وظائف مفتش أمن في قطر
٣٦٢٢ وظائف شاغرة
Job Description<br><br>We are seeking a skilled Application Security Specialist to join our Cybersecurity Practice. In this role, you will work closely with our application security, development, and QA teams to secure our clients’ applications across their entire lifecycle. You will conduct security testing, perform penetration tests, and assess vulnerabilities across web, mobile, API applications.<br><br>Your responsibilities will span application penetration testing, automated security scanning (SAST, DAST, SCA), threat modelling, secure code review, and developer enablement. You will embed security best practices throughout the software development lifecycle and ensure that applications are designed and built with robust security controls.<br><br>You will collaborate with development and Dev Ops teams to integrate security into CI/CD pipelines, triage and validate findings, and provide clear, actionable remediation guidance. The role requires hands-on technical expertise, strong analytical skills, and the ability to translate complex security findings into practical fixes that developers can implement.<br><br>Responsibilities<br><br>Penetration Testing:Conduct penetration tests on web applications, mobile applications, APIs, and thick-client applications. Prepare detailed reports with clear risk ratings and actionable remediation recommendations. Security Scanning:Implement, tune, and manage automated security scanning tools (SAST, DAST, SCA) to continuously identify vulnerabilities in code, configurations, and third-party dependencies across all application types. Threat Modelling:Perform threat modelling to identify potential security risks and attack surfaces associated with applications early in the design process, and provide guidance on mitigating these risks. Secure Code Review:Review application source code for security vulnerabilities across multiple platforms and languages, and offer practical, developer-friendly recommendations for remediation. Dev Sec Ops Integration:Integrate security testing and controls into CI/CD pipelines, enabling continuous and automated security validation as part of the development workflow. Training & Awareness:Develop and deliver secure coding training sessions and workshops to raise application security awareness among development teams and other stakeholders. Tool Evaluation:Assess and recommend tools and technologies to enhance application security testing and monitoring capabilities across various platforms. Documentation:Create and maintain comprehensive documentation related to security assessments, vulnerability management, and application security standards and policies.<br><br>Qualifications<br><br>Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field. Experience: At least 3 years of experience in application security, secure software development, penetration testing, or a closely related field. Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:Off Sec certifications (e.g., OSWA, OSWE)e Learn Security (e.g., e WPT, e WPTX) GIAC / SANS (e.g., SEC542, GWAPT) BCSP or other application security certifications. Technical Skills: Proficiency with security testing tools such as Burp Suite (required), and familiarity with Snyk, HCL App Scan, Fority, and Postman (preferred). Strong understanding of secure coding practices and hands-on experience with at least one programming language. Familiarity with Dev Sec Ops practices and CI/CD pipelines is preferred. Knowledge: In-depth knowledge of application security principles and practices, with strong familiarity with security frameworks and guidelines (e.g., OWASP Top 10, ASVS, MASVS, WSTG, MSTG). Understanding of common vulnerability classes, exploitation techniques, and remediation strategies. Knowledge of Qatar National Information Assurance (NIA) is a plus.
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><b>Purpose:</b></p><p>- To report on implementation effectiveness of security strategy, security performance outputs and related risk, compliance/non-conformance, incident’s outcome and investigation findings.</p><p>- To apply operational management response so as to ensure effective implementation of security strategy, attain security performance requirements, mitigate security related risk, achieve regulatory and obligation compliance.</p><p><b>External Communication:</b></p><p>Contracted manned security supplier.</p><p><b>Purpose:</b></p><p>- To manage effective application of Security strategy with the operational environment, Milaha HSSEQ framework, HSSEQ related risk identification and control processes, Compliance mapping</p><p><b><u>Occupational Health & Safety and Environment</u></b></p><p><b>Accountability:</b></p><p>Are accountable for their acts and omissions.</p><p><b>Responsibility:</b></p><p>To follow agreed safe systems of work; to follow training and instructions; and to report accidents, incidents and near misses.</p><p><b>Authority:</b></p><p>To stop work if they think the work is unsafe.</p><p> </p><p>Responsibilities</p><p><b><u>Key Roles & Responsibilities</u></b></p><p>• To oversee and ensure implementation Shipyard Security Plan.</p><p>• To ensure that all incoming visitors are coordinated and escorted by the point of contact during site visit and inspection.</p><p>• To observe and report any security concerns noted in the Shipyard to ensure proper protection of Milaha employees, properties and all items of value on the organization's premises from any preventable harm or danger.</p><p>• To deliver security induction and control issuance of Jetty Pass.</p><p>• To conduct physical assessment to ensure compliance with security policies and standards.</p><p>• To deliver security updates and share relevant information regarding security concerns and requirements to the security guards.</p><p>• Ensure implementation of/adherence to security policies and procedures to comply with Legal & regulatory guidelines, requirements, and standards.</p><p>• Investigate any reported suspicious activities that take place to security management.</p><p>• To review and recommend updates to the Shipyard Security Plan for approval of MOI and Milaha Management.</p><p>• Respond to emergencies by calling the police, ambulance or fire brigade if required.</p><p>• Oversee the general appearance of the security guards to be within standards.</p><p>• Perform other job-related duties as assigned.</p><p> </p><p>Qualifications</p><p><b>Education & Professional Qualification:</b></p><p>Diploma in related field</p><p><b>Professional Experience: </b></p><p>2-3 Years of experience in related field</p><p><b>Geographic Experience: </b></p><p>- Within Qatar or middle east</p><p><b>Computer Skills: </b></p><p>Basic knowledge of office application and web applications</p><p><b>Language Skills: </b></p><p>- Able to write and speak English, Arabic will be an advantage.</p><p><b>Market/Industry/Functional Knowledge: </b></p><p>Good knowledge of local laws and regulations</p> </div><h2 class="h5">Skills</h2>
<div data-jb-field="skills"><p>To organize and monitor physical security activities and operations at Milaha Shipyard in coordination with relevant departments, business units, contractors, and government authorities to ensure compliance with the Security Plan, Job Post Orders, and instructions from security management.</p><p><br></p><p>To ensure that all security personnels are alert and performing the jobs assigned to them. To disseminate instruction and gather information that are essential for the day-to-day operation of the security at the site.</p><p><br></p><p>To ensure that all security requirements for non-security personnel to gain entry at the site are communicated for compliance.</p><p><br></p></div>
