The Information Security Officer is responsible for leading and executing end-to-end security assurance activities across technology landscape, including applications, cloud, infrastructure, identity, and third-party environments.
The role ensures security controls are properly designed, implemented, validated, and continuously enforced, including the definition and verification of secure configuration baselines across the enterprise, in alignment with ISMS, NCSA (Qatar NIA/QCSF), ISO 27001, and NIST CSF.
Key Responsibilities
Security Assurance & Risk Management
Lead security assessments, architecture reviews, vulnerability management, and assurance activities. Establish and operate a structured Security Assurance Framework covering control validation, coverage tracking, and continuous assurance. Manage the full security lifecycle from risk identification through remediation and validation. Translate technical findings into business-level risk statements and remediation plans.
Application, Cloud & Infrastructure Security
Perform in-depth security assessments of web applications, APIs, mobile applications, cloud platforms, containers, and infrastructure. Identify advanced security risks such as business logic flaws, authentication weaknesses, privilege abuse, and modern attack techniques. Validate secure architectures, configuration baselines, and cloud-native security controls. Support secure SDLC and Dev Sec Ops practices, including security testing and release controls.
Configuration Baselines & Continuous Hardening (New)
Define and maintain secure configuration baselines across the enterprise technology stack (OS, databases, network devices, cloud services, identity platforms, and security tools). Align baselines with industry standards (e.g., CIS Benchmarks) and organizational risk requirements. Implement automated configuration compliance checks and continuous monitoring mechanisms. Conduct periodic reviews and validation of configurations to detect drift, misconfigurations, and unauthorized changes. Work with engineering and operations teams to enforce hardening standards and remediate deviations.
Architecture, Threat Modeling & Secure Design
Lead security architecture and design reviews across applications, platforms, and integrations. Conduct threat modeling to identify attack paths, risks, and mitigation strategies. Ensure alignment with enterprise security architecture and Zero Trust principles.
Third-Party, Data Protection & Resilience
Conduct security assessments of vendors, Saa S providers, and external integrations. Validate data protection, encryption, and privacy controls for sensitive and regulated data. Support cyber resilience activities, including OT/ICS security reviews, red team exercises, and incident response simulations.
Governance, Compliance & Reporting
Ensure continuous alignment with regulatory and framework requirements (ISO 27001, NIST CSF, Qatar NIA, QCSF). Support internal and external audits with defensible, evidence-based controls. Define and report on security metrics, KPIs, and executive dashboards.
Required Experience & Skills
8+ years of experience in information security assessments and assurance. Strong expertise in application, API, mobile, and cloud security. Hands-on experience in penetration testing, vulnerability management, and security architecture reviews. Practical experience in system hardening, configuration baselines, and security control validation. Deep understanding of modern attack techniques and identity/authentication mechanisms. Proven ability to communicate technical risks to business stakeholders.
Preferred Certifications
OSCP / OSEP / OSWECISSPCloud Security Certifications (Azure / GCP) IEC 62443
يتولى مسؤول أمن المعلومات قيادة وتنفيذ أنشطة ضمان الأمن من البداية إلى النهاية عبر بيئة التكنولوجيا، بما في ذلك التطبيقات والسحابة والبنية التحتية والهوية والبيئات الخارجية.
يضمن الدور أن تكون ضوابط الأمن مصممة بشكل صحيح وتنفيذها والتحقق منها وإنفاذها باستمرار، بما في ذلك تعريف والتحقق من خطوط الأساس للتكوين الآمن عبر المؤسسة، بما يتماشى مع نظام إدارة أمن المعلومات (ISMS) وNCSA (هيئة الإنترنت الوطنية القطرية / QCSF) ومعايير ISO 27001 وNIST CSF.
