وظائف مفتش أمن في قطر
٣٦٢٢ وظائف شاغرة
Position Purpose Summary Principle Information Security Assurance Engineer/ Specialist lead and enforce enterprise-wide security assurance initiatives by evaluating and strengthening security mechanisms across systems, applications, and databases. Conduct comprehensive audits to detect and prevent unauthorized or malicious activities by users and administrators. Drive the adoption and continuous improvement of a secure SDLC framework across the be IN. Oversee and execute regular penetration testing and vulnerability assessments to safeguard the integrity, confidentiality, and availability of information assets. Provide strategic, administrative, and technical leadership to support the Director of Information Security in developing and implementing robust cybersecurity strategies.<br>Key Responsibilities and Accountabilities Review audit log of user applications, profile administration activities and privileged users, review objects/services access and usage. Audit operational change due to the change request. Audit privileged level access and changes to services, applications, databases. Ensure security mechanisms are considered within the SDLC. Conduct periodically internal penetration testing in assigned areas and contribute to the assessment of the security posture across all of infrastructure and oversee scheduled and event/service driven external penetration testing. Conduct vulnerability scanning and be able to interpret the results. Tracks and coordinate the security patching activities with relevant teams and provide the required support. Assess change request for the risk it poses to application and databases security and review the subsequent impact on operations. Approve the request after checking for approval from necessary authorities. Examine mechanisms and technologies in achieving and optimizing security controls and processes. To provide support and analysis during and after a security incidents, as necessary. Analyzes general information assurance-related technical problems and provide support in solving these problems. Research security enhancements and make recommendations to management. Coordinate the activities related to Information Security Projects.<br>Education Minimum Bachelor Degree in IT, Computer Science, Cyber Security, Business Administration or related field.<br>Experience Minimum 6 years of experience in IT domain, penetration testing, professional experience in corporate Applications Security, Analysis and Solutions Delivery or in any similar role.<br><br>Please refer to our privacy policy to know more about how we process your personal data
About the Role We are seeking an experienced IT Security Specialist to strengthen our cybersecurity posture, protect IT assets, and ensure resilience against evolving threats. The role focuses on security risk assessments, incident response, compliance, and continuous improvement of security controls across cloud and on-premise environments.<br>Key Responsibilities Act as custodian of IT security policies and ensure their implementation and periodic review Support IT security governance and liaise with IS Manager and internal auditors Ensure compliance with security standards, regulations, and audit requirements Manage and monitor security tools and infrastructure across cloud and on-prem environments Monitor logs, perform audits, and ensure secure backup and access controls Detect, investigate, and respond to security incidents and suspicious activities Monitor networks for intrusions using tools such as IDS/IPS, SIEM, firewalls, and related CND solutions Conduct vulnerability assessments and security testing of systems and applications Configure, maintain, and optimize security solutions (firewalls, antivirus, anti-spam, IDS/IPS, VPN, etc.) Ensure secure network configurations and adherence to change management processes Collaborate with vendors, conduct PoCs, and report findings to management Prepare technical incident reports and support disaster recovery and business continuity planning Continuously assess emerging threats and recommend mitigation actions<br>Technical Skills & Experience Strong knowledge of IDS/IPS, SIEM, and Computer Network Defense tools Hands-on experience with tools such as Wireshark, Nessus, Kali Linux, Burp Suite, and Nmap Experience in SOC/CIRT/CERT/CSIRC environments or IT audit functions Knowledge of security frameworks: ISO 27001, NIST 800, COBITExperience with Microsoft security stack (Defender for Endpoint, Azure Sentinel, Microsoft 365 Security, Defender for Cloud) Experience with Azure Key Vault, HSM, BYOK encryption Strong Windows OS administration and hardening skills Experience with firewalls, WAF, VPNs, antivirus, and network security controls Exposure to Cisco FTD, Palo Alto, Barracuda firewalls, and NAC solutions Experience in SIEM management, intrusion analysis, and malware/virus outbreak handling<br>Qualifications Bachelor’s degree in Computer Engineering, IT, or related field Certifications preferred: CISSP, CISM, CEHVendor certifications (Cisco, Palo Alto, F5, Barracuda) are an advantage
Job Summary<br><br>The role holder has prime responsibility for assisting Senior Security Officer/Site Security Officer in managing all activities related to Security at the Company’s site/ facilities. The role holder will be required to act as Senior Security Officer/Site Security Officer, if and when required. The role holder shall administer and follow –up the day-to-day activities of Security.<br><br>The role holder shall coordinate in ensuring that all Security activities are carried out in a smooth and efficient manner in line with the procedures in the Organization. The role holder will also be responsible to ensure that the Company’s site/ facilities access is secured (fence, gates etc.)<br><br>Key Accountabilities<br><br>Assist in Coordinating and supervise day-to-day functioning of the Security Team in order to meet customer requirements. Supervise the main gate and check the company's fence and also check other gates/ premises periodically. Monitoring car park condition / signs. Checking materials in / out from the company's premises. Control of vehicles access to the company's premises. Patrolling fences and gates. Carry out risk assessments for activities related to Security Team personnel and review them regularly. Prepare reports on various surveys carried out as requested by the Senior/Site Security Officer and provide recommendations, if required. Participate in studies, investigation and improvement projects related to security. Contribute to improving the practices and facilities related to Security. Ensuring Maintenance of main barrier gate and turnstile by coordinating with the concerned trade. Ensure that Security staffs are trained on their role. Provide information, demonstration on security check. Work closely with staff of different level within the organization for various activities like assignment of routine jobs within security group, follow-up of relevant projects Participate in meetings/ discussions and communicate with external parties in the field of interest. CCTV monitoring, alarm systems, and access control operations. Conduct refresher training on procedures Ensure adherence to organizational security policies and regulatory requirements. Support audits, inspections, and compliance reviews. Maintain updated records of incidents, patrol logs, access lists, and equipment. Coordinate with internal teams and external authorities when required. Prepare detailed incident reports and maintain accurate security logs.<br><br>Desired Candidate Profile<br><br>Minimum Higher Secondar School (12 years) in relevant discipline. Minimum of 5 years of experience in a similar role. Having Relevant training courses in Security. Having good proficiency in English is a must and good Arabic (spoken and written) is an additional advantage. Having good computer skills and proficiency in MS Office Application. Having good skill to operate CCTV monitoring, and access control.