Role Purpose<br><br>The Data Security Consultant assesses data-security risks and supports the design, implementation and validation of security controls for client data, platforms, integrations and analytics solutions. The role converts approved security, privacy and classification requirements into practical technical and operational measures covering identity, access, encryption, monitoring, incident response and resilience.<br><br>The consultant works alongside security leadership, architects, engineers, platform teams, compliance specialists and client system owners. It may implement or test authorised controls within client environments, but privileged authority, production ownership and risk acceptance remain with the client. The role is expected to produce clear requirements, evidence, remediation guidance and handover documentation, and to communicate technical findings in terms of business exposure and operational action.<br><br>Key Responsibilities<br><br>Assess data-security risks, threat exposure, control design, configurations and available operational evidence. Translate security, privacy and classification requirements into technical and procedural control specifications. Review identity, authentication, authorisation, role design, privileged access and segregation of duties. Assess encryption, key management, secrets handling, secure transfer and data-masking requirements. Review security for APIs, integrations, pipelines, storage, analytics platforms and shared datasets. Evaluate logging, monitoring, alerting, vulnerability management and incident-response arrangements. Support security testing, evidence collection, defect triage and remediation validation. Develop risk records, control matrices, implementation actions, exceptions and residual-risk summaries. Coordinate security requirements with architecture, engineering, platform, privacy, audit and operations teams. Support backup, recovery, continuity and secure-disposal controls affecting client data. Prepare security guidance, configuration standards, test evidence and operational handover material. Deliver security walkthroughs and role-based knowledge transfer to client teams.<br><br>Minimum Requirements<br><br>Education<br><br>Bachelor's degree in cybersecurity, computer science, information systems or a related field. An equivalent combination of relevant education and directly applicable consulting or implementation experience may be considered.<br><br>Professional Experience<br><br>Typically 4-8 years in information security, security engineering or technology risk. Experience in cybersecurity, information security, security engineering, technology risk or related roles. Experience assessing or implementing controls for data platforms, cloud services, APIs or enterprise systems. Experience with identity, encryption, logging, vulnerability management and incident response. Experience documenting findings and communicating remediation priorities to technical and business stakeholders.<br><br>Technical and Domain Knowledge<br><br>Security assessment, threat and risk analysis. Identity and access management and privileged-access controls. Encryption, key management, secure transfer and data masking. API, integration, pipeline, platform and cloud security. Logging, monitoring, vulnerability and incident management. Classification, privacy, retention and secure-disposal controls. Backup, recovery, resilience and continuity safeguards. Security evidence, testing, remediation and exception management.<br><br>Core Competencies<br><br>IAM. Risk assessment. Monitoring. Incident response. Secure architecture. Security mindset. Technical judgement. Incident awareness. Conducting security discovery and control walkthroughs. Explaining technical vulnerabilities in business-impact language. Writing clear requirements, findings and remediation guidance. Working safely within privileged and controlled client environments. Collaborating across security, data, technology and compliance teams. Maintaining confidentiality and complete evidence records. Supporting client risk decisions without assuming risk-acceptance authority.<br><br>Preferred Certifications<br><br>CISSP for senior positions CISMRelevant cloud-security certification<br><br>Focus areas<br><br>Security controls IAMRisk assessment<br><br>Ready to apply for this role?<br><br>Apply for Data Security Consultant
We currently have an opportunity for a Senior ICS Security Engineer role. This position is based in Qatar onshore.<br> <br>Duration Two (2) year initial contract with a possibility of extension.<br>Work location Onshore (Ras Laffan/Doha HQ)<br> <br>Key Job Accountabilities<br>Implements Industrial Control Systems (ICS) Security engineering, supports the ICS Security sustainment activities, provides project support and participates in ICS Security audits, risk assessments, technology evaluations, & self-assessments, advises ICS Custodians and ICSE Technicians to ensure ICS Security maintenance performance is achieved, and supports in periodic reviews of ICS security equipment strategies, ICS Security Policy and Design Specifications.<br>Support the implementation of ICS Security engineering specifications and related procedures, work practices, , manuals, and development of equipment strategies for new projects. Identify limitations of existing systems, recommend best practices and upgrades.<br>Review the design such as System Architecture, Network Architecture, Functional Design Specifications, Detailed Design Specifications, Interface Agreements and ensure compliance to ICS Security engineering specifications.<br>Participate, review the ICS risk assessments, technology evaluations, and deviation requests, DRP (Disaster Recovery Plan) simulations.<br>Validate the system built through FAT, SAT for the department. <br>Coordinate and ensure deliverables as per the Operational Readiness Procedure to ensure smooth handover to ICS Security Operations.<br>Participate in ICS Security incident investigations or Root Cause Failure Analysis, continuous improvement and productivity enhancement initiatives.<br>Serve as focal point to ICS Security Custodians and ICSE Technicians to ensure alignment with the ICS Security Policy & Specifications.<br>Provide technical support for clarifying, following and implementing ICS Security Policy requirements across engineering sections, development teams, expansion teams, and operations.<br>Support in planning and conducting periodic ICS Security self-assessments to evaluate compliance to the ICS Security Policy.<br>Participate in life cycle management review of ICS in scope inventory and update inventory periodically.<br> <br>Qualifications<br>Bachelor’s degree in Engineering (Instrumentation & Control, Electrical, Electronic, Computer) or Computer Science. <br> <br>Knowledge and Experience<br>6 years’ experience in Oil and Gas Industry operations, technical, engineering with ICS Security Experience.<br>Experience of implementing security controls within an OT environment.<br>Understanding of different Industrial Control Systems environments. <br>ICS System Security Experience, Knowledge of Networking, Security tools , Knowledge of ICS Security monitoring like IDS/IPS, SIEM etc.,<br> <br>Technical and Business Skills <br>Proficient in written and spoken English.<br>Computer Literate.<br>Excellent interpersonal skills, highly proficient in handling personnel, administrative, organizational and logistical issues. <br>Solve issues associated with ICS Security design, sustainment.<br>Lead ownership of issues related to ICS Security to support and drive continuous improvement.<br> <br><br>People are our business worldwide<br> <br>Orion Group was founded in 1987 and is now one of the largest, independent, international recruitment companies. We have a network of 200 employees working from 24 offices, delivering a range of services – Talent Acquisition, Recruitment Outsourcing Services, Retained Search, Global Workforce Solutions, Completions & Commissioning and Materials Management – across 68 countries. As a global leader in workforce solutions, we recruit personnel across the Engineering & Technical, Office & Commercial, Scientific and Skilled Trades disciplines, for sectors including Oil & Gas, Life Science, Power & Utilities, Constructions & Infrastructure, Manufacturing and Renewables.
