وظائف مهندسى امن معلومات في قطر
٧٨٨٠ وظائف شاغرة
<h2 class="h5">وصف الوظيفة</h2>
<div class="t-break" data-jb-field="description">
<strong>تنبيه التوظيف – مهندس facilities (ميكانيكي) </strong><br> <strong>الموقع:</strong> مدينة رأس لفان الصناعية (RLIC)، قطر<br> <strong>القسم:</strong> قسم الهندسة الميكانيكية<br> <strong>مدة العقد:</strong> 24 شهرًا<br> <strong>جدول العمل:</strong> 8 ساعات/اليوم | 5 أيام/الأسبوع | 22 يوم عمل/الشهر<br> <strong>الصناعة:</strong> النفط والغاز / LNG <br> <strong>عن الدور</strong><br> نحن نبحث عن مهندس مرافق عالي التحفيز <strong>ميكانيكي</strong> لدعم أنشطة هندسة مرافق LNG، الدراسات جدوى، إدارة التغيير (MOC)، مبادرات سلامة وسلامة الأصول، ومشروعات التحسين المستمر لأصول الشركة.<br> سيوفر المرشح الناجح خبرة هندسية طوال دورة حياة المشروع لضمان تشغيل آمن وموثوق وفعال للمصنع بينما يدعم التميز التشغيلي وأهداف الأعمال. <br> <br><strong>المسؤوليات الرئيسية</strong><br> ✅ إعداد <strong>دراسات الجدوى التقنية-الاقتصادية</strong> والدراسات الهندسية المتعلقة بـ:<ul><li>إدارة التغيير (MOC)</li><li>تحسينات الاعتمادية</li><li>الامتثال التنظيمي</li><li>تحسينات السلامة والبيئة</li><li>فرص تحسين التكلفة</li><li>مشروعات تعزيز التشغيل</li></ul>✅ إجراء تقييمات اقتصادية ومالية باستخدام <strong>نماذج PPMID</strong>.<br> ✅ تطوير وإعداد <strong>حزم البوابة</strong> وفقًا لأنظمة إدارة المشاريع بالشركة (PMS).<br> ✅ توفير الدعم الهندسي لفِرق التشغيل لضمان:<ul><li>سلامة الأصول</li><li>اعتمادية المصنع</li><li>تشغيل آمن</li><li>الإنتاج المستمر</li></ul>✅ المشاركة في الأنشطة الهندسية من خلال:<ul><li>Pre-FEED</li><li>FEED</li><li>تصميم تفصيلي</li></ul>✅ مراجعة والتحقق من:<ul><li>الرسومات الهندسية</li><li>ورقات البيانات</li><li>المواصفات</li><li>فلسفات التصميم</li><li>وثائق الموردين</li></ul>✅ المشاركة في:<ul><li>HAZOP وورش عمل السلامة</li><li>ورش عمل تحسين القيمة (VIW)</li><li>مراجعات العين الباردة</li><li>اجتماعات المراجعة الفنية</li></ul>✅ دعم تنفيذ المعايير الهندسية والإجراءات وأفضل الممارسات.<br> ✅ توجيه مهندسي برنامج التطوير الوطني (NDP) ومشاركة المعرفة الفنية.<br> ✅ ضمان الامتثال لمتطلبات الصحة والسلامة والبيئة والجودة بشركة. <br> <strong>المؤهلات</strong><br> <strong>التعليم</strong><br> ✔ شهادة البكالوريوس في:<ul><li>الهندسة الميكانيكية</li></ul><strong>متطلبات الخبرة</strong><br> ✔ الحد الأدنى <strong>4 سنوات خبرة</strong> في صناعة النفط والغاز<br> ✔ خبرة في دعم:<ul><li>مرافق LNG</li><li>التكرير</li><li>المرافق البتروكيماوية</li><li>العمليات العليا أو السفلى</li></ul>✔ خبرة في:<ul><li>إدارة التغيير (MOC)</li><li>الدراسات الهندسية</li><li>سلامة الأصول</li><li>الهندسة المرافق</li></ul>✔ التعرض لمراحل تطوير المشروع:<ul><li>اختيار المفاهيم</li><li>Pre-FEED</li><li>FEED</li><li>التصميم التفصيلي</li></ul><strong>الخبرة الفنية المفضلة</strong><br> ✅ الهندسة المرافق<br> ✅ الهندسة الميكانيكية<br> ✅ الدراسات techno-اقتصادية<br> ✅ هندسة الاعتمادية<br> ✅ إدارة سلامة الأصول<br> ✅ مراجعات تصميم الهندسة<br> ✅ أنظمة إدارة المشاريع (PMS)<br> ✅ تقييمات المخاطر والسلامة<br> ✅ مراجعة الوثائق الهندسية <br> <strong>المهارات المطلوبة</strong><br> ✔ مهارات تحليلية قوية وحل المشكلات<br> ✔ مهارات تواصل شفهية وكتابية بالإنجليزية ممتازة<br> ✔ مهارات إدارة أصحاب المصلحة القوية<br> ✔ القدرة على العمل في فرق متعددة التخصصات<br> ✔ إجادة الحاسب الآلي والبرامج الهندسية المتقدمة<br> ✔ القدرة على إدارة أولويات ومواعيد متعددة<br> ✔ مهارات تقرير فنية قوية<br>مع أكثر من 90 عامًا من الخبرة المجمعة، تفخر NES Fircroft (NES) بأن تكون المزود الرائد عالميًا لخدمات التوظيف الهندسي في مجالات النفط والغاز، والطاقة والمتجدّدات، والكيماويات، والبناء والبنية التحتية، وعلوم الحياة، والتعدين، والتصنيع. مع أكثر من 80 مكتبًا في 45 دولة، يمكننا توفير الخبرة الهندسية والفنية لعملائنا أينما ومتى لزم الأمر. نحن نقدم للمتعهدين أكثر من مجرد خدمة توظيف تقليدية، داعمين بكل شيء من تأمين التأشيرات وتصاريح العمل، إلى توفير باقات مزايا رائدة في السوق وإسكان، بما يضمن قدرتهم على دعم عملائنا بشكل آمن ومتوافق. <br><br>
<p>نحن حالياً نبحث عن مدير الشبكات والأمن لعملياتنا في قطر.</p><p>المهارات: تثبيت وتكوين وصيانة أجهزة الشبكة بما في ذلك الموجهات والمفاتيح وجدران الحماية ونقاط الوصول اللاسلكية. مراقبة أداء الشبكة وضمان أعلى معدل توافر واستمرارية. إدارة LAN وWAN وVPN وWLAN واتصال الإنترنت. تكوين واستكشاف أخطاء بروتوكولات وخدمات الشبكة.</p><p><strong>الملف الشخصي للمرشح المطلوب</strong></p><p>غير متاح حالياً</p>
ROLES & RESPONSIBILITIES:<br>Plan, coordinate, and execute Threat Hunting (TH) and penetration testing activities on a quarterly basis to proactively identify security weaknesses and emerging threats Establish, own, and maintain a centralized security findings tracking mechanism to record, monitor, prioritize, and ensure timely closure of all identified security issues Execute and manage the annual Vulnerability Assessment and Penetration Testing (VAPT) program across IT, OT, and Education City Stadium (ECS) environments Leverage Threat Intelligence (TI) platforms to their full capabilities, in line with best practices, to protect Qatar Foundation’s reputation and proactively defend against internal and external threats Review, analyze, and act upon NCSA advisories, as well as threat intelligence and threat hunting reports from reputable internal and external sources Ensure all relevant Indicators of Compromise (IOCs) are actively monitored, detected, and blocked across applicable security controls and QF environments Establish, operate, and continuously improve the Vulnerability Management (VM) program on a monthly basis, ensuring effective remediation tracking and risk reduction Escalate critical and high-risk security findings in a timely manner to relevant stakeholders to mitigate potential threats and reduce organizational risk Establish, maintain, and continuously update the Cyber Offensive knowledge base, including processes and procedures, asset scope, attack surface analysis, critical infrastructure coverage, and escalation paths Conduct weekly reviews of the security findings tracker to ensure progress, accountability, and closure of outstanding items Contribute to increasing the maturity of Qatar Foundation’s security controls through proactive testing, validation, and continuous improvement initiatives Propose actionable security recommendations and enhancements to strengthen Qatar Foundation’s overall cybersecurity maturity Ensure Vulnerability Assessments and Penetration Tests are aligned with recognized frameworks such as MITRE ATT&CK and OWASP Top 10Identify, propose, and enhance automation opportunities within offensive security activities to improve efficiency, coverage, and response times Manage application security scanning and provide security assurance across the software development lifecycle (SDLC), ensuring secure coding practices, timely identification of application vulnerabilities, and alignment with QF security standards before and after deployment Support secure application hardening and continuous improvement of web security controls Act as a red team–oriented security specialist, continuously simulating attacker behavior to identify control gaps Design and execute offensive security use cases that test detection, response, and resilience Produce actionable threat intelligence and hunting reports for SOC, Cyber Security leadership, and provide clear reporting to Cyber Security leadership on risk exposure, attack trends, and improvement areas Work closely with SOC, MSP/MSSP, IT, OT, and external vendors Contribute to continuous improvement initiatives and cybersecurity maturity uplift Stay up to date with emerging cloud threats, vulnerabilities, and best practices, translating insights into recommendations for QFExecute other cybersecurity tasks as assigned by Cyber Security seniors<br>SKILLS & COMPETENCIES:<br>Strong knowledge of Threat Intelligence platforms, feeds, and analysis techniques. Hands-on experience with Threat Hunting methodologies and MITRE ATT&CK framework. Strong understanding of Vulnerability Management tools and processes. Experience managing VAPT engagements and interpreting penetration testing results. Solid understanding of Web Application Security and OWASP Top10. Experience managing or working with WAF technologies. Knowledge of network security, endpoint security, and cloud security concepts. Familiarity with SIEM platforms (e.g., Splunk, Sentinel) for correlation and analysis. Understanding of OT security concepts and critical infrastructure risks is an advantage. Capable of developing clear reports, dashboards, procedures, and executive-level summaries. Excellent communication and presentation skills, with the ability to engage both technical and non-technical stakeholders, including senior management. Proven ability to manage multiple cloud security initiatives in a dynamic environment, delivering on time with strong planning and documentation skills. Demonstrates ownership in delivering assigned projects and contributes professionally to cross-functional initiatives without compromising primary responsibilities. Able to operate independently when needed, ensuring continuity of cybersecurity operations during team absences.<br><br>EXPERIENCE:5+ years of experience in Offensive Security, Threat Intelligence, Threat Hunting, Vulnerability Management, or Red Team–related roles. Proven experience managing VAPT and vulnerability remediation programs in large enterprise environments. Experience working in complex environments spanning IT, OT, and Cloud. Experience working with external security vendors, MSSPs, or consultants. Experience supporting cybersecurity drills, red team exercises, or adversary simulations is highly desirable.