Job Description<br><br>Role- Cyber Security Analyst<br><br>Experience - 7+ years<br><br>Mandatory Skills<br><br>Cyber Security Incident Response<br><br>Cyber Security Monitoring<br><br>SOC Operations – L2<br><br>Forensic Analysis<br><br>Threat Analysis & Incident Investigation<br><br>Role & Responsibilities<br><br>Monitor and analyze security events/incidents.<br><br>Perform triage, escalation, and response activities for security incidents.<br><br>Provide L2 SOC support and incident management.<br><br>Perform malware analysis and reverse engineering.<br><br>Analyze logs, network traffic, forensic data, and threat intelligence.<br><br>Validate threats, assess impact, and recommend remediation actions
Job Description<br><br>Role- Cyber Security Analyst<br><br>Experience - 7+ years<br><br>Mandatory Skills<br><br>Cyber Security Incident Response<br><br>Cyber Security Monitoring<br><br>SOC Operations – L2<br><br>Forensic Analysis<br><br>Threat Analysis & Incident Investigation<br><br>Role & Responsibilities<br><br>Monitor and analyze security events/incidents.<br><br>Perform triage, escalation, and response activities for security incidents.<br><br>Provide L2 SOC support and incident management.<br><br>Perform malware analysis and reverse engineering.<br><br>Analyze logs, network traffic, forensic data, and threat intelligence.<br><br>Validate threats, assess impact, and recommend remediation actions
Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Dubai - United Arab Emirates; Doha, Qatar; Riyadh Saudi Arabia. Minimum qualifications:<br><br>Bachelor's degree in Cybersecurity, with a focus on offensive security or equivalent practical experience.3 years of experience in three of the following security areas: web application security assessment, mobile application security assessment, API security assessment, red team assessments, EDR evasion, exploit development, cloud, social engineering, scripting, tool development. Experience delivering reporting and presentations to both technical and executive audiences. Experience with operating system security across operating systems or Linux.<br><br>Preferred qualifications:<br><br>Certifications related to application security including BSCP, OSWE, e WPTX, e MAPT, 8ksec CMSE or relevant SANS courses. Experience in creating security tools and understanding of underlying programming languages (such as Python, C#, C/C++, Rust, Nim or similar). Experience conducting web application, API, and mobile (i OS and Android) security assessments following industry standards such as OWASP WSTG/ASVS, OWASP Top 10, OWASP API Top 10 and OWASP MASVS/MASTG. Experience in web application and API penetration testing tooling including Burp Suite Professional, Burp Suite extensions, Postman, nuclei, ffuf and sqlmap.<br><br>About The Job<br><br>As a Security Consultant, you will be responsible for helping clients effectively prepare for, proactively mitigate, and detect and respond to cyber security threats. Security Consultants have an understanding of computer science, operating system functionality and networking, cloud services, corporate network environments and how to apply this knowledge to cyber security threats.<br><br>As a Security Consultant, you could work on engagements including assisting clients in navigating technically complex and high-profile incidents, performing forensic analysis, threat hunting, and malware triage. You may also test client networks, applications and devices by emulating the latest techniques to help them defend against threats, and will be the technical advocate for information security requirements and provide an in-depth understanding of the information security domain. You will also articulate and present complex concepts to business stakeholders, executive leadership, and technical contributors and successfully lead complex engagements alongside cross functional teams.<br><br>We are seeking a highly skilled and experienced Application Security Consultant to join the team.<br><br>In this role, you will be responsible for providing cybersecurity consulting services and support to the clients, including assessing and advising clients on both technical and process-based controls for all manner of environments.<br><br>Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.<br><br>Responsibilities<br><br>Conduct comprehensive security assessments of Web applications, APIs, and Mobile applications by identifying, exploiting and validating vulnerabilities using industry-standard methodologies such as the OWASP Web Security Testing Guide (WSTG), OWASP API Security Top 10, and OWASP Mobile Application Security Testing Guide (MASTG). Discover critical vulnerabilities in applications and be able to weaponize them. Expand the team’s capabilities through tool creation, research on offensive techniques, incorporation of threat actor intelligence, internal presentations and knowledge share. Develop comprehensive and accurate reports and presentations for both technical and executive audiences, and act as a trusted advisor to c-level, security leaders and other customer stakeholders. Assist with scoping prospective engagements, leading teams for engagements from kickoff through remediation phase, as well as mentoring other staff.<br><br><br>Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form .
About The Role<br><br>Our client is seeking a SCADA Cyber Security Engineer to support the secure operation of critical operational technology (OT) environments across a major infrastructure network. The role will focus on cyber security, industrial communications, network monitoring and SCADA system reliability.<br><br>Key Responsibilities<br><br>Monitor and maintain secure OT and SCADA communications. Support cyber security systems and network management platforms. Monitor communication performance across operational systems. Investigate cyber security incidents and implement corrective actions. Coordinate with internal IT teams and external vendors. Support server maintenance and communications infrastructure. Produce security, network performance and operational reports. Review cyber security risks and recommend improvements. Support disaster recovery and business continuity initiatives.<br><br>Requirements<br><br>Bachelor's degree in Engineering or related discipline. Minimum 10 years' experience supporting SCADA or Industrial Control Systems. Experience within utilities, water, wastewater, energy or critical infrastructure. Strong knowledge of industrial cyber security and network management. Experience with SCADA, OT systems, networking and communications. Understanding of cyber security standards and best practices. Excellent troubleshooting and stakeholder management skills.
