BAE Systems Strategic Aerospace Services WLL, a limited liability company jobs
13 Jobs Found
<p>We are seeking an experienced <strong>Senior Data Protection & Privacy Specialist</strong> to support the organization's data protection and privacy governance initiatives. The successful candidate will be responsible for managing day-to-day privacy operations, conducting privacy risk assessments, reviewing personal data management processes, and supporting investigations and complaint handling related to personal data protection.</p><p>The role requires a strong understanding of data protection regulations, cybersecurity principles, privacy governance, and emerging technologies to ensure the organization's compliance with applicable legal and regulatory requirements.</p><p>Key Responsibilities</p><ul><li><p>Perform day-to-day operational activities related to data protection, including receiving and handling complaints, investigations, and privacy-related inquiries.</p></li><li><p>Review and assess Personal Data Management Systems to ensure compliance with applicable privacy requirements and best practices.</p></li><li><p>Conduct Personal Data Privacy Risk Assessments and provide recommendations to mitigate identified risks.</p></li><li><p>Evaluate requests involving the processing of sensitive or special-category personal data and submit recommendations to management for approval.</p></li><li><p>Execute and support procedures related to privacy complaints, investigations, and incident handling.</p></li><li><p>Assist in ensuring compliance with organizational policies and applicable data protection regulations.</p></li><li><p>Prepare reports, documentation, and recommendations related to privacy assessments and investigations.</p></li><li><p>Collaborate with internal stakeholders to promote privacy awareness and support continuous improvement of data protection practices.</p></li></ul><p><br></p><p><strong>Desired Candidate Profile</strong></p><p><strong>Education</strong></p><ul><li><p>Bachelor's or Master's degree in Computer Science, Information Technology, Information Security, Cybersecurity, or a related discipline.</p></li></ul><p><strong>Professional Certifications</strong></p><p>Candidates holding one or more of the following certifications will be preferred:</p><ul><li><p>Certified Information Privacy Manager (CIPM)</p></li><li><p>Certified Information Privacy Professional (CIPP)</p></li><li><p>Equivalent Data Protection or Privacy certifications</p></li></ul><p>Experience</p><ul><li><p>Minimum <strong>8 years</strong> of relevant professional experience in data protection, privacy, information security, cybersecurity, compliance, or related fields.</p></li></ul><p>Required Skills & Knowledge</p><ul><li><p>Strong knowledge of data protection and privacy principles.</p></li><li><p>Understanding of cybersecurity concepts, cyber threats, and vulnerabilities.</p></li><li><p>Knowledge of data protection laws, regulations, governance frameworks, policies, and procedures.</p></li><li><p>Familiarity with Artificial Intelligence (AI), blockchain, and other emerging technologies and their impact on privacy.</p></li><li><p>Technical understanding of computer networking concepts, network protocols, and network security methodologies.</p></li><li><p>Experience conducting privacy risk assessments and supporting privacy compliance activities.</p></li><li><p>Ability to manage multiple priorities while maintaining a high level of accuracy and professionalism.</p></li></ul><p>Language Requirements</p><ul><li><p><strong>English:</strong> Required (written and spoken).</p></li><li><p><strong>Arabic:</strong> Preferred but not mandatory.</p></li></ul><p><br></p><br>
<p>We are looking for a skilled ICT Governance & Change Management Specialist to lead and govern the technology change management lifecycle. The role ensures that all technology changes are implemented in a controlled, compliant, and business-aligned manner, minimizing risk while maximizing value. This position plays a critical role in maintaining operational stability and enabling continuous improvement.</p><br><p><strong>Key Responsibilities: </strong></p><ul><li><p>Lead and govern the end-to-end technology change management lifecycle</p></li><li><p>Develop, implement, and enforce change management policies, standards, and frameworks</p></li><li><p>Manage and facilitate Change Advisory Board (CAB) meetings</p></li><li><p>Assess and approve technology change requests based on risk, impact, and readiness</p></li><li><p>Ensure technology changes align with overall business strategy and objectives</p></li><li><p>Oversee change impact assessments, rollback plans, and implementation schedules</p></li><li><p>Monitor change performance, success rates, and post-implementation reviews (PIRs)</p></li></ul><p><br></p><p><strong>Desired Candidate Profile</strong></p><ul><li><p>Bachelor’s degree in Information Technology, Computer Science, or a related discipline</p></li><li><p>Minimum <strong>5 years of experience</strong> in ICT operations, change management, or a related role</p></li><li><p>Strong knowledge of IT service management and change management best practices</p></li><li><p>Experience working with governance frameworks and structured approval processes</p></li><li><p>Excellent analytical, coordination, and documentation skills</p></li><li><p>Proficiency in <strong>Arabic and English</strong> (spoken and written)</p></li><li><p>Relevant certifications (e.g., ITIL, COBIT) are considered a plus</p></li></ul>
<p>
· Provide technical and strategic advisory services to government entities to help them build their data asset registers and implement classification policies.
· Design guidelines and toolkits to enable government employees to classify data independently and efficiently.
· Measure the level of compliance of government entities with national data classification policies and submit periodic performance reports to decision-makers.
· Lead national initiatives to assess cybersecurity risks resulting from improper classification of sensitive data at the state level.
· Ensure alignment of different entities’ policies with national data protection and privacy legislation, and identify data sovereignty requirements.
· Evaluate global technical solutions in data classification and provide recommendations to government entities on the best tools suited to the national infrastructure.
· Organize national workshops and conferences to transfer knowledge and discuss challenges faced by institutions in implementing data classification projects.
</p><p><strong>Desired Candidate Profile</strong></p><p>Required Academic Degree
· Bachelor’s degree in (Information Security, Computer Science, or Management Information Systems).
· Strongly preferred: Master’s or PhD in (Data Governance or Public Cybersecurity Policy).
Required Training Certificates (If required)
· CDMP (Certified Data Management Professional) – Advanced level
· CGEIT (Certified in the Governance of Enterprise IT)
· Audit and compliance certifications such as CISA (Certified Information Systems Auditor)
· ISO/IEC 27001 Lead Auditor / Implementer
Required Years of Experience
· Minimum 10 years of experience in data governance and security.