Job Overview<br><br>An established organization is seeking an experienced Security Supervisor to lead and oversee security operations across commercial facilities. The successful candidate will be responsible for supervising security personnel, ensuring compliance with security procedures, coordinating emergency response activities, and maintaining a safe and secure environment for clients, employees, and visitors.<br><br>Key Responsibilities<br><br>Supervise and coordinate security officers during assigned shifts. Monitor access control systems and CCTV operations to ensure effective site security. Conduct routine site patrols, inspections, and security checks. Manage security incidents, investigations, and incident reporting. Ensure compliance with company policies, client requirements, and established security procedures. Coordinate and support emergency response activities when required. Train, mentor, and evaluate security personnel to maintain high performance standards. Prepare daily, weekly, and incident reports for management and clients.<br><br>Requirements<br><br>Minimum 5 years of experience in the security industry. Previous experience in a supervisory or team leadership role. Fluent in Arabic and English (spoken and written). Willing and able to attend client interviews prior to deployment. Strong leadership, communication, and problem-solving skills. Ability to manage teams, respond effectively to incidents, and maintain operational discipline.<br><br>Preferred Qualifications<br><br>Security-related certifications. Valid First Aid Certificate. Valid Qatar Driving Licence.
Job Overview<br><br>An established organization is seeking an experienced Security Supervisor to lead and oversee security operations across commercial facilities. The successful candidate will be responsible for supervising security personnel, ensuring compliance with security procedures, coordinating emergency response activities, and maintaining a safe and secure environment for clients, employees, and visitors.<br><br>Key Responsibilities<br><br>Supervise and coordinate security officers during assigned shifts. Monitor access control systems and CCTV operations to ensure effective site security. Conduct routine site patrols, inspections, and security checks. Manage security incidents, investigations, and incident reporting. Ensure compliance with company policies, client requirements, and established security procedures. Coordinate and support emergency response activities when required. Train, mentor, and evaluate security personnel to maintain high performance standards. Prepare daily, weekly, and incident reports for management and clients.<br><br>Requirements<br><br>Minimum 5 years of experience in the security industry. Previous experience in a supervisory or team leadership role. Fluent in Arabic and English (spoken and written). Willing and able to attend client interviews prior to deployment. Strong leadership, communication, and problem-solving skills. Ability to manage teams, respond effectively to incidents, and maintain operational discipline.<br><br>Preferred Qualifications<br><br>Security-related certifications. Valid First Aid Certificate. Valid Qatar Driving Licence.
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>Identity Security / Security Engineering<br><br></p><p><br></p><p>We are currently looking Identity Security Consultant our Qatar operations.<br><br></p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><ul><li>8+ years in Identity Security / Security Engineering</li><li>Deep hands on experience with:</li><ul><li>Active Directory security</li><li>Active Directory Security</li><li>Active Directory hardening</li><li>Identity Security</li><li>Red team remediations</li></ul><li>Understanding of red team findings</li><li>Change management</li></ul><p></p></section>
Primary Purpose Of The Job<br><br>Governance and execution of the Information Security Management System (ISMS) including developing policies,standards and procedures required for the corporate information security in both an Information technology (IT) and Operational Technology (OT) capacity. Define required information security policies, standards and procedures related to their areas of operation as well as raising awareness of those polices, standards and procedures. Ensure adequate an effective IT controls exist to meet applicable current and future security compliance requirements. --Conduct compliance and operational maturity assessments to ensure optimal operation of the information and operational technology environments under the guidelines of the ISMS. Develop reporting Metrics, dashboards and evidences of compliance activities. Coordinate with IT stakeholders, project managers, and business owners to facilitate vendor risk assessments, due diligence review and security requirements definition. Maintain third-party assessment documentation.<br><br>Stay updated on the latest security trends, emerging threats and best practices to continuously improve the overall security posture.<br><br>Collaborate with cross-functional teams, including AI and digital functions, to ensure alignment of security governance with emerging technologies and applied intelligence initiatives. Carry out other Security related activities as assigned by team Lead.<br><br>Required Experience And Skills<br><br> Bachelor degree in information security, computer science, or engineering. Professional certifications in information security management and standards compliance (e.g., CISSP, CISM, CRISC, GIAC, ISO27001, etc.) and experience with control frameworks (e.g., NIST Cybersecurity Control Framework)<br><br>Educational Qualifications<br><br> 10+ years of relevant professional experience. Experience with large ICS & ICT environments in the Energy sector, preferably in Oil & Gas. Experience with and understanding of customized information security management systems. Experience in defining Governance, Risk, and Compliance (GRC) processes and leveraging industry-standard GRC tools and products. Knowledge of information security capabilities and requirements analysis. Knowledge of relevant state laws, industry regulations, and security standards. Excellent written, verbal and presentation communication skills