Job Description<br><br> Job Details: <br><br> Position Title: Cybersecurity Specialist<br><br> Reports to: IT Manager<br><br> Department: Information Technology (IT)<br><br>Job Purpose<br><br>To lead and oversee GDI’s information security IT operations, network infrastructure, and Operational Technology (OT) environments, ensuring the confidentiality, integrity, and availability of IT and industrial systems (IACS). The role is responsible for leading IT security operations, vulnerability management, incident response, and compliance in alignment with ISMS (ISO 27001) and relevant industrial cybersecurity standards, including ISA/IEC 62443. The role also provides technical direction and oversight of IT operational functions, including Network Administration, to ensure secure, resilient, and efficient technology service delivery across the organization.<br><br>Description<br><br> Key Accountabilities: <br><br>Network Infrastructure & Connectivity Support<br><br> Lead and oversee the secure design, implementation, operation, and continuous improvement of GDI’s network infrastructure to ensure availability, performance, resilience, and security across corporate and operational environments. Supervise network administration activities, including routers, switches, firewalls, VPN services, wireless networks, communication platforms, and related infrastructure technologies, to ensure compliance with approved security standards, operational requirements, and best practices. Ensure reliable and secure connectivity for users, systems, operational technologies, and external integrations through continuous monitoring, performance management, and proactive resolution of network-related issues. Enforce network security controls, including segmentation, access control, monitoring, logging, and secure communications, to protect organizational assets and support compliance with ISMS and regulatory requirements. Provide technical direction and oversight to Network Administration resources to ensure effective service delivery, compliance with service levels, and consistent implementation of operational and security procedures. Coordinate with internal stakeholders and external service providers to support communication systems, data center connectivity, VSAT services, internet services, and third-party connectivity requirements. Support incident response, business continuity, and disaster recovery activities by maintaining network resilience, availability, recoverability, and operational readiness. Ensure the security of Operational Technology (OT) and Industrial Automation and Control Systems (IACS) environments through network segmentation, secure remote access controls, monitoring activities, and implementation of applicable industrial cybersecurity requirements (including ISA/IEC 62443 standards). <br><br>Network Security & Access Control<br><br> Lead and oversee the implementation, operation, and continuous improvement of network security controls and access management frameworks to protect GDI’s information assets, infrastructure, and operational environments. Define and enforce secure access requirements relating to authentication, authorization, network segmentation, privileged access, and remote connectivity in alignment with ISMS requirements, cybersecurity standards, and regulatory obligations. Oversee administration of identity and access controls across network and security environments and ensure adherence to the principles of least privilege and segregation of duties. Direct the configuration, management, and optimization of firewalls, VPNs, Network Access Control (NAC) solutions, intrusion detection and prevention technologies, and related security platforms in coordination with Network Administration resources. Monitor and review access rights, privileged accounts, network security events, and security logs to identify unauthorized activities and ensure compliance with approved security requirements. Coordinate periodic access reviews, access recertification activities, and remediation actions to maintain appropriate access governance and security compliance. Provide technical guidance on secure network architecture, access control design, and security requirements to support business needs while maintaining an effective security posture. Support incident investigations, forensic reviews, compliance assessments, and audit activities relating to network security and access management. <br><br>Incident Management & Operational Security Support<br><br> Lead and govern the end-to-end incident management process for IT and security-related events, ensuring timely detection, response, resolution, and documentation in line with approved procedures and SLAs. Establish and maintain incident management processes, escalation procedures, communication protocols, and reporting mechanisms aligned with ISMS requirements and business continuity objectives. Oversee monitoring, triage, analysis, prioritization, and escalation of cybersecurity and operational incidents and coordinate response activities with internal teams and external service providers. Direct incident response and recovery activities, ensuring root cause analyses are completed and corrective actions are implemented to prevent recurrence and strengthen operational resilience. Provide technical leadership and guidance to IT support and Network Administration teams in resolving complex incidents and maintaining service availability. Ensure incident records, investigation findings, response activities, and closure documentation are accurately maintained to support audit, compliance, and performance monitoring requirements. Develop and maintain incident response playbooks, coordinate incident response exercises, and support disaster recovery and business continuity readiness activities. <br><br>Vulnerability Management<br><br> Lead and govern GDI’s vulnerability management program to ensure timely identification, assessment, prioritization, remediation, and reporting of vulnerabilities across systems, networks, applications, cloud environments, and operational technologies. Oversee vulnerability scanning, assessment, reporting, and remediation activities and ensure identified vulnerabilities are appropriately risk-ranked, assigned, tracked, and resolved through approved remediation processes. Direct implementation of corrective actions, patch management activities, configuration hardening initiatives, and security improvement measures in coordination with Network Administration and other IT resources. Provide analysis, reporting, and recommendations regarding security risks, vulnerability trends, threat exposure, and remediation performance to management and relevant stakeholders. Support incident investigations, audit activities, compliance assessments, and security reviews through provision of vulnerability management data, remediation evidence, and security assurance information. Oversee vulnerability identification and remediation activities relating to OT and IACS environments in alignment with industrial cybersecurity requirements and operational risk considerations. <br><br>Compliance, Audit & Risk Management<br><br> Ensure compliance with information security policies, standards, ISMS (ISO 27001) requirements, industrial cybersecurity requirements, and applicable regulatory obligations through effective implementation and monitoring of security controls and operational practices. Coordinate internal audits, external audits, cybersecurity assessments, certification activities, compliance reviews, and remediation programs to support audit readiness and ongoing compliance. Oversee identification, tracking, reporting, and remediation of audit findings, non-conformities, security observations, and control gaps and ensure corrective actions are completed within agreed timelines. Maintain security documentation, policies, procedures, access review records, vulnerability management records, incident documentation, and audit evidence required to support compliance and assurance activities. Conduct and coordinate security risk assessments, vulnerability risk assessments, and control reviews and ensure identified risks are appropriately documented and incorporated into relevant risk registers. Monitor implementation of risk treatment plans, mitigation activities, and corrective actions and provide reporting on residual risks, remediation progress, and risk exposure. Prepare and present security risk reports, compliance updates, assessment results, and cybersecurity insights to management and stakeholders to support informed decision-making. Conduct cybersecurity risk assessments relating to Operational Technology (OT) and Industrial Automation and Control Systems (IACS), considering operational impacts, safety implications, and applicable industrial cybersecurity requirements. <br><br>Communications & Working Relationships<br><br>Internal<br><br> IT Manager and IT Teams Operations, Technical, Finance, Internal Audit, Governance, HR, and QHSE Teams <br><br>External<br><br> Infrastructure, Cybersecurity, Telecommunications and Managed Service Providers Cloud Service Providers and Technology Vendors Hardware, Software, Network, and Communication Systems Vendors External Technical Consultants <br><br>Context, Work Environment & Decision-Making Authority<br><br> Operates within a security-critical technology environment supporting GDI’s Information Security Management System (ISMS), cybersecurity strategy, network infrastructure, enterprise technology platforms, and Operational Technology (OT) environments. Leads cybersecurity operations, network security, vulnerability management, incident response, compliance, and risk management activities across corporate and operational technology environments. Provides technical leadership, oversight, and direction to Network Administration and IT support resources to ensure compliance with security standards, operational requirements, and approved procedures. Exercises professional judgment in assessing cybersecurity risks, directing incident response activities, implementing security controls, prioritizing remediation actions, and recommending security improvements within approved governance frameworks. Monitors emerging cybersecurity threats, vulnerabilities, regulatory developments, and industrial cybersecurity requirements and recommends actions to strengthen organizational security posture and resilience. Escalates significant cybersecurity risks, major incidents, control deficiencies, and compliance concerns to IT Management for resolution and strategic decision-making. <br><br>Minimum Qualifications<br><br>Qualifications, Experience & Skills: <br><br> Bachelor’s degree in information technology, Computer Science or a related field from an internationally recognized university or relevant proven experience. Professional certifications such as CISSP, CISM, CEH, Security+, GSEC, GIAC certifications, or equivalent are preferred. Knowledge of information security and industrial cybersecurity standards, including ISO/IEC 27001 and ISA/IEC 62443. Familiarity with Operational Technology (OT), Industrial Automation and Control Systems (IACS), and IT/OT convergence principles is advantageous . <br><br>Minimum Experience<br><br> Minimum of 8 years of relevant experience in IT security or cybersecurity roles, including exposure to network security, vulnerability management, incident response, and familiarity with OT/IACS environments is an advantage. <br><br>Job-Specific Skills (Generic / Technical)<br><br> Strong knowledge of network security architecture, network administration, access control frameworks, and cybersecurity technologies including firewalls, VPNs, NAC, SIEM, endpoint security, and monitoring platforms. Strong understanding of incident response, vulnerability management, threat mitigation, security operations, risk assessment, and security governance practices. Knowledge of information security management systems, ISO 27001 requirements, cybersecurity compliance practices, and audit readiness requirements. Good understanding of Operational Technology (OT), Industrial Automation and Control Systems (IACS), industrial cybersecurity principles, ISA/IEC 62443 requirements, and IT/OT convergence environments. Ability to assess cybersecurity risks, analyze vulnerabilities, investigate incidents, and recommend practical mitigation and remediation strategies. Strong leadership, stakeholder management, communication, and coordination skills with the ability to guide technical teams and collaborate effectively with business and technology stakeholders. Strong analytical, problem-solving, decision-making, and incident management capabilities in complex operational environments. Ability to manage multiple priorities, security initiatives, incidents, and operational activities in a fast-paced environment. Language proficiency: English (required).
