Qatari Diar is hiring for an exceptional Qatari IT Security professional to oversee, protect, and continuously improve organization's cybersecurity infrastructure.
In this role, Manager, IT security will lead security team, managing risk, and act as a principal architect of security policies while ensuring compliance with industry standards and governmental regulations.
Preferred candidates should be:
- Qatari candidate with bachelor's degree in information systems, Cyber Security or related discipline. Master's in information systems/ cyber security/ MBA is preferred.
- Certifications like CISSP/ CISM will be a plus. ITIL foundation certificate is desirable.
- He/ she should have 10+ years of experience in IT Security environment with technical proficiency in security related hardware and software.
Job Responsibilities:
- Developing, maintaining and enforcing an enterprise-wide information security standards and provide advice and guidance on the implementation of information security policies and standards.
- Conducting regular risk assessments and identifying vulnerabilities and implement strategies to mitigate them.
- Measuring and monitoring level of information security compliance.
- Ensuring compliance with relevant legal and regulatory framework governed by NCSA, NIA and Qatar's PDPPL and global best practices.
- Establishing and maintaining security architecture based on international standards such as ISO/ IEC 27001, NIST, and CIS controls.
- Directing continuous vulnerability scanning and coordinate periodic penetration testing across all infrastructure, cloud environments, and applications while issuing regular security assessment reports.
- Partnering with IT Infrastructure teams to design, test, and maintain robust Disaster recovery and Business Continuity plans capable of handling critical outages and hacking threats.
- Enforcing strict authentication controls and network and system access controls.
- Developing and approving secure configurations for cloud environments, Zero Trust networks, firewalls and Endpoint detection and response solutions.
- Championing organizational security awareness campaigns, including simulated phishing exercises for all business units.
- Leading incident response team during active cyber threats, data breaches or critical vulnerabilities, minimizing disruption and executing post incident root cause analysis.