وظائف مهندسى امن معلومات - الدوحة قطر
٤٢٤٢ وظائف شاغرة
Network Infrastructure Manager40,000 - 45,000 QAR<br>Network Systems Delivery• Creates high level plans, rules, and designs for networks and technology systems needed to support the business.• Makes plans for networks and communication systems, sets service level agreements, and organizes the Network infrastructure to meet these agreements.• Oversees networking and infrastructure projects, identifies and reduces risks, ensures projects are completed on time and with good quality, and makes sure resources are used effectively.• Negotiates agreements for network services, diagnoses issues, and takes action to improve service delivery.• Develop and implement strategic plans for network infrastructure that align with the company’s goals and objectives.• Provide visionary leadership to guide the evolution of the network infrastructure to meet future business needs.• Oversee the execution of large-scale network infrastructure projects, ensuring alignment with strategic objectives and business requirements.• Ensure projects are delivered on time, within budget, and to the highest quality standards.• Establish project governance frameworks and ensure adherence to best practices.• Drive continuous improvement and innovation within the network infrastructure domain.• Evaluate emerging technologies and trends to enhance network capabilities and performance.• Optimize existing infrastructure to improve efficiency, scalability, and reliability.• Communicate project status, risks, and outcomes effectively to stakeholders at all levels.• Lead, and develop a high-performing team of network engineers and project managers.• Ensure the team is equipped with the necessary skills and resources to succeed.• Identify, assess, and mitigate risks associated with network infrastructure projects and operations.• Develop and maintain strategic relationships with key vendors and partners.• Negotiate contracts and service level agreements (SLAs) to ensure optimal service delivery and value.• Monitor vendor performance and address any issues proactively.• Disaster recovery plans for testing of recovery procedures and ensures that the network and infrastructure meet all agreed performance targets and service levels.• Keeps track of the ICT market to learn about new technologies like cloud computing, Saa S, and data analytics. Evaluates their usefulness and potential value for the Organization.• Supervises professional, technical and support staff engaged in performing duties related to specialization.<br>Communication/Documentation Skill• Ability to clearly explain technical concepts to both technical and non-technical stakeholders.• Proficiency in creating accurate and accessible documentation for projects and procedures.• Skill in negotiating with vendors and resolving conflicts to ensure project success.• Communicate project status, issues, and recommendations to senior management and stakeholders clearly and concisely.• Essential skills for drafting comprehensive and effective RFPs, RFQs, and similar documents to facilitate successful vendor selection and project execution. Problem Solving Skills• Capable of leading and providing guidance to the team to resolve complex network infrastructure problems.• Capable to resolve issues escalated internally.<br>• Minimum 15 years of in managing enterprise level network environments, supporting large business organizations.• Extensive experience in designing, delivering, and operating large scale, branch wide, and multi site distributed network infrastructures.• Proven experience working in client operational environments with multi tenancy models, shared infrastructure, and service segregation requirements.• Strong understanding of network technologies, architectures, protocols, security, resilience, and industry best practices across core, data center, WAN, and access networks.• Demonstrated ability to balance deep technical expertise with managerial, operational, and strategic responsibilities.• Solid knowledge of project and program management methodologies, including planning, execution, risk management, and delivery governance.• Strong knowledge of financial management, budgeting, procurement processes including RFP preparation, technical evaluation, and vendor selection, as well as negotiation and management of complex technical contracts and SLAs.• Proven track record of strategic planning, service optimization, and continuous improvement in complex IT and network environments.• Strong leadership capability to manage, mentor, and develop multi disciplinary technical teams.• Excellent communication, stakeholder engagement, and negotiation skills, particularly in client facing and vendor managed environments.• Possession of a recognized bachelor’s or Master degree in computer science, Computer Information Systems, Information Systems Management, Computer Engineering or a related area.• Significant experience in network infrastructure management, typically 8+ years, supported by a minimum of 10 years of technical network experience in enterprise level, multi site and large business organization environments.• Relevant certifications such as CCIE (SP, R&S, Wireless, or Data Center) (Cisco Certified Internetwork Expert) is highly recommended.• PMP (Project Management Professional) certification or equivalent is plus.• Experience with Routing and switching, including protocols like TCP/IP, OSPF, and BGP.• Skill in using monitoring tools to oversee network performance and optimize efficiency.• Ability to diagnose and resolve network issues promptly.• Knowledge of capacity planning methodologies to ensure network scalability and performance.• Understanding of disaster recovery planning and implementation, ensuring network resilience.• Experience in managing relationships with network hardware/software vendors and service providers.• Familiarity with cloud computing concepts and integration of cloud services into network infrastructure.• Knowledge in Virtualization technologies like ACI, NSX, SD-WAN, SD-ACESS etc.• Knowledge in VPN Technologies like IPSec, DMVPN, GRE, GETVPN etc.• Proficiency in wireless networking, including 802.11 Standards, Wireless Controllers, RF Management, SSID Configuration, Wireless Security, Tunneling and Encryption.• Proficiency in LDP, L3VPN, L2VPN, VPLS, AToM, CsC, Inter-AS, MPLS-TE, and FRR.• Expertise in Border Gateway Protocol (BGP) and Multi-Protocol BGP (MP-BGP) for routing and managing network traffic.
<p>نحن حالياً نبحث عن مدير الشبكات والأمن لعملياتنا في قطر.</p><p>المهارات: تثبيت وتكوين وصيانة أجهزة الشبكة بما في ذلك الموجهات والمفاتيح وجدران الحماية ونقاط الوصول اللاسلكية. مراقبة أداء الشبكة وضمان أعلى معدل توافر واستمرارية. إدارة LAN وWAN وVPN وWLAN واتصال الإنترنت. تكوين واستكشاف أخطاء بروتوكولات وخدمات الشبكة.</p><p><strong>الملف الشخصي للمرشح المطلوب</strong></p><p>غير متاح حالياً</p>
ROLES & RESPONSIBILITIES:<br>Plan, coordinate, and execute Threat Hunting (TH) and penetration testing activities on a quarterly basis to proactively identify security weaknesses and emerging threats Establish, own, and maintain a centralized security findings tracking mechanism to record, monitor, prioritize, and ensure timely closure of all identified security issues Execute and manage the annual Vulnerability Assessment and Penetration Testing (VAPT) program across IT, OT, and Education City Stadium (ECS) environments Leverage Threat Intelligence (TI) platforms to their full capabilities, in line with best practices, to protect Qatar Foundation’s reputation and proactively defend against internal and external threats Review, analyze, and act upon NCSA advisories, as well as threat intelligence and threat hunting reports from reputable internal and external sources Ensure all relevant Indicators of Compromise (IOCs) are actively monitored, detected, and blocked across applicable security controls and QF environments Establish, operate, and continuously improve the Vulnerability Management (VM) program on a monthly basis, ensuring effective remediation tracking and risk reduction Escalate critical and high-risk security findings in a timely manner to relevant stakeholders to mitigate potential threats and reduce organizational risk Establish, maintain, and continuously update the Cyber Offensive knowledge base, including processes and procedures, asset scope, attack surface analysis, critical infrastructure coverage, and escalation paths Conduct weekly reviews of the security findings tracker to ensure progress, accountability, and closure of outstanding items Contribute to increasing the maturity of Qatar Foundation’s security controls through proactive testing, validation, and continuous improvement initiatives Propose actionable security recommendations and enhancements to strengthen Qatar Foundation’s overall cybersecurity maturity Ensure Vulnerability Assessments and Penetration Tests are aligned with recognized frameworks such as MITRE ATT&CK and OWASP Top 10Identify, propose, and enhance automation opportunities within offensive security activities to improve efficiency, coverage, and response times Manage application security scanning and provide security assurance across the software development lifecycle (SDLC), ensuring secure coding practices, timely identification of application vulnerabilities, and alignment with QF security standards before and after deployment Support secure application hardening and continuous improvement of web security controls Act as a red team–oriented security specialist, continuously simulating attacker behavior to identify control gaps Design and execute offensive security use cases that test detection, response, and resilience Produce actionable threat intelligence and hunting reports for SOC, Cyber Security leadership, and provide clear reporting to Cyber Security leadership on risk exposure, attack trends, and improvement areas Work closely with SOC, MSP/MSSP, IT, OT, and external vendors Contribute to continuous improvement initiatives and cybersecurity maturity uplift Stay up to date with emerging cloud threats, vulnerabilities, and best practices, translating insights into recommendations for QFExecute other cybersecurity tasks as assigned by Cyber Security seniors<br>SKILLS & COMPETENCIES:<br>Strong knowledge of Threat Intelligence platforms, feeds, and analysis techniques. Hands-on experience with Threat Hunting methodologies and MITRE ATT&CK framework. Strong understanding of Vulnerability Management tools and processes. Experience managing VAPT engagements and interpreting penetration testing results. Solid understanding of Web Application Security and OWASP Top10. Experience managing or working with WAF technologies. Knowledge of network security, endpoint security, and cloud security concepts. Familiarity with SIEM platforms (e.g., Splunk, Sentinel) for correlation and analysis. Understanding of OT security concepts and critical infrastructure risks is an advantage. Capable of developing clear reports, dashboards, procedures, and executive-level summaries. Excellent communication and presentation skills, with the ability to engage both technical and non-technical stakeholders, including senior management. Proven ability to manage multiple cloud security initiatives in a dynamic environment, delivering on time with strong planning and documentation skills. Demonstrates ownership in delivering assigned projects and contributes professionally to cross-functional initiatives without compromising primary responsibilities. Able to operate independently when needed, ensuring continuity of cybersecurity operations during team absences.<br><br>EXPERIENCE:5+ years of experience in Offensive Security, Threat Intelligence, Threat Hunting, Vulnerability Management, or Red Team–related roles. Proven experience managing VAPT and vulnerability remediation programs in large enterprise environments. Experience working in complex environments spanning IT, OT, and Cloud. Experience working with external security vendors, MSSPs, or consultants. Experience supporting cybersecurity drills, red team exercises, or adversary simulations is highly desirable.