· Must include at least 4 years working on regulatory frameworks, national policies, or consulting for major government institutions.
Required Language Proficiency
· Arabic: Optional
· English: Required
· Other: Arabic preferred but not mandatory
Other Required Qualifications
· Regulatory background: Deep understanding of local data and privacy laws and national cybersecurity standards.
· Consulting skills: Strong ability to influence and negotiate with senior leadership across government entities.
· Strategic vision: Ability to link data classification to national priorities such as digital transformation, data economy, and digital sovereignty.
· Institutional excellence: Familiarity with government excellence standards and quality models (e.g., EFQM) to ensure world-class advisory services.</p>
<p>The Senior Cybersecurity Accreditation Auditor is responsible for delivering day-to-day accreditation services and ensuring that assessments of third parties are conducted in a fair, consistent, and objective manner. The role focuses on evaluating compliance with national and international cybersecurity standards, managing accreditation applications, and maintaining the integrity of the accreditation process. It also supports continuous improvement of accreditation frameworks, tools, and methodologies aligned with national cybersecurity requirements.
Key Responsibilities:
Responsible for the conduct of the day to day of accreditation services.
Maintain detailed and organized records of the accreditation process, ensuring accuracy and completeness.
Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across accreditation activities;
Undertake compliance activities against security standards.
Operational role, to manage national accreditation scheme applications.
Document observations/findings in such a manner that they are clearly understandable and traceable and are based on objective evidence.
Develop and maintain accreditation procedures and required tools based on National Information Security Compliance framework.
Maintain impartiality, confidentiality and to declare any potential conflicts of interest that might jeopardize an objective assessment as required.
Perform periodic surveillance accreditation assessment on Third parties to monitor and review compliance.
Develop measurement and compliance mechanisms & tools to monitor improvements.
Knowledge of various international standards, regulation, and best practices, (ISO27001, OWASP, PTES, SOC CMM etc.) and implementation experience against at least one.
Knowledge of Local Laws & Regulations in different sectors: Cybercrime, PDPPL, eCommerce, etc.
Knowledge about national cyber security standards and frameworks (NIA, CSF…)
Stay up to date with the latest developments in security, emerging threats, and evolving technology to ensure the accreditation process remains relevant.
Manage the external communication during the assessment: from the application till the issue of decision.
Act as escalation point of contact for accreditation issues/requests.
Team player who collaborates with the team to maintain, improve the accreditation program.
</p><p><strong>Desired Candidate Profile</strong></p><p>Education & Experience:
Bachelor’s degree in Computer Science, Information Technology, Information Systems, Cybersecurity, or equivalent.
Minimum 12 years of experience in Information Security, Cybersecurity, Risk Assessment, or Assurance.
Hands-on experience in information security auditing, accreditation, or cybersecurity management.
Experience in cybersecurity consulting or implementation aligned with national/international standards is an advantage.
Certifications (Preferred):
NIA Certified Auditor, CISSP, CISA, CISM, ISO 27001 Lead Auditor or equivalent.
Technical Skills:
Strong knowledge of cybersecurity frameworks and standards (ISO 27001, NIST, NIA, OWASP, PTES, SOC-CMM, etc.).
Understanding of accreditation standards (ISO/IEC 17011, ISO/IEC 17025) and certification processes.
Experience in risk assessment and audit methodologies.
Knowledge of national cybersecurity laws and regulations (e.g., Cybercrime laws, data protection, eCommerce regulations).
Strong awareness of third-party audit and certification practices.
Ability to assess security controls and compliance against formal schemes objectively.
Core Skills:
Strong analytical thinking and problem-solving abilities.
Excellent technical report writing and documentation skills.
Ability to communicate clearly with technical and senior executive stakeholders.
Experience in delivering workshops, training, or knowledge-sharing sessions.
Strong attention to detail and ability to work under pressure and tight deadlines.
Behavioral Competencies:
Strong teamwork and collaboration skills.
High level of integrity, impartiality, and professionalism.
Ability to manage multiple stakeholders and competing priorities.
Strong interpersonal and communication skills.
Proactive, self-driven, and able to work independently with minimal supervision.
