding information security technologies provide feasible requirements and are consistent with contracts and regulations.
    Knowledge, Skills & Experience

    Academic & Professional Qualifications:

    • Bachelor’s degree in computer science, Information Systems, Engineering, or Equivalent.

    Experience:

    • 5-6 years of experience in technology services or a similar field.

    Skills and Requirements:

    • Expertise in service design principles, methodologies, and tools to lead the design and development of complex information security solutions.
    • Familiar with technologies like DLP, PAM, IAM, MDM, DNS security, FIM, deception solutions, NGFW, XDR, SIEM tools, SOAR tools, Email security, proxy, and WAF technologies.
    • Strong leadership and collaboration skills to effectively work with cross-functional teams, stakeholders, and clients, ensuring the successful execution of service design projects.
    • Proficient in conducting thorough analysis, translating client requirements into innovative and efficient service design architectures that align with business objectives and deliver exceptional user experiences.
    • Understanding of enterprise technologies including data centers (Tier-III), WAN/MAN/LAN networks, enterprise storage, server technologies, enterprise applications (e.g., ERP, BI, CRM, CMS etc.), security and enterprise management systems.
    • Understanding and application of Architecture Framework for service design, definitions, and documentation.
    • Strong knowledge of systems coding, security analysis, data modeling and database management.
    • Strong experience with designing modern information security solutions and services; preferably in MSSP and cloud environments.
    Position Details
    • Seniority level : Associate
    • Employment type : Full-time
    • Job function : Information Technology
    • Industries : IT Services and IT Consulting and IT System Data Services

    #J-18808-Ljbffr
    This advertiser has chosen not to accept applicants from your region.

    Nearby Locations

    Other Jobs Near Me

    Industry

    1. request_quote Accounting
    2. work Administrative
    3. eco Agriculture Forestry
    4. smart_toy AI & Emerging Technologies
    5. school Apprenticeships & Trainee
    6. apartment Architecture
    7. palette Arts & Entertainment
    8. directions_car Automotive
    9. flight_takeoff Aviation
    10. account_balance Banking & Finance
    11. local_florist Beauty & Wellness
    12. restaurant Catering
    13. volunteer_activism Charity & Voluntary
    14. science Chemical Engineering
    15. child_friendly Childcare
    16. foundation Civil Engineering
    17. clean_hands Cleaning & Sanitation
    18. diversity_3 Community & Social Care
    19. construction Construction
    20. brush Creative & Digital
    21. currency_bitcoin Crypto & Blockchain
    22. support_agent Customer Service & Helpdesk
    23. medical_services Dental
    24. medical_services Driving & Transport
    25. medical_services E Commerce & Social Media
    26. school Education & Teaching
    27. electrical_services Electrical Engineering
    28. bolt Energy
    29. local_mall Fmcg
    30. gavel Government & Non Profit
    31. emoji_events Graduate
    32. health_and_safety Healthcare
    33. beach_access Hospitality & Tourism
    34. groups Human Resources
    35. precision_manufacturing Industrial Engineering
    36. security Information Security
    37. handyman Installation & Maintenance
    38. policy Insurance
    39. code IT & Software
    40. gavel Legal
    41. sports_soccer Leisure & Sports
    42. inventory_2 Logistics & Warehousing
    43. supervisor_account Management
    44. supervisor_account Management Consultancy
    45. supervisor_account Manufacturing & Production
    46. campaign Marketing
    47. build Mechanical Engineering
    48. perm_media Media & PR
    49. local_hospital Medical
    50. local_hospital Military & Public Safety
    51. local_hospital Mining
    52. medical_services Nursing
    53. local_gas_station Oil & Gas
    54. biotech Pharmaceutical
    55. checklist_rtl Project Management
    56. shopping_bag Purchasing
    57. home_work Real Estate
    58. person_search Recruitment Consultancy
    59. store Retail
    60. point_of_sale Sales
    61. science Scientific Research & Development
    62. wifi Telecoms
    63. psychology Therapy
    64. pets Veterinary
    View All Sr Security Consultant Identity Presales Jobs View All Jobs in Doha