ROLES & RESPONSIBILITIES:<br>Plan, coordinate, and execute Threat Hunting (TH) and penetration testing activities on a quarterly basis to proactively identify security weaknesses and emerging threats Establish, own, and maintain a centralized security findings tracking mechanism to record, monitor, prioritize, and ensure timely closure of all identified security issues Execute and manage the annual Vulnerability Assessment and Penetration Testing (VAPT) program across IT, OT, and Education City Stadium (ECS) environments Leverage Threat Intelligence (TI) platforms to their full capabilities, in line with best practices, to protect Qatar Foundation’s reputation and proactively defend against internal and external threats Review, analyze, and act upon NCSA advisories, as well as threat intelligence and threat hunting reports from reputable internal and external sources Ensure all relevant Indicators of Compromise (IOCs) are actively monitored, detected, and blocked across applicable security controls and QF environments Establish, operate, and continuously improve the Vulnerability Management (VM) program on a monthly basis, ensuring effective remediation tracking and risk reduction Escalate critical and high-risk security findings in a timely manner to relevant stakeholders to mitigate potential threats and reduce organizational risk Establish, maintain, and continuously update the Cyber Offensive knowledge base, including processes and procedures, asset scope, attack surface analysis, critical infrastructure coverage, and escalation paths Conduct weekly reviews of the security findings tracker to ensure progress, accountability, and closure of outstanding items Contribute to increasing the maturity of Qatar Foundation’s security controls through proactive testing, validation, and continuous improvement initiatives Propose actionable security recommendations and enhancements to strengthen Qatar Foundation’s overall cybersecurity maturity Ensure Vulnerability Assessments and Penetration Tests are aligned with recognized frameworks such as MITRE ATT&CK and OWASP Top 10Identify, propose, and enhance automation opportunities within offensive security activities to improve efficiency, coverage, and response times Manage application security scanning and provide security assurance across the software development lifecycle (SDLC), ensuring secure coding practices, timely identification of application vulnerabilities, and alignment with QF security standards before and after deployment Support secure application hardening and continuous improvement of web security controls Act as a red team–oriented security specialist, continuously simulating attacker behavior to identify control gaps Design and execute offensive security use cases that test detection, response, and resilience Produce actionable threat intelligence and hunting reports for SOC, Cyber Security leadership, and provide clear reporting to Cyber Security leadership on risk exposure, attack trends, and improvement areas Work closely with SOC, MSP/MSSP, IT, OT, and external vendors Contribute to continuous improvement initiatives and cybersecurity maturity uplift Stay up to date with emerging cloud threats, vulnerabilities, and best practices, translating insights into recommendations for QFExecute other cybersecurity tasks as assigned by Cyber Security seniors<br>SKILLS & COMPETENCIES:<br>Strong knowledge of Threat Intelligence platforms, feeds, and analysis techniques. Hands-on experience with Threat Hunting methodologies and MITRE ATT&CK framework. Strong understanding of Vulnerability Management tools and processes. Experience managing VAPT engagements and interpreting penetration testing results. Solid understanding of Web Application Security and OWASP Top10. Experience managing or working with WAF technologies. Knowledge of network security, endpoint security, and cloud security concepts. Familiarity with SIEM platforms (e.g., Splunk, Sentinel) for correlation and analysis. Understanding of OT security concepts and critical infrastructure risks is an advantage. Capable of developing clear reports, dashboards, procedures, and executive-level summaries. Excellent communication and presentation skills, with the ability to engage both technical and non-technical stakeholders, including senior management. Proven ability to manage multiple cloud security initiatives in a dynamic environment, delivering on time with strong planning and documentation skills. Demonstrates ownership in delivering assigned projects and contributes professionally to cross-functional initiatives without compromising primary responsibilities. Able to operate independently when needed, ensuring continuity of cybersecurity operations during team absences.<br><br>EXPERIENCE:5+ years of experience in Offensive Security, Threat Intelligence, Threat Hunting, Vulnerability Management, or Red Team–related roles. Proven experience managing VAPT and vulnerability remediation programs in large enterprise environments. Experience working in complex environments spanning IT, OT, and Cloud. Experience working with external security vendors, MSSPs, or consultants. Experience supporting cybersecurity drills, red team exercises, or adversary simulations is highly desirable.
ROLES & RESPONSIBILITIES:<br>Plan, coordinate, and execute Threat Hunting (TH) and penetration testing activities on a quarterly basis to proactively identify security weaknesses and emerging threats Establish, own, and maintain a centralized security findings tracking mechanism to record, monitor, prioritize, and ensure timely closure of all identified security issues Execute and manage the annual Vulnerability Assessment and Penetration Testing (VAPT) program across IT, OT, and Education City Stadium (ECS) environments Leverage Threat Intelligence (TI) platforms to their full capabilities, in line with best practices, to protect Qatar Foundation’s reputation and proactively defend against internal and external threats Review, analyze, and act upon NCSA advisories, as well as threat intelligence and threat hunting reports from reputable internal and external sources Ensure all relevant Indicators of Compromise (IOCs) are actively monitored, detected, and blocked across applicable security controls and QF environments Establish, operate, and continuously improve the Vulnerability Management (VM) program on a monthly basis, ensuring effective remediation tracking and risk reduction Escalate critical and high-risk security findings in a timely manner to relevant stakeholders to mitigate potential threats and reduce organizational risk Establish, maintain, and continuously update the Cyber Offensive knowledge base, including processes and procedures, asset scope, attack surface analysis, critical infrastructure coverage, and escalation paths Conduct weekly reviews of the security findings tracker to ensure progress, accountability, and closure of outstanding items Contribute to increasing the maturity of Qatar Foundation’s security controls through proactive testing, validation, and continuous improvement initiatives Propose actionable security recommendations and enhancements to strengthen Qatar Foundation’s overall cybersecurity maturity Ensure Vulnerability Assessments and Penetration Tests are aligned with recognized frameworks such as MITRE ATT&CK and OWASP Top 10Identify, propose, and enhance automation opportunities within offensive security activities to improve efficiency, coverage, and response times Manage application security scanning and provide security assurance across the software development lifecycle (SDLC), ensuring secure coding practices, timely identification of application vulnerabilities, and alignment with QF security standards before and after deployment Support secure application hardening and continuous improvement of web security controls Act as a red team–oriented security specialist, continuously simulating attacker behavior to identify control gaps Design and execute offensive security use cases that test detection, response, and resilience Produce actionable threat intelligence and hunting reports for SOC, Cyber Security leadership, and provide clear reporting to Cyber Security leadership on risk exposure, attack trends, and improvement areas Work closely with SOC, MSP/MSSP, IT, OT, and external vendors Contribute to continuous improvement initiatives and cybersecurity maturity uplift Stay up to date with emerging cloud threats, vulnerabilities, and best practices, translating insights into recommendations for QFExecute other cybersecurity tasks as assigned by Cyber Security seniors<br>SKILLS & COMPETENCIES:<br>Strong knowledge of Threat Intelligence platforms, feeds, and analysis techniques. Hands-on experience with Threat Hunting methodologies and MITRE ATT&CK framework. Strong understanding of Vulnerability Management tools and processes. Experience managing VAPT engagements and interpreting penetration testing results. Solid understanding of Web Application Security and OWASP Top10. Experience managing or working with WAF technologies. Knowledge of network security, endpoint security, and cloud security concepts. Familiarity with SIEM platforms (e.g., Splunk, Sentinel) for correlation and analysis. Understanding of OT security concepts and critical infrastructure risks is an advantage. Capable of developing clear reports, dashboards, procedures, and executive-level summaries. Excellent communication and presentation skills, with the ability to engage both technical and non-technical stakeholders, including senior management. Proven ability to manage multiple cloud security initiatives in a dynamic environment, delivering on time with strong planning and documentation skills. Demonstrates ownership in delivering assigned projects and contributes professionally to cross-functional initiatives without compromising primary responsibilities. Able to operate independently when needed, ensuring continuity of cybersecurity operations during team absences.<br><br>EXPERIENCE:5+ years of experience in Offensive Security, Threat Intelligence, Threat Hunting, Vulnerability Management, or Red Team–related roles. Proven experience managing VAPT and vulnerability remediation programs in large enterprise environments. Experience working in complex environments spanning IT, OT, and Cloud. Experience working with external security vendors, MSSPs, or consultants. Experience supporting cybersecurity drills, red team exercises, or adversary simulations is highly desirable.