Key Responsibilities Customer Engagement & Strategy Opportunity Qualification: Partner with Account Executives to technically qualify sales leads, ensuring alignment between client budgets, timelines, and our delivery capabilities. Requirement Gathering & Analysis: Lead deep-dive discovery sessions to uncover clients' current security posture, pain points, regulatory compliance gaps, and business objectives. Customer Workshops & Assessments: Design and execute technical workshops and high-level maturity assessments to identify vulnerabilities and position relevant security frameworks. Solution Architecture & Proposal Development Solution Architecture & Design: Architect robust, end-to-end cybersecurity solutions that integrate seamlessly into diverse client environments (on-premises, hybrid, and multi-cloud). RFI/RFP/RFQ Response Preparation: Own the technical response strategy for complex tenders, ensuring comprehensive compliance, competitive differentiation, and timely submission. Bill of Material (BoM) Creation: Engineer accurate, cost-optimized multi-vendor BoMs, leveraging vendor frameworks and discount structures to maximize profitability. Statement of Work (SoW) Preparation: Author highly detailed SoWs that define the exact project scope, technical deliverables, assumptions, milestones, and out-of-scope boundaries to mitigate delivery risk. Technical Validation & Sales Enablement Technical Presentations & Demonstrations: Deliver high-impact technical presentations and tailored product demonstrations that clearly articulate the business value and ROI of the proposed architecture. Proof of Concept (PoC) Management: Define success criteria, scope, and execute PoCs and Proof of Values (PoVs) to technically validate solutions and overcome buyer hesitations. Vendor Coordination: Maintain strong relationships with strategic security vendors to stay ahead of product roadmaps, secure specialized deal pricing, and co-architect complex solutions. Project Handover to Delivery Teams: Lead comprehensive post-sale handover sessions with implementation and delivery teams to ensure flawless execution. Sales Enablement: Conduct internal training sessions for the broader sales team on new security technologies, vendor programs, and competitive displacement strategies.<br>Technical Competencies The ideal candidate must demonstrate mid-to-senior level architectural and conceptual expertise across the following domains:Network & Edge Security: Secure Web Gateway (SWG), Forward/Reverse Proxy Solutions, Web Application Firewall (WAF), and DDoS Protection. Content & Endpoint Security: Next-Generation Endpoint Security, Endpoint Detection & Response (EDR), Extended Detection & Response (XDR), and Email Security ecosystems. Security Operations & Automation: Security Orchestration, Automation, and Response (SOAR), Threat Intelligence Platform (TIP) integration, and Vulnerability Management life cycles. Identity & Access Governance: Privileged Access Management (PAM), Identity and Access Management (IAM), and Directory Services. Modern Security Architectures: Zero Trust Architecture (ZTA) design, Secure Access Service Edge (SASE), and Security Service Edge (SSE). Cloud & Data Security: Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWPP), Data Loss Prevention (DLP), and data encryption/masking strategies.<br>Preferred Vendor Knowledge While platform-agnostic architectural skills are essential, practical presales or implementation experience with a combination of the following vendor ecosystems is highly valued:Next-Gen Firewall & SASE: Palo Alto Networks (Strata/Prisma), Fortinet (Forti Gate/Forti SASE) Endpoint & XDR: Paloalto, Trend Micro, Crowd Strike Network Visibility & NDR: Extra Hop, Darktrace, Vectra AI, Trellix Application & Edge Delivery: F5 (BIG-IP, Distributed Cloud), Cloudflare Email Security: Proofpoint, Fortinet, Trellix Identity & Privileged Access: Delinea, Xage, Beyond Trust Cloud Security & SSE: Zscaler, Netskope Vulnerability Management: Tenable, Trellix Qualifications & Certifications Academic Background Required: Bachelor’s degree from an accredited institution in Computer Science, Cyber Security, Information Technology, Computer Engineering, or a closely related technical field.<br>Professional Certifications Candidates are expected to hold, or be actively pursuing, certifications that validate both broad security knowledge and vendor-specific expertise:Core Security Knowledge: CISSP (preferred), CISM, or CCSP. Technical Foundations: CEH (Certified Ethical Hacker) or Comp TIA Security+. Vendor-Specific Tracks: Fortinet NSE (Level 4 or higher), Palo Alto Networks PCNSE, or Cisco Security Certifications (CCNP Security).<br>Experience Requirements Presales Expertise: At least 3–5 years dedicated to a customer-facing Cyber Security Presales role, driving technical wins within a System Integrator or Value-Added Reseller (VAR). Consulting & Design: Proven track record of conducting security consultations and building defense-in-depth enterprise architectures. Tendering Proficiency: Demonstrable experience independently managing, writing, and winning high-value RFP/RFI responses for both commercial enterprises and public sector/government entities. Sector Exposure: Significant experience navigating the distinct procurement processes, compliance requirements, and stakeholder landscapes of enterprise corporations and government agencies.<br>Soft Skills & Leadership Attributes Executive Presentation Skills: Ability to command a room, articulating highly technical, granular security risks into clear, business-driven outcomes for C-level executives. Communication & Relationship Management: Exceptional verbal and written communication skills; a natural ability to build rapport and establish long-term technical credibility with clients. Analytical Thinking & Problem Solving: Methodical approach to deconstructing chaotic, poorly defined client environments into structured, secure, and compliant architectures. Collaboration & Time Management: Ability to self-manage tight tender deadlines, multi-task across concurrent sales opportunities, and collaborate seamlessly across cross-functional teams (Sales, Delivery, Finance, Vendors). Leadership Potential: Drive to mentor junior presales engineers, take ownership of specific technology practices, and champion internal process improvements.