About the Role:We are seeking a skilled Application Security Specialist to strengthen the security of applications across their full lifecycle. You will work closely with development, Dev Ops, and QA teams to ensure secure design, development, and deployment of web, mobile, API, and thick-client applications. The role focuses on identifying vulnerabilities, performing security testing, enabling secure coding practices, and integrating security into CI/CD pipelines as part of a Dev Sec Ops approach.<br>Key Responsibilities:Conduct penetration testing across web, mobile, API, and thick-client applications. Perform automated security scanning (SAST, DAST, SCA) to identify vulnerabilities in code, configurations, and dependencies. Carry out threat modelling during the design phase to identify risks and define mitigation strategies. Perform secure code reviews and provide developer-friendly remediation guidance. Integrate security controls into CI/CD pipelines to enable Dev Sec Ops practices. Develop and deliver secure coding training and awareness sessions for development teams. Evaluate and recommend application security tools and technologies. Prepare and maintain documentation for security assessments, vulnerabilities, and application security standards.<br>Required Skills & Experience:3+ years of experience in application security, secure software development, or penetration testing. Strong hands-on experience with web, mobile, API, and application security testing. Proficiency with Burp Suite (required) and familiarity with tools such as Snyk, HCL App Scan, Fortify, and Postman. Strong understanding of secure coding practices and at least one programming language. Experience with Dev Sec Ops and CI/CD pipeline integration. Strong knowledge of OWASP Top 10, ASVS, MASVS, WSTG, and MSTG. Understanding of vulnerability classes, exploitation techniques, and remediation approaches. Strong analytical, reporting, and communication skills.<br>Qualifications:Bachelor’s degree in Computer Science, Information Security, or related field.<br>Preferred Certifications:Off Sec (OSWA, OSWE)e Learn Security (e WPT, e WPTX) GIAC / SANS (SEC542, GWAPT) Other relevant application security certifications<br>Additional Advantage:Knowledge of Qatar National Information Assurance (NIA) framework.
Primary Purpose Of The Job<br><br>Governance and execution of the Information Security Management System (ISMS) including developing policies,standards and procedures required for the corporate information security in both an Information technology (IT) and Operational Technology (OT) capacity. Define required information security policies, standards and procedures related to their areas of operation as well as raising awareness of those polices, standards and procedures. Ensure adequate an effective IT controls exist to meet applicable current and future security compliance requirements. --Conduct compliance and operational maturity assessments to ensure optimal operation of the information and operational technology environments under the guidelines of the ISMS. Develop reporting Metrics, dashboards and evidences of compliance activities. Coordinate with IT stakeholders, project managers, and business owners to facilitate vendor risk assessments, due diligence review and security requirements definition. Maintain third-party assessment documentation.<br><br>Stay updated on the latest security trends, emerging threats and best practices to continuously improve the overall security posture.<br><br>Collaborate with cross-functional teams, including AI and digital functions, to ensure alignment of security governance with emerging technologies and applied intelligence initiatives. Carry out other Security related activities as assigned by team Lead.<br><br>Required Experience And Skills<br><br> Bachelor degree in information security, computer science, or engineering. Professional certifications in information security management and standards compliance (e.g., CISSP, CISM, CRISC, GIAC, ISO27001, etc.) and experience with control frameworks (e.g., NIST Cybersecurity Control Framework)<br><br>Educational Qualifications<br><br> 10+ years of relevant professional experience. Experience with large ICS & ICT environments in the Energy sector, preferably in Oil & Gas. Experience with and understanding of customized information security management systems. Experience in defining Governance, Risk, and Compliance (GRC) processes and leveraging industry-standard GRC tools and products. Knowledge of information security capabilities and requirements analysis. Knowledge of relevant state laws, industry regulations, and security standards. Excellent written, verbal and presentation communication skills
Primary Purpose Of The Job<br><br>Governance and execution of the Information Security Management System (ISMS) including developing policies,standards and procedures required for the corporate information security in both an Information technology (IT) and Operational Technology (OT) capacity. Define required information security policies, standards and procedures related to their areas of operation as well as raising awareness of those polices, standards and procedures. Ensure adequate an effective IT controls exist to meet applicable current and future security compliance requirements. --Conduct compliance and operational maturity assessments to ensure optimal operation of the information and operational technology environments under the guidelines of the ISMS. Develop reporting Metrics, dashboards and evidences of compliance activities. Coordinate with IT stakeholders, project managers, and business owners to facilitate vendor risk assessments, due diligence review and security requirements definition. Maintain third-party assessment documentation.<br><br>Stay updated on the latest security trends, emerging threats and best practices to continuously improve the overall security posture.<br><br>Collaborate with cross-functional teams, including AI and digital functions, to ensure alignment of security governance with emerging technologies and applied intelligence initiatives. Carry out other Security related activities as assigned by team Lead.<br><br>Required Experience And Skills<br><br> Bachelor degree in information security, computer science, or engineering. Professional certifications in information security management and standards compliance (e.g., CISSP, CISM, CRISC, GIAC, ISO27001, etc.) and experience with control frameworks (e.g., NIST Cybersecurity Control Framework)<br><br>Educational Qualifications<br><br> 10+ years of relevant professional experience. Experience with large ICS & ICT environments in the Energy sector, preferably in Oil & Gas. Experience with and understanding of customized information security management systems. Experience in defining Governance, Risk, and Compliance (GRC) processes and leveraging industry-standard GRC tools and products. Knowledge of information security capabilities and requirements analysis. Knowledge of relevant state laws, industry regulations, and security standards. Excellent written, verbal and presentation communication skills
Job Overview<br><br>An established organization is seeking an experienced Security Supervisor to oversee security personnel and ensure the effective delivery of security operations across commercial facilities.<br><br>Key Responsibilities<br><br>Supervise security officers during assigned shifts. Monitor access control and CCTV operations. Conduct routine patrols and inspections. Manage incident reporting and investigations. Ensure compliance with security procedures. Coordinate emergency response activities. Train and mentor security staff. Prepare operational reports.<br><br>Requirements<br><br>Minimum 5 years' experience in the security industry. Previous supervisory experience. Fluent in both Arabic and English (spoken and written). Able to attend client interviews before deployment. Strong leadership and communication skills.<br><br>Preferred<br><br>Security-related certifications. First Aid Certificate. Valid Qatar Driving Licence.