ROLES & RESPONSIBILITIES:<br>Plan, coordinate, and execute Threat Hunting (TH) and penetration testing activities on a quarterly basis to proactively identify security weaknesses and emerging threats Establish, own, and maintain a centralized security findings tracking mechanism to record, monitor, prioritize, and ensure timely closure of all identified security issues Execute and manage the annual Vulnerability Assessment and Penetration Testing (VAPT) program across IT, OT, and Education City Stadium (ECS) environments Leverage Threat Intelligence (TI) platforms to their full capabilities, in line with best practices, to protect Qatar Foundation’s reputation and proactively defend against internal and external threats Review, analyze, and act upon NCSA advisories, as well as threat intelligence and threat hunting reports from reputable internal and external sources Ensure all relevant Indicators of Compromise (IOCs) are actively monitored, detected, and blocked across applicable security controls and QF environments Establish, operate, and continuously improve the Vulnerability Management (VM) program on a monthly basis, ensuring effective remediation tracking and risk reduction Escalate critical and high-risk security findings in a timely manner to relevant stakeholders to mitigate potential threats and reduce organizational risk Establish, maintain, and continuously update the Cyber Offensive knowledge base, including processes and procedures, asset scope, attack surface analysis, critical infrastructure coverage, and escalation paths Conduct weekly reviews of the security findings tracker to ensure progress, accountability, and closure of outstanding items Contribute to increasing the maturity of Qatar Foundation’s security controls through proactive testing, validation, and continuous improvement initiatives Propose actionable security recommendations and enhancements to strengthen Qatar Foundation’s overall cybersecurity maturity Ensure Vulnerability Assessments and Penetration Tests are aligned with recognized frameworks such as MITRE ATT&CK and OWASP Top 10Identify, propose, and enhance automation opportunities within offensive security activities to improve efficiency, coverage, and response times Manage application security scanning and provide security assurance across the software development lifecycle (SDLC), ensuring secure coding practices, timely identification of application vulnerabilities, and alignment with QF security standards before and after deployment Support secure application hardening and continuous improvement of web security controls Act as a red team–oriented security specialist, continuously simulating attacker behavior to identify control gaps Design and execute offensive security use cases that test detection, response, and resilience Produce actionable threat intelligence and hunting reports for SOC, Cyber Security leadership, and provide clear reporting to Cyber Security leadership on risk exposure, attack trends, and improvement areas Work closely with SOC, MSP/MSSP, IT, OT, and external vendors Contribute to continuous improvement initiatives and cybersecurity maturity uplift Stay up to date with emerging cloud threats, vulnerabilities, and best practices, translating insights into recommendations for QFExecute other cybersecurity tasks as assigned by Cyber Security seniors<br>SKILLS & COMPETENCIES:<br>Strong knowledge of Threat Intelligence platforms, feeds, and analysis techniques. Hands-on experience with Threat Hunting methodologies and MITRE ATT&CK framework. Strong understanding of Vulnerability Management tools and processes. Experience managing VAPT engagements and interpreting penetration testing results. Solid understanding of Web Application Security and OWASP Top10. Experience managing or working with WAF technologies. Knowledge of network security, endpoint security, and cloud security concepts. Familiarity with SIEM platforms (e.g., Splunk, Sentinel) for correlation and analysis. Understanding of OT security concepts and critical infrastructure risks is an advantage. Capable of developing clear reports, dashboards, procedures, and executive-level summaries. Excellent communication and presentation skills, with the ability to engage both technical and non-technical stakeholders, including senior management. Proven ability to manage multiple cloud security initiatives in a dynamic environment, delivering on time with strong planning and documentation skills. Demonstrates ownership in delivering assigned projects and contributes professionally to cross-functional initiatives without compromising primary responsibilities. Able to operate independently when needed, ensuring continuity of cybersecurity operations during team absences.<br><br>EXPERIENCE:5+ years of experience in Offensive Security, Threat Intelligence, Threat Hunting, Vulnerability Management, or Red Team–related roles. Proven experience managing VAPT and vulnerability remediation programs in large enterprise environments. Experience working in complex environments spanning IT, OT, and Cloud. Experience working with external security vendors, MSSPs, or consultants. Experience supporting cybersecurity drills, red team exercises, or adversary simulations is highly desirable.
ROLES & RESPONSIBILITIES:<br>Plan, coordinate, and execute Threat Hunting (TH) and penetration testing activities on a quarterly basis to proactively identify security weaknesses and emerging threats Establish, own, and maintain a centralized security findings tracking mechanism to record, monitor, prioritize, and ensure timely closure of all identified security issues Execute and manage the annual Vulnerability Assessment and Penetration Testing (VAPT) program across IT, OT, and Education City Stadium (ECS) environments Leverage Threat Intelligence (TI) platforms to their full capabilities, in line with best practices, to protect Qatar Foundation’s reputation and proactively defend against internal and external threats Review, analyze, and act upon NCSA advisories, as well as threat intelligence and threat hunting reports from reputable internal and external sources Ensure all relevant Indicators of Compromise (IOCs) are actively monitored, detected, and blocked across applicable security controls and QF environments Establish, operate, and continuously improve the Vulnerability Management (VM) program on a monthly basis, ensuring effective remediation tracking and risk reduction Escalate critical and high-risk security findings in a timely manner to relevant stakeholders to mitigate potential threats and reduce organizational risk Establish, maintain, and continuously update the Cyber Offensive knowledge base, including processes and procedures, asset scope, attack surface analysis, critical infrastructure coverage, and escalation paths Conduct weekly reviews of the security findings tracker to ensure progress, accountability, and closure of outstanding items Contribute to increasing the maturity of Qatar Foundation’s security controls through proactive testing, validation, and continuous improvement initiatives Propose actionable security recommendations and enhancements to strengthen Qatar Foundation’s overall cybersecurity maturity Ensure Vulnerability Assessments and Penetration Tests are aligned with recognized frameworks such as MITRE ATT&CK and OWASP Top 10Identify, propose, and enhance automation opportunities within offensive security activities to improve efficiency, coverage, and response times Manage application security scanning and provide security assurance across the software development lifecycle (SDLC), ensuring secure coding practices, timely identification of application vulnerabilities, and alignment with QF security standards before and after deployment Support secure application hardening and continuous improvement of web security controls Act as a red team–oriented security specialist, continuously simulating attacker behavior to identify control gaps Design and execute offensive security use cases that test detection, response, and resilience Produce actionable threat intelligence and hunting reports for SOC, Cyber Security leadership, and provide clear reporting to Cyber Security leadership on risk exposure, attack trends, and improvement areas Work closely with SOC, MSP/MSSP, IT, OT, and external vendors Contribute to continuous improvement initiatives and cybersecurity maturity uplift Stay up to date with emerging cloud threats, vulnerabilities, and best practices, translating insights into recommendations for QFExecute other cybersecurity tasks as assigned by Cyber Security seniors<br>SKILLS & COMPETENCIES:<br>Strong knowledge of Threat Intelligence platforms, feeds, and analysis techniques. Hands-on experience with Threat Hunting methodologies and MITRE ATT&CK framework. Strong understanding of Vulnerability Management tools and processes. Experience managing VAPT engagements and interpreting penetration testing results. Solid understanding of Web Application Security and OWASP Top10. Experience managing or working with WAF technologies. Knowledge of network security, endpoint security, and cloud security concepts. Familiarity with SIEM platforms (e.g., Splunk, Sentinel) for correlation and analysis. Understanding of OT security concepts and critical infrastructure risks is an advantage. Capable of developing clear reports, dashboards, procedures, and executive-level summaries. Excellent communication and presentation skills, with the ability to engage both technical and non-technical stakeholders, including senior management. Proven ability to manage multiple cloud security initiatives in a dynamic environment, delivering on time with strong planning and documentation skills. Demonstrates ownership in delivering assigned projects and contributes professionally to cross-functional initiatives without compromising primary responsibilities. Able to operate independently when needed, ensuring continuity of cybersecurity operations during team absences.<br><br>EXPERIENCE:5+ years of experience in Offensive Security, Threat Intelligence, Threat Hunting, Vulnerability Management, or Red Team–related roles. Proven experience managing VAPT and vulnerability remediation programs in large enterprise environments. Experience working in complex environments spanning IT, OT, and Cloud. Experience working with external security vendors, MSSPs, or consultants. Experience supporting cybersecurity drills, red team exercises, or adversary simulations is highly desirable.