</p>
<p>The Senior Cybersecurity Assurance Consultant is responsible for leading, planning, and enhancing assurance services, ensuring effective delivery of cybersecurity, information security, and compliance assessment activities. The role translates strategic objectives into operational programs, manages assurance teams, and ensures continuous improvement of processes aligned with national and international standards. The position also plays a key role in stakeholder engagement, accreditation support (including NISCF), and coordination across departments to strengthen governance, risk, and compliance outcomes.</p><p><strong>Key Responsibilities: </strong></p><ul><li><p>Planning, directing, monitoring, improvement and maintenance of assurance service.<br></p></li><li><p>Translate the strategic direction from the department head into actionable projects and programs.<br></p></li><li><p>Provide solutions for challenges encountered in the operation and promotion of assurance services.<br></p></li><li><p>Continuously assess and improve the efficiency and effectiveness of the Department operations.<br></p></li><li><p>Manage the teams with in the department and ensure effective Resource Management.<br></p></li><li><p>Coordinate with other departments on matters concerning the delivery of projects and operations.<br></p></li><li><p>Develop and plan department objectives and key results.<br></p></li><li><p>Follow-up with the top management on resources and requirements for the benefits of the department.<br></p></li><li><p>Review development of deliverables related to NISCF.<br></p></li><li><p>Manage the tasks and assignments among the NISCF team.<br></p></li><li><p>Assist in setting up efficient and effective operation of NISCF assurance services.</p></li><li><p>Interact with stakeholders, providing expert feedback on challenges and insights to the operation team.<br></p></li><li><p>Interact with other departments in NCSA.<br></p></li><li><p>Interact with external stakeholders for development and adoption of assurance services.</p></li><li><p>Manage, mentor and lead the NISCF resources and certification/accreditation specialists, providing operational guidance, professional development, and capability enhancement</p></li></ul><p><strong>Desired Candidate Profile</strong></p><p><strong>Education & Experience:</strong></p><ul><li><p>Master’s degree in IT, Cybersecurity, Risk Management, or related field, or minimum 18 years of relevant experience.</p></li><li><p>At least 5 years of experience in audit and assurance.</p></li><li><p>Minimum 4 years of assessment or auditing experience in a specialized field.</p></li><li><p>Proven hands-on experience in cybersecurity, information security, IT audit, and assurance.</p></li></ul><p><strong>Technical & Professional Skills:</strong></p><ul><li><p>Strong knowledge of risk management and compliance assessment.</p></li><li><p>Familiarity with international standards (ISO 27001, COBIT, NIA, Common Criteria, etc.).</p></li><li><p>Knowledge of accreditation and certification standards (ISO 17021, 17024, 17025, 17065, 27006).</p></li><li><p>Experience in governance, regulatory compliance, and management system development.</p></li><li><p>Project management and team leadership experience.</p></li><li><p>Professional certifications in auditing, compliance, or risk management (preferred).</p></li><li><p>Experience engaging with senior executives and decision-makers.</p></li></ul><p><strong>Behavioral Competencies:</strong></p><ul><li><p>Strong leadership, mentoring, and team management abilities.</p></li><li><p>Excellent communication skills (oral and written) in English.</p></li><li><p>Strong analytical, problem-solving, and critical thinking skills.</p></li><li><p>Ability to manage multiple priorities under pressure and meet deadlines.</p></li><li><p>Effective stakeholder management and conflict resolution skills.</p></li></ul><p><strong>Language:</strong> English (required)</p><p><strong>Availability:</strong> As soon as possible</p>
<p>The Senior Cybersecurity Certification Consultant is responsible for leading and executing certification assessment activities to evaluate organizations’ compliance with national and international cybersecurity and information security standards. The role ensures fair, consistent, and objective certification decisions while overseeing assessment teams, managing certification cases, and maintaining the integrity of the certification process. It also contributes to developing certification methodologies, tools, and frameworks aligned with regulatory and accreditation requirements.</p><br><p><strong>Key Responsibilities: </strong></p><ul><li><p> Delivery of certification services Senior Information Security / Cyber Security Assessor is responsible for the day to day certification application assessment review, validation<br></p></li><li><p>Manage the team and assign the cases<br></p></li><li><p>Maintain detailed and organize records of the certification process, ensuring accuracy and completeness<br></p></li><li><p>Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across certification activities<br></p></li><li><p>Review different organizations’ Information Security / Cyber Security compliance to national or international standards and best practices in Information Security / Cyber Security<br></p></li><li><p>Evaluate the design and operating effectiveness of Information Security / Cyber Security controls<br></p></li><li><p>Document observations/findings in such a manner that they are clearly understandable and traceable and are based on objective evidence<br></p></li><li><p>Develop and maintain certification procedures and required tools based on National Information Security Compliance framework<br></p></li><li><p>Maintain impartiality, confidentiality and to declare any potential conflicts of interest that might jeopardize an objective assessment as required<br></p></li><li><p>Develop measurement and compliance mechanisms & tools to monitor improvements<br></p></li><li><p>Provide a recommendation on the outcome of an assessment<br></p></li><li><p>Stay up to date with the latest developments in security, emerging threats, and evolving technology to ensure the certification process remains relevant<br></p></li><li><p>Conduct efficient and effective Cyber Security risk assessments and Information Security / Cyber Security audit procedures<br></p></li><li><p>Develop and deliver internal training and workshop to upscale and build Information Security / Cyber Security, compliance, assurance and audit capabilities within the team.<br></p></li><li><p>Manage the external communication during the audit: from the application till the issue of decision</p></li></ul><p><strong>Desired Candidate Profile</strong></p><p><strong>Education & Experience</strong></p><ul><li><p>Bachelor’s degree in Information Technology, Computer Information Systems, Cyber Security, or equivalent.</p></li><li><p>Minimum 20 years of professional experience in IT / Information Security / Cyber Security.</p></li><li><p>At least 4 years of experience as a senior auditor, assessor, or in cybersecurity risk/security management roles.