ROLES & RESPONSIBILITIES:<br>Plan, coordinate, and execute Threat Hunting (TH) and penetration testing activities on a quarterly basis to proactively identify security weaknesses and emerging threats Establish, own, and maintain a centralized security findings tracking mechanism to record, monitor, prioritize, and ensure timely closure of all identified security issues Execute and manage the annual Vulnerability Assessment and Penetration Testing (VAPT) program across IT, OT, and Education City Stadium (ECS) environments Leverage Threat Intelligence (TI) platforms to their full capabilities, in line with best practices, to protect Qatar Foundation’s reputation and proactively defend against internal and external threats Review, analyze, and act upon NCSA advisories, as well as threat intelligence and threat hunting reports from reputable internal and external sources Ensure all relevant Indicators of Compromise (IOCs) are actively monitored, detected, and blocked across applicable security controls and QF environments Establish, operate, and continuously improve the Vulnerability Management (VM) program on a monthly basis, ensuring effective remediation tracking and risk reduction Escalate critical and high-risk security findings in a timely manner to relevant stakeholders to mitigate potential threats and reduce organizational risk Establish, maintain, and continuously update the Cyber Offensive knowledge base, including processes and procedures, asset scope, attack surface analysis, critical infrastructure coverage, and escalation paths Conduct weekly reviews of the security findings tracker to ensure progress, accountability, and closure of outstanding items Contribute to increasing the maturity of Qatar Foundation’s security controls through proactive testing, validation, and continuous improvement initiatives Propose actionable security recommendations and enhancements to strengthen Qatar Foundation’s overall cybersecurity maturity Ensure Vulnerability Assessments and Penetration Tests are aligned with recognized frameworks such as MITRE ATT&CK and OWASP Top 10Identify, propose, and enhance automation opportunities within offensive security activities to improve efficiency, coverage, and response times Manage application security scanning and provide security assurance across the software development lifecycle (SDLC), ensuring secure coding practices, timely identification of application vulnerabilities, and alignment with QF security standards before and after deployment Support secure application hardening and continuous improvement of web security controls Act as a red team–oriented security specialist, continuously simulating attacker behavior to identify control gaps Design and execute offensive security use cases that test detection, response, and resilience Produce actionable threat intelligence and hunting reports for SOC, Cyber Security leadership, and provide clear reporting to Cyber Security leadership on risk exposure, attack trends, and improvement areas Work closely with SOC, MSP/MSSP, IT, OT, and external vendors Contribute to continuous improvement initiatives and cybersecurity maturity uplift Stay up to date with emerging cloud threats, vulnerabilities, and best practices, translating insights into recommendations for QFExecute other cybersecurity tasks as assigned by Cyber Security seniors<br>SKILLS & COMPETENCIES:<br>Strong knowledge of Threat Intelligence platforms, feeds, and analysis techniques. Hands-on experience with Threat Hunting methodologies and MITRE ATT&CK framework. Strong understanding of Vulnerability Management tools and processes. Experience managing VAPT engagements and interpreting penetration testing results. Solid understanding of Web Application Security and OWASP Top10. Experience managing or working with WAF technologies. Knowledge of network security, endpoint security, and cloud security concepts. Familiarity with SIEM platforms (e.g., Splunk, Sentinel) for correlation and analysis. Understanding of OT security concepts and critical infrastructure risks is an advantage. Capable of developing clear reports, dashboards, procedures, and executive-level summaries. Excellent communication and presentation skills, with the ability to engage both technical and non-technical stakeholders, including senior management. Proven ability to manage multiple cloud security initiatives in a dynamic environment, delivering on time with strong planning and documentation skills. Demonstrates ownership in delivering assigned projects and contributes professionally to cross-functional initiatives without compromising primary responsibilities. Able to operate independently when needed, ensuring continuity of cybersecurity operations during team absences.<br><br>EXPERIENCE:5+ years of experience in Offensive Security, Threat Intelligence, Threat Hunting, Vulnerability Management, or Red Team–related roles. Proven experience managing VAPT and vulnerability remediation programs in large enterprise environments. Experience working in complex environments spanning IT, OT, and Cloud. Experience working with external security vendors, MSSPs, or consultants. Experience supporting cybersecurity drills, red team exercises, or adversary simulations is highly desirable.
ROLES & RESPONSIBILITIES:<br>Plan, coordinate, and execute Threat Hunting (TH) and penetration testing activities on a quarterly basis to proactively identify security weaknesses and emerging threats Establish, own, and maintain a centralized security findings tracking mechanism to record, monitor, prioritize, and ensure timely closure of all identified security issues Execute and manage the annual Vulnerability Assessment and Penetration Testing (VAPT) program across IT, OT, and Education City Stadium (ECS) environments Leverage Threat Intelligence (TI) platforms to their full capabilities, in line with best practices, to protect Qatar Foundation’s reputation and proactively defend against internal and external threats Review, analyze, and act upon NCSA advisories, as well as threat intelligence and threat hunting reports from reputable internal and external sources Ensure all relevant Indicators of Compromise (IOCs) are actively monitored, detected, and blocked across applicable security controls and QF environments Establish, operate, and continuously improve the Vulnerability Management (VM) program on a monthly basis, ensuring effective remediation tracking and risk reduction Escalate critical and high-risk security findings in a timely manner to relevant stakeholders to mitigate potential threats and reduce organizational risk Establish, maintain, and continuously update the Cyber Offensive knowledge base, including processes and procedures, asset scope, attack surface analysis, critical infrastructure coverage, and escalation paths Conduct weekly reviews of the security findings tracker to ensure progress, accountability, and closure of outstanding items Contribute to increasing the maturity of Qatar Foundation’s security controls through proactive testing, validation, and continuous improvement initiatives Propose actionable security recommendations and enhancements to strengthen Qatar Foundation’s overall cybersecurity maturity Ensure Vulnerability Assessments and Penetration Tests are aligned with recognized frameworks such as MITRE ATT&CK and OWASP Top 10Identify, propose, and enhance automation opportunities within offensive security activities to improve efficiency, coverage, and response times Manage application security scanning and provide security assurance across the software development lifecycle (SDLC), ensuring secure coding practices, timely identification of application vulnerabilities, and alignment with QF security standards before and after deployment Support secure application hardening and continuous improvement of web security controls Act as a red team–oriented security specialist, continuously simulating attacker behavior to identify control gaps Design and execute offensive security use cases that test detection, response, and resilience Produce actionable threat intelligence and hunting reports for SOC, Cyber Security leadership, and provide clear reporting to Cyber Security leadership on risk exposure, attack trends, and improvement areas Work closely with SOC, MSP/MSSP, IT, OT, and external vendors Contribute to continuous improvement initiatives and cybersecurity maturity uplift Stay up to date with emerging cloud threats, vulnerabilities, and best practices, translating insights into recommendations for QFExecute other cybersecurity tasks as assigned by Cyber Security seniors<br>SKILLS & COMPETENCIES:<br>Strong knowledge of Threat Intelligence platforms, feeds, and analysis techniques. Hands-on experience with Threat Hunting methodologies and MITRE ATT&CK framework. Strong understanding of Vulnerability Management tools and processes. Experience managing VAPT engagements and interpreting penetration testing results. Solid understanding of Web Application Security and OWASP Top10. Experience managing or working with WAF technologies. Knowledge of network security, endpoint security, and cloud security concepts. Familiarity with SIEM platforms (e.g., Splunk, Sentinel) for correlation and analysis. Understanding of OT security concepts and critical infrastructure risks is an advantage. Capable of developing clear reports, dashboards, procedures, and executive-level summaries. Excellent communication and presentation skills, with the ability to engage both technical and non-technical stakeholders, including senior management. Proven ability to manage multiple cloud security initiatives in a dynamic environment, delivering on time with strong planning and documentation skills. Demonstrates ownership in delivering assigned projects and contributes professionally to cross-functional initiatives without compromising primary responsibilities. Able to operate independently when needed, ensuring continuity of cybersecurity operations during team absences.<br><br>EXPERIENCE:5+ years of experience in Offensive Security, Threat Intelligence, Threat Hunting, Vulnerability Management, or Red Team–related roles. Proven experience managing VAPT and vulnerability remediation programs in large enterprise environments. Experience working in complex environments spanning IT, OT, and Cloud. Experience working with external security vendors, MSSPs, or consultants. Experience supporting cybersecurity drills, red team exercises, or adversary simulations is highly desirable.