We are seeking an experienced SOC L2 Security Analyst to monitor, investigate, and respond to cybersecurity incidents while supporting the organization's Security Operations Center (SOC). The role involves threat detection, incident response, security monitoring, and continuous improvement of security controls.<br><br>Key Responsibilities<br><br>Monitor and analyze security alerts, logs, and events. Investigate and respond to security incidents and threats. Perform threat analysis and incident correlation. Support incident response, containment, and remediation activities. Optimize SIEM use cases, correlation rules, and alerting mechanisms. Maintain security incident documentation and reports. Collaborate with IT and security teams to strengthen security posture. Mentor junior SOC analysts when required.<br><br>Requirements<br><br>Bachelor's Degree in Cybersecurity, Computer Science, IT, or related field. Minimum 7 years of experience in SOC, cybersecurity, or incident response roles. Strong experience with SIEM and EDR solutions. Solid understanding of network security, operating systems, and cyber threats. Excellent analytical, troubleshooting, and communication skills.<br><br>Preferred Certifications<br><br>CISSP, GCIH, GCIA, CEH, Security+, SC-200, or equivalent.<br><br>Preferred Skills<br><br>Experience with Microsoft Sentinel (Azure Sentinel). Knowledge of NIST, ISO 27001, and MITRE ATT&CK frameworks. Experience in enterprise or government security environments.<br><br>Skills: siem,soc,cybersecurity,sentinel,azure
About QNB<br><br>Established in 1964 as the country’s first Qatari-owned commercial bank, QNB Group has steadily grown to become the largest bank in the Middle East and Africa (MEA) region.<br><br>QNB Group’s presence through its subsidiaries and associate companies extends to more than 31 countries across three continents providing a comprehensive range of advanced products and services. The total number of employees is more than 28,000 serving up to 20 million customers operating through 1,000 locations, with an ATM network of 4,300 machines.<br><br>QNB has maintained its position as one of the highest rated regional banks from leading credit rating agencies including Standard & Poor’s (A), Moody’s (Aa3) and Fitch (A+). The Bank has also been the recipient of many awards from leading international specialised financial publications.<br><br>Based on the Group’s consistent strong financial performance and its expanding international presence, QNB currently ranks as the most valuable bank brand in the Middle East and Africa, according to Brand Finance Magazine.<br><br>QNB Group has an active community support program and sponsors various social, educational and sporting events.<br><br>Job Summary<br><br>The incumbent will be responsible for the setup and management of the Cyber Security Strategy and Product management function in the Group Information Security (GIS) department. The incumbent will be a banking and finance technology thinker who constantly analyses the market for new technologies that would be best suited to support the Group’s strategy<br><br>Main Responsibilities<br><br> Shareholder & Financial: - Participate in the development, execution and maintenance of the IT Security strategy aligned to the overall corporate strategy, group long term goals and assist in the prioritization process. - Assist in the overall and annual IT Security business planning with the view of achieving the Group’s short term goals and submit periodic reviews and resolution. - Provide inputs to the Technology Key Risk indicators (KRIs) which shall be applicable across the Group to manage Group’s exposure to IT related risks effectively. Lead IT market research and provide applicable suggestions to further the Group’s strategy and develop cost / benefit analysis to alternative technologies and processes. - Focal Point from GIS in the preparation of the GIS budget to support Group’s long and short term goals. - Responsible for coordinating all aspects of the GIS budget process including: review of service area business plans and key performance indicators; annual capital budget and forecasts that include available and appropriate funding sources along with required project justification analysis; operating budget and forecast submissions that adhere to direction set by bank - Liaise with all Business Units Heads for preparing the yearly IT Business Plans, Prepare monthly and quarterly update on IT Business Plan. Monitor the Progress Status and raise issues / risks to GIS management. - Produce Availability Plans in line with QNB’s business planning cycle; identifying Availability requirements early enough to take account of procurement lead times. - Create implement and report on Key Performance Indicators (KPIs) for performance monitoring purposes for the GIS group and monitor their achievement on a regular basis. - Produce Capacity Plans in line with QNB’s business planning cycle; identifying Capacity requirements early enough to take account of procurement lead times. - Document the need for any increase or reduction in hardware resources based on service level requirements and cost constraints - Implements KPI’s and best practices for Cyber Security Strategy and Product Management. - Promote cost consciousness and efficiency and enhance productivity, to minimise cost, avoid waste, and optimise benefits for the bank. - Act within the limits of the powers delegated to the incumbent and delegate authority to the respective staff and monitor exercise of the same. - Demonstrate clear understanding of the important factors behind the bank's financial & non-financial performance. Customer (Internal & External): - Build and maintain strong relationship with all other related departments, external entities and sections within GIS. - Defining & implementing Service Level Agreements (SLAs) and Operation Level Agreements (OLAs) between GIS, IT Group, other Business Units and International Branches. - Monitors capital and operating budget performance of GIS to identify unfavourable budget variances and recommend mitigating actions or additional approvals required to minimize impact to yearend surplus/deficit. - Seek to continually exceed internal and external customer expectations through introduction of breakthrough IT Security technologies and processes aimed to improve the Group’s products/services. - Produce regular management reports which include current usage of resources, trends and forecasts - Build and maintain a strong relationship with the Business Relationship Manager, technical teams within IT, finance team and external vendors of products and services - To assist customers in all their queries on Bank’s product and seek solution to their requests. - Maintain activities in accordance with Service Level Agreements (SLAs) with internal departments/units to achieve improvements in turn-around time. - Build and maintain strong/effective relationships with related departments/units to achieve the Group’s objectives Internal (Processes, Products, Regulatory): - Review and identify areas for improvement in the process to deliver effective & efficient GIS projects and services - Act as a BCP Coordinator for GIS, coordinate implementation of DR setup as per the defined strategy - Assist in recruiting, motivating and developing personnel to ensure the function is staffed with individuals of the required caliber and that there is adequate succession planning and provision for future demands. - Analyse and recommend new products and solutions for GIS and business users to ensure that the group is upto-date with the latest trends in technology. - Support the new technology’s development process, and ensure that project deliverables are met according to specifications and timeframes. - Compile and present relevant MIS to the Group CISO on a periodic basis for the existing systems and compare the existing functionalities vis-à-vis the efficiencies to be gained from proposed technologies. - Assist in the overall recruitment of the individual resources in the areas concerned - Continuous Improvement: - Set examples by leading improvement initiatives through cross-functional teams ensuring successes. - Identify and encourage people to adopt practices better than the industry standard. - Continuously encourage and recognise the importance of thinking out-of-the-box within the team. - Encourage, solicit and reward innovative ideas even in day-to-day issues. Learning & Knowledge: - Possess good knowledge and experience in COBIT and ITIL framework. - Detailed understanding of IT systems and secure architecture designs. - Good understanding of suitable solutions for configuration management, service desk, software library etc. - Identify areas for professional development for self and direct reports and take necessary actions - Hold meetings with direct reports and assess their performance. - Attend specific conferences in areas of financial services technology breakthroughs and innovations to adapt suitable ones to the bank’s security architecture and product portfolio. - Possess a superior knowledge of the GIS structure, its products and related risks together with a good knowledge of operations and related controls. - Identify areas for professional