About Commercial Bank Of Qatar
Commercial Bank, founded in 1975 and headquartered in Doha, plays a vital role in Qatar's economic development by offering a range of personal, business, government, international and investment services.
We believe in empowering our employees, providing them with opportunities for growth and professional development.
By Joining us, you'll be part of a workplace culture that fosters innovation, supports work-life balance, and encourages you to reach your full potential.
Join us in shaping the future of banking!
Job Summary
The Senior Security Assessment Specialist will be a subject matter expert in all aspects of security assessment: architecture, application security, penetration testing, ethical hack/red team and vulnerability assessment. They will be the lead role in ensuring the banks level of security is assessed, taking into account the current and future threat landscape, attacker tradecraft and regulatory requirements.
This role will suit an individual who has a passion to develop their own skills and knowledge in information security and security assessment; a proactive person who is a hands on starter/finisher, that's driven, enjoys responsibility and achieving results; a highly organised person in their ability to manage and prioritise workload; adept at operating effectively within an organization delivering via influence and relationships rather than all under their control.
Key Accountabilities
Penetration Testing, Ethical Hack and Red Team
- Design, delivery and development of penetration testing processes
- Design, delivery and development of the ethical hack and red team programs and ensure they are aligned to current and future threats and attacker techniques
- Design, delivery, selection and adoption of automated tools where applicable
Application Security
- Design, delivery and development of application security processes (eg: SAST, DAST, RASP, IAST) and integrate these processes into the SDLC.
- Effectively identify information security issues, concerns, threats and vulnerabilities in the current environment in order to ensure the security of existing systems.
- Investigate the effectiveness of current security technologies, and recommend vendor specific security solutions to treat or mitigate the threats and vulnerabilities.
- Assist in the configuration, enhancement, and fine-tuning of the existing application security controls and manage the deployment of security solutions.
Secure Architecture
- Conduct security architecture review in coordination with relevant stakeholders and participate in performing the risk management process to facilitate adherence of all operations to the defined security regulations.
Vulnerability scanning
- Design, delivery and development of regular external and internal vulnerability scanning
Continuous Improvement
- Motivate subordinates and contribute to the identification of opportunities for continuous improvement of systems, processes and practices taking into account international leading practice, improvement of business processes, cost reduction and productivity improvement.
Responsibilities
Policies, Systems, Processes & Procedures
- Recommend improvements to departmental procedure and direct the implementation of instructions and controls covering a specific area of activity so that all relevant procedural/legislative requirements are fulfilled while delivering a quality, cost-effective service.
Quality, Health, Safety, & Environment
- Ensure compliance to all relevant quality, health, safety and environmental management procedures and controls within a defined area of activity to guarantee employee safety, compliance, delivery of high quality products/service and a responsible environmental attitude.
MIS and Reports
- Prepare departmental MIS statements and reports timely and accurately to meet CBQ and department requirements, policies and standards.
Related Assignments
- Perform other related duties or assignments as directed.
Qualifications
Minimum Qualifications:
- Bachelor's degree in Cybersecurity
Minimum Experience
- 5-8 years relevant experience
- Relevant security assessment certifications
Knowledge, & Other Skills
- Web application, Infrastructure and think application penetration testing
- Experience performing code reviews and working with developers to remediate
- Effective communication and interpersonal skills.
- High computer literacy skills.
- Ability to work under pressure and adjust quickly to changing priorities
Key Interactions
Internal: All business and support groups (IT users) across the bank
External: System Security Vendors
Why Commercial Bank
- Best Digital Bank in the Middle East 2024 by World Finance and Best Mobile Banking App in the Middle East 2024 by Global Finance.
- An Innovation-Driven, Digital-First Environment where employees work with the latest tools and technologies to redefine banking
- Opportunities for Global Partnerships & International Exposure, connecting employees with global networks and perspectives.
- A focus on Employee Well-being & Work-Life Balance, ensuring a healthy and supportive environment for all team members
- Competitive Compensation & Benefits that ensure our employees are rewarded for their dedication and performance
- A strong Commitment to Diversity, Equity & Inclusion, fostering a culture that values every individual's unique perspective.
At Commercial Bank, we don't just offer careers, We shape futures by pioneering
digital transformation in Qatar's banking sector, blending
digital-first approach to redefine banking through
innovative solutions.
Disclaimer
We appreciate your interest in joining CBQ! Please note that only selected candidates will be contacted for further steps in the hiring process. This job posting is for informational purposes only, and CBQ reserves the right to modify, withdraw, or close it at any time without notice.