ROLES & RESPONSIBILITIES:<br>Plan, coordinate, and execute Threat Hunting (TH) and penetration testing activities on a quarterly basis to proactively identify security weaknesses and emerging threats Establish, own, and maintain a centralized security findings tracking mechanism to record, monitor, prioritize, and ensure timely closure of all identified security issues Execute and manage the annual Vulnerability Assessment and Penetration Testing (VAPT) program across IT, OT, and Education City Stadium (ECS) environments Leverage Threat Intelligence (TI) platforms to their full capabilities, in line with best practices, to protect Qatar Foundation’s reputation and proactively defend against internal and external threats Review, analyze, and act upon NCSA advisories, as well as threat intelligence and threat hunting reports from reputable internal and external sources Ensure all relevant Indicators of Compromise (IOCs) are actively monitored, detected, and blocked across applicable security controls and QF environments Establish, operate, and continuously improve the Vulnerability Management (VM) program on a monthly basis, ensuring effective remediation tracking and risk reduction Escalate critical and high-risk security findings in a timely manner to relevant stakeholders to mitigate potential threats and reduce organizational risk Establish, maintain, and continuously update the Cyber Offensive knowledge base, including processes and procedures, asset scope, attack surface analysis, critical infrastructure coverage, and escalation paths Conduct weekly reviews of the security findings tracker to ensure progress, accountability, and closure of outstanding items Contribute to increasing the maturity of Qatar Foundation’s security controls through proactive testing, validation, and continuous improvement initiatives Propose actionable security recommendations and enhancements to strengthen Qatar Foundation’s overall cybersecurity maturity Ensure Vulnerability Assessments and Penetration Tests are aligned with recognized frameworks such as MITRE ATT&CK and OWASP Top 10Identify, propose, and enhance automation opportunities within offensive security activities to improve efficiency, coverage, and response times Manage application security scanning and provide security assurance across the software development lifecycle (SDLC), ensuring secure coding practices, timely identification of application vulnerabilities, and alignment with QF security standards before and after deployment Support secure application hardening and continuous improvement of web security controls Act as a red team–oriented security specialist, continuously simulating attacker behavior to identify control gaps Design and execute offensive security use cases that test detection, response, and resilience Produce actionable threat intelligence and hunting reports for SOC, Cyber Security leadership, and provide clear reporting to Cyber Security leadership on risk exposure, attack trends, and improvement areas Work closely with SOC, MSP/MSSP, IT, OT, and external vendors Contribute to continuous improvement initiatives and cybersecurity maturity uplift Stay up to date with emerging cloud threats, vulnerabilities, and best practices, translating insights into recommendations for QFExecute other cybersecurity tasks as assigned by Cyber Security seniors<br>SKILLS & COMPETENCIES:<br>Strong knowledge of Threat Intelligence platforms, feeds, and analysis techniques. Hands-on experience with Threat Hunting methodologies and MITRE ATT&CK framework. Strong understanding of Vulnerability Management tools and processes. Experience managing VAPT engagements and interpreting penetration testing results. Solid understanding of Web Application Security and OWASP Top10. Experience managing or working with WAF technologies. Knowledge of network security, endpoint security, and cloud security concepts. Familiarity with SIEM platforms (e.g., Splunk, Sentinel) for correlation and analysis. Understanding of OT security concepts and critical infrastructure risks is an advantage. Capable of developing clear reports, dashboards, procedures, and executive-level summaries. Excellent communication and presentation skills, with the ability to engage both technical and non-technical stakeholders, including senior management. Proven ability to manage multiple cloud security initiatives in a dynamic environment, delivering on time with strong planning and documentation skills. Demonstrates ownership in delivering assigned projects and contributes professionally to cross-functional initiatives without compromising primary responsibilities. Able to operate independently when needed, ensuring continuity of cybersecurity operations during team absences.<br><br>EXPERIENCE:5+ years of experience in Offensive Security, Threat Intelligence, Threat Hunting, Vulnerability Management, or Red Team–related roles. Proven experience managing VAPT and vulnerability remediation programs in large enterprise environments. Experience working in complex environments spanning IT, OT, and Cloud. Experience working with external security vendors, MSSPs, or consultants. Experience supporting cybersecurity drills, red team exercises, or adversary simulations is highly desirable.
ROLES & RESPONSIBILITIES:<br>Plan, coordinate, and execute Threat Hunting (TH) and penetration testing activities on a quarterly basis to proactively identify security weaknesses and emerging threats Establish, own, and maintain a centralized security findings tracking mechanism to record, monitor, prioritize, and ensure timely closure of all identified security issues Execute and manage the annual Vulnerability Assessment and Penetration Testing (VAPT) program across IT, OT, and Education City Stadium (ECS) environments Leverage Threat Intelligence (TI) platforms to their full capabilities, in line with best practices, to protect Qatar Foundation’s reputation and proactively defend against internal and external threats Review, analyze, and act upon NCSA advisories, as well as threat intelligence and threat hunting reports from reputable internal and external sources Ensure all relevant Indicators of Compromise (IOCs) are actively monitored, detected, and blocked across applicable security controls and QF environments Establish, operate, and continuously improve the Vulnerability Management (VM) program on a monthly basis, ensuring effective remediation tracking and risk reduction Escalate critical and high-risk security findings in a timely manner to relevant stakeholders to mitigate potential threats and reduce organizational risk Establish, maintain, and continuously update the Cyber Offensive knowledge base, including processes and procedures, asset scope, attack surface analysis, critical infrastructure coverage, and escalation paths Conduct weekly reviews of the security findings tracker to ensure progress, accountability, and closure of outstanding items Contribute to increasing the maturity of Qatar Foundation’s security controls through proactive testing, validation, and continuous improvement initiatives Propose actionable security recommendations and enhancements to strengthen Qatar Foundation’s overall cybersecurity maturity Ensure Vulnerability Assessments and Penetration Tests are aligned with recognized frameworks such as MITRE ATT&CK and OWASP Top 10Identify, propose, and enhance automation opportunities within offensive security activities to improve efficiency, coverage, and response times Manage application security scanning and provide security assurance across the software development lifecycle (SDLC), ensuring secure coding practices, timely identification of application vulnerabilities, and alignment with QF security standards before and after deployment Support secure application hardening and continuous improvement of web security controls Act as a red team–oriented security specialist, continuously simulating attacker behavior to identify control gaps Design and execute offensive security use cases that test detection, response, and resilience Produce actionable threat intelligence and hunting reports for SOC, Cyber Security leadership, and provide clear reporting to Cyber Security leadership on risk exposure, attack trends, and improvement areas Work closely with SOC, MSP/MSSP, IT, OT, and external vendors Contribute to continuous improvement initiatives and cybersecurity maturity uplift Stay up to date with emerging cloud threats, vulnerabilities, and best practices, translating insights into recommendations for QFExecute other cybersecurity tasks as assigned by Cyber Security seniors<br>SKILLS & COMPETENCIES:<br>Strong knowledge of Threat Intelligence platforms, feeds, and analysis techniques. Hands-on experience with Threat Hunting methodologies and MITRE ATT&CK framework. Strong understanding of Vulnerability Management tools and processes. Experience managing VAPT engagements and interpreting penetration testing results. Solid understanding of Web Application Security and OWASP Top10. Experience managing or working with WAF technologies. Knowledge of network security, endpoint security, and cloud security concepts. Familiarity with SIEM platforms (e.g., Splunk, Sentinel) for correlation and analysis. Understanding of OT security concepts and critical infrastructure risks is an advantage. Capable of developing clear reports, dashboards, procedures, and executive-level summaries. Excellent communication and presentation skills, with the ability to engage both technical and non-technical stakeholders, including senior management. Proven ability to manage multiple cloud security initiatives in a dynamic environment, delivering on time with strong planning and documentation skills. Demonstrates ownership in delivering assigned projects and contributes professionally to cross-functional initiatives without compromising primary responsibilities. Able to operate independently when needed, ensuring continuity of cybersecurity operations during team absences.<br><br>EXPERIENCE:5+ years of experience in Offensive Security, Threat Intelligence, Threat Hunting, Vulnerability Management, or Red Team–related roles. Proven experience managing VAPT and vulnerability remediation programs in large enterprise environments. Experience working in complex environments spanning IT, OT, and Cloud. Experience working with external security vendors, MSSPs, or consultants. Experience supporting cybersecurity drills, red team exercises, or adversary simulations is highly desirable.