development of self and direct reports and act to enhance professional development of self and others - Proactively identify areas for professional development of self and undertake development activities. - Seek out opportunities to remain current with all developments in professional field. - Hold meetings with staff and assess their performance and your teams overall performance on a regular basis. - Take decisive action to ensure speedy resolution of unresolved grievances or conflicts within the team members. - Identify development opportunities and activities for staff and facilitate/coach them to improve their effectives and prepare them to assume greater responsibilities. Legal, Regulatory, and Risk Framework Responsibilities: - Comply with all applicable legal, regulatory and internal compliance requirements including, but not limited to, Group Compliance Policies and Procedures (AML & CTF, Sanctions Policy, Data Protection Policy, Fraud Control Policy, Whistle Blowing Policy, Conflict of Interest and Insider Dealing Policy). - Understand and effectively perform your role under the Three Lines of Defence principle to identify measure, monitor, manage and report risks. - Ensure systematic good outcomes for clients in accordance with Conduct Risk policy. - Support the framework of RCSA, KRI, Incident reporting and remediation, as appropriate, in accordance with the Operational Risk Management requirements. - Maintain appropriate knowledge to ensure full qualification to undertake the role. - Complete all mandatory training provided by the Bank, attain, and maintain the required levels of competence. - Attend mandatory (internal and external) seminars as instructed by the Bank. Other: - Ensure high standards of data protection and confidentiality to safeguard commercially sensitive information. - Maintaining utmost confidentiality concerning customer and internal bank information obtained during the course of business and provide such information on a need to know basis only to Senior Management of QNB, Audit and Compliance functions, and relevant Regulators. - Maintain high professional standards to uphold QNB's reputation and to strengthen its market leadership position. - All other ad hoc duties/activities related to QNB that management might request from time to time. - Lead and develop the Cyber Security Strategy of the bank in line with the business strategy, regulatory requirement, best practices and ongoing cyber security challenges. - Benchmark and evaluate the performance of the technologies engineered and operated by the GIS Cyber Security Technologies & Services teams to ensure that these are kept fine-tuned and updated with the latest technological developments.- Constantly scanning the market and competitors capabilities and bringing in technology proven in other markets and suggesting them across the group. - Keeping the CISO updated with latest developments in Cyber Security and raising any new cyber security risks to his attention. - Maintain the security architecture blueprints of the bank, liaising with the Enterprise IT architect and GITD Heads to develop and track the plans to achieve compliance. - Help to form the Information Security budget in collaboration with the Group Information Security Officer ensuring that systems under management are licensed and appropriately sized for the environment - Ensure that all the licenses and contracts are maintained and kept updated.<br><br>Education And Experience Requirements<br><br> Bachelor’s/Master’s Degree in Computer Science, Computer Engineering or any related subject. Experience in IT service management of systems Technical Design, Implementation, and Maintenance on wide variety of platform including the main banking platform. At least 15 year’s experience in a major bank of which at least 5 years in bank in a managerial capacity in an IT Security engineering or architecture function. Training courses and certifications in application development, database administration, security, and management is a plus. Professional certifications, an ITIL foundation, TOGAF and COBIT is a must - Professional certification such as CISSP, CISM, CISA is preferred.<br><br>Note: you will be required to attach the following:<br><br>Resume/CVCopy of Passport or QID Copy of Education Certificate Copy of Birth Certificate
### هدف العمل<br>سيكون مدير مشروع تكنولوجيا المعلومات مسؤولاً عن إدارة وتوصيل مشاريع تكنولوجيا المعلومات عبر بيئة البنوك من البداية حتى التنفيذ والإغلاق. يتطلب الدور حوكمة مشروع قوية، إدارة أصحاب المصلحة، تنسيق المورّدين، إدارة المخاطر، والقدرة على تقديم المشاريع ضمن النطاق، الجدول الزمني، الميزانية، ومتطلبات الجودة.<br>### المسؤوليات الأساسية<br>* إدارة مشاريع تكنولوجيا المعلومات من البداية للنهاية، من البدء والتخطيط حتى التنفيذ، التشغيل الفعلي، النقل، والإغلاق.* وضع وصيانة خطط المشروع والجداول الزمنية وال milestones والميزانيات وخطط الموارد.* إدارة *النطاق، المخاطر، القضايا، الاعتمادات، التغييرات، والتحكم بالمشروع*. *تنسيق مع الأعمال، التطبيق، البنية التحتية، الأمن السيبراني، العمليات، PMO، والبائعين الخارجيين.* إدارة علاقات البائعين والعقود والتسليمات ومقاييس الأداء (SLA).* إعداد تقارير حالة المشروع ولوحات القيادة وعروض لجنة التوجيه والتقارير التنفيذية.* قيادة اجتماعات المشروع وضمان الحلول الفورية للقضايا والاعتمادات.* تنسيق جمع المتطلبات، الاختبار، UAT، النشر، التشغيل الفعلي، ونقل العملية.* ضمان الامتثال لسياسات البنوك والمتطلبات التنظيمية وضوابط التدقيق وأمن المعلومات ومعايير الحوكمة.* متابعة تقدم المشروع واتخاذ إجراءات تصحيحية لضمان *التسليم في الوقت المحدد وضمن الميزانية*.* تطبيق أساليب إدارة المشاريع *الأجايل، الشلال، أو الهجين* حسب الحاجة.* الحفاظ على وثائق المشروع بما في ذلك الميثاق، SOW، WBS، سجل RAID، سجل المخاطر، طلبات التغيير، خطط التنفيذ، وتقارير الإغلاق.<br>### المتطلبات الإلزامية<br>* *8+ سنوات من الخبرة المثبتة في إدارة مشاريع تكنولوجيا المعلومات.** *شهادة PMP / PMI إلزامية.** *خبرة في قطاع البنوك إلزامية.** خبرة قوية في *تحول تكنولوجيا المعلومات / مشاريع تقنية مؤسسية*.** خبرة في إدارة فرق متعددة الوظائف وبائعين من الغير.* معرفة قوية بـ *حوكمة المشروع، إدارة المخاطر، إدارة التغيير، وإدارة أصحاب المصلحة*.*** مهارات اتصال وتقرير وقيادة وحل مشاكل ممتازة.* خبرة مع *أساليب الأجايل / سكرم، الشلال، أو الهجين*.<br>### خبرة بنكية مفضلة<br>سيُفضَّل جداً وجود خبرة في أي من التالي:<br>*المصرفية الأساسية | الخدمات المصرفية الرقمية | المدفوعات | البطاقات | أجهزة الصراف الآلي | T24/Temenos | تطبيقات بنكية | مشاريع تنظيمية | بنية بنكية | تكامل النظام*<br>### مهارات إلزامية قصيرة<br>*PMP/PMI | إدارة مشاريع تكنولوجيا المعلومات | 8+ سنوات | بنوك | حوكمة المشروع | إدارة المخاطر | إدارة أصحاب المصلحة | إدارة البائعين | أجايل/شلال | تحويل تكنولوجيا المعلومات*
يركز فريق القطاع العام الدولي المتنامي في شركة Scale على استخدام الذكاء الاصطناعي لمواجهة التحديات الحاسمة التي تواجه القطاع العام حول العالم. تتكون أعمالنا الأساسية من:<br><br>إنشاء تطبيقات ذكاء اصطناعي مخصصة سيكون لها تأثير على ملايين المواطنين، وإنشاء بيانات تدريب عالية الجودة لنماذج لغوية كبيرة (LLMs) مخصصة، وتقديم خدمات رفع المهارات والاستشارات لنشر تأثير الذكاء الاصطناعي.<br><br>بصفتك مهندس برمجيات متكامل (Full Stack) (يعمل ميدانياً)، ستتعاون مباشرة مع نظرائك في القطاع العام لبناء تطبيقات ذكاء اصطناعي متكاملة بسرعة، وذلك لحل أكثر تحدياتهم إلحاحاً وتحقيق تأثير ملموس للمواطنين.<br><br>في Scale، نحن لا نبني حلول الذكاء الاصطناعي فحسب، بل نمكّن القطاع العام من تحويل عملياتهم وخدمة المواطنين بشكل أفضل من خلال التكنولوجيا المتطورة. إذا كنت مستعداً لتشكيل مستقبل الذكاء الاصطناعي في القطاع العام وأن تكون عضواً مؤسساً في فريقنا، فنحن نود أن نسمع منك.<br><br>ستقوم بـ:<br><br>العمل كاستراتيجي تقني رئيسي لمشاريع القطاع العام، وتحويل متطلبات المهمة الغامضة إلى خرائط طريق معمارية قوية وتوجيه التنفيذ في الموقع. هندسة الأطر الأساسية لتطبيقات الذكاء الاصطناعي الجاهزة للإنتاج، ووضع المعيار الذهبي لكيفية دمج واجهات المستخدم التفاعلية وأنظمة الواجهة الخلفية ونماذج الذكاء الاصطناعي على نطاق واسع لتقديم نتائج موثوقة. توجيه تطور البنية التحتية السحابية، وضمان الأمن، وقابلية التوسع العالمي، وسلامة النظام على المدى الطويل عبر جميع البيئات. توجيه تطوير المنصات الأساسية والخدمات المشتركة، وضمان حلها للاحتياجات المتقاطعة لحالات استخدام متنوعة للعملاء العالميين. الشراكة مع القيادة متعددة الوظائف لتوجيه خارطة الطريق التقنية، وتوجيه الموظفين من ذوي الخبرة والمبتدئين، وضمان توافق جميع المنتجات مع بنية تقنية متماسكة ومستقبلية. سد الفجوة بين العمل الميداني والمنصة الأساسية من خلال تحويل دروس العملاء الواقعية إلى أنماط قابلة لإعادة الاستخدام تدعم فريق الهندسة بأكمله.<br><br>من الناحية المثالية، يجب أن تمتلك:<br><br>درجة الماجستير أو الدكتوراه في علوم الحاسب أو خبرة صناعية عميقة مماثلة في هندسة الأنظمة المعقدة والموزعة. خبرة تزيد عن 10 سنوات في تطوير البرمجيات المتكاملة (Full-stack) عبر Python و Node.js و React، مع سجل حافل في تصميم بنيات عالية النطاق على Kubernetes والبنى التحتية السحابية العالمية (AWS/Azure/GCP). قدرة الخبير على تصميم والإشراف على الأنظمة الجاهزة للإنتاج، وضمان معايير عالمية لسلامة النظام، والأمن، وقابلية التوسع على المدى الطويل. خبرة واسعة في نشر واستكشاف أخطاء الحلول المتطورة من البداية إلى النهاية مباشرة داخل بيئات العملاء المعقدة وعالية الأمان. سجل حافل في بناء حلول تعتمد على النماذج اللغوية الكبيرة (LLM) مع البصيرة الاستراتيجية لتوقع تحولات المشهد وهندسة أنظمة مستقبلية. قائد يتمتع بالدافع الذاتي وقادر على حل الغموض الشديد، وتوجيه الموظفين الكبار، ووضع الرؤية التقنية للمنظمة. محرك لسير العمل غير المتزامن وثقافة "التوثيق أولاً" لتبسيط سرعة الهندسة العالمية وتقليل الاحتكاك.