About Accenture<br><br>Accenture helps the world’s leading enterprises reinvent by building their digital core and unleashing the power of AI to create value at speed for organizations across industries. Our strategy is to be the reinvention partner of choice for our clients and lead in the safe, widespread adoption of AI, and to be the most client-focused, AI-enabled, great place to work in the world. We bring together the talent of our approximately 786,000 people with proprietary assets and platforms, deep process and industry expertise, and leading ecosystem relationships to deliver end-to-end solutions and measurable outcomes at scale. Through our Reinvention Services, we offer broad expertise across Cybersecurity, Digital Core, Finance, Industry and Enterprise, Song, Supply Chain and Engineering, and Talent, with advanced capabilities in AI and Data, Industry and Process, and Technology. We serve approximately 9,000 clients and generated approximately $70 billion in FY25 revenue. Visit us at accenture.com.<br><br>About Accenture Security<br><br>Accenture Security helps organizations prepare for, prevent, detect, respond to, and recover from cyber threats. We bring together deep industry knowledge, advanced security capabilities, and cutting-edge technology to help our clients protect their most critical assets, comply with regulatory requirements, and build resilient security programs.<br><br>Role Overview<br><br>We are looking for a Cloud Security Specialist to strengthen the security posture of our cloud environments, with a strong focus on Google Cloud Platform (GCP) and exposure to AWS and Azure. You will work closely with engineering, Dev Ops, and security teams to design, implement, and operate secure cloud‑native solutions while ensuring compliance with industry and regulatory standards.<br><br>Key Functions<br><br><br>Design and implement security controls across multi‑cloud environments, with primary focus on GCP<br>Secure cloud‑native services including Google Kubernetes Engine (GKE), Compute Engine, and Cloud Storage<br>Implement and manage identity, access, and network security controls across cloud platforms<br>Embed security into CI/CD pipelines and Dev Ops workflows, enabling secure‑by‑design cloud solutions<br><br><br>Responsibilities<br><br><br>Design, deploy, and maintain cloud security architectures aligned with best practices and the shared responsibility model<br>Implement Identity and Access Management (IAM) and Identity‑Aware Proxy (IAP) to enforce least‑privilege access<br>Configure and enforce network security controls using VPCs, Cloud Armor, Cloud VPN, and firewall rules<br>Implement data protection mechanisms including encryption, key management, and data loss prevention using Cloud KMS and Secret Manager<br>Monitor, detect, and respond to cloud security events leveraging Security Command Center, Cloud Logging, and Cloud Monitoring<br>Perform cloud security assessments, vulnerability analysis, and misconfiguration reviews<br>Support cloud‑related incident response and forensic activities<br>Integrate security controls into Infrastructure as Code (Terraform or similar)<br>Ensure compliance with frameworks such as ISO 27001, NIST, and National Cybersecurity Authority (NCA / ECC)<br>Develop and maintain cloud security policies, standards, and hardening guidelines<br>Partner with engineering teams to remediate findings and continuously improve security posture<br><br><br>Qualifications<br><br><br>3–6 years of experience in cloud security, cybersecurity, or infrastructure security<br>Hands‑on experience securing at least one major cloud platform (GCP preferred)<br>Strong understanding of cloud architecture and the shared responsibility model<br>Solid knowledge of:<br>Identity and Access Management<br>Network security, segmentation, firewalls, and private connectivity<br>Data protection and encryption practices<br>Experience with cloud security services such as:<br>Security Command Center<br>Cloud KMS<br>Cloud Armor<br>Ability to identify, analyze, and remediate cloud misconfigurations and vulnerabilities<br>Familiarity with Infrastructure as Code (Terraform or similar)<br>Experience integrating security into CI/CD pipelines<br>Understanding of compliance frameworks (ISO 27001, NIST, NCA/ECC preferred)<br>Strong troubleshooting, documentation, and communication skills<br>Ability to work independently and proactively drive security initiatives<br><br>To learn more about life @AccentureMiddleEast, follow us on social media and keep up with our latest news . Accenture Middle East Africa : Linked In, Instagram, Facebook, Twitter, You Tube.