</p></li><li><p>Experience in cybersecurity consulting or implementation aligned with national/international standards is an advantage.</p></li></ul><p><strong>Certifications (Preferred)</strong></p><ul><li><p>CISSP, CISA, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or equivalent certifications.</p></li></ul><p><strong>Technical Skills</strong></p><ul><li><p>Strong knowledge of cybersecurity risk assessment and audit methodologies.</p></li><li><p>Expertise in security frameworks and standards (ISO 27001, NIST, NIA, CSF, etc.).</p></li><li><p>Understanding of certification and accreditation standards (ISO/IEC 17021, 17024, 17065, 17006, ISO 19011, ISA, ITAF).</p></li><li><p>Hands-on experience in information security auditing and assurance.</p></li><li><p>Strong awareness of evolving cybersecurity threats and technologies.</p></li></ul><p><strong>Core Skills</strong></p><ul><li><p>Excellent analytical, evaluation, and problem-solving abilities.</p></li><li><p>Strong technical report writing and documentation skills.</p></li><li><p>Ability to interpret compliance frameworks and certification criteria objectively.</p></li><li><p>Excellent communication and presentation skills in English (written and verbal).</p></li><li><p>Experience delivering training and workshops across government and private sectors.</p></li></ul><p><strong>Behavioral Competencies</strong></p><ul><li><p>High attention to detail and ability to work under pressure and tight deadlines.</p></li><li><p>Strong interpersonal and stakeholder management skills.</p></li><li><p>Ability to work independently with high levels of professionalism and integrity.</p></li><li><p>Capability to manage multiple assignments and cross-functional teams effectively.</p></li><li><p>Commitment to impartiality, confidentiality, and ethical assessment practices.</p></li></ul><p><strong>Language:</strong> English (required)</p><p><strong>Availability:</strong> As soon as possible</p>
<p>The ICT Change Management Specialist is responsible for leading the end-to-end delivery of cybersecurity certification programs and assurance services. The role oversees certification assessments, critical sector audits, and the development of standardized methodologies and frameworks. It ensures the effectiveness, consistency, and continuous improvement of certification operations while translating strategic objectives into executable programs. The role also leads stakeholder engagement, team management, and the delivery of national-level cybersecurity certification initiatives.</p><p><strong>Key Responsibilities: </strong><br></p><ul><li><p>Lead end-to-end delivery of all certification services and programs<br></p></li><li><p>Oversee certification review assessment for all certification programs<br></p></li><li><p>Responsible for critical sector audits as the Certification Lead<br></p></li><li><p>Establish, monitor and enhance standardized audit methodologies, practices, and certification standards.<br></p></li><li><p>Continuously assess and improve the efficiency and effectiveness of the Certification program.<br></p></li><li><p>Translate the strategic direction from the department head into actionable projects and programs.<br></p></li><li><p>Plan, build and operate cybersecurity certification standards and related assurance mechanisms<br></p></li><li><p>Plan, prioritize, and oversee delivery of projects and initiatives within the Certification Services portfolio<br></p></li><li><p>Provide solutions for challenges encountered in the operation and promotion of assurance services.<br></p></li><li><p>Follow-up with the top management on resources and requirements for the benefits of the department.<br></p></li><li><p>Manage, monitor and support the planning, preparation and delivery of certification related public events (workshops, trainings, conferences, etc.)</p></li><li><p>Interact with stakeholders, providing expert feedback on challenges and insights to the operation team.<br></p></li><li><p>Coordinate with other departments activities in relation to assurance.<br></p></li><li><p>Manage stakeholder interaction for collaboration with internal and external projects</p></li><li><p>Manage, mentor and lead the certification team and improve service delivery (operational guidance, professional development, and capability enhancement)<br></p></li></ul><p><br></p><p><strong>Desired Candidate Profile</strong></p><p><strong>Education & Experience:</strong></p><ul><li><p>Master’s degree in IT, Cybersecurity, Risk Management, or related field, or minimum 15 years of relevant experience.</p></li><li><p>At least 6 years of experience in cybersecurity assessment, IT auditing, or certification-related roles.</p></li><li><p>Strong background in cybersecurity governance, risk, and compliance.</p></li></ul><p><strong>Certifications (Preferred):</strong></p><ul><li><p>CISA, ISO 27001 Lead Auditor/Implementer.</p></li><li><p>COBIT, CRISC, CGEIT, or other governance and risk management certifications.</p></li></ul><p><strong>Technical Skills:</strong></p><ul><li><p>Strong knowledge of cybersecurity and information security standards (ISO 27001, NIA, COBIT, Common Criteria, etc.).</p></li><li><p>Understanding of accreditation and certification frameworks (ISO 17021, 17024, 17065, 17025, 27006).</p></li><li><p>Experience in developing standards, technical directives, SOPs, and audit documentation.</p></li><li><p>Strong background in risk management and compliance assessment.</p></li><li><p>Proven project management experience delivering initiatives on time, within scope, and budget.</p></li><li><p>Experience in regulatory compliance and national cybersecurity standard development.</p></li></ul><p><strong>Core Skills:</strong></p><ul><li><p>Strong technical report writing and documentation skills.</p></li><li><p>Excellent communication and presentation skills, including briefing senior executives.</p></li><li><p>Strong analytical, problem-solving, and critical thinking abilities.</p></li><li><p>Ability to manage multiple projects and stakeholders in complex environments.</p></li></ul><p><strong>Behavioral Competencies:</strong></p><ul><li><p>Strong leadership and team management capabilities.</p></li><li><p>Ability to work under pressure and manage competing priorities effectively.</p></li><li><p>High attention to detail with a commitment to quality and accuracy.</p></li><li><p>Strong interpersonal and stakeholder engagement skills.</p></li><li><p>Ability to work independently and drive initiatives proactively.</p></li></ul>