<br><br>يفضل وجود:<br><br>خبرة سابقة في العمل في شركة ناشئة كمدير تقني (CTO) أو مهندس مؤسس، أو في دور مهندس ميداني / مهندس عملاء مخصص. خبرة في العمل بشكل متعدد الوظائف مع العمليات. إجادة اللغة العربية.<br><br>بالنسبة للمتقدمين المقيمين في قطر: تتطلب الإقامة والعمل في قطر تصاريح معينة (تأشيرات وتراخيص) صادرة عن السلطات القطرية. كجزء من عملية التقديم، سيُطلب من المرشحين تقديم معلومات شخصية، بما في ذلك حالة الإقامة والجنسية، وهو أمر مطلوب لمعالجة التأشيرة. يتم جمع هذه المعلومات فقط لأغراض الامتثال للهجرة ولن تُستخدم كمعيار في أي قرار توظيف ما لم يكن هذا الاستخدام مسموحاً به قانوناً. إصدار التأشيرة يخضع لتقدير السلطات القطرية. إذا نجحت في طلبك، سيُطلب منك تقديم الوثائق التي تطلبها شركة Scale والسلطات للحصول على التصاريح اللازمة للعيش والعمل في قطر، وستعمل Scale مع المرشحين الناجحين لدعم عملية طلب التأشيرة.<br><br>يرجى الملاحظة: تتطلب سياستنا فترة انتظار مدتها 90 يوماً قبل إعادة النظر في المرشحين لنفس الدور. هذا يسمح لنا بضمان تقييم عادل وشامل لجميع المتقدمين.<br><br>عن شركتنا:<br><br>في Scale، مهمتنا هي تطوير أنظمة ذكاء اصطناعي موثوقة لأهم قرارات العالم. توفر منتجاتنا البيانات عالية الجودة وتقنيات البرمجيات المتكاملة التي تدعم النماذج الرائدة عالمياً، وتساعد الشركات والحكومات على بناء ونشر والإشراف على تطبيقات الذكاء الاصطناعي التي تقدم تأثيراً حقيقياً. نحن نعمل بشكل وثيق مع قادة الصناعة مثل Meta وErnst & Young وMayo Clinic وTime Inc. وحكومة قطر والوكالات الحكومية الأمريكية بما في ذلك الجيش والقوات الجوية. نحن نعمل على توسيع فريقنا لتسريع تطوير تطبيقات الذكاء الاصطناعي.<br><br>نحن نؤمن بأن الجميع يجب أن يكونوا قادرين على تقديم أفضل ما لديهم في العمل، ولهذا السبب نحن فخورون بأن نكون مكان عمل شامل ويمنح فرصاً متساوية. نحن ملتزمون بتكافؤ فرص العمل بغض النظر عن العرق، أو اللون، أو الأصل، أو الدين، أو الجنس، أو الأصل القومي، أو التوجه الجنسي، أو العمر، أو المواطنة، أو الحالة الاجتماعية، أو حالة الإعاقة، أو الهوية الجندرية، أو حالة المحاربين القدامى.<br><br>نحن ملتزمون بالعمل مع المتقدمين ذوي الإعاقات الجسدية والعقلية وتوفير التسهيلات المعقولة لهم. إذا كنت بحاجة إلى مساعدة و/أو تسهيلات معقولة في عملية التقديم أو التوظيف بسبب إعاقة، يرجى الاتصال بنا على accommodations@scale.com. يرجى الاطلاع على ملصق "اعرف حقوقك" الصادر عن وزارة العمل الأمريكية للحصول على معلومات إضافية.<br><br>نحن نمتثل لشرط شفافية الأجور الصادر عن وزارة العمل الأمريكية.<br><br>يرجى الملاحظة: نحن نجمع ونحتفظ ونستخدم البيانات الشخصية لأغراض أعمالنا المهنية، بما في ذلك إخطارك بفرص العمل التي قد تهمك ومشاركتها مع الشركات التابعة لنا. نحن نقصر البيانات الشخصية التي نجمعها على ما نعتقد أنه مناسب وضروري لإدارة احتياجات المتقدمين، وتقديم خدماتنا، والامتثال للقوانين المعمول بها. سيتم التعامل مع أي معلومات نجمعها فيما يتعلق بطلبك وفقاً لسياساتنا وبرامجنا الداخلية المصممة لحماية البيانات الشخصية. يرجى الاطلاع على سياسة الخصوصية الخاصة بنا للحصول على معلومات إضافية.
Note: By applying to this position you will have an opportunity to share your preferred working location from the following: Dubai - United Arab Emirates; Doha, Qatar; Riyadh Saudi Arabia. Minimum qualifications:<br><br>Bachelor's degree in Cybersecurity, with a focus on offensive security or equivalent practical experience.3 years of experience in three of the following security areas: web application security assessment, mobile application security assessment, API security assessment, red team assessments, EDR evasion, exploit development, cloud, social engineering, scripting, tool development. Experience delivering reporting and presentations to both technical and executive audiences. Experience with operating system security across operating systems or Linux.<br><br>Preferred qualifications:<br><br>Certifications related to application security including BSCP, OSWE, e WPTX, e MAPT, 8ksec CMSE or relevant SANS courses. Experience in creating security tools and understanding of underlying programming languages (such as Python, C#, C/C++, Rust, Nim or similar). Experience conducting web application, API, and mobile (i OS and Android) security assessments following industry standards such as OWASP WSTG/ASVS, OWASP Top 10, OWASP API Top 10 and OWASP MASVS/MASTG. Experience in web application and API penetration testing tooling including Burp Suite Professional, Burp Suite extensions, Postman, nuclei, ffuf and sqlmap.<br><br>About The Job<br><br>As a Security Consultant, you will be responsible for helping clients effectively prepare for, proactively mitigate, and detect and respond to cyber security threats. Security Consultants have an understanding of computer science, operating system functionality and networking, cloud services, corporate network environments and how to apply this knowledge to cyber security threats.<br><br>As a Security Consultant, you could work on engagements including assisting clients in navigating technically complex and high-profile incidents, performing forensic analysis, threat hunting, and malware triage. You may also test client networks, applications and devices by emulating the latest techniques to help them defend against threats, and will be the technical advocate for information security requirements and provide an in-depth understanding of the information security domain. You will also articulate and present complex concepts to business stakeholders, executive leadership, and technical contributors and successfully lead complex engagements alongside cross functional teams.<br><br>We are seeking a highly skilled and experienced Application Security Consultant to join the team.<br><br>In this role, you will be responsible for providing cybersecurity consulting services and support to the clients, including assessing and advising clients on both technical and process-based controls for all manner of environments.<br><br>Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.<br><br>Responsibilities<br><br>Conduct comprehensive security assessments of Web applications, APIs, and Mobile applications by identifying, exploiting and validating vulnerabilities using industry-standard methodologies such as the OWASP Web Security Testing Guide (WSTG), OWASP API Security Top 10, and OWASP Mobile Application Security Testing Guide (MASTG). Discover critical vulnerabilities in applications and be able to weaponize them. Expand the team’s capabilities through tool creation, research on offensive techniques, incorporation of threat actor intelligence, internal presentations and knowledge share. Develop comprehensive and accurate reports and presentations for both technical and executive audiences, and act as a trusted advisor to c-level, security leaders and other customer stakeholders. Assist with scoping prospective engagements, leading teams for engagements from kickoff through remediation phase, as well as mentoring other staff.<br><br><br>Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Google's EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our Accommodations for Applicants form .
عن الدور: الإشراف على مشرفي وموظفي الأمن المتعاقدين وتوجيه الأنشطة اليومية لضمان جودة المخرجات والتنفيذ وفقاً للخطة. التواصل مع أصحاب المصلحة المعنيين فيما يتعلق بتعريفات وصول الموظفين والطلبات لإبقاء جميع الأشخاص المعنيين على اطلاع. دعم أصحاب المصلحة والأعضاء داخل القسم فيما يتعلق بتجميع المستندات والإحصائيات المتعلقة بتقارير الحوادث ومعالجتها، وتحليل الاتجاهات، من أجل تقديم مشاريع التحسين المستمر. إنشاء إحصائيات وتقارير بانتظام من تقارير النوبة اليومية وتقارير الحوادث لأغراض مرجعية. تسهيل تجميع تقارير النوبة اليومية وتقارير الحوادث من خلال جمع البيانات، من أجل تقديم النتائج بطريقة هادفة. المساعدة في الاستجابة لأي حالة طوارئ أو اضطراب تشغيلي كبير أو تهديد يؤثر على مطار حمد الدولي أو الشركات التابعة لمجموعته، بما في ذلك دعم برنامج المساعدة الخاصة للخطوط الجوية القطرية (مثل مرافقة مركبات الطوارئ، والمساعدة في توفير أطواق أمنية) لضمان تنفيذ خطط الطوارئ بسلاسة. القيام بدوريات راجلة/محمولة منتظمة في مباني ركاب المسافرين، ومواقع البناء، ومناطق ساحة الطائرات، ومنطقة منتصف الميدان، وغيرها من المناطق مثل الجانب البري/الجانب الجوي (المحيط) للحماية من أي خرق أمني، أو اعتداءات، أو تخريب، أو سرقة، أو تلف في الممتلكات، أو حريق، أو غيرها من المخاطر التي تهدد الممتلكات. إجراء اختبار المخدرات والكحول (إذا لزم الأمر) وتنفيذ سياسة حق التفتيش كما هو مصرح به، لضمان الالتزام بسياسة شركة الخطوط الجوية القطرية. الاستجابة في حالة وقوع أي حادث أو واقعة تشغيلية يتم الإبلاغ عنها في كل من الجانب البري والجانب الجوي للمطار وبدء الاستجابة اللازمة. إبلاغ الإدارة بالأمر فوراً لضمان تصعيد الأمور المهمة واتخاذ إجراءات سريعة استجابةً للحادث/الواقعة. التأكد من تنفيذ نقاط التفتيش الأمنية للركاب العابرين وعملية فحص الأمتعة المحمولة بما يتوافق مع اللوائح المحلية والحفاظ على اتفاقية مستوى الخدمة طوال الوقت. التأكد من أداء واجبات الفحص الثانوي وفقاً لمتطلبات السلطات الأجنبية. مسؤول عن التأكد من تقديم خدمات أمن شركات الطيران الأخرى وفقاً لمتطلبات السلطات الأجنبية وإدارة جميع تغطية الإشراف المطلوبة وعمليات التوثيق بدقة. الإشراف على مواقع فحص الموظفين والحراسة الأمنية وتنفيذ أنشطة مراقبة الجودة التشغيلية لضمان تقديم العملية الموثقة بفعالية. أداء واجبات قسم أخرى تتعلق بمنصبه حسب توجيهات رئيس القسم. عنك: شهادة ثانوية/مهنية/دبلوم أو ما يعادلها مع خبرة لا تقل عن 4 سنوات في مجال العمل، أو درجة البكالوريوس أو ما يعادلها مع خبرة لا تقل عن 4 سنوات في مجال العمل. خبرة في مجال أمن المطار/الطيران. مهارات تقنية ممتازة في تقنية المعلومات بما في ذلك MS Office (PowerPoint، Word، Excel). يفضل الحصول على رخصة قيادة.