<p>نحن نبحث عن مسؤول أمني يقظ ومحترف لينضم إلى فريقنا في مدينة لوسيل، قطر. في هذا الدور، ستكون مهمتك الحفاظ على بيئة آمنة ومأمونة لموظفينا والزوار والأصول القيمة. كمسؤول أمني، ستجمع بين ذهنك التحليلي وقرارك الحازم لمنع حوادث الأمن والاستجابة بشكل فعال لأي اضطرابات. نحن نبحث عن شخص منظم، يولي التفاصيل اهتماماً، وقادر على البقاء هادئاً تحت الضغط مع تعزيز ثقافة مكان عمل تعاونية وشاملة.</p><p>المراقبة المنهجية للمناطق المحددة لمنع واكتشاف مؤشرات التسلل، وضمان أمان الأبواب والنوافذ والبوابات ونقاط الدخول الأخرى راقب وافتح/تصرّف في دخول وخروج الموظفين والزوار وغيرهم من الأفراد للدفاع عن السرقة والحفاظ على أمان المبنى استجب فوراً للإنذارات وحقق في الاضطرابات بنزاهة وحكم سليم اكتب تقارير حوادث تفصيلية ودقيقة واحفظ سجلات النشاط اليومية الشاملة شغّل ورصد كاميرات المراقبة ومعدات الأمن الأخرى بإتقان واهتمام بالتفاصيل نفذ إجراءات التحكم في الوصول وأجرِ فحص أمن للأفراد والمركبات حسب الحاجة اصطحب أو قدِّم خدمات قيادة مركبات آلية لنقل الأشخاص إلى المواقع المحددة وقدم حماية شخصية عند الحاجة تعاون بفاعلية مع وكالات إنفاذ القانون المحلية وموظفي الأمن عند ضرورة الظروف الالتزام بجميع سياسات وإجراءات الشركة المتعلقة بالصحة والسلامة والمعايير البيئية أظهر خدمة عملاء استثنائية من خلال الرد على استفسارات ومخاوف الموظفين والزوار بلطف ومهنية ابقَ مطّلعاً على بروتوكولات الأمن وأفضل الممارسات في الصناعة واللوائح الأمنية الخاصة بقطر</p><p><strong>الملف المرشح المرغوب</strong></p><ul><li>شهادة الثانوية العامة أو مؤهل مكافئ</li><li>رخصة حارس أمن سارية ومعترف بها في قطر</li><li>خبرة مهنية في عمليات الأمن لمدة 2-3 سنوات على الأقل</li><li>شهادة الإسعاف الأولي و CPR (سارية ومفعلة)</li><li>لياقة بدنية ممتازة وقدرة على التحمل لأداء الواجبات بفعالية</li><li>إتقان في تقنيات المراقبة والرصد</li><li>معرفة قوية بإجراءات وخطط الاستجابة للطوارئ</li><li>اتصالات ومهارات شخصية استثنائية</li><li>إثبات القدرة على حل النزاعات وتخفيف التوتر</li><li>الإلمام بكتابة التقارير ومهارات الكمبيوتر الأساسية</li><li>معرفة شاملة بالقوانين واللوائح المحلية المتعلقة بعمليات الأمن في قطر</li><li>الألفة مع بروتوكولات الأمن وأفضل الممارسات في الصناعة</li><li>القدرة على البقاء هادئاً ومتماسكاً واتخاذ قرارات سليمة تحت الضغط</li><li>الاستعداد للعمل بساعات مرنة، بما في ذلك الليل والويكند والعطلات حسب الحاجة</li><li>إتقان اللغة الإنجليزية؛ يُفضل معرفة العربية</li><li>القدرة على العمل بفعالية في بيئة متعددة الثقافات ومتنوعة</li><li>تصريح عمل ساري أو أهلية تأشيرة للعمل في قطر</li><li>مهارات تنظيمية قوية واهتمام بالتفاصيل</li><li>المرونة والقدرة على التكيف في بيئات أمنية ديناميكية</li></ul>
<p>نحن نبحث عن مهندس PCS 7 / Siemens Failsafe Safety System ذو خبرة لمشروع بحري لدعم أنشطة تشغيل الموقع لأنظمة الأتمتة الصناعية والتحكم في العمليات. يجب أن يمتلك المتقدم المثالي خبرة قوية في Siemens PCS 7 DCS، أنظمة السلامة الفلايسيف (F-Systems)، والتشغيل، الاختبار، استكشاف الأخطاء، ودعم البدء ضمن بيئات النفط والغاز البحرية.</p><p><strong>المهام الأساسية</strong></p><ul><li>فحص لوحة التحكم والخزانة في البيئات البحرية. التحقق من التوصيلات وفق الرسومات الكهربائية ومخططات الحلقة. تنفيذ فحص الحلقة والتحقق من المدخلات/المخرجات. دعم اختبار القبول في المصنع (FAT) واختبار القبول في الموقع (SAT). التحقق من أجهزة المجال والاتصال مع أنظمة التحكم. التنسيق مع فرق الموقع البحرية والعملاء أثناء أنشطة التشغيل.</li><li>تكوين وتعديل منطق التحكم في Siemens PCS 7. تطوير وتعديل منطق السلامة F-CPU وفقاً لمتطلبات المشروع. إجراء اختبارات المنطق، اختبارات التتابع، والاختبارات الوظيفية. تكوين وتعديل رسومات HMI/OS وواجهات المشغل.</li><li>استكشاف مشكلات الأجهزة والبرمجيات والاتصالات.</li><li>دعم أنشطة البدء، التشغيل، وتسليم النظام.</li><li>إعداد تقارير التشغيل والوثائق الفنية.</li></ul><p><strong>المُرشَّح المثالي</strong></p><ul><li>خبرة قوية مع نظام التحكم الموزع Siemens PCS 7 (DCS).</li><li>خبرة عملية مع أنظمة السلامة الفلايسية من Siemens (F-CPU/F-Systems).</li><li>معرفة بأنظمة السلامةInstrumented (SIS).</li><li>خبرة في FAT وSAT وفحص الحلقة والتشغيل.</li><li>خبرة في استكشاف أعطال DCS وPLC وأجهزة المجال.</li><li>الإلمام بـ Profibus، Profinet، Industrial Ethernet وبروتوكولات الاتصالات الصناعية الأخرى.</li><li>فهم جيد لـ P&IDs ومخططات السبب والتأثير، مخططات المنطق، ورسم دوائر الحلقة.</li><li>مهارات تحليلية ممتازة، استكشاف الأخطاء، والتواصل.</li><li>الخبرة الصناعية المُفضلة في Offshore Oil & Gas Petrochemical Chemical Power Refinery Process Automation</li><li>التأهيل: درجة البكالوريوس أو الدبلوم في Instrumentation، Electronics، Electrical، أو Control Engineering.</li><li>الخبرة: الحد الأدنى 4 سنوات من الخبرة المتعلقة بـ Siemens PCS 7 وأنظمة السلامة الفلايسية.</li><li>خبرة عملية في التشغيل، البدء، واستكشاف أخطاء أنظمة الأتمتة الصناعية إلزامية</li></ul>
<h2 class="h5">وصف الوظيفة</h2>
<div class="t-break" data-jb-field="description">
نظرة عامة على الوظيفة<p>تبحث مؤسسة راسخة عن مشرف أمني متمرس للإشراف على أفراد الأمن وضمان تقديم عمليات الأمن بشكل فعال عبر المرافق التجارية.</p><br><br>المسؤوليات الأساسية<ul><li>الإشراف على ضباط الأمن خلال فترات المناوبة المحددة.</li><li>مراقبة أنظمة التحكم في الدخول وأنظمة المراقبة بالفيديو.</li><li>إجراء جولات تفتيش دورية وتفتيشات.</li><li>إدارة تقارير الحوادث والتحقيقات.</li><li>ضمان الالتزام بإجراءات الأمن.</li><li>تنسيق أنشطة الاستجابة للطوارئ.</li><li>تدريب وتوجيه موظفي الأمن.</li><li>إعداد تقارير تشغيلية.</li></ul>المتطلبات<ul><li>الحد الأدنى <strong>5 سنوات خبرة في مجال الأمن.</strong></li><li>خبرة إشراف سابقة.</li><li><strong>مطلوب الطلاقة باللغتين العربية والإنجليزية (نطقاً وكتابة).</strong></li><li>القدرة على حضور مقابلات العملاء قبل النشر.</li><li>مهارات قيادية واتصال قوية.</li></ul>المفضل<ul><li>شهادات متعلقة بالأمن.</li><li>شهادة إسعافات أولية.</li><li>رخصة قيادة سارية في قطر.</li></ul>
<br><br> </div>
We are seeking an experienced SOC L2 Security Analyst to monitor, investigate, and respond to cybersecurity incidents while supporting the organization's Security Operations Center (SOC). The role involves threat detection, incident response, security monitoring, and continuous improvement of security controls.<br><br>Key Responsibilities<br><br>Monitor and analyze security alerts, logs, and events. Investigate and respond to security incidents and threats. Perform threat analysis and incident correlation. Support incident response, containment, and remediation activities. Optimize SIEM use cases, correlation rules, and alerting mechanisms. Maintain security incident documentation and reports. Collaborate with IT and security teams to strengthen security posture. Mentor junior SOC analysts when required.<br><br>Requirements<br><br>Bachelor's Degree in Cybersecurity, Computer Science, IT, or related field. Minimum 7 years of experience in SOC, cybersecurity, or incident response roles. Strong experience with SIEM and EDR solutions. Solid understanding of network security, operating systems, and cyber threats. Excellent analytical, troubleshooting, and communication skills.<br><br>Preferred Certifications<br><br>CISSP, GCIH, GCIA, CEH, Security+, SC-200, or equivalent.<br><br>Preferred Skills<br><br>Experience with Microsoft Sentinel (Azure Sentinel). Knowledge of NIST, ISO 27001, and MITRE ATT&CK frameworks. Experience in enterprise or government security environments.<br><br>Skills: siem,soc,cybersecurity,sentinel,azure
<section><p class="heading jdMain">وصف الوظيفة</p><p class="heading">الأدوار والمسؤوليات</p><div class="paragraph"><p>سيكون ضابط الأمن مسؤولاً عن دوريات في المناطق العامة والمناطق الخاصة بالموظفين لضمان تقليل الخسائر من أي مصدر وبأي وسيلة، والحفاظ على سياسات الأمن والالتزام بلوائح الصحة والسلامة.</p></div></section><section><p class="heading">الملف المرشح المطلوب</p><p class="paragraph"></p><h2>المؤهلات والمهارات المفضلة</h2><ul><li>1-2 سنوات من الخبرة في وظيفة مماثلة بفندق فخم أو منتجع.</li><li>سيكون لدى المرشح المثالي شخصية اجتماعية ونهج يمكن تحقيقه لأي مهمة!</li><li>يتطلب القراءة والكتابة ومهارة التحدث باللغة الإنجليزية، العربية ستكون ميزة.</li></ul><p></p></section>
<h2 class="h5">وصف الوظيفة</h2>
<div class="t-break" data-jb-field="description">
وصف الوظيفة<br><p>نحن حالياً نبحث عن مدير الشبكات والأمن لعملياتنا في قطر.</p><br><p>المهارات:</p><br><p>تثبيت وتكوين وصيانة أجهزة الشبكة بما في ذلك أجهزة التوجيه والمحولات وجدران الحماية ونقاط الوصول اللاسلكية.</p><br><p>مراقبة أداء الشبكة وضمان أقصى وقت تشغيل وتوفر.</p><br><p>إدارة شبكة LAN وWAN وVPN وWLAN والاتصال بالإنترنت.</p><br><p>تكوين واستكشاف بروتوكولات وخدمات الشبكة.</p><br><p>النطاق: الخدمات المصرفية</p><br><p> إطار الانضمام: أسبوعان (حد أقصى شهر واحد)</p><br><br><br> </div>