<p>A <strong>GRC Senior Analyst / Specialist</strong> supports the governance, risk, and compliance framework to ensure alignment with national cyber regulations, security policies and government assurance standards.</p><p>The role focuses on identifying, assessing and managing cyber and information security risks across systems and operations, while ensuring compliance with applicable regulatory frameworks, security controls and audit requirements. It involves maintaining risk registers, supporting security assessments and tracking remediation of vulnerabilities and control gaps.</p><p>The position also works closely with security, IT, and government stakeholders to strengthen cybersecurity governance, support accreditation processes and ensure continuous compliance with national cybersecurity mandates.</p><p><strong>Core Activities:</strong></p><ul><li><p>Provide expert consultation on Governance, Risk, and Compliance (GRC) matters.</p></li><li><p>Review, assess, and enhance enterprise cybersecurity architecture.</p></li><li><p>Conduct reviews of QCSF evidence and provide compliance recommendations.</p></li><li><p>Deliver cybersecurity consultancy and practical security solutions to internal stakeholders.</p></li><li><p>Identify cybersecurity risks and recommend mitigation strategies.</p></li><li><p>Support the implementation of cybersecurity policies, standards, and best practices.</p></li><li><p>Collaborate with business and technical teams to improve cybersecurity posture.</p></li><li><p>Prepare reports, assessments, and recommendations for management.</p></li><li><p>Stay updated with emerging cybersecurity threats, technologies, and regulatory requirements.</p></li></ul><p><strong>Key Responsibilities: </strong></p><ul><li><p>Act as a subject matter expert for cybersecurity governance, risk, and compliance.</p></li><li><p>Review and improve enterprise cybersecurity architecture to ensure alignment with business and security objectives.</p></li><li><p>Evaluate compliance against the Qatar Cyber Security Framework (QCSF) and recommend corrective actions.</p></li><li><p>Provide strategic cybersecurity guidance to stakeholders across the organisation.</p></li><li><p>Develop and recommend cybersecurity controls and solutions based on risk assessments.</p></li><li><p>Support cybersecurity audits, assessments, and compliance activities.</p></li><li><p>Ensure cybersecurity initiatives align with organisational policies and industry standards.</p></li><li><p>Produce high-quality documentation, reports, and technical recommendations.</p></li><li><p>Mentor stakeholders on cybersecurity best practices where required</p></li></ul><p><strong>Desired Candidate Profile</strong></p><p><strong>Education:<br></strong></p><ul><li><p>Bachelor's or Master's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related discipline.</p></li></ul><p>Experience:</p><ul><li><p>Minimum of 10 years' experience in cybersecurity, with strong expertise in Governance, Risk & Compliance (GRC), enterprise cybersecurity architecture and regulatory compliance.</p></li></ul><p>Mandatory Certifications:</p><ul><li><p>CIIP (Certified Information Infrastructure Professional)</p></li><li><p>CISM (Certified Information Security Manager)</p></li></ul><p>Preferred Certifications:</p><ul><li><p>GICSP (Global Industrial Cyber Security Professional)</p></li><li><p>CCISO (Certified Chief Information Security Officer)</p></li></ul><p>Skills & Competencies:</p><ul><li><p>Strong knowledge of Governance, Risk & Compliance (GRC) frameworks.</p></li><li><p>Extensive experience with Enterprise Cybersecurity Architecture.</p></li><li><p>Thorough understanding of the Qatar Cyber Security Framework (QCSF).</p></li><li><p>Strong cybersecurity consulting and advisory skills.</p></li><li><p>Excellent analytical and problem-solving abilities.</p></li><li><p>Ability to assess risks and recommend effective security solutions.</p></li><li><p>Excellent communication, stakeholder management, and report-writing skills.</p></li><li><p>Ability to work independently and collaboratively within multidisciplinary teams.</p></li><li><p>Strong understanding of international cybersecurity standards and best practices.</p></li></ul><p><strong>Language Proficiency:</strong></p><ul><li><p>Proficiency in English & Arabic is required.</p></li></ul>
<p><strong>Key Responsibilities:</strong><br></p><ul><li><p>Designing and delivering cybersecurity training programs.<br></p></li><li><p>Creating and updating cyber security awareness/educational content.<br></p></li><li><p>Assess the training needs and evaluate the current security awareness level of organizations.<br></p></li><li><p>Develop customized training programs tailored to different employee roles and departments.<br></p></li><li><p>Review and update programs based on feedback, emerging threats, or organizational needs.<br></p></li><li><p>Develop Simulation Scenarios and Practical Exercises<br></p></li><li><p>Conducting research on emerging threats and technologies.</p></li><li><p>Monitoring and reporting training and development metrics.</p></li></ul><p><strong>Desired Candidate Profile</strong></p><p><strong>Education:</strong></p><ul><li><p>Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.</p></li><li><p>Master’s degree in Cybersecurity (Preferred)</p></li></ul><p><strong>Certifications:</strong></p><ul><li><p>CompTIA Security+<br></p></li><li><p>GIAC Security Essentials (GSEC)<br></p></li><li><p>Cisco Certified Network Associate (CCNA)<br></p></li><li><p>CompTIA Cybersecurity Analyst (CySA+)<br></p></li><li><p>Computer Hacking Forensic Investigator (CHFI)<br></p></li><li><p>CompTIA PenTest+<br></p></li><li><p>Certified Ethical Hacker (CEH)<br></p></li><li><p>Certified Penetration Tester (CPENT)<br></p></li><li><p>GIAC Certified Incident Handler (GCIH)<br></p></li><li><p>GIAC Certified Penetration Tester (GPEN)<br></p></li><li><p>Offensive Security Certified Professional (OSCP)<br></p></li><li><p>Certified Information Systems Auditor (CISA)<br></p></li><li><p>Certified Information Security Manager (CISM)<br></p></li><li><p>Certified Information Systems Security Professional (CISSP)<br></p></li></ul><p><strong>Experience:</strong></p><ul><li><p>5-10 years of experience in the Cyber Security field</p></li></ul><p><strong>Language Proficiency:</strong></p><ul><li><p>Proficiency in English & Arabic is required.</p></li></ul><p><strong>Additional Required Skills and Knowledge:</strong></p><ul><li><p>Strong presentation and communication skills.<br></p></li><li><p>Ability to simplify complex technical concepts for non-technical audiences.<br></p></li><li><p>In-depth knowledge of the latest cybersecurity threats and defence strategies.<br></p></li><li><p>Analytical thinking and problem-solving abilities.<br></p></li><li><p>Capability to assess and improve security awareness programs.</p></li></ul>