المسؤوليات الرئيسية
ضمان الأمن وإدارة المخاطر
قيادة تقييمات الأمن ومراجعات البنية التحتية وإدارة الثغرات وأنشطة الضمان. إنشاء وتشغيل إطار عمل ضمان الأمن الهيكلي الذي يغطي التحقق من الضوابط وتتبع التغطية وضمان الاستمرارية. إدارة دورة حياة الأمن الكاملة بدءًا من تحديد المخاطر وحتى العلاج والتحقق. ترجمة النتائج الفنية إلى بيانات مخاطر على مستوى الأعمال وخطط العلاج.
أمن التطبيقات والسحابة والبنية التحتية
إجراء تقييمات أمنية متعمقة للتطبيقات الويب وواجهات برمجة التطبيقات والتطبيقات المحمولة ومنصات السحابة والحاويات والبنية التحتية. تحديد المخاطر الأمنية المتقدمة مثل عيوب المنطق التجاري وضعف المصادقة وإساءة استخدام الامتيازات وتقنيات الهجوم الحديثة. التحقق من البنى الأمنية الآمنة وخطوط الأساس للتكوين والضوابط الأمنية الأصلية للسحابة. دعم ممارسات SDLC الآمنة وDevSecOps، بما في ذلك اختبار الأمن وضوابط الإصدار.
خطوط الأساس للتكوين والتقوية المستمرة (جديد)
تعريف والحفاظ على خطوط الأساس للتكوين الآمن عبر مجموعة تكنولوجيا المؤسسة (نظم التشغيل وقواعد البيانات وأجهزة الشبكة وخدمات السحابة ومنصات الهوية وأدوات الأمن). محاذاة الخطوط الأساسية مع المعايير الصناعية (مثل معاير CIS) ومتطلبات مخاطر المؤسسة. تنفيذ عمليات التحقق التلقائي من الامتثال للتكوين ومراقبة الاستمرارية. إجراء مراجعات دورية للتحقق من التكوينات لاكتشاف الانحرافات وسوء التكوين والتغييرات غير المصرح بها. العمل مع فرق الهندسة والعمليات لفرض معايير التقوية ومعالجة الانحرافات.
البنية التحتية، نمذجة التهديدات والتصميم الآمن
قيادة مراجعات بنية الأمن والتصميم عبر التطبيقات والمنصات والتكاملات. إجراء نمذجة التهديدات لتحديد مسارات الهجوم والمخاطر واستراتيجيات التخفيف. ضمان التوافق مع بنية أمن المؤسسة ومبادئ الثقة الصفرية.
الطرف الثالث، حماية البيانات والمرونة
إجراء تقييمات أمنية للموردين ومزودي SaaS والتكاملات الخارجية. التحقق من حماية البيانات وضوابط التشفير والخصوصية للبيانات الحساسة والمنظمة. دعم أنشطة المرونة السيبرانية، بما في ذلك مراجعات أمن OT/ICS وتمارين الفريق الأحمر ومحاكاة استجابة الحوادث.
الإشراف والامتثال والإبلاغ
ضمان التوافق المستمر مع المتطلبات التنظيمية وإطار العمل (ISO 27001، NIST CSF، هيئة الإنترنت الوطنية القطرية، QCSF). دعم عمليات التدقيق الداخلية والخارجية مع ضوابط قائمة على الأدلة. تعريف والإبلاغ عن مقاييس الأمن ومؤشرات الأداء الرئيسية ولوحات المعلومات التنفيذية.
الخبرة والمهارات المطلوبة
8 سنوات على الأقل من الخبرة في تقييمات وضمان أمن المعلومات. خبرة قوية في أمن التطبيقات وواجهات برمجة التطبيقات والتطبيقات المحمولة والسحابة. خبرة عملية في اختبار الاختراق وإدارة الثغرات ومراجعات بنية الأمن. خبرة عملية في تقوية الأنظمة وخطوط الأساس للتكوين والتحقق من ضوابط الأمن. فهم عميق لتقنيات الهجوم الحديثة وآليات الهوية/المصادقة. القدرة المثبتة على توصيل المخاطر الفنية لأصحاب المصلحة في الأعمال.
الشهادات المفضلة
OSCP / OSEP / OSWE
CISSP
شهادات أمن السحابة (Azure / GCP)
IEC 62443