وصف الوظيفة
رئيس أمن المعلومات هو التنفيذي المسؤول عن وظيفة أمن معلومات منظمة العميل. يتولى الدور حماية أصول المعلومات الخاصة بالمنظمة من خلال تحديد استراتيجية الأمن وضمان الإدارة الفعالة للمخاطر والتهديدات التي قد تؤثر على المنظمة. يوفر رئيس أمن المعلومات القيادة في تأسيس بيئة تشغيل آمنة ومرنة، ويعزز ثقافة أمنية قوية، ويضمن الامتثال للمتطلبات التنظيمية والحوكمة المعمول بها. كونه مسؤولاً تنفيذياً رفيع المستوى، يقدم رئيس أمن المعلومات المشورة للإدارة التنفيذية في الشؤون المتعلقة بالأمن ويتأكد من أن أهداف الأمن تظل متوافقة مع أولويات الأعمال وأهداف المؤسسة.
المسؤوليات الأساسية:
1. وضع فهم عميق لأهداف عمل المنظمة وظروف التشغيل وأصول المعلومات الحرجة.
2. تحديد استراتيجية أمن المعلومات والتأكد من توافقها مع أهداف الشركة.
3. إنشاء والحفاظ على إطار حوكمة الأمن داخل المنظمة.
4. تحديد والإشراف على السياسات الأمنية والمبادرات الأمنية الإستراتيجية.
5. ضمان تحديد وتقييم وإدارة مخاطر الأمن بالشكل المناسب.
6. تعزيز الوعي الأمني وتبنّي ثقافة المساءلة عبر المؤسسة.
7. توفير إشراف تنفيذي خلال الحوادث الأمنية الكبيرة والظروف crisis.
8. ضمان الامتثال للوائح والمعايير وحوكمة المتطلبات المعمول بها.
9. تقييم دورياً فاعلية قدرات الأمن والمبادرات التحسينية في المنظمة.
10. تعريف مقاييس تنفيذية ومؤشرات أداء لقياس فاعلية الأمن والتعرض للمخاطر.
11. الإبلاغ بانتظام لقيادة التنفيذيين عن وضع الأمن في المنظمة والمخاطر الرئيسية والأولويات الاستراتيجية.
12. تنسيق الأنشطة المتعلقة بالأمن مع قادة الأعمال وأصحاب المصلحة المؤسسيين الرئيسيين.
13. العمل كنقطة المحاذاة الأساسية بين أولويات الأعمال وأهداف الأمن.
14. الإشراف على مخاطر الأمن من الأطراف الثالثة وضمان الحوكمة المناسبة لمقدمي الخدمات الخارجيين.
15. تحديد أولويات الاستثمار الإستراتيجي وإدارة ميزانية الأمن لدعم أهداف الأعمال.
16. رئاسة أو رعاية لجنة حوكمة الأمن في المنظمة.
المهارات
المواطن القطري (إلزامي)
• خبرة لا تقل عن 10 سنوات ذات صلة في أمن المعلومات، إدارة مخاطر السايبر، أو أدوار قيادية مشابهة.
• خبرة لا تقل عن 3–5 سنوات في إدارة عمل مشابه – قيادة وظيفة أمن معلومات / cybersecurity أو تقديم المشورة على مستوى تنفيذي.
• خبرة في تعريف استراتيجية أمن المعلومات بما يتوافق مع أهداف الأعمال، وإدارة مخاطر وتهديدات الأمن بشكل شامل.
• إثبات القدرة على التواصل والتأثير على الإدارة التنفيذية والأنظمة والجهات المعنية الرئيسية.
• خبرة في قيادة فرق متعددة التخصصات وإدارة مواقف وحوادث معقدة وبضغط عالٍ.
• إدارة مخاطر أمن المعلومات وتحديد استراتيجية الأمن
• فهم قوي لأطر الأمن والمخاطر والحوكمة والتنظيمية
• القدرة على ترجمة متطلبات الأمن إلى أولويات عمل ومبادرات استراتيجية
• القدرة على تعزيز ونشر ثقافة الأمن عبر المؤسسة
• قيادة الحوادث الأمنية والأزمات
تقني
• استراتيجية الأمن والحوكمة
• إدارة المخاطر والتهديدات
• التنظيم والامتثال (NCSA, NIA, CIIP, PDPPL)
• الهندسة الأمنية والمرونة
• إدارة الحوادث والأزمات
• حوكمة الأمن لدى الأطراف الثالثة / البائعين
Job description
The Head of Information Security is the executive accountable for the client organization’s information security function. The role is responsible for protecting the organization’s information assets by defining the security strategy and ensuring effective management of the risks and threats that may impact the organization. The Head of Information Security provides leadership in establishing a secure and resilient operating environment, promotes a strong security culture, and ensures compliance with applicable regulatory and governance requirements. As a senior executive, the Head of Information Security advises executive management on security-related matters and ensures that security objectives remain aligned with business priorities and organizational goals.
Key Responsibilities:
1. Develop a deep understanding of the organisation’s business objectives, operating environment and critical information assets.
2. Define the information security strategy and ensure alignment with corporate objectives.
3. Establish and maintain the organization’s security governance framework.
4. Define and oversee security policies and strategic security initiatives.
5. Ensure that security risks are identified, assessed and managed appropriately.
6. Promote security awareness and foster a culture of accountability across the organization.
7. Provide executive oversight during significant security incidents and crisis situations.
8. Ensure compliance with applicable regulations, standards and governance requirements.
9. Periodically assess the effectiveness of the organization’s security capabilities and improvement initiatives.
10. Define executive metrics and performance indicators to measure security effectiveness and risk exposure.
11. Report regularly to executive leadership on the organization’s security posture, key risks and strategic priorities.
12. Coordinate security-related activities with business leaders and key corporate stakeholders.
13. Act as the primary point of alignment between business priorities and security objectives.
14. Oversee third-party security risks and ensure appropriate governance of external service providers.
15. Define strategic investment priorities and manage the security budget to support business objectives.
16. Chair or sponsor the organization’s security governance committee.
Skills
Qatari National (mandatory)
• Minimum 10+ years of relevant experience in information security, cyber risk management, or related leadership roles.
• Minimum 3–5 years of experience managing similar work – leading an information security / cybersecurity function or advising at executive level.
• Experience defining an information security strategy aligned with business objectives, and managing security risks and threats end-to-end.
• Demonstrated experience with Qatar’s regulatory frameworks (NCSA, NIA, CIIP, PDPPL).
• Proven ability to engage and influence executive management, boards and key stakeholders.
• Experience leading multidisciplinary teams and managing complex, high-pressure situations and incidents.
• Information security risk management and security strategy definition
• Strong understanding of security, risk, governance and regulatory frameworks
• Ability to translate security requirements into business priorities and strategic initiatives
• Ability to promote and foster a security-aware culture across the organisation
• Security incident and crisis leadership
Technical
• Security strategy & governance
• Risk & threat management
• Regulatory & compliance (NCSA, NIA, CIIP, PDPPL)
• Security architecture & resilience
• Incident & crisis management
• Third-party / vendor security governance