<p>The Senior Common Criteria Certification Specialist is responsible for leading and executing cybersecurity product and system certification activities in alignment with internationally recognized standards, particularly Common Criteria. The role involves evaluating security documentation, conducting technical risk assessments, overseeing testing processes, and providing expert recommendations on certification decisions (e.g., EAL levels).</p><p>This position plays a critical role in ensuring the integrity, consistency, and credibility of the certification process, while collaborating with developers, evaluators, and regulatory stakeholders. The specialist also contributes to the development of certification policies and stays current with emerging cybersecurity threats, technologies, and standards.</p><p><strong>Key Responsibilities: </strong></p><ul><li><p>Senior Certifier is responsible for the conduct of the day to day certification, validation, oversight, certificate maintenance and mutual recognition with the common criteria standards.<br></p></li><li><p>Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across all evaluation and certification activities;<br></p></li><li><p>Possess a deep understanding of Common Criteria standards, Protection Profiles, Security Targets, Evaluation Assurance Levels (EALs), and related documentation<br></p></li><li><p>Provide guidance and mentorship to CB team members Certifiers and evaluators, ensuring their understanding of the certification process and helping them with complex evaluations.<br></p></li><li><p>Lead and oversee the review and assessment of documentation submitted by product developers, including Security Target documents, design specifications, and test plans.<br></p></li><li><p>Conduct advanced technical risk assessments, identifying potential security weaknesses or flaws in products or systems and providing expert guidance for mitigation.<br></p></li><li><p>Oversee and manage the testing phase, ensuring that security testing is conducted rigorously and accurately.<br></p></li><li><p>Conduct of day-to-day certification, certificate maintenance and mutual recognition projects and in compliance with scheme documentations.<br></p></li><li><p>Assisting with the development of policies, standards, procedures and guidelines.<br></p></li><li><p>Make recommendations regarding certification at specific Evaluation Assurance Levels (EALs) based on extensive evaluation expertise and knowledge of the certification process.<br></p></li><li><p>Stay up-to-date with the latest developments in security, emerging threats, and evolving technology to ensure the certification process remains relevant.<br></p></li><li><p>Collaborate with stakeholders, such as developers, evaluators, and national certification authorities, to ensure a consistent and accurate evaluation process.</p></li></ul><p><strong>Desired Candidate Profile</strong></p><ul><li><p>A university degree-level qualification in IT, information security or a related field. ideally with a focus on security domains.<br></p></li><li><p>Certification from a recognized Common Criteria certification body and previous experience as a Certifier is desired<br></p></li><li><p>IT Security Overview Training and certification<br></p></li><li><p>Common Criteria for IT Security Evaluation Training and certification<br></p></li><li><p>Minimum 8 years<br></p></li><li><p>Minimum 4 years of work experience as a Senior IT / Information Security / Cyber Security Auditor and/or Risk Management and/or Cyber Security/Information Security Management.<br></p></li><li><p>Proficiency in Arabic and English (spoken and written) is preferred<br></p></li></ul><p><strong>Other Required Qualifications:</strong></p><br><p><strong>General:</strong></p><ul><li><p>Analytical and problem-solving skills<br></p></li><li><p>Proven experience in IT and Information Security Assessment<br></p></li><li><p>Common Criteria for IT Security Evaluation Training<br></p></li><li><p>Experience in Risk Assessment and management.<br></p></li><li><p>Should have hands on experience in information security<br></p></li><li><p>Understanding of ISO27001 certification audit requirements<br></p></li><li><p>Excellent communication, documentation, and report-writing skills.<br></p></li><li><p>In-depth knowledge of security testing methodologies and tools.<br></p></li><li><p>Have analytical & assessment experience of formal schemes and can assess a situation in a fair and objective manner in order to arrive at a firm conclusion.<br></p></li><li><p>Have training, workshops planning and delivery experience across Government & private sector.</p></li></ul><p><br></p><p><strong>Technical:</strong></p><ul><li><p>Experience in Risk Assessment and management including audit methodologies and risk assessment methodologies.<br></p></li><li><p>Understanding of NIA controls and implementation requirements<br></p></li><li><p>Proficiency in security frameworks and standards like NIST, ISO27001, NIA.<br></p></li><li><p>Strong awareness of Information Security / Cyber Security trends.</p></li></ul><p><br></p><p><strong>Behavioural:</strong></p><ul><li><p>Ability to multitask and work effectively with multiple project teams, sponsors, and customers.<br></p></li><li><p>Ability to pay close attention to detail, meet deadlines and work under pressure.<br></p></li><li><p>Interpersonal skills<br></p></li><li><p>Work autonomously with a high degree of enthusiasm</p></li></ul><p><br></p><p><strong>Specific:</strong></p><ul><li><p>Excellent technical report writing skills.<br></p></li><li><p>Have capabilities to understand and interpret the Certification Criteria (ISO/ IEC 17021, ISO/ IEC 17024, ISO/ IEC 27006 and ISO/IEC 17065).<br></p></li><li><p>Knowledge of auditing and information assurance standards like ISA, ITAF, ISO17021, ISO19011.<br></p></li><li><p>Proficiency in security frameworks and standards like, ISO27001, NIA, CSF Q2022.<br></p></li><li><p>Familiarity with third-party audit, Certification and Information Security / Cyber Security audits.<br></p></li><li><p>Proven, hands on, experience in Information Security Audit or Information Security Management.<br></p></li></ul><p><br></p>
<p>The Senior Cybersecurity Certification & QMS Specialist is responsible for managing and continuously improving the quality management system (QMS) that governs cybersecurity certification schemes. The role ensures compliance with international standards and regulatory requirements while enhancing the efficiency, consistency, and reliability of certification processes.</p><p>This position combines expertise in cybersecurity certification with strong quality assurance and audit capabilities, including conducting internal audits, managing documentation, and driving corrective and preventive actions. The specialist works closely with technical teams and stakeholders to maintain high standards of certification, support governance activities, and align processes with evolving industry frameworks and best practices.</p><p><strong>Key Responsibilities: </strong></p><p><br></p><ul><li><p>Planning, implement, monitoring, improvement and maintenance of quality management system for the different schemes in NISCF.<br></p></li><li><p>Ensure that the internal process complies with relevant national and international regulations, guidelines.<br></p></li><li><p>Review the quality of technical content.<br></p></li><li><p>Continuously assess and improve the efficiency and effectiveness of the certification process.<br></p></li><li><p>Oversee the documentation and record-keeping processes to ensure that all records are accurate, complete, and readily accessible. Ensure that the QMS documentation is up-to-date.<br></p></li><li><p>Plan and conduct internal audits and reviews of the certification process to verify compliance with established procedures and to identify opportunities for improvement.<br></p></li><li><p>Plan and organize scheme management review meetings.