About QNB<br><br>Established in 1964 as the country’s first Qatari-owned commercial bank, QNB Group has steadily grown to become the largest bank in the Middle East and Africa (MEA) region.<br><br>QNB Group’s presence through its subsidiaries and associate companies extends to more than 31 countries across three continents providing a comprehensive range of advanced products and services. The total number of employees is more than 28,000 serving up to 20 million customers operating through 1,000 locations, with an ATM network of 4,300 machines.<br><br>QNB has maintained its position as one of the highest rated regional banks from leading credit rating agencies including Standard & Poor’s (A), Moody’s (Aa3) and Fitch (A+). The Bank has also been the recipient of many awards from leading international specialised financial publications.<br><br>Based on the Group’s consistent strong financial performance and its expanding international presence, QNB currently ranks as the most valuable bank brand in the Middle East and Africa, according to Brand Finance Magazine.<br><br>QNB Group has an active community support program and sponsors various social, educational and sporting events.<br><br>Job Summary<br><br>The incumbent will be responsible for the setup and management of the Cyber Security Strategy and Product management function in the Group Information Security (GIS) department. The incumbent will be a banking and finance technology thinker who constantly analyses the market for new technologies that would be best suited to support the Group’s strategy<br><br>Main Responsibilities<br><br> Shareholder & Financial: - Participate in the development, execution and maintenance of the IT Security strategy aligned to the overall corporate strategy, group long term goals and assist in the prioritization process. - Assist in the overall and annual IT Security business planning with the view of achieving the Group’s short term goals and submit periodic reviews and resolution. - Provide inputs to the Technology Key Risk indicators (KRIs) which shall be applicable across the Group to manage Group’s exposure to IT related risks effectively. Lead IT market research and provide applicable suggestions to further the Group’s strategy and develop cost / benefit analysis to alternative technologies and processes. - Focal Point from GIS in the preparation of the GIS budget to support Group’s long and short term goals. - Responsible for coordinating all aspects of the GIS budget process including: review of service area business plans and key performance indicators; annual capital budget and forecasts that include available and appropriate funding sources along with required project justification analysis; operating budget and forecast submissions that adhere to direction set by bank - Liaise with all Business Units Heads for preparing the yearly IT Business Plans, Prepare monthly and quarterly update on IT Business Plan. Monitor the Progress Status and raise issues / risks to GIS management. - Produce Availability Plans in line with QNB’s business planning cycle; identifying Availability requirements early enough to take account of procurement lead times. - Create implement and report on Key Performance Indicators (KPIs) for performance monitoring purposes for the GIS group and monitor their achievement on a regular basis. - Produce Capacity Plans in line with QNB’s business planning cycle; identifying Capacity requirements early enough to take account of procurement lead times. - Document the need for any increase or reduction in hardware resources based on service level requirements and cost constraints - Implements KPI’s and best practices for Cyber Security Strategy and Product Management. - Promote cost consciousness and efficiency and enhance productivity, to minimise cost, avoid waste, and optimise benefits for the bank. - Act within the limits of the powers delegated to the incumbent and delegate authority to the respective staff and monitor exercise of the same. - Demonstrate clear understanding of the important factors behind the bank's financial & non-financial performance. Customer (Internal & External): - Build and maintain strong relationship with all other related departments, external entities and sections within GIS. - Defining & implementing Service Level Agreements (SLAs) and Operation Level Agreements (OLAs) between GIS, IT Group, other Business Units and International Branches. - Monitors capital and operating budget performance of GIS to identify unfavourable budget variances and recommend mitigating actions or additional approvals required to minimize impact to yearend surplus/deficit. - Seek to continually exceed internal and external customer expectations through introduction of breakthrough IT Security technologies and processes aimed to improve the Group’s products/services. - Produce regular management reports which include current usage of resources, trends and forecasts - Build and maintain a strong relationship with the Business Relationship Manager, technical teams within IT, finance team and external vendors of products and services - To assist customers in all their queries on Bank’s product and seek solution to their requests. - Maintain activities in accordance with Service Level Agreements (SLAs) with internal departments/units to achieve improvements in turn-around time. - Build and maintain strong/effective relationships with related departments/units to achieve the Group’s objectives Internal (Processes, Products, Regulatory): - Review and identify areas for improvement in the process to deliver effective & efficient GIS projects and services - Act as a BCP Coordinator for GIS, coordinate implementation of DR setup as per the defined strategy - Assist in recruiting, motivating and developing personnel to ensure the function is staffed with individuals of the required caliber and that there is adequate succession planning and provision for future demands. - Analyse and recommend new products and solutions for GIS and business users to ensure that the group is upto-date with the latest trends in technology. - Support the new technology’s development process, and ensure that project deliverables are met according to specifications and timeframes. - Compile and present relevant MIS to the Group CISO on a periodic basis for the existing systems and compare the existing functionalities vis-à-vis the efficiencies to be gained from proposed technologies. - Assist in the overall recruitment of the individual resources in the areas concerned - Continuous Improvement: - Set examples by leading improvement initiatives through cross-functional teams ensuring successes. - Identify and encourage people to adopt practices better than the industry standard. - Continuously encourage and recognise the importance of thinking out-of-the-box within the team. - Encourage, solicit and reward innovative ideas even in day-to-day issues. Learning & Knowledge: - Possess good knowledge and experience in COBIT and ITIL framework. - Detailed understanding of IT systems and secure architecture designs. - Good understanding of suitable solutions for configuration management, service desk, software library etc. - Identify areas for professional development for self and direct reports and take necessary actions - Hold meetings with direct reports and assess their performance. - Attend specific conferences in areas of financial services technology breakthroughs and innovations to adapt suitable ones to the bank’s security architecture and product portfolio. - Possess a superior knowledge of the GIS structure, its products and related risks together with a good knowledge of operations and related controls. - Identify areas for professional development of self and direct reports and act to enhance professional development of self and others - Proactively identify areas for professional development of self and undertake development activities. - Seek out opportunities to remain current with all developments in professional field. - Hold meetings with staff and assess their performance and your teams overall performance on a regular basis. - Take decisive action to ensure speedy resolution of unresolved grievances or conflicts within the team members. - Identify development opportunities and activities for staff and facilitate/coach them to improve their effectives and prepare them to assume greater responsibilities. Legal, Regulatory, and Risk Framework Responsibilities: - Comply with all applicable legal, regulatory and internal compliance requirements including, but not limited to, Group Compliance Policies and Procedures (AML & CTF, Sanctions Policy, Data Protection Policy, Fraud Control Policy, Whistle Blowing Policy, Conflict of Interest and Insider Dealing Policy). - Understand and effectively perform your role under the Three Lines of Defence principle to identify measure, monitor, manage and report risks. - Ensure systematic good outcomes for clients in accordance with Conduct Risk policy. - Support the framework of RCSA, KRI, Incident reporting and remediation, as appropriate, in accordance with the Operational Risk Management requirements. - Maintain appropriate knowledge to ensure full qualification to undertake the role. - Complete all mandatory training provided by the Bank, attain, and maintain the required levels of competence. - Attend mandatory (internal and external) seminars as instructed by the Bank. Other: - Ensure high standards of data protection and confidentiality to safeguard commercially sensitive information. - Maintaining utmost confidentiality concerning customer and internal bank information obtained during the course of business and provide such information on a need to know basis only to Senior Management of QNB, Audit and Compliance functions, and relevant Regulators. - Maintain high professional standards to uphold QNB's reputation and to strengthen its market leadership position. - All other ad hoc duties/activities related to QNB that management might request from time to time. - Lead and develop the Cyber Security Strategy of the bank in line with the business strategy, regulatory requirement, best practices and ongoing cyber security challenges. - Benchmark and evaluate the performance of the technologies engineered and operated by the GIS Cyber Security Technologies & Services teams to ensure that these are kept fine-tuned and updated with the latest technological developments.