Job Description<br><br>We are seeking a skilled Senior Cloud Security Engineer to join our Cybersecurity Practice. In this role, you will work closely with cloud, infrastructure, network, endpoint, and application teams to design, implement, and maintain enterprise security controls that protect our clients’ digital environments.<br><br>Your responsibilities will span Identity & Access Management (IAM), Data Security, Cloud Security, Endpoint Security, and Network Security. You will support the implementation of security best practices, monitor security posture, identify risks, and contribute to improving the overall security architecture across hybrid IT environments.<br><br>You will assist in assessing security architectures, identifying vulnerabilities, implementing security solutions, and supporting incident response activities to ensure confidentiality, integrity, and availability of systems and data. The role requires hands-on technical expertise, strong analytical capabilities, and the ability to translate security requirements into practical and scalable security solutions.<br><br>Responsibilities<br><br>Enterprise Security Architecture and Risk Assessment:Support the assessment of enterprise IT and cloud environments to identify security risks and recommend appropriate controls across identity, data, network, endpoint, and cloud domains. Conduct security reviews of infrastructure, configurations, and deployments and provide actionable remediation recommendations aligned with industry best practices. Identity and Access Management (IAM):Implement and support secure identity and access controls, including role-based access control (RBAC), least privilege, multi-factor authentication (MFA), privileged access management (PAM), and identity governance practices across enterprise and cloud environments. Data Security:Assist in implementing data protection controls including data classification, encryption at rest and in transit, key management, data loss prevention (DLP), and secure data handling practices to ensure regulatory and organizational compliance. Cloud Security:Support secure configuration and monitoring of public, private, and hybrid cloud platforms. Implement security controls related to IAM, network segmentation, workload protection, encryption, logging, and compliance monitoring. Contribute to cloud security posture management and vulnerability remediation efforts. Endpoint Security:Support deployment and management of endpoint protection solutions including EDR/XDR platforms, antivirus, device control, patch management, and hardening baselines. Monitor endpoint security alerts and assist in incident investigation and response. Security Technology Stack:Support the implementation and management of security platforms and monitoring tools to strengthen security posture, improve visibility, and enhance threat detection across enterprise and cloud environments. Documentation and Reporting:Prepare and maintain documentation related to security configurations, risk assessments, incident reports, and operational procedures. Provide regular security posture updates to internal stakeholders and clients as required.<br><br>Qualifications<br><br>Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field. Experience: At least 5 years of experience in cloud security, cloud infrastructure, cybersecurity operations, or a closely related role. Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:Microsoft Azure Security Engineer Associate (AZ-500) Microsoft Certified: Identity and Access Administrator Associate (SC-300) Microsoft Certified: Azure Administrator Associate (AZ-104) Comp TIA Security+, CySA+, or similar ISC2 (e.g., CC or SSCP) CSA or other cloud security certifications.). Technical Skills: Hands-on experience with security technologies including identity platforms (such as Entra ID and Active Directory), cloud-native security tools, endpoint protection solutions (EDR/XDR), network security technologies (firewalls, IDS/IPS, VPN), SIEM and log monitoring solutions, encryption and key management systems, and vulnerability management tools. Familiarity with integrating security controls across enterprise and cloud environments is preferred. Knowledge: Strong understanding of cybersecurity principles including defense-in-depth, zero trust, least privilege, segmentation, encryption, vulnerability management, and incident response. Familiarity with security frameworks and guidelines (e.g., CIS Benchmarks, NIST, ISO 27001) and general compliance/governance concepts. Knowledge of Qatar National Information Assurance (NIA) is a plus.
We have a new requirement for a Senior Systems Engineer to join SOC Fusion Center team in Doha. This is a hands-on infrastructure role covering Linux, Windows, virtualization, monitoring, and backup across a mission-critical environment.<br>Experience required: 8+ years in systems engineering/administration, with strong exposure to networks, servers, and virtualization platforms.<br>Key responsibilities:On the Linux side, you'll handle OS installation and configuration, user and access management, package management (apt/yum), routine patching, performance monitoring, backup and recovery, firewall and IDS/IPS configuration, security audits, and network services like DNS, DHCP, and VPN. On the Windows side, you'll manage Windows Server environments, user/group administration, Group Policy Objects, security updates, file shares, antivirus and firewall configuration, security audits and risk assessments, and core network services. On virtualization, you'll work across VMware v Sphere (ESXi, v Center) and Nutanix clusters — deployment, configuration, performance tuning, VM management, and networking, including VXRail. You'll also own Zabbix monitoring end-to-end (server setup, host/trigger configuration, dashboards, alerting and reporting) and Veeam Backup operations (job monitoring, alerting, storage management, deduplication, and capacity planning).<br>Required skills: Unix and Windows administration, VMware and Nutanix, VXRail, Zabbix, Veeam Backup, and a strong grasp of security, storage, data protection, and disaster recovery best practices. Good written and verbal communication is essential.<br>Certifications: RHCE is mandatory.<br>Nice to have: Experience supporting 24x7 production / mission-critical systems, Dev Ops exposure, and willingness to travel to client sites and datacenters.<br>Qualifications: Bachelor's degree or equivalent relevant work experience.<br>Location: Doha, Qatar – SOC Fusion Center<br>If this matches your background, send your CV or reach out to info@simplix.qa directly.
We have a new requirement for a Senior Systems Engineer to join SOC Fusion Center team in Doha. This is a hands-on infrastructure role covering Linux, Windows, virtualization, monitoring, and backup across a mission-critical environment.<br>Experience required: 8+ years in systems engineering/administration, with strong exposure to networks, servers, and virtualization platforms.<br>Key responsibilities:On the Linux side, you'll handle OS installation and configuration, user and access management, package management (apt/yum), routine patching, performance monitoring, backup and recovery, firewall and IDS/IPS configuration, security audits, and network services like DNS, DHCP, and VPN. On the Windows side, you'll manage Windows Server environments, user/group administration, Group Policy Objects, security updates, file shares, antivirus and firewall configuration, security audits and risk assessments, and core network services. On virtualization, you'll work across VMware v Sphere (ESXi, v Center) and Nutanix clusters — deployment, configuration, performance tuning, VM management, and networking, including VXRail. You'll also own Zabbix monitoring end-to-end (server setup, host/trigger configuration, dashboards, alerting and reporting) and Veeam Backup operations (job monitoring, alerting, storage management, deduplication, and capacity planning).<br>Required skills: Unix and Windows administration, VMware and Nutanix, VXRail, Zabbix, Veeam Backup, and a strong grasp of security, storage, data protection, and disaster recovery best practices. Good written and verbal communication is essential.<br>Certifications: RHCE is mandatory.<br>Nice to have: Experience supporting 24x7 production / mission-critical systems, Dev Ops exposure, and willingness to travel to client sites and datacenters.<br>Qualifications: Bachelor's degree or equivalent relevant work experience.<br>Location: Doha, Qatar – SOC Fusion Center<br>If this matches your background, send your CV or reach out to info@simplix.qa directly.