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>ABOUT THE ROLE We are seeking a vigilant, physically fit, and professional Security Guard with strong observational skills and the discipline to maintain a safe and secure environment at all times. KEY RESPONSIBILITIES : Monitor and control access to the premises. Conduct regular patrols and report suspicious activity. Respond to security incidents and emergencies in a calm and professional manner. Monitor CCTV systems and security equipment. Maintain visitor and vehicle logs. Enforce company security policies and procedures.</p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><ul><li>Previous security experience or relevant certification preferred.</li><li>Good physical fitness and ability to stand/patrol for extended periods.</li><li>Strong observation and communication skills.</li><li>Ability to remain calm and act decisively in emergency situations.</li><li>Willingness to work rotating shifts including nights and weekends.</li></ul><p></p></section>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
Job Description<br><p>We are currently looking Security Admin our Qatar operations.</p><br><p>Skills:</p><br><p>Manage platform, users, services, resources, security, and deployment environments</p><br><p>Joining time frame: 2 weeks (maximum 1 month)</p><br><br><br> </div>
Role:Perform technical testing and specialized cybersecurity assessments as part of the IT & IS audit engagement. Responsibilities:Conduct vulnerability assessments and penetration testing. Review cloud hosting environments and security configurations. Perform web application security assessments. Review network, infrastructure, and IT asset configurations. Assess cybersecurity, monitoring, backup, and disaster recovery controls. Prepare technical findings, risk ratings, and recommendations. Qualifications:5–7 years of experience in penetration testing, vulnerability assessment, cloud security, web application security, network security, or IT auditing. Relevant certifications are preferred, such as CEH, OSCP, CISSP, CISM, CISA, or ISO 27001 Lead Auditor / Lead Implementer. Strong technical reporting and documentation skills.
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
Job Description<br><p>We are currently looking Security Admin our Qatar operations.</p><br><p>Skills:</p><br><p>Manage platform, users, services, resources, security, and deployment environments</p><br><p>Joining time frame: 2 weeks (maximum 1 month)</p><br><br><br> </div>
General Description<br>Join a leading consulting engagement supporting a major enterprise organization in Doha, Qatar, supporting enterprise-wide adoption of Artificial Intelligence, Generative AI, and intelligent automation platforms.<br>We are looking for an experienced AI Security Expert to help establish secure AI practices, governance frameworks, and security controls across emerging AI technologies including agent-based AI solutions, AI-as-a-Service platforms, Microsoft Copilot, Service Now AI, Snowflake AI capabilities, and other enterprise AI solutions.<br>This role focuses on securing the entire AI lifecycle, from architecture and development through deployment, governance, monitoring, and incident response. The selected consultant will work closely with AI engineering teams, enterprise architects, cybersecurity specialists, and business stakeholders to ensure AI solutions are deployed securely, responsibly, and in accordance with organizational risk and governance requirements.<br>This opportunity is ideal for professionals with hands-on experience securing Generative AI, LLM platforms, AI governance, AI threat modelling, and Responsible AI initiatives within enterprise environments.<br>This is a 12-month contract / freelance engagement.<br>Key Responsibilities<br>AI Security Architecture Review security controls for agent-based AI solutions, AI-as-a-Service platforms, and embedded AI capabilities Assess AI solution architectures to ensure secure design and deployment Recommend AI-specific security controls aligned with enterprise cybersecurity standards Support secure implementation of enterprise AI technologies including Microsoft Copilot, Service Now AI, and Snowflake AI capabilities.<br>AI Threat Modelling Perform lifecycle-based threat modelling for AI applications and intelligent systems Identify AI-specific attack vectors, risks, and vulnerabilities Develop mitigation strategies for AI workloads and Large Language Model (LLM) implementations Support secure design throughout the AI development lifecycle.<br>AI Governance & Responsible AIDefine Secure AI Dataset Governance practices Establish Responsible AI controls and governance frameworks Develop secure AI architecture, hosting, and development standards Support AI risk management and regulatory compliance initiatives Recommend AI deployment best practices across enterprise environments.<br>AI Incident Response & Security Operations Develop AI-specific Incident Detection and Response Plans Create AI security playbooks and response procedures Support AI monitoring, threat detection, and security readiness initiatives Recommend security controls for AI model deployment and operational monitoring.<br>Stakeholder Engagement & Advisory Collaborate with AI engineering teams, enterprise architects, cybersecurity teams, and business stakeholders Provide expert guidance on AI security strategy and governance Participate in architecture reviews and AI security assessments Produce documentation, security recommendations, governance standards, and architecture guidance.<br>Required Experience Practical experience (approximately 1–3 years) securing enterprise AI platforms, Generative AI solutions, or intelligent automation technologies Experience securing agent-based AI systems, AI-as-a-Service platforms, or embedded AI capabilities Strong understanding of AI threat modelling methodologies Experience designing secure AI architectures and AI security controls Knowledge of Responsible AI principles and AI governance frameworks Experience developing AI Incident Detection and Response Plans Familiarity with AI dataset governance, secure AI development, and AI deployment practices Experience working with enterprise AI technologies such as Microsoft Copilot, Service Now AI, Snowflake AI, or similar platforms is highly desirable Knowledge of LLM security concepts, AI risk management, and emerging AI threats is advantageous Strong stakeholder communication and documentation skills Experience within enterprise or consulting environments is preferred Immediate or short-notice availability is highly preferred<br>Work Setup Onsite Engagement12-Month Contract / Freelance Engagement
Responsibilities<br><br> Penetration Testing: Conduct penetration tests on web applications, mobile applications, APIs, and thick client applications. Prepare detailed reports with actionable recommendations for remediation. Security Scanning: Implement and manage automated security scanning tools (SAST, DAST, SCA) to continuously monitor and identify vulnerabilities in code, configurations, and dependencies across all application types. Threat Modelling: Perform threat modelling to identify potential security risks associated with various types of applications. Provide guidance on mitigating these risks. Code Review: Review application code for security vulnerabilities across multiple platforms and offer practical recommendations for remediation. Training & Awareness: Develop and deliver training sessions and workshops to raise awareness about application security among development teams and other stakeholders, tailored to different application types. Tool Evaluation: Assess and recommend tools and technologies to enhance application security testing and monitoring capabilities across various platforms. Documentation: Create and maintain comprehensive documentation related to security assessments, vulnerability management, and security policies for diverse application types. <br><br>Qualifications<br><br> Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field. Experience: At least 2 years of experience in application security, software development, or a related field. Certifications: Relevant certifications (e.g., BCSP, OSWA, OSWE, e WPT, e WPTX, SEC542) are highly desirable. Technical Skills: Proficiency with security testing tools such as Burp Suite (required), Fortify, Sonar Qube, and Postman (preferred). Strong understanding of secure coding practices and experience with at least one programming language. Knowledge: In-depth knowledge of application security principles and practices, familiar with security frameworks and guidelines (e.g., OWASP Top 10, ASVS, MASVS, WSTG, MSTG). Familiarity with Dev Sec Ops practices and CI/CD pipelines is a plus. <br><br>About Malomatia<br><br> ABOUT US <br><br>malomatia is a leading Qatar-based IT services and solutions provider, bringing together top Qatari and international talent to deliver innovative, end-to-end technology solutions that empower clients to achieve their strategic goals.