Job Description<br><br>We are seeking an experienced Microsoft Security Consultant to join our Cybersecurity Practice. In this role, you will work closely with our cloud, infrastructure, and security teams to design, implement, and operate security controls across the Microsoft security stack to protect our clients' cloud and hybrid environments.<br><br>Your responsibilities will include deploying and configuring Microsoft Defender (including Defender for Endpoint, Defender for Cloud, Defender for Office 365, and Defender for Identity) and Microsoft Purview for data governance, data loss prevention, information protection, insider risk management, and compliance. You will assess existing Microsoft 365 and Azure environments, identify security gaps, harden configurations against established baselines, and continuously monitor these platforms to ensure the confidentiality, integrity, and availability of systems and data.<br><br>You will support the secure adoption of Microsoft cloud services across Microsoft 365, Azure, and hybrid environments, configuring policies and controls that align with organizational requirements, industry standards (such as the Microsoft Cloud Security Benchmark, CIS, and NIST), and Qatari regulatory requirements. This includes implementing conditional access, identity and access management through Microsoft Entra ID, threat detection and response workflows, and compliance and data protection controls through Purview.<br><br>Responsibilities<br><br> Microsoft Security Architecture and Assessment: Assess Microsoft 365, Azure, and hybrid environments to identify security risks and design appropriate controls using native Microsoft capabilities. Conduct security reviews of Azure subscriptions, workloads, and configurations across compute, storage, networking, identity, and platform services, using Microsoft Defender for Cloud secure score and recommendations as a baseline. Provide detailed assessment reports with clear, actionable remediation recommendations aligned with the Microsoft Cloud Security Benchmark, CIS, and NIST. Microsoft Security Governance: Define, implement, and maintain cloud security governance frameworks, including security policies, standards, baselines, and control frameworks built on Azure Policy, Microsoft Defender for Cloud regulatory compliance, and Purview governance capabilities. Establish clear roles and responsibilities through RACI models and support the development of operating procedures to ensure consistent, repeatable, and auditable security practices across Microsoft environments. Security Monitoring and Threat Detection: Implement and operate Microsoft Defender and Microsoft Sentinel to detect misconfigurations, vulnerabilities, and suspicious activities. Analyze alerts and incidents across the Defender XDR portal and Sentinel, build detection rules and analytics, investigate potential incidents, and support timely response and remediation to maintain the confidentiality, integrity, and availability of cloud environments. Identity and Access Management: Review and support the secure implementation of identity and access controls through Microsoft Entra ID, including role-based access control, least privilege, conditional access, multifactor authentication, and Privileged Identity Management across Microsoft cloud platforms and services. Cloud Security Configuration: Implement native Azure security controls including Microsoft Defender for Cloud, network security groups, encryption, key management (Azure Key Vault), and logging and monitoring to enforce a strong security posture. <br><br>Qualifications<br><br> Education: Bachelor’s / college degree in Computer Science, Information Technology, or a related field. Experience: At least 3 years of hands-on experience implementing and configuring Microsoft Azure and Microsoft 365 security solutions, or a closely related role, with demonstrable experience deploying Microsoft Defender and Microsoft Purview. Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to: Microsoft Certified: Security Operations Analyst Associate (SC-200) Microsoft Certified: Identity and Access Administrator Associate (SC-300) Microsoft Certified: Information Protection and Compliance Administrator Associate (SC-400) Microsoft Certified: Azure Security Engineer Associate (AZ-500) Microsoft Certified: Cybersecurity Architect Expert (SC-100) Microsoft Certified: Azure Administrator Associate (AZ-104) or Azure Solutions Architect Expert (AZ-305) Vendor-agnostic security certifications (CISSP, CCSP, CSA CCSK, GIAC, etc.) Technical Skills: Strong hands-on experience deploying and configuring the Microsoft security stack, including Microsoft Defender (Defender for Cloud, Endpoint, Office 365, and Identity), Microsoft Sentinel, Microsoft Purview, and Microsoft Entra ID. Experience with core Azure services across compute, storage, networking, and identity, along with native security tooling such as Key Vault, Network Security Groups, and Azure Policy. Knowledge: Solid understanding of cloud architecture principles and the Microsoft Cloud Adoption Framework and Azure Well-Architected Framework. Working knowledge of security concepts including Zero Trust, least privilege, network segmentation, and encryption, with practical understanding of how Microsoft technologies implement them (Conditional Access, Privileged Identity Management, Defender for Cloud secure score). Familiarity with the Microsoft Cloud Security Benchmark, CIS Benchmarks, NIST, and ISO 27001. Knowledge of Qatar National Information Assurance (NIA) is a plus.
Job Title: Security Operations Officer-Data Security <br>Role Overview We are looking for an experienced Data Security Engineer to design, implement, and manage enterprise-wide data protection strategies across on-premise and multi-cloud environments. This role will focus on securing sensitive data, ensuring regulatory compliance, and embedding security and privacy controls across the data lifecycle, including emerging AI-driven systems.