- Constantly scanning the market and competitors capabilities and bringing in technology proven in other markets and suggesting them across the group. - Keeping the CISO updated with latest developments in Cyber Security and raising any new cyber security risks to his attention. - Maintain the security architecture blueprints of the bank, liaising with the Enterprise IT architect and GITD Heads to develop and track the plans to achieve compliance. - Help to form the Information Security budget in collaboration with the Group Information Security Officer ensuring that systems under management are licensed and appropriately sized for the environment - Ensure that all the licenses and contracts are maintained and kept updated.<br><br>Education And Experience Requirements<br><br> Bachelor’s/Master’s Degree in Computer Science, Computer Engineering or any related subject. Experience in IT service management of systems Technical Design, Implementation, and Maintenance on wide variety of platform including the main banking platform. At least 15 year’s experience in a major bank of which at least 5 years in bank in a managerial capacity in an IT Security engineering or architecture function. Training courses and certifications in application development, database administration, security, and management is a plus. Professional certifications, an ITIL foundation, TOGAF and COBIT is a must - Professional certification such as CISSP, CISM, CISA is preferred.<br><br>Note: you will be required to attach the following:<br><br>Resume/CVCopy of Passport or QID Copy of Education Certificate Copy of Birth Certificate
### هدف العمل<br>سيكون مدير مشروع تكنولوجيا المعلومات مسؤولاً عن إدارة وتوصيل مشاريع تكنولوجيا المعلومات عبر بيئة البنوك من البداية حتى التنفيذ والإغلاق. يتطلب الدور حوكمة مشروع قوية، إدارة أصحاب المصلحة، تنسيق المورّدين، إدارة المخاطر، والقدرة على تقديم المشاريع ضمن النطاق، الجدول الزمني، الميزانية، ومتطلبات الجودة.<br>### المسؤوليات الأساسية<br>* إدارة مشاريع تكنولوجيا المعلومات من البداية للنهاية، من البدء والتخطيط حتى التنفيذ، التشغيل الفعلي، النقل، والإغلاق.* وضع وصيانة خطط المشروع والجداول الزمنية وال milestones والميزانيات وخطط الموارد.* إدارة *النطاق، المخاطر، القضايا، الاعتمادات، التغييرات، والتحكم بالمشروع*. *تنسيق مع الأعمال، التطبيق، البنية التحتية، الأمن السيبراني، العمليات، PMO، والبائعين الخارجيين.* إدارة علاقات البائعين والعقود والتسليمات ومقاييس الأداء (SLA).* إعداد تقارير حالة المشروع ولوحات القيادة وعروض لجنة التوجيه والتقارير التنفيذية.* قيادة اجتماعات المشروع وضمان الحلول الفورية للقضايا والاعتمادات.* تنسيق جمع المتطلبات، الاختبار، UAT، النشر، التشغيل الفعلي، ونقل العملية.* ضمان الامتثال لسياسات البنوك والمتطلبات التنظيمية وضوابط التدقيق وأمن المعلومات ومعايير الحوكمة.* متابعة تقدم المشروع واتخاذ إجراءات تصحيحية لضمان *التسليم في الوقت المحدد وضمن الميزانية*.* تطبيق أساليب إدارة المشاريع *الأجايل، الشلال، أو الهجين* حسب الحاجة.* الحفاظ على وثائق المشروع بما في ذلك الميثاق، SOW، WBS، سجل RAID، سجل المخاطر، طلبات التغيير، خطط التنفيذ، وتقارير الإغلاق.<br>### المتطلبات الإلزامية<br>* *8+ سنوات من الخبرة المثبتة في إدارة مشاريع تكنولوجيا المعلومات.** *شهادة PMP / PMI إلزامية.** *خبرة في قطاع البنوك إلزامية.** خبرة قوية في *تحول تكنولوجيا المعلومات / مشاريع تقنية مؤسسية*.** خبرة في إدارة فرق متعددة الوظائف وبائعين من الغير.* معرفة قوية بـ *حوكمة المشروع، إدارة المخاطر، إدارة التغيير، وإدارة أصحاب المصلحة*.*** مهارات اتصال وتقرير وقيادة وحل مشاكل ممتازة.* خبرة مع *أساليب الأجايل / سكرم، الشلال، أو الهجين*.<br>### خبرة بنكية مفضلة<br>سيُفضَّل جداً وجود خبرة في أي من التالي:<br>*المصرفية الأساسية | الخدمات المصرفية الرقمية | المدفوعات | البطاقات | أجهزة الصراف الآلي | T24/Temenos | تطبيقات بنكية | مشاريع تنظيمية | بنية بنكية | تكامل النظام*<br>### مهارات إلزامية قصيرة<br>*PMP/PMI | إدارة مشاريع تكنولوجيا المعلومات | 8+ سنوات | بنوك | حوكمة المشروع | إدارة المخاطر | إدارة أصحاب المصلحة | إدارة البائعين | أجايل/شلال | تحويل تكنولوجيا المعلومات*
Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Dubai - United Arab Emirates; Doha, Qatar; Riyadh Saudi Arabia. Minimum qualifications:<br><br>Bachelor's degree in Cybersecurity, with a focus on offensive security or equivalent practical experience.3 years of experience in three of the following security areas: web application security assessment, mobile application security assessment, API security assessment, red team assessments, EDR evasion, exploit development, cloud, social engineering, scripting, tool development. Experience delivering reporting and presentations to both technical and executive audiences. Experience with operating system security across operating systems or Linux.<br><br>Preferred qualifications:<br><br>Certifications related to application security including BSCP, OSWE, e WPTX, e MAPT, 8ksec CMSE or relevant SANS courses. Experience in creating security tools and understanding of underlying programming languages (such as Python, C#, C/C++, Rust, Nim or similar). Experience conducting web application, API, and mobile (i OS and Android) security assessments following industry standards such as OWASP WSTG/ASVS, OWASP Top 10, OWASP API Top 10 and OWASP MASVS/MASTG. Experience in web application and API penetration testing tooling including Burp Suite Professional, Burp Suite extensions, Postman, nuclei, ffuf and sqlmap.<br><br>About The Job<br><br>As a Security Consultant, you will be responsible for helping clients effectively prepare for, proactively mitigate, and detect and respond to cyber security threats. Security Consultants have an understanding of computer science, operating system functionality and networking, cloud services, corporate network environments and how to apply this knowledge to cyber security threats.<br><br>As a Security Consultant, you could work on engagements including assisting clients in navigating technically complex and high-profile incidents, performing forensic analysis, threat hunting, and malware triage. You may also test client networks, applications and devices by emulating the latest techniques to help them defend against threats, and will be the technical advocate for information security requirements and provide an in-depth understanding of the information security domain. You will also articulate and present complex concepts to business stakeholders, executive leadership, and technical contributors and successfully lead complex engagements alongside cross functional teams.<br><br>We are seeking a highly skilled and experienced Application Security Consultant to join the team.<br><br>In this role, you will be responsible for providing cybersecurity consulting services and support to the clients, including assessing and advising clients on both technical and process-based controls for all manner of environments.<br><br>Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.<br><br>Responsibilities<br><br>Conduct comprehensive security assessments of Web applications, APIs, and Mobile applications by identifying, exploiting and validating vulnerabilities using industry-standard methodologies such as the OWASP Web Security Testing Guide (WSTG), OWASP API Security Top 10, and OWASP Mobile Application Security Testing Guide (MASTG). Discover critical vulnerabilities in applications and be able to weaponize them. Expand the team’s capabilities through tool creation, research on offensive techniques, incorporation of threat actor intelligence, internal presentations and knowledge share. Develop comprehensive and accurate reports and presentations for both technical and executive audiences, and act as a trusted advisor to c-level, security leaders and other customer stakeholders. Assist with scoping prospective engagements, leading teams for engagements from kickoff through remediation phase, as well as mentoring other staff.<br><br><br>Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form .