<br></p></li><li><p>Review the quality of scheme documents i.e. manuals, policies, procedure, forms, templates etc.<br></p></li><li><p>Implement corrective and preventive actions to address non-conformities and improve the QMS. Ensure that corrective actions are taken when issues are identified.<br></p></li><li><p>Monitoring the changes of requirements (i.e. International Standards (ISO17021, 17024, 17065, 17025, 27006, 9001), National Standards)<br></p></li><li><p>Assisting with the development of policies, standards, procedures and guidance based on audit findings<br></p></li><li><p>Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across all evaluation and certification activities;<br></p></li><li><p>Possess a deep understanding of Common Criteria standards, Protection Profiles, Security Targets, Evaluation Assurance Levels (EALs), and related documentation<br></p></li><li><p>Provide guidance and mentorship to CB team members Certifiers and evaluators, ensuring their understanding of the certification process and helping them with complex evaluations.<br></p></li><li><p>Assisting with the development of policies, standards, procedures and guidelines.<br></p></li><li><p>Make recommendations regarding certification at specific Evaluation Assurance Levels (EALs) based on extensive evaluation expertise and knowledge of the certification process.<br></p></li><li><p>Stay up-to-date with the latest developments in security, emerging threats, and evolving technology to ensure the certification process remains relevant.</p></li></ul><p><strong>Desired Candidate Profile</strong></p><ul><li><p>A university Master’s degree-level qualification in IT, information security or a related field. ideally with a focus on security domains<br></p></li><li><p>Certification from a recognized Common Criteria certification body and previous experience as a Certifier is desired<br></p></li><li><p>IT Security Overview Training and certification<br></p></li><li><p>Common Criteria for IT Security Evaluation Training and certification<br></p></li><li><p>Minimum10 years experience<br></p></li><li><p>5 minimum years of work experience as a Senior IT / Information Security / Cyber Security Auditor and/or Risk Management and/or Cyber Security/Information Security Management.<br></p></li><li><p>Proficiency in Arabic and English (spoken and written) is preferred<br></p></li></ul><p><strong>Other Required Qualifications:</strong></p><br><p><strong>General:</strong></p><ul><li><p>Analytical and problem-solving skills</p></li><li><p>Proven experience in IT and Information Security Assessment<br></p></li><li><p>Common Criteria for IT Security Evaluation Training<br></p></li><li><p>Experience in Risk Assessment and management.<br></p></li><li><p>Should have hands on experience in information security<br></p></li><li><p>Understanding of ISO27001 certification audit requirements<br></p></li><li><p>Excellent communication, documentation, and report-writing skills.<br></p></li><li><p>In-depth knowledge of security testing methodologies and tools.<br></p></li><li><p>Have analytical & assessment experience of formal schemes and can assess a situation in a fair and objective manner in order to arrive at a firm conclusion.<br></p></li><li><p>Have training, workshops planning and delivery experience across Government & private sector<br><br></p></li></ul><p><strong>Technical:</strong></p><ul><li><p>Proven experience in IT, Information Security and Quality management Audit.<br></p></li><li><p>Should have hands on experience in information security, cyber security & Quality management systems.<br></p></li><li><p>Experience in Risk management and GAP analysis.<br></p></li><li><p>Experience briefing senior executive staff<br></p></li><li><p>Experience in Risk Assessment and management including audit methodologies and risk assessment methodologies<br></p></li></ul><p><br></p><p><strong>Behavioural:</strong></p><ul><li><p>Ability to multitask and work effectively with multiple project teams, sponsors, and customers.<br></p></li><li><p>Ability to pay close attention to detail, meet deadlines and work under pressure.<br></p></li><li><p>Interpersonal skills<br></p></li><li><p>Work autonomously with a high degree of enthusiasm</p></li></ul><p><br></p><p><strong>Specific:</strong></p><ul><li><p>Excellent technical report writing skills.<br></p></li><li><p>Have capabilities to understand and interpret the Certification Criteria (ISO/ IEC 17021, ISO/ IEC 17024, ISO/ IEC 27006 and ISO/IEC 17065).<br></p></li><li><p>Knowledge of auditing and information assurance standards like ISA, ITAF, ISO17021, ISO19011.<br></p></li><li><p>Proficiency in security frameworks and standards like, ISO27001, NIA, CSF Q2022.<br></p></li><li><p>Familiarity with third-party audit, Certification and Information Security / Cyber Security audits.<br></p></li><li><p>Proven, hands on, experience in Information Security Audit or Information Security Management</p></li></ul>
<p>We are seeking a highly experienced <strong>Senior Information Security / Senior Cyber Security Assessor (Certification)</strong> to lead and support cyber security certification and compliance assessment activities. The role is responsible for reviewing certification applications, evaluating organizations’ compliance with national and international security standards, conducting cyber security risk assessments and audits, and ensuring consistency, impartiality, and quality throughout the certification lifecycle.</p><p>The ideal candidate will possess strong technical expertise in information security governance, risk management, compliance, auditing, and certification frameworks, along with proven leadership and stakeholder management capabilities.</p><p><strong>Key Responsibilities: </strong><br></p><ul><li><p>Lead and deliver certification assessment and review activities for organizations seeking Information Security / Cyber Security certification.</p></li><li><p>Manage assessment teams, assign cases, and oversee daily certification operations. <br></p></li><li><p>Review and evaluate organizations’ compliance with national and international cyber security standards and frameworks.</p></li><li><p>Assess the design and operating effectiveness of cyber security and information security controls <br></p></li><li><p>Conduct cyber security risk assessments, audits, and compliance reviews.</p></li><li><p>Maintain accurate, complete, and organized records of certification and assessment activities.</p></li><li><p>Ensure impartiality, confidentiality, consistency, and compliance throughout certification processes.</p></li><li><p>Document assessment observations and findings based on objective evidence and ensure traceability.</p></li><li><p>Develop and maintain certification procedures, methodologies, and supporting tools aligned with national compliance frameworks.</p></li><li><p>Develop compliance measurement mechanisms and monitoring tools to track improvements.</p></li><li><p>Provide recommendations and assessment outcomes to stakeholders and decision-makers.</p></li><li><p>Manage external communication throughout the audit and certification lifecycle, from application to final decision issuance.