<br>Key Responsibilities<br>1. Data Security Engineering Design and implement data protection controls across enterprise systems, cloud environments, and AI solutions Deploy and manage solutions such as Data Loss Prevention (DLP), data masking, and tokenization Collaborate with application and infrastructure teams to integrate security into the data lifecycle Implement and manage data discovery and classification tools to identify sensitive data Continuously monitor data security posture and generate compliance and risk reports Support incident response by investigating and responding to data breaches and insider threats<br>2. Cloud Data Security Implement and manage data security controls in Google Cloud Platform (GCP) and Microsoft Azure Secure databases, data lakes, and cloud-native storage solutions Configure encryption at rest, in transit, and in use, including BYOK (Bring Your Own Key) strategies Deploy cloud-native data discovery and classification solutions Manage secrets management systems and ensure secure data access Implement governance and protection controls for AI/ML data environments<br>3. Cryptography Define and enforce enterprise cryptographic standards and key management practices Manage encryption strategies for data across all states (at rest, in transit, in use) Ensure compliance with industry and organizational cryptographic standards<br>4. Data Privacy Ensure compliance with global privacy regulations such as GDPR, HIPAA, and PDPPLEmbed privacy-by-design principles into technical implementations Drive enterprise data classification and governance initiatives to protect sensitive data<br>5. Database Security Secure structured and unstructured databases including relational and NoSQL systems Implement Database Activity Monitoring (DAM) and enforce user access controls Conduct regular security reviews, vulnerability assessments, and system hardening<br>6. Collaboration & Governance Collaborate with cross-functional teams on data protection strategies Ensure compliance with Qatar NCSA framework and international standards Conduct vendor and third-party data security assessments Review and approve data-sharing agreements Define and track data security KPIs and metrics Maintain dashboards for continuous monitoring and reporting Stay updated on emerging threats, tools, and best practices<br>Qualifications Bachelor’s degree in Computer Science, Information Security, or related field8+ years of experience in information security with a focus on data protection, cryptography, and database security Experience working in multi-cloud environments (GCP & Azure preferred) Bilingual (Arabic speaker) preferred<br>Certifications (Preferred) CISSP, CCSP, CDPSE, CCSKCloud Security Certifications (GCP / Azure / AWS Security Specialty)<br>Required Skills Hands-on experience with DLP solutions (Forcepoint, Microsoft Purview, Google Cloud DLP) Strong expertise in data masking, tokenization, anonymization, and pseudonymization techniques Experience with data discovery and classification tools (Forcepoint, Microsoft Purview) Proficiency in Database Activity Monitoring tools (Imperva, IBM Guardium) Strong knowledge of cryptographic protocols and Key Management Systems (KMS) Experience securing relational, NoSQL, and data lake environments Expertise in database vulnerability assessments and security audits Hands-on experience with secrets management tools (Hashi Corp Vault, Azure Key Vault, GCP Secret Manager, AWS Secrets Manager) Familiarity with integrating security into CI/CD pipelines
Black & Grey HR is recruiting for an established technology solutions and services provider in Doha, Qatar. Our client is seeking an experienced Security Operations Officer – Data Security Specialist responsible for executing and enhancing security operations, monitoring and responding to threats with a focus on mega sports events and non-event periods. Collaborate across teams to implement effective security measures for information systems.<br>Key Responsibilities Data Security Engineering Design and implement data protection controls across enterprise, cloud environments and Artificial Intelligence Solutions. Deploy and manage solutions such as Data Loss Prevention (DLP), data masking, and tokenization. Collaborate with application and infrastructure teams to embed security into data lifecycle management. Implement and manage data discovery and classification tools to identify, categorize, and label sensitive data across the organization. Continuously monitor data security posture and produce regular compliance and risk reports. Assist the incident response team in investigating and responding to data security incidents, including insider threats and breaches.<br>Cloud Data Security Implement and manage data protection controls in GCP and Azure. Secure databases and data lakes. Configure encryption at rest, in transit, and in use, with BYOK strategies. Deploy cloud-native data discovery and classification solutions. Manage secrets management and ensure secure access to data storage systems. Implement controls for AI data governance.<br>Cryptography Define and enforce cryptographic practices and key management standards. Manage enterprise encryption practices for data at rest, in transit, and in use. Ensure compliance with organizational and industry cryptographic standards.<br>Data Privacy Ensure compliance with privacy regulations (GDPR, HIPAA, PDPPL). Embed privacy-by-design principles and requirements into technical controls. Drive data classification and governance programs to safeguard personal and sensitive information.<br>Database Security Secure structured and unstructured data repositories, including relational and NoSQL databases. Implement database activity monitoring (DAM) and user access controls. Perform regular security reviews and hardening of database systems.<br>Collaboration & Governance Collaborate with other stakeholders on data protection strategies. Ensure compliance with Qatar’s NCSA framework and international standards. Conduct data security assessments for vendors and third-party integrations. Review and approve data sharing agreements. Define and track data security KPIs and metrics. Maintain data security dashboards for continuous monitoring. Stay current with emerging threats, technologies, and industry best practices.<br>Requirements8+ years of experience in information security with a focus on data protection, cryptography, and database security. Bilingual (Arabic Speaker) Preferred. Hands-on experience with cloud platforms, especially GCP and Azure. Strong understanding of encryption standards, cryptographic protocols, and key management processes. Practical experience with secrets management (Hashi Corp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager). Proven expertise in cloud-native data protection across multi-cloud environments. Experience implementing data masking, tokenization, and anonymization techniques. Bachelor’s degree in computer science, Information Security, or related field. Professional certifications such as CISSP, CCSP, CDPSE, or CCSK. Cloud security certifications (GCP, Azure, or AWS Security Specialty) preferred.<br>Required Skillsets Hands-on experience with DLP solutions (Forcepoint, Microsoft Purview, Google Cloud DLP). Implementation of data anonymization, pseudonymization, and masking techniques. Configuration and monitoring of DAM solutions (Imperva, IBM Guardium). Experience with data discovery and classification tools (Forcepoint, Microsoft Purview). Strong knowledge of cryptographic and key management systems (KMS, GCP Cloud KMS, Azure Key Vault). Securing relational, NoSQL, and data lake environments. Performing database vulnerability assessments and security audits. Working knowledge of secret management solutions and integration with CI/CD pipelines.