<br><br>Our mission<br><br>Empowering Qatar’s businesses and governments to leap into the digital future with agile, knowledge-driven solutions.<br><br>Our vision<br><br>To become Qatar’s trusted knowledge partner in digital transformation, disrupting industries, shaping the future, and building a world-class tech ecosystem.<br><br>Driving change that makes a real impact<br><br>Since 2008, malomatia has been driving Qatar’s digital transformation through innovative, ISO-certified IT solutions. With expertise across key public and private sectors, we empower the nation’s vision with advanced services in cloud, cybersecurity, AI, and contact center excellence, elevating the role of technology in shaping Qatar’s sustainable future.<br><br>About The Team<br><br>Established in 2008, malomatia is a Qatari leader in IT services and digital transformation. We serve key sectors including Government, Healthcare, Education, Customs, and Transportation, delivering impactful solutions that support national development goals. Powered by a diverse team of skilled Qatari and international IT professionals, we deliver innovative, high-value digital solutions tailored to the unique needs of our clients.<br><br>Our mission is to inspire customers to thrive through digital excellence, and we envision becoming the trusted partner of choice in building a smarter society through technology and talent. We are driven by core values that define our culture and approach: ownership, integrity, empathy, teamwork, transparency, agility, excellence, trust, and innovation.<br><br>Join us in shaping the future of technology in Qatar
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>Manage platform, users, services, resources, security, and deployment environments</p><p><br></p><p><br></p><p><span >Skills: Manage platform, users, services, resources, security, and deployment environments</span></p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><p><br></p><p></p></section>
Overview<br><br>At ITA International, we’re a tech-enabled professional services company. Headquartered in Newport News, Virginia, we leverage subject matter expertise, data analytics and technology to challenge boundaries and transform possibilities.<br><br>With a global presence and a passionate team of over 200 ITAers, we’re driven by mission success for our customers, “In The Arena.” Our expertise spans Operations, Training, Engineering, Nanotechnology, Statistics, Machine Learning and Software Engineering – enabling data and tech-enabled solutions that deliver real value.<br><br>Join our impactful journey at ITA International. As Theodore Roosevelt said, “The credit belongs to the man who is actually in the arena.” We’re here, standing beside our customers, ready to serve and succeed.<br><br>ITA is seeking a qualified candidate to join the team in Qatar as a Wing Information/Personnel/Industrial Security Support Professional.<br><br>Responsibilities<br><br>The selected candidate will play a vital role in supporting the 9th Air Force, a key component of the United States Air Force Central Command (AFCENT) overseeing operations in the Middle East. This position provides subject matter expertise to the 9th Air Force Expeditionary Security Forces Squadron, helping ensure base security and critical support services in one of the most dynamic and strategically important regions in the world. The 9 th Air Force serves at other locations such as Al Dhafra AB, UAE; Ali Al Salem AB, Kuwait; Al Mubarak Air Base, Kuwait; Prince Sultan AB (PSAB), Kingdom of Saudi Arabia (KSA); Muwaffaq-Salti AB (MSAB), Jordan; Al Udeid AB, Qatar and in CONUS.<br><br>Other Responsibilities, Include But Are Not Limited To<br><br> Conduct annual staff assistance visits of all Wing, installation, and associated units geared to assist Commanders in effective administration of unit information and personnel security programs. Provide technical guidance to agency security managers in all aspects of program implementation. Advise on security process countermeasure strategies. Develop and conduct formal classroom training for agency security managers. Conduct annual industrial inspections of contractors handling classified information on behalf of the Wing Commander. Evaluate all aspects of these programs for compliance with standards, policies, and instructions. Analyze and report on all security violations and impacted classified operations. Develop metrics for violations for trends analysis. Develop guidance and establish policy for the implementation of the personnel security program. Review and submit all personnel security investigations (PSI). Evaluate requests for establishment and maintain and track special information files. Conduct wing program reviews of personnel security managers on PSI processing, to ensure the proper management and accomplishment of their assigned duties for the personnel security program. During contingency operations, this role will perform duties as assigned by the contract program manager. <br><br>Qualifications<br><br> Two years of experience in managing wing-level information protection, security, personnel security, and industrial security programs. Proficient in the use of Microsoft Office. Must posses active Secret security clearance. <br><br>All employees must successfully pass all medical screening as required per CENTCOM deployment standards.<br><br>Under The 9AF ESFS Contract, All Applicants Are Subject To An In-depth Background Check To Ensure Regulation Compliance. Eligible Applicants Will Not Have Any Of The Following<br><br> Pending criminal or civil charges (including divorce/child custody proceedings) Felony arrest record Alcohol related arrest in the last five years Any type of moral turpitude arrest record/history (including, but not limited to, prostitution, pandering, voyeurism, public indecency) Any type of involvement in hate crimes History of violence Involvement in any group or organization that espouses extralegalviolence as a legitimate means to achieve an end <br><br>Benefit And Compensation Transparency<br><br>ITA International proudly complies with all federal and state benefit and pay transparency laws. Employees of ITA can expect a robust benefit package, including:<br><br> Medical, dental and vision plans Life Insurance Short Term Disability insurance (where applicable) Voluntary ancillary benefit options 401k retirement benefits with employer matching contributions <br><br> Application and Employment at ITA International <br><br>ITA International is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.<br><br>In compliance with the ADA Amendments Act (ADAAA), ITA International would like to ensure that your application process goes as smoothly as possible. If you would like to preview the physical requirements for this position, or if you have a disability and would like to request an accommodation in order to apply for a currently open position with ITA, please contact us by phone at 757-246-6781 or email us at HR@ita-intl.com.