About the Role:We are looking for a Cloud Security Engineer / Analyst to join our Cybersecurity Practice. In this role, you'll help design, implement, and strengthen security across multi-cloud environments while working closely with cloud architects, Dev Ops, infrastructure, and application teams. You'll be responsible for securing cloud platforms, improving security posture, supporting compliance, and integrating security throughout the cloud lifecycle.<br>Key Responsibilities:Assess cloud environments and identify security risks, vulnerabilities, and misconfigurations. Design and implement cloud security controls across Azure, OCI, AWS, and hybrid environments. Manage cloud security monitoring, threat detection, and incident response activities. Implement Identity & Access Management (IAM) best practices, including RBAC and least privilege. Support cloud security governance, compliance, and regulatory requirements. Collaborate with Dev Ops teams to integrate security into CI/CD pipelines and Infrastructure as Code (IaC). Deploy and manage cloud security solutions such as Microsoft Defender for Cloud, Azure Policy, OCI Cloud Guard, and CNAPP platforms (e.g., Prisma Cloud). Prepare security documentation, assessment reports, and provide guidance on cloud security best practices.<br>What We're Looking For:Bachelor's degree in Computer Science, Information Security, or a related field. Proficient experience in Cloud Security, Cloud Infrastructure, or Cybersecurity. Hands-on experience with Azure, OCI, AWS, or other cloud platforms. Knowledge of IAM, network security, encryption, logging, cloud monitoring, and Infrastructure as Code (Terraform, ARM/Bicep preferred). Understanding of cloud security frameworks such as NIST, ISO 27001, CIS Benchmarks, and CSA CCM. Familiarity with Dev Sec Ops and cloud compliance practices.<br>Preferred Certifications:OCI Security Professional Microsoft Azure Security Engineer Associate (AZ-500) AWS or Google Cloud Security Certifications CCSK, GIAC, Comp TIA Security+, SSCP, or CISSP
About the Role:We are looking for a Cloud Security Engineer / Analyst to join our Cybersecurity Practice. In this role, you'll help design, implement, and strengthen security across multi-cloud environments while working closely with cloud architects, Dev Ops, infrastructure, and application teams. You'll be responsible for securing cloud platforms, improving security posture, supporting compliance, and integrating security throughout the cloud lifecycle.<br>Key Responsibilities:Assess cloud environments and identify security risks, vulnerabilities, and misconfigurations. Design and implement cloud security controls across Azure, OCI, AWS, and hybrid environments. Manage cloud security monitoring, threat detection, and incident response activities. Implement Identity & Access Management (IAM) best practices, including RBAC and least privilege. Support cloud security governance, compliance, and regulatory requirements. Collaborate with Dev Ops teams to integrate security into CI/CD pipelines and Infrastructure as Code (IaC). Deploy and manage cloud security solutions such as Microsoft Defender for Cloud, Azure Policy, OCI Cloud Guard, and CNAPP platforms (e.g., Prisma Cloud). Prepare security documentation, assessment reports, and provide guidance on cloud security best practices.<br>What We're Looking For:Bachelor's degree in Computer Science, Information Security, or a related field. Proficient experience in Cloud Security, Cloud Infrastructure, or Cybersecurity. Hands-on experience with Azure, OCI, AWS, or other cloud platforms. Knowledge of IAM, network security, encryption, logging, cloud monitoring, and Infrastructure as Code (Terraform, ARM/Bicep preferred). Understanding of cloud security frameworks such as NIST, ISO 27001, CIS Benchmarks, and CSA CCM. Familiarity with Dev Sec Ops and cloud compliance practices.<br>Preferred Certifications:OCI Security Professional Microsoft Azure Security Engineer Associate (AZ-500) AWS or Google Cloud Security Certifications CCSK, GIAC, Comp TIA Security+, SSCP, or CISSP
المسؤوليات الرئيسية:✓ توفير حماية شخصية احترافية وأمن شخصي للموكل وأفراد أسرته عند الحاجة.✓ الحفاظ على مستوى عالٍ من الوعي الظرفي، وتحديد وإدارة المخاطر والتهديدات الأمنية المحتملة.✓ إجراء التقييمات الأمنية، والاستطلاع المسبق، وتخطيط الطرق، وفحص مواقع الإقامة والفنادق والأماكن ووجهات السفر.✓ ضمان أمن الموكل أثناء السفر محلياً ودولياً، بما في ذلك المطارات، ووسائل النقل، والفنادق، والفعاليات، والمشاركات العامة.✓ الحفاظ على بيئة آمنة داخل الإقامة الخاصة ومراقبة الدخول لتحديد أي نشاط غير مصرح به أو مشبوه.✓ الاستجابة بهدوء وفعالية للحوادث الأمنية، وحالات الطوارئ، والمواقف الطبية، وتقديم المساعدة الأولية المناسبة عند الحاجة.✓ العمل بشكل وثيق مع السائقين، وطاقم الخدمة المنزلية، والفرق الأمنية، والسلطات المحلية، وغيرهم من الموظفين المعنيين لضمان ترتيبات أمنية سلسة.✓ الموازنة بين المتطلبات الأمنية والنهج الذي يركز بشدة على الخدمة، لضمان احترام راحة الموكل وخصوصيته ونمط حياته.✓ الحفاظ على السرية التامة، والتقدير، والاحترافية، والنزاهة فيما يتعلق بالموكل، والأسرة، والإقامة، والتحركات، والجداول الزمنية، والشؤون الشخصية.✓ البقاء مرناً وقابلاً للتكيف مع جدول الموكل المتغير، وساعات العمل، ومتطلبات السفر، ونمط الحياة. من منظور الدور الوظيفي، يجب أن يتمتع المرشحون بخبرة في:✓ توفير الحماية المقربة لكبار الشخصيات، والأفراد ذوي الثروات الفائقة (UHNWI)، والأفراد ذوي الثروات العالية (HNWI)، وكبار المسؤولين التنفيذيين، والعائلات المالكة، أو غيرهم من الأفراد البارزين.✓ خبرة سابقة في الجيش، أو القوات الخاصة، أو إنفاذ القانون، أو الحماية المقربة، أو الحماية التنفيذية، أو الأمن المهني.✓ العمل داخل منازل خاصة بارزة أو بيئات كبار الشخصيات حيث يعد التقدير والسرية أمراً جوهرياً.✓ إدارة الأمن أثناء السفر الدولي، والمهام السكنية، والمشاركات العامة، والفعاليات رفيعة المستوى.✓ العمل بفعالية كجزء من فريق أمني ومنزلي محترف مع الحفاظ على تواصل قوي وحدود مهنية. <br> المتطلبات: ✓ يفضل المرشحون المقيمون حالياً في قطر؛ كما سيتم النظر في المرشحين من الخارج ويجب أن يكونوا على استعداد للانتقال إلى قطر.✓ مهارات التواصل باللغة الإنجليزية قوية وإلزامية.✓ يفضل بشدة وجود خبرة سابقة في الحماية المقربة، أو الحماية التنفيذية، أو الجيش، أو القوات الخاصة، أو إنفاذ القانون، أو الأمن المهني.✓ الطول فوق المتوسط، واللياقة البدنية الممتازة، ومعايير المظهر الاحترافي ضرورية.✓ وعي ظرفي قوي، ومهارات ملاحظة، وحكم سليم، والقدرة على البقاء هادئاً تحت الضغط.✓ جواز سفر ساري المفعول والاستعداد للسفر دولياً مع الموكل.✓ مستوى عالٍ من التقدير، والسرية، والاحترافية، والنزاهة، والموثوقية.✓ ستكون شهادات الأمن ذات الصلة، والحماية المقربة، والجيش، وإنفاذ القانون، أو الإسعافات الأولية، والمراجع المهنية القوية ميزة إضافية.
Job Description – Pre-Sales Engineer (Cybersecurity) Position Summary<br><br>We are seeking an experienced Pre-Sales Engineer – Cybersecurity to support the development of technical proposals and tender responses. The successful candidate will analyze RFPs, RFIs, and RFQs, translate customer security requirements into comprehensive technical solutions, and prepare high-quality proposal documentation. This is a technical pre-sales role focused on solution design, proposal writing, and compliance rather than direct sales activities.<br><br>Key Responsibilities Technical & Proposal Development<br><br>Analyze RFP, RFI, and RFQ documents to identify mandatory, technical, and commercial requirements. Prepare, review, and maintain high-quality technical proposals aligned with customer requirements. Develop Statements of Work (SOW), Bills of Quantities (BOQ), solution descriptions, and technical documentation. Create compliance matrices and requirement traceability documents. Coordinate with technical teams and vendors to gather solution inputs and supporting documentation. Ensure proposals meet quality standards, compliance requirements, and submission deadlines. Maintain and enhance reusable proposal templates and technical content libraries.<br><br>Operational Support<br><br>Collaborate with internal technical teams and technology partners during solution development. Assist in solution scoping and effort estimation. Track proposal timelines and ensure timely submission. Stay current with cybersecurity technologies, industry standards, and best practices. Support technical presentations and customer solution discussions when required.<br><br>Required Qualifications<br><br>Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field. Professional cybersecurity certifications are an advantage but not mandatory.5–8 years of experience in cybersecurity pre-sales, proposal management, bid writing, technical consulting, or cybersecurity implementation with strong documentation experience. Proven experience preparing technical proposals and responding to RFPs/RFIs/RFQs.<br><br>Required Technical Skills <br><br>Strong experience in technical proposal writing and bid management. Knowledge of cybersecurity technologies, including:Security Operations Center (SOC) Managed Detection & Response (MDR) Governance, Risk & Compliance (GRC) Identity & Access Management (IAM/PAM) Endpoint Detection & Response (EDR) Security Information & Event Management (SIEM) Data Loss Prevention (DLP) Network Detection & Response (NDR) Network, Endpoint, Data, and Application Security Familiarity with cybersecurity frameworks such as ISO/IEC 27001 and NIST. Strong proficiency in Microsoft Word, Excel, and Power Point.<br>Skills & Competencies<br><br>Excellent technical writing and documentation skills. Strong analytical and problem-solving abilities. Ability to interpret complex tender and procurement documents. High attention to detail and accuracy. Strong organizational and time management skills. Ability to work effectively under tight deadlines. Excellent communication and collaboration skills. Self-motivated with a strong sense of ownership and accountability.<br><br>Language Requirements<br><br>Excellent written and spoken English. Arabic is an advantage.<br><br>Skills: cybersecurity,soc,rfps,pre-sales engineer,arabic