يركز فريق القطاع العام الدولي المتنامي في شركة Scale على استخدام الذكاء الاصطناعي لمواجهة التحديات الحاسمة التي تواجه القطاع العام حول العالم. تتكون أعمالنا الأساسية من:<br><br>إنشاء تطبيقات ذكاء اصطناعي مخصصة سيكون لها تأثير على ملايين المواطنين، وإنشاء بيانات تدريب عالية الجودة لنماذج لغوية كبيرة (LLMs) مخصصة، وتقديم خدمات رفع المهارات والاستشارات لنشر تأثير الذكاء الاصطناعي.<br><br>بصفتك مهندس برمجيات متكامل (Full Stack) (يعمل ميدانياً)، ستتعاون مباشرة مع نظرائك في القطاع العام لبناء تطبيقات ذكاء اصطناعي متكاملة بسرعة، وذلك لحل أكثر تحدياتهم إلحاحاً وتحقيق تأثير ملموس للمواطنين.<br><br>في Scale، نحن لا نبني حلول الذكاء الاصطناعي فحسب، بل نمكّن القطاع العام من تحويل عملياتهم وخدمة المواطنين بشكل أفضل من خلال التكنولوجيا المتطورة. إذا كنت مستعداً لتشكيل مستقبل الذكاء الاصطناعي في القطاع العام وأن تكون عضواً مؤسساً في فريقنا، فنحن نود أن نسمع منك.<br><br>ستقوم بـ:<br><br>العمل كاستراتيجي تقني رئيسي لمشاريع القطاع العام، وتحويل متطلبات المهمة الغامضة إلى خرائط طريق معمارية قوية وتوجيه التنفيذ في الموقع. هندسة الأطر الأساسية لتطبيقات الذكاء الاصطناعي الجاهزة للإنتاج، ووضع المعيار الذهبي لكيفية دمج واجهات المستخدم التفاعلية وأنظمة الواجهة الخلفية ونماذج الذكاء الاصطناعي على نطاق واسع لتقديم نتائج موثوقة. توجيه تطور البنية التحتية السحابية، وضمان الأمن، وقابلية التوسع العالمي، وسلامة النظام على المدى الطويل عبر جميع البيئات. توجيه تطوير المنصات الأساسية والخدمات المشتركة، وضمان حلها للاحتياجات المتقاطعة لحالات استخدام متنوعة للعملاء العالميين. الشراكة مع القيادة متعددة الوظائف لتوجيه خارطة الطريق التقنية، وتوجيه الموظفين من ذوي الخبرة والمبتدئين، وضمان توافق جميع المنتجات مع بنية تقنية متماسكة ومستقبلية. سد الفجوة بين العمل الميداني والمنصة الأساسية من خلال تحويل دروس العملاء الواقعية إلى أنماط قابلة لإعادة الاستخدام تدعم فريق الهندسة بأكمله.<br><br>من الناحية المثالية، يجب أن تمتلك:<br><br>درجة الماجستير أو الدكتوراه في علوم الحاسب أو خبرة صناعية عميقة مماثلة في هندسة الأنظمة المعقدة والموزعة. خبرة تزيد عن 10 سنوات في تطوير البرمجيات المتكاملة (Full-stack) عبر Python و Node.js و React، مع سجل حافل في تصميم بنيات عالية النطاق على Kubernetes والبنى التحتية السحابية العالمية (AWS/Azure/GCP). قدرة الخبير على تصميم والإشراف على الأنظمة الجاهزة للإنتاج، وضمان معايير عالمية لسلامة النظام، والأمن، وقابلية التوسع على المدى الطويل. خبرة واسعة في نشر واستكشاف أخطاء الحلول المتطورة من البداية إلى النهاية مباشرة داخل بيئات العملاء المعقدة وعالية الأمان. سجل حافل في بناء حلول تعتمد على النماذج اللغوية الكبيرة (LLM) مع البصيرة الاستراتيجية لتوقع تحولات المشهد وهندسة أنظمة مستقبلية. قائد يتمتع بالدافع الذاتي وقادر على حل الغموض الشديد، وتوجيه الموظفين الكبار، ووضع الرؤية التقنية للمنظمة. محرك لسير العمل غير المتزامن وثقافة "التوثيق أولاً" لتبسيط سرعة الهندسة العالمية وتقليل الاحتكاك.<br><br>يفضل وجود:<br><br>خبرة سابقة في العمل في شركة ناشئة كمدير تقني (CTO) أو مهندس مؤسس، أو في دور مهندس ميداني / مهندس عملاء مخصص. خبرة في العمل بشكل متعدد الوظائف مع العمليات. إجادة اللغة العربية.<br><br>بالنسبة للمتقدمين المقيمين في قطر: تتطلب الإقامة والعمل في قطر تصاريح معينة (تأشيرات وتراخيص) صادرة عن السلطات القطرية. كجزء من عملية التقديم، سيُطلب من المرشحين تقديم معلومات شخصية، بما في ذلك حالة الإقامة والجنسية، وهو أمر مطلوب لمعالجة التأشيرة. يتم جمع هذه المعلومات فقط لأغراض الامتثال للهجرة ولن تُستخدم كمعيار في أي قرار توظيف ما لم يكن هذا الاستخدام مسموحاً به قانوناً. إصدار التأشيرة يخضع لتقدير السلطات القطرية. إذا نجحت في طلبك، سيُطلب منك تقديم الوثائق التي تطلبها شركة Scale والسلطات للحصول على التصاريح اللازمة للعيش والعمل في قطر، وستعمل Scale مع المرشحين الناجحين لدعم عملية طلب التأشيرة.<br><br>يرجى الملاحظة: تتطلب سياستنا فترة انتظار مدتها 90 يوماً قبل إعادة النظر في المرشحين لنفس الدور. هذا يسمح لنا بضمان تقييم عادل وشامل لجميع المتقدمين.<br><br>عن شركتنا:<br><br>في Scale، مهمتنا هي تطوير أنظمة ذكاء اصطناعي موثوقة لأهم قرارات العالم. توفر منتجاتنا البيانات عالية الجودة وتقنيات البرمجيات المتكاملة التي تدعم النماذج الرائدة عالمياً، وتساعد الشركات والحكومات على بناء ونشر والإشراف على تطبيقات الذكاء الاصطناعي التي تقدم تأثيراً حقيقياً. نحن نعمل بشكل وثيق مع قادة الصناعة مثل Meta وErnst & Young وMayo Clinic وTime Inc. وحكومة قطر والوكالات الحكومية الأمريكية بما في ذلك الجيش والقوات الجوية. نحن نعمل على توسيع فريقنا لتسريع تطوير تطبيقات الذكاء الاصطناعي.<br><br>نحن نؤمن بأن الجميع يجب أن يكونوا قادرين على تقديم أفضل ما لديهم في العمل، ولهذا السبب نحن فخورون بأن نكون مكان عمل شامل ويمنح فرصاً متساوية. نحن ملتزمون بتكافؤ فرص العمل بغض النظر عن العرق، أو اللون، أو الأصل، أو الدين، أو الجنس، أو الأصل القومي، أو التوجه الجنسي، أو العمر، أو المواطنة، أو الحالة الاجتماعية، أو حالة الإعاقة، أو الهوية الجندرية، أو حالة المحاربين القدامى.<br><br>نحن ملتزمون بالعمل مع المتقدمين ذوي الإعاقات الجسدية والعقلية وتوفير التسهيلات المعقولة لهم. إذا كنت بحاجة إلى مساعدة و/أو تسهيلات معقولة في عملية التقديم أو التوظيف بسبب إعاقة، يرجى الاتصال بنا على accommodations@scale.com. يرجى الاطلاع على ملصق "اعرف حقوقك" الصادر عن وزارة العمل الأمريكية للحصول على معلومات إضافية.<br><br>نحن نمتثل لشرط شفافية الأجور الصادر عن وزارة العمل الأمريكية.<br><br>يرجى الملاحظة: نحن نجمع ونحتفظ ونستخدم البيانات الشخصية لأغراض أعمالنا المهنية، بما في ذلك إخطارك بفرص العمل التي قد تهمك ومشاركتها مع الشركات التابعة لنا. نحن نقصر البيانات الشخصية التي نجمعها على ما نعتقد أنه مناسب وضروري لإدارة احتياجات المتقدمين، وتقديم خدماتنا، والامتثال للقوانين المعمول بها. سيتم التعامل مع أي معلومات نجمعها فيما يتعلق بطلبك وفقاً لسياساتنا وبرامجنا الداخلية المصممة لحماية البيانات الشخصية. يرجى الاطلاع على سياسة الخصوصية الخاصة بنا للحصول على معلومات إضافية.
