TS Controller (IT Security Compliance)

About Hamad International Airport:

Hamad International Airport enjoys a dominant position in the aviation industry. It has been voted the best airport in the world by Skytrax in 2024. Our passenger volumes are on a steady and fast-growing path thanks to an unprecedented facility expansion that enhanced operational capacity and will drive business growth in the next years.



About the role

:This role is required to be part of MATAR-IT Cyber Security and Risk Management team, with a primary role to manage information security management system (ISMS) across MATAR and its business units. Ensure compliance to ISMS through periodic review, audit and assessments. Report & track any non-compliance to closure and maintain risk under acceptable level


.
Key responsibilitie

  • s:Assess the efficacy of implemented information security controls in alignment with the Information Security Management System (ISMS) framework requirement
  • s.Create robust security standards, procedures, and controls to effectively manage risks in align with business requirement
  • s.Regularly evaluate risks associated with information systems and supporting infrastructure
  • s.Maintain ongoing surveillance of information security controls, exceptions, and risk
  • s.Generate comprehensive management reports including key performance indicators for information security control
  • s.Engage with both internal and external stakeholders to facilitate audits and assessments, including SOC-2, ISO 27001, 27017, 27018, NCSA, CSF, and PC
  • I.Review IT service requests to ensure security complianc
  • e.Evaluate proposed project and operational changes with a focus on information security requirement adherenc
  • e.Familiarity with applicable information security management, governance, and compliance principles, practices, laws, rules, and regulation
  • s.Understanding of information technology systems, network infrastructure, data architecture, processes, and protocol
  • s.Proficiency in cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, solutions, and service orchestratio
  • n.Knowledge of information systems auditing, monitoring, controlling, and assessment processe
  • s.Competence in incident response management and risk assessment methodologie


s.
About y

  • ou:Certification in either CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) is mandato
  • ry.CISA (Certified Information Systems Auditor) or CRISC (Certified in Risk and Information Systems Contro
  • l).ISO 27001:2022
  • LACloud Security Certificate / AZURE / GOOGLE /
  • AWSPayment Card Industry Data Security Standard (PCI-DSS) requirements (CPIS
  • I).Specialized knowledge in securing operational technology (OT) systems such as ISA 62443 is an added advantage, preferr


ed
Post date: Today
Publisher: LinkedIn
Post date: Today
Publisher: LinkedIn