About the Role:We are looking for an IT Security Governance Officer to establish and manage information security governance frameworks within a government environment. The role ensures compliance with national cybersecurity regulations, government policies, and international standards while supporting risk management, audits, and secure digital service delivery.<br>Key Responsibilities:Develop and maintain information security policies, standards, and procedures aligned with government requirements. Ensure compliance with national cybersecurity regulations, data protection laws, and government directives. Align security governance with ISO 27001, NIST, COBIT, and relevant government standards. Conduct information security risk assessments and support risk treatment plans. Monitor compliance of security controls across systems and entities. Coordinate internal/external audits, regulatory reviews, and compliance assessments. Track security risks, exceptions, and remediation actions. Support cybersecurity incident governance, reporting, and post-incident reviews. Review third-party and vendor security compliance for government contracts. Ensure enforcement of data classification, access control, and information handling policies. Support cybersecurity awareness programs and mandatory training initiatives. Prepare governance reports, dashboards, and compliance submissions for senior management. Collaborate with legal, compliance, IT, and national cybersecurity authorities.<br>Required Skills & Experience:Strong knowledge of government cybersecurity governance and regulatory frameworks. Experience in public sector IT compliance, risk management, and audit coordination. Knowledge of ISO 27001, NIST, COBIT, and security governance frameworks. Strong risk assessment, compliance monitoring, and audit support skills. Strong documentation, reporting, and policy writing abilities. Ability to communicate security risks in a clear, executive-friendly manner. High integrity and ability to handle confidential information.<br>Qualifications:Bachelor’s degree in Information Security, Computer Science, IT, or related field.4–7 years of experience in information security governance, risk, or compliance (public sector preferred).<br>Certifications (Preferred):CISMCISSPISO 27001 Lead Implementer / Lead Auditor CRISC
Position Purpose Summary Principal Information Security Assurance Engineer/ Specialist lead and enforce enterprise-wide security assurance initiatives by evaluating and strengthening security mechanisms across systems, applications, and databases. Conduct comprehensive audits to detect and prevent unauthorized or malicious activities by users and administrators. Drive the adoption and continuous improvement of a secure SDLC framework across the be IN. Oversee and execute regular penetration testing and vulnerability assessments to safeguard the integrity, confidentiality, and availability of information assets. Provide strategic, administrative, and technical leadership to support the Director of Information Security in developing and implementing robust cybersecurity strategies.<br>Key Responsibilities and Accountabilities Review audit log of user applications, profile administration activities and privileged users, review objects/services access and usage. Audit operational change due to the change request. Audit privileged level access and changes to services, applications, databases. Ensure security mechanisms are considered within the SDLC. Conduct periodically internal penetration testing in assigned areas and contribute to the assessment of the security posture across all of infrastructure and oversee scheduled and event/service driven external penetration testing. Conduct vulnerability scanning and be able to interpret the results. Tracks and coordinate the security patching activities with relevant teams and provide the required support. Assess change request for the risk it poses to application and databases security and review the subsequent impact on operations. Approve the request after checking for approval from necessary authorities. Examine mechanisms and technologies in achieving and optimizing security controls and processes. To provide support and analysis during and after a security incidents, as necessary. Analyzes general information assurance-related technical problems and provide support in solving these problems. Research security enhancements and make recommendations to management. Coordinate the activities related to Information Security Projects.<br>Education Minimum Bachelor Degree in IT, Computer Science, Cyber Security, Business Administration or related field.<br>Experience Minimum 6 years of experience in IT domain, penetration testing, professional experience in corporate Applications Security, Analysis and Solutions Delivery or in any similar role.<br>Please refer to our privacy policy to know more about how we process your personal data
Position Purpose Summary Principle Information Security Assurance Engineer/ Specialist lead and enforce enterprise-wide security assurance initiatives by evaluating and strengthening security mechanisms across systems, applications, and databases. Conduct comprehensive audits to detect and prevent unauthorized or malicious activities by users and administrators. Drive the adoption and continuous improvement of a secure SDLC framework across the be IN. Oversee and execute regular penetration testing and vulnerability assessments to safeguard the integrity, confidentiality, and availability of information assets. Provide strategic, administrative, and technical leadership to support the Director of Information Security in developing and implementing robust cybersecurity strategies.<br>Key Responsibilities and Accountabilities Review audit log of user applications, profile administration activities and privileged users, review objects/services access and usage. Audit operational change due to the change request. Audit privileged level access and changes to services, applications, databases. Ensure security mechanisms are considered within the SDLC. Conduct periodically internal penetration testing in assigned areas and contribute to the assessment of the security posture across all of infrastructure and oversee scheduled and event/service driven external penetration testing. Conduct vulnerability scanning and be able to interpret the results. Tracks and coordinate the security patching activities with relevant teams and provide the required support. Assess change request for the risk it poses to application and databases security and review the subsequent impact on operations. Approve the request after checking for approval from necessary authorities. Examine mechanisms and technologies in achieving and optimizing security controls and processes. To provide support and analysis during and after a security incidents, as necessary. Analyzes general information assurance-related technical problems and provide support in solving these problems. Research security enhancements and make recommendations to management. Coordinate the activities related to Information Security Projects.<br>Education Minimum Bachelor Degree in IT, Computer Science, Cyber Security, Business Administration or related field.<br>Experience Minimum 6 years of experience in IT domain, penetration testing, professional experience in corporate Applications Security, Analysis and Solutions Delivery or in any similar role.<br><br>Please refer to our privacy policy to know more about how we process your personal data
Position Purpose Summary Principle Information Security Assurance Engineer/ Specialist lead and enforce enterprise-wide security assurance initiatives by evaluating and strengthening security mechanisms across systems, applications, and databases. Conduct comprehensive audits to detect and prevent unauthorized or malicious activities by users and administrators. Drive the adoption and continuous improvement of a secure SDLC framework across the be IN. Oversee and execute regular penetration testing and vulnerability assessments to safeguard the integrity, confidentiality, and availability of information assets. Provide strategic, administrative, and technical leadership to support the Director of Information Security in developing and implementing robust cybersecurity strategies.<br>Key Responsibilities and Accountabilities Review audit log of user applications, profile administration activities and privileged users, review objects/services access and usage. Audit operational change due to the change request. Audit privileged level access and changes to services, applications, databases. Ensure security mechanisms are considered within the SDLC. Conduct periodically internal penetration testing in assigned areas and contribute to the assessment of the security posture across all of infrastructure and oversee scheduled and event/service driven external penetration testing. Conduct vulnerability scanning and be able to interpret the results. Tracks and coordinate the security patching activities with relevant teams and provide the required support. Assess change request for the risk it poses to application and databases security and review the subsequent impact on operations. Approve the request after checking for approval from necessary authorities. Examine mechanisms and technologies in achieving and optimizing security controls and processes. To provide support and analysis during and after a security incidents, as necessary. Analyzes general information assurance-related technical problems and provide support in solving these problems. Research security enhancements and make recommendations to management. Coordinate the activities related to Information Security Projects.<br>Education Minimum Bachelor Degree in IT, Computer Science, Cyber Security, Business Administration or related field.<br>Experience Minimum 6 years of experience in IT domain, penetration testing, professional experience in corporate Applications Security, Analysis and Solutions Delivery or in any similar role.<br><br>Please refer to our privacy policy to know more about how we process your personal data