Job Summary We are seeking an experienced ICS Cybersecurity Specialist to strengthen the cybersecurity posture of Industrial Control Systems (ICS) and Operational Technology (OT) environments. The successful candidate will be responsible for securing critical industrial control systems, conducting cybersecurity risk assessments, implementing security controls, monitoring OT environments, responding to security incidents, and ensuring compliance with ISA/IEC 62443 and other industrial cybersecurity standards. The ideal candidate will have hands-on experience with SCADA, DCS, PLC, SIS, industrial networks, SIEM, IDS/IPS, endpoint security, vulnerability management, and OT security frameworks. Experience in Oil & Gas, Petrochemical, Chemical, Energy, Utilities, Manufacturing, or Process Industries is highly preferred. Key Responsibilities ICS/OT Cybersecurity Design, implement, and maintain cybersecurity controls for Industrial Control Systems (ICS) and Operational Technology (OT). Develop and maintain OT cybersecurity strategies, policies, standards, and procedures. Implement defense-in-depth strategies for industrial environments. Ensure secure operation of critical infrastructure and industrial automation systems. Industrial Control Systems Security Secure and support:SCADA Systems Distributed Control Systems (DCS) Programmable Logic Controllers (PLC) Safety Instrumented Systems (SIS) Human Machine Interfaces (HMI) Engineering Workstations Historians Industrial Communication Networks Implement secure configurations and hardening practices for industrial assets. Risk Assessment & Vulnerability Management Conduct cybersecurity risk assessments for ICS/OT environments. Perform vulnerability assessments and gap analysis. Recommend mitigation strategies and remediation plans. Assess cybersecurity risks associated with industrial automation systems. Track remediation activities until closure. Security Monitoring & Incident Response Monitor OT security events using SIEM platforms. Configure and manage IDS/IPS solutions. Monitor endpoint security for industrial assets. Investigate cybersecurity incidents. Perform Root Cause Analysis (RCA). Coordinate incident response and recovery activities. Develop incident response playbooks for OT environments. Network Security Secure industrial networks. Configure and manage industrial firewalls. Monitor network traffic. Implement network segmentation. Secure remote access solutions. Support Zero Trust initiatives where applicable. System Hardening & Patch Management Perform system hardening for OT assets. Implement patch management strategies. Manage secure baseline configurations. Validate system integrity after updates. Ensure compliance with OEM recommendations and cybersecurity best practices. Compliance & Governance Ensure compliance with:ISA/IEC 62443NIST Cybersecurity Framework (preferred) NIST SP 800-82 (preferred) Organizational cybersecurity policies Conduct cybersecurity audits. Prepare compliance documentation. Support internal and external audits. Documentation & Reporting Prepare and maintain:Cybersecurity Policies Security Standards Risk Assessment Reports Vulnerability Assessment Reports Audit Reports Incident Reports Compliance Documentation Technical Recommendations Security Procedures Collaboration Work closely with:Control Systems Engineers Instrumentation Engineers Operations Teams Maintenance Teams IT Infrastructure Teams Network Engineers Cybersecurity Teams Vendors and OEMsSupport cybersecurity improvement initiatives across industrial environments. Training & Awareness Conduct OT cybersecurity awareness sessions. Develop cybersecurity best practice guidelines. Support user awareness programs. Provide technical guidance to engineering and operations teams. Education Bachelor's Degree in:Electrical Engineering Electronics Engineering Instrumentation Engineering Automation Engineering Computer Engineering Cybersecurity Computer Science Information Technology Related Engineering Discipline Required Experience Minimum 5+ years of experience in Industrial Control Systems (ICS), Control Systems Engineering, Industrial Automation, or Industrial Operations. Minimum 3+ years of dedicated experience in ICS/OT Cybersecurity. Experience in:Oil & Gas Petrochemical Chemical Manufacturing Energy Utilities Process Industries
About QNB<br><br>Established in 1964 as the country’s first Qatari-owned commercial bank, QNB Group has steadily grown to become the largest bank in the Middle East and Africa (MEA) region.<br><br>QNB Group’s presence through its subsidiaries and associate companies extends to more than 31 countries across three continents providing a comprehensive range of advanced products and services. The total number of employees is more than 28,000 serving up to 20 million customers operating through 1,000 locations, with an ATM network of 4,300 machines.<br><br>QNB has maintained its position as one of the highest rated regional banks from leading credit rating agencies including Standard & Poor’s (A), Moody’s (Aa3) and Fitch (A+). The Bank has also been the recipient of many awards from leading international specialised financial publications.<br><br>Based on the Group’s consistent strong financial performance and its expanding international presence, QNB currently ranks as the most valuable bank brand in the Middle East and Africa, according to Brand Finance Magazine.<br><br>QNB Group has an active community support program and sponsors various social, educational and sporting events.<br><br>Job Summary<br><br>The incumbent will be primarily responsible in providing support of the Information Security solutions. This includes provide first and second line support and maintain key technology solutions designed to protect the firm from cyber security attacks. The incumbent will be the focal point for end user escalations for security technology issues they may be experiencing.<br><br>Main Responsibilities<br><br> Shareholder & Financial: - Promote cost consciousness and efficiency and enhance productivity, to minimise cost, avoid waste, and optimise benefits for the bank. - Implements KPI’s and best practices for Security Technologies Services - Act within the limits of the powers delegated to the incumbent. - Support to maintain KPI’s and best practices for AVP – Cyber Security Technologies & Services Customer (Internal & External): - Provide 1st level support to key technical security solutions in line with business strategies and objectives of the group - Support operational process, procedures and guidelines, aligned to good practise for service management, problem and incident management, change management and configuration management. - Support end users with installation and troubleshooting of GIS provided and supported security products on their devices. - Review of IT and business requests for change requests to security controls (for example: firewall change reviews) - To assist customers in all their queries on Bank’s product and seek solution to their requests. - Maintain activities in accordance with Service Level Agreements (SLAs) with internal departments/units to achieve improvements in turn-around time. - Build and maintain strong/effective relationships with related departments/units to achieve the Group’s objectives. - Provide timely/accurate data to external/internal Auditors, Compliance, Financial Control and Risk when required. Internal (Processes, Products, Regulatory): - Support the design and implementation of the QNB's information security program. - Develop, implement and administer technical security standards, as well as a suite of security services and tools to address and mitigate security risk. - Examine impacts of new technologies on the QNB's overall information security profile. - Establish processes to review implementation of new technologies to ensure security compliance. - Responsible to ensuring that any audit issues or identified regulatory gaps are addressed