عن الدور: الإشراف على مشرفي وموظفي الأمن المتعاقدين وتوجيه الأنشطة اليومية لضمان جودة المخرجات والتنفيذ وفقاً للخطة. التواصل مع أصحاب المصلحة المعنيين فيما يتعلق بتعريفات وصول الموظفين والطلبات لإبقاء جميع الأشخاص المعنيين على اطلاع. دعم أصحاب المصلحة والأعضاء داخل القسم فيما يتعلق بتجميع المستندات والإحصائيات المتعلقة بتقارير الحوادث ومعالجتها، وتحليل الاتجاهات، من أجل تقديم مشاريع التحسين المستمر. إنشاء إحصائيات وتقارير بانتظام من تقارير النوبة اليومية وتقارير الحوادث لأغراض مرجعية. تسهيل تجميع تقارير النوبة اليومية وتقارير الحوادث من خلال جمع البيانات، من أجل تقديم النتائج بطريقة هادفة. المساعدة في الاستجابة لأي حالة طوارئ أو اضطراب تشغيلي كبير أو تهديد يؤثر على مطار حمد الدولي أو الشركات التابعة لمجموعته، بما في ذلك دعم برنامج المساعدة الخاصة للخطوط الجوية القطرية (مثل مرافقة مركبات الطوارئ، والمساعدة في توفير أطواق أمنية) لضمان تنفيذ خطط الطوارئ بسلاسة. القيام بدوريات راجلة/محمولة منتظمة في مباني ركاب المسافرين، ومواقع البناء، ومناطق ساحة الطائرات، ومنطقة منتصف الميدان، وغيرها من المناطق مثل الجانب البري/الجانب الجوي (المحيط) للحماية من أي خرق أمني، أو اعتداءات، أو تخريب، أو سرقة، أو تلف في الممتلكات، أو حريق، أو غيرها من المخاطر التي تهدد الممتلكات. إجراء اختبار المخدرات والكحول (إذا لزم الأمر) وتنفيذ سياسة حق التفتيش كما هو مصرح به، لضمان الالتزام بسياسة شركة الخطوط الجوية القطرية. الاستجابة في حالة وقوع أي حادث أو واقعة تشغيلية يتم الإبلاغ عنها في كل من الجانب البري والجانب الجوي للمطار وبدء الاستجابة اللازمة. إبلاغ الإدارة بالأمر فوراً لضمان تصعيد الأمور المهمة واتخاذ إجراءات سريعة استجابةً للحادث/الواقعة. التأكد من تنفيذ نقاط التفتيش الأمنية للركاب العابرين وعملية فحص الأمتعة المحمولة بما يتوافق مع اللوائح المحلية والحفاظ على اتفاقية مستوى الخدمة طوال الوقت. التأكد من أداء واجبات الفحص الثانوي وفقاً لمتطلبات السلطات الأجنبية. مسؤول عن التأكد من تقديم خدمات أمن شركات الطيران الأخرى وفقاً لمتطلبات السلطات الأجنبية وإدارة جميع تغطية الإشراف المطلوبة وعمليات التوثيق بدقة. الإشراف على مواقع فحص الموظفين والحراسة الأمنية وتنفيذ أنشطة مراقبة الجودة التشغيلية لضمان تقديم العملية الموثقة بفعالية. أداء واجبات قسم أخرى تتعلق بمنصبه حسب توجيهات رئيس القسم. عنك: شهادة ثانوية/مهنية/دبلوم أو ما يعادلها مع خبرة لا تقل عن 4 سنوات في مجال العمل، أو درجة البكالوريوس أو ما يعادلها مع خبرة لا تقل عن 4 سنوات في مجال العمل. خبرة في مجال أمن المطار/الطيران. مهارات تقنية ممتازة في تقنية المعلومات بما في ذلك MS Office (PowerPoint، Word، Excel). يفضل الحصول على رخصة قيادة.
Job Description<br><br>We are seeking a skilled Senior Cloud Security Engineer to join our Cybersecurity Practice. In this role, you will work closely with cloud, infrastructure, network, endpoint, and application teams to design, implement, and maintain enterprise security controls that protect our clients’ digital environments.<br><br>Your responsibilities will span Identity & Access Management (IAM), Data Security, Cloud Security, Endpoint Security, and Network Security. You will support the implementation of security best practices, monitor security posture, identify risks, and contribute to improving the overall security architecture across hybrid IT environments.<br><br>You will assist in assessing security architectures, identifying vulnerabilities, implementing security solutions, and supporting incident response activities to ensure confidentiality, integrity, and availability of systems and data. The role requires hands-on technical expertise, strong analytical capabilities, and the ability to translate security requirements into practical and scalable security solutions.<br><br>Responsibilities<br><br>Enterprise Security Architecture and Risk Assessment:Support the assessment of enterprise IT and cloud environments to identify security risks and recommend appropriate controls across identity, data, network, endpoint, and cloud domains. Conduct security reviews of infrastructure, configurations, and deployments and provide actionable remediation recommendations aligned with industry best practices. Identity and Access Management (IAM):Implement and support secure identity and access controls, including role-based access control (RBAC), least privilege, multi-factor authentication (MFA), privileged access management (PAM), and identity governance practices across enterprise and cloud environments. Data Security:Assist in implementing data protection controls including data classification, encryption at rest and in transit, key management, data loss prevention (DLP), and secure data handling practices to ensure regulatory and organizational compliance. Cloud Security:Support secure configuration and monitoring of public, private, and hybrid cloud platforms. Implement security controls related to IAM, network segmentation, workload protection, encryption, logging, and compliance monitoring. Contribute to cloud security posture management and vulnerability remediation efforts. Endpoint Security:Support deployment and management of endpoint protection solutions including EDR/XDR platforms, antivirus, device control, patch management, and hardening baselines. Monitor endpoint security alerts and assist in incident investigation and response. Security Technology Stack:Support the implementation and management of security platforms and monitoring tools to strengthen security posture, improve visibility, and enhance threat detection across enterprise and cloud environments. Documentation and Reporting:Prepare and maintain documentation related to security configurations, risk assessments, incident reports, and operational procedures. Provide regular security posture updates to internal stakeholders and clients as required.<br><br>Qualifications<br><br>Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field. Experience: At least 5 years of experience in cloud security, cloud infrastructure, cybersecurity operations, or a closely related role. Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:Microsoft Azure Security Engineer Associate (AZ-500) Microsoft Certified: Identity and Access Administrator Associate (SC-300) Microsoft Certified: Azure Administrator Associate (AZ-104) Comp TIA Security+, CySA+, or similar ISC2 (e.g., CC or SSCP) CSA or other cloud security certifications.). Technical Skills: Hands-on experience with security technologies including identity platforms (such as Entra ID and Active Directory), cloud-native security tools, endpoint protection solutions (EDR/XDR), network security technologies (firewalls, IDS/IPS, VPN), SIEM and log monitoring solutions, encryption and key management systems, and vulnerability management tools. Familiarity with integrating security controls across enterprise and cloud environments is preferred. Knowledge: Strong understanding of cybersecurity principles including defense-in-depth, zero trust, least privilege, segmentation, encryption, vulnerability management, and incident response. Familiarity with security frameworks and guidelines (e.g., CIS Benchmarks, NIST, ISO 27001) and general compliance/governance concepts. Knowledge of Qatar National Information Assurance (NIA) is a plus.
<section><p class="heading jdMain">وصف الوظيفة</p><p class="heading">الأدوار والمسؤوليات</p><div class="paragraph"><p>نحن نبحث عن مهندسي اختبارات المشي ذوي الخبرة في مشاريع هواوي للقيام باختبارات RF داخلية، والتحقق من التغطية، وتحليل الأداء لشبكات GSM، UMTS، LTE، و5G. يجب أن يكون لدى المرشح المثالي معرفة قوية باختبار حلول المباني الداخلية (IBS) وأن يكون قادرًا على إجراء اختبارات المشي بشكل مستقل وإعداد تقارير تقنية.</p><p><b>الأدوار والمسؤوليات:</b></p><ul><li>إجراء اختبارات تحقق الموقع الواحد الداخلي (SSV) لشبكات GSM، UMTS، LTE، و5G.</li><li>تحديد متطلبات اختبار الموقع داخل المبنى وإجراء اختبارات المشي على مستوى الطابق وعلى مستوى المبنى.</li><li>إجراء تدقيق RF داخلي والتحقق من التغطية والأداء الشبكي.</li><li>تنفيذ اختبارات تغطية وأداء IBS.</li><li>إعداد تقارير Walk Test SSV وتقارير اختبارات IBS.</li><li>تحليل أداء الشبكة الداخلي وتحديد مشاكل التغطية.</li><li>ضمان امتثال أنشطة الاختبار لمعايير قبول المشروع ومعايير التقارير.</li><li>التنسيق مع فرق المشروع لحل مشاكل أداء الشبكة.</li></ul></div></section><section><p class="heading">الملف المرشح المطلوب</p><p class="paragraph"></p><ul><li>دبلوم أو شهادة بكالوريوس في الإلكترونيات، الاتصالات، الهندسة الكهربائية، أو مجال ذو صلة (مفضل)</li><li>خبرة لا تقل عن 3-5 سنوات في اختبارات المشي</li><li>يفضل الخبرة في مشاريع هواوي</li><li>يفضل الخبرة في مشاريع خارج الدولة</li><li>خبرة في اختبار الشبكات الداخلية لـ GSM، UMTS، LTE، و5G</li><li>معرفة قوية باختبار RF الداخلي، واختبار IBS، واختبار المشي، وتدقيق RF، وتحليل التغطية</li><li>القدرة على إعداد تقارير تقنية وتحليل سجلات الاختبار</li><li>مهارات تواصل وحل مشكلات جيدة</li></ul><p></p></section>