About Hamad International Airport:
Hamad International Airport enjoys a dominant position in the aviation industry. It has been voted the best airport in the world by Skytrax in 2024. Our passenger volumes are on a steady and fast-growing path thanks to an unprecedented facility expansion that enhanced operational capacity and will drive business growth in the next years.
About the role
:This role is required to be part of MATAR-IT Cyber Security and Risk Management team, with a primary role to manage information security management system (ISMS) across MATAR and its business units. Ensure compliance to ISMS through periodic review, audit and assessments. Report & track any non-compliance to closure and maintain risk under acceptable level
.
Key responsibilitie
- s:Assess the efficacy of implemented information security controls in alignment with the Information Security Management System (ISMS) framework requirement
- s.Create robust security standards, procedures, and controls to effectively manage risks in align with business requirement
- s.Regularly evaluate risks associated with information systems and supporting infrastructure
- s.Maintain ongoing surveillance of information security controls, exceptions, and risk
- s.Generate comprehensive management reports including key performance indicators for information security control
- s.Engage with both internal and external stakeholders to facilitate audits and assessments, including SOC-2, ISO 27001, 27017, 27018, NCSA, CSF, and PC
- I.Review IT service requests to ensure security complianc
- e.Evaluate proposed project and operational changes with a focus on information security requirement adherenc
- e.Familiarity with applicable information security management, governance, and compliance principles, practices, laws, rules, and regulation
- s.Understanding of information technology systems, network infrastructure, data architecture, processes, and protocol
- s.Proficiency in cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, solutions, and service orchestratio
- n.Knowledge of information systems auditing, monitoring, controlling, and assessment processe
- s.Competence in incident response management and risk assessment methodologie
s.
About y
- ou:Certification in either CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) is mandato
- ry.CISA (Certified Information Systems Auditor) or CRISC (Certified in Risk and Information Systems Contro
- l).ISO 27001:2022
- LACloud Security Certificate / AZURE / GOOGLE /
- AWSPayment Card Industry Data Security Standard (PCI-DSS) requirements (CPIS
- I).Specialized knowledge in securing operational technology (OT) systems such as ISA 62443 is an added advantage, preferr
ed