timely. Learning & Knowledge: - Possess an understanding of business processes and controls in all related operational areas. - Must have an expert understanding of information security issues, best practices, and a working knowledge of IT systems. - Create education and training program within the team and advise operating units at all levels on security issues, best practices, and vulnerabilities. - Proactively identify areas for professional development of self and undertake development activities. - Seek out opportunities to remain current with all developments in professional field. - Ensure speedy resolution of unresolved grievances or conflicts within the team members. E. Legal, Regulatory, and Risk Framework Responsibilities: - Comply with all applicable legal, regulatory and internal compliance requirements including, but not limited to, Group Compliance Policies and Procedures (AML & CTF, Sanctions Policy, Data Protection Policy, Fraud Control Policy, Whistle Blowing Policy, Conflict of Interest and Insider Dealing Policy). - Understand and effectively perform your role under the Three Lines of Defence principle to identify measure, monitor, manage and report risks. Other: - Ensure high standards of data protection and confidentiality to safeguard commercially sensitive information. - Maintaining utmost confidentiality concerning customer and internal bank information obtained during the course of business and provide such information on a need to know basis only to Senior Management of QNB, Audit and Compliance functions, and relevant Regulators. - Maintain high professional standards to uphold QNB's reputation and to strengthen its market leadership position. - All other ad hoc duties/activities related to QNB that management might request from time to time.<br><br>Education And Experience Requirements<br><br> Bachelor’s degree preferably in computer science, computer engineering or related subjects. At least 6 years of relevant experience, preferably within a highly rated international bank or large corporate in an information security engineering capacity. Professional certification such as CISSP is mandatory Security engineering certifications and qualifications in Microsoft operating systems (such as MCSA, MCSE, et al) or Linux (such as RHCP, et al) are mandatory<br><br>Note: you will be required to attach the following:<br><br>Resume/CVCopy of Passport or QID Copy of Education Certificate Copy of Birth Certificate
About Agoda<br><br>At Agoda, we bridge the world through travel. Our story began in 2005, when two lifelong friends and entrepreneurs, driven by their passion for travel, launched Agoda to make it easier for everyone to explore the world.<br><br>Today, we are part of Booking Holdings [NASDAQ: BKNG], with a diverse team of over 7,000 people from 90 countries, working together in offices around the globe. Every day, we connect people to destinations and experiences, with our great deals across our millions of hotels and holiday properties, flights, and experiences worldwide.<br><br>No two days are the same at Agoda. Data and technology are at the heart of our culture, fueling our curiosity and innovation. If you’re ready to begin your best journey and help build travel for the world, join us.<br><br>We are looking for a hands on Senior Security Engineer to secure our cloud and platform environments. This role works closely with engineering teams and focuses on building, reviewing, and operating security controls using Infrastructure as Code, Kubernetes, and custom security services written in Go and Type Script.<br><br>Key Responsibilities:<br><br>Secure Cloud Deployment:<br><br>Design, implement, and manage secure cloud deployments across AWS and GCP environments using Terraform. Kubernetes & Git Ops Security: Deploy and manage both internal and third‑party security products within the Kubernetes ecosystem. Work with Git Ops workflows using tools like Argo CD and Flux, and Helm charts. Security Automation & Tooling: Design and build security tooling and services using Go and Type Script. Misconfiguration Management: Proactively identify, analyze, and remediate cloud misconfigurations. Cloud Architecture Guidance: Provide guidance to Engineering teams on secure architecture. Threat Detection & Response: Build and optimize cloud-native detection rules and alerting pipelines to monitor for suspicious activities within the cloud and container workloads.<br><br>Required Skills & Experience:<br><br>8+ years of experience in security engineering, cloud security, or platform engineering roles. Hands-on experience securing production workloads in AWS and GCP. Strong experience designing and securing Infrastructure as Code using Terraform. Deep understanding of Kubernetes security, including troubleshooting Helm deployments and Git Ops-based workflows. Strong programming skills in Go and Type Script, with Python used for automation where appropriate. Experience embedding security controls into CI/CD pipelines. Certifications (Required) Certified Kubernetes Administrator (CKA) Certified Kubernetes Security Specialist (CKS) Certifications (Preferred) AWS Certified Security Specialty Google Professional Cloud Security Engineer Hashi Corp Certified: Terraform Associate Nice-to-Have Experience with Policy-as-Code frameworks such as Open Policy Agent (OPA). Experience securing service mesh environments (Istio). Background in software engineering or platform engineering before moving into security.<br><br>#sanfrancisco #sanjose #losangeles #sandiego #oakland #denver #miami #orlando #atlanta #chicago #boston #detroit #newyork #portland #philadelphia #dallas #houston #austin #seattle #sydney #melbourne #perth #toronto #vancouver #montreal #shanghai #beijing #shenzhen #prague #Brno #Ostrava #cairo #alexandria #giza #estonia #paris #berlin #munich #hamburg #stuttgart #cologne #frankfurt #hongkong #budapest #jakarta #bali #dublin #telaviv #milan #rome #venice #florence #naples #turin #palermo #bologna #tokyo #osaka #kualalumpur #malta #amsterdam #oslo #manila #warsaw #krakow #doha #alrayyan #riyadh #jeddah #mecca #medina #singapore #seoul #barcelona #madrid #stockholm #zurich #taipei #tainan #taichung #kaohsiung #bangkok #Phuket #istanbul #london #manchester #edinburgh #hcmc #hanoi #lodz #wroclaw #poznan #katowice #rio #salvador #newdelhi #bangalore #bandung #yokohama #nagoya #okinawa #fukuoka #jerusalem #IT #4<br><br>Please review our Hiring Process Guidelines before your interview — click here to learn how interviewing at Agoda works.<br><br>Discover More About Working At Agoda<br><br>Agoda Careers https://careersatagoda.com Facebook https://www.facebook.com/agodacareers/Linked In https://www.linkedin.com/company/agoda You Tube https://www.youtube.com/agodalife<br><br>Equal Opportunity Employer <br><br>At Agoda, we pride ourselves on being a company represented by people of all different backgrounds and orientations. We prioritize attracting diverse talent and cultivating an inclusive environment that encourages collaboration and innovation. Employment at Agoda is based solely on a person’s merit and qualifications. We are committed to providing equal employment opportunity regardless of sex, age, race, color, national origin, religion, marital status, pregnancy, sexual orientation, gender identity, disability, citizenship, veteran or military status, and other legally protected characteristics.<br><br>We will keep your application on file so that we can consider you for future vacancies and you can always ask to have your details removed from the file. For more details please read our privacy policy.<br><br>Disclaimer<br><br>We do not accept any terms or conditions, nor do we recognize any agency’s representation of a candidate, from unsolicited third-party or agency submissions. If we receive unsolicited or speculative CVs, we reserve the right to contact and hire the candidate directly without any obligation to pay a recruitment fee.