</p></li><li><p>Stay updated on emerging cyber security threats, technologies, standards, and industry best practices.</p></li><li><p>Develop and deliver internal training sessions and workshops to enhance team capabilities in cyber security, compliance, assurance, and auditing.</p></li><li><p>Collaborate effectively with internal teams, clients, and stakeholders across multiple projects.</p></li></ul><p><strong>Desired Candidate Profile</strong></p><p><strong>Requirements</strong></p><p>Education:<br></p><ul><li><p>Bachelor’s degree in Information Technology, Computer Information Systems, Cyber Security, or a related field.<br></p></li></ul><p>Professional Certifications:<br></p><p>One or more relevant professional certifications are preferred, such as:<br></p><ul><li><p>CISSP<br></p></li><li><p>CISA<br></p></li><li><p>CISM<br></p></li><li><p>CRISC<br></p></li><li><p>ISO 27001 Lead Auditor / Implementer<br></p></li></ul><p>Experience:<br></p><ul><li><p>Minimum 7 years of professional experience in Information Security / Cyber Security.<br></p></li><li><p>Minimum 4 years of experience in one or more of the following areas:</p><ul><li><p>Information Security Auditing<br></p></li><li><p>Cyber Security Auditing<br></p></li><li><p>Risk Management<br></p></li><li><p>Information Security Management<br></p></li></ul></li><li><p>Experience in consulting or implementing cyber security programs aligned with national or international standards is highly desirable.<br></p></li></ul><p>Technical Skills & Knowledge:<br></p><ul><li><p>Strong knowledge of cyber security governance, risk assessment, and audit methodologies.<br></p></li><li><p>Experience with security frameworks and standards such as:</p><ul><li><p>ISO 27001<br></p></li><li><p>NIST<br></p></li><li><p>NIA Controls<br></p></li><li><p>CSF Q2022<br></p></li></ul></li><li><p>Familiarity with certification and audit standards including:</p><ul><li><p>ISO/IEC 17021<br></p></li><li><p>ISO/IEC 17024<br></p></li><li><p>ISO/IEC 27006<br></p></li><li><p>ISO/IEC 17065<br></p></li><li><p>ISO 19011<br></p></li><li><p>ITAF<br></p></li><li><p>ISA<br></p></li></ul></li><li><p>Hands-on experience in Information Security Auditing and Information Security Management.<br></p></li><li><p>Strong understanding of cyber security trends, threats, and emerging technologies.<br></p></li><li><p>Excellent technical report writing and documentation skills.<br></p></li></ul><p>Soft Skills:<br></p><ul><li><p>Strong analytical and problem-solving abilities.<br></p></li><li><p>Excellent communication and stakeholder management skills.<br></p></li><li><p>Ability to work independently and manage multiple priorities effectively.<br></p></li><li><p>High attention to detail and ability to work under pressure and meet deadlines.<br></p></li><li><p>Strong interpersonal and team collaboration skills.<br></p></li><li><p>Experience in delivering workshops, training sessions, and awareness programs.<br></p></li></ul><p>Language Requirement:<br></p><ul><li><p>Fluency in English is required.<br></p></li><li><p>Arabic is a plus.</p></li></ul>
<p>The <strong>CSEA Contractor</strong> is expected to provide hands-on support to the Cyber Security Engineering and Architecture section by contributing to security architecture activities, technical security reviews, control implementation, risk assessments and advisory services across enterprise systems, infrastructure, cloud environments and applications.</p><p>The contractor is expected to have:</p><ul><li><p>Hands-on experience with Enterprise Security Architecture methodologies and modern security technologies, including IAM, SIEM, EDR/XDR, WAF, SASE, Zero Trust, cloud security, and security automation tools.</p></li><li><p>Strong knowledge of IT infrastructure security, including network security, cloud security, endpoint security, identity security, and secure architecture design principles.</p></li><li><p>Strong knowledge of application security, including secure SDLC, DevSecOps, API security, secure coding practices, and application threat modeling.</p></li><li><p>Experience implementing, validating, and reviewing security controls across IT infrastructure, cloud platforms such as AWS, Azure, and GCP, and enterprise applications.</p></li><li><p>Experience developing, maintaining, and enhancing security control libraries, security patterns, baselines, and architecture standards, while ensuring their integration into security architecture and engineering activities.</p></li><li><p>Strong understanding of cybersecurity standards, laws, and frameworks, including NIST, ISO/IEC 27001, CIS Controls, GDPR, PCI-DSS, and other relevant regulatory or compliance requirements.</p></li><li><p>Strong understanding of cybersecurity best practices, including secure network architecture, endpoint protection, identity and access management, cloud security, DevSecOps, and defense-in-depth design.</p></li><li><p>Experience conducting security design reviews, architecture assessments, threat modeling, technical risk assessments, and security gap assessments.</p></li><li><p>Ability to support business units, project teams, IT teams, and security stakeholders in selecting, designing, and implementing secure information systems and technology solutions.</p></li><li><p>Experience with security automation and scripting using tools and languages such as Python, PowerShell, Bash, Terraform, Ansible, or similar technologies.</p></li><li><p>Ability to support security investigations, incident response activities, forensic analysis, root cause analysis, and post-incident improvement recommendations when required.</p></li><li><p>Experience providing technical consultation and advisory support on CSEA-related projects, initiatives, and engagements as requested by the CSEA Section Head.</p></li><li><p>Excellent ability to translate technical cybersecurity concepts, risks, and recommendations into clear business language for both technical and non-technical stakeholders.</p></li><li><p>Experience participating in cybersecurity committees, technical working groups, architecture review boards, project meetings, and cross-functional security discussions.</p></li><li><p>Strong problem-solving, analytical, and decision-support skills, with the ability to assess complex technical environments and recommend practical security solutions.</p></li><li><p>Ability to work independently while also collaborating effectively with security architects, SOC analysts, IT teams, application teams, project managers, and business stakeholders.</p></li><li><p>Excellent verbal and written communication skills, with the ability to document security findings, architecture recommendations, risks, and remediation actions clearly and professionally.</p></li><li><p>Ability to mentor and support CSEA team members as needed by transferring knowledge, sharing technical expertise, and contributing to the development of internal cybersecurity engineering and architecture capabilities.</p></li></ul><p><strong>Key Deliverables:<br></strong></p><p>The contractor may be expected to support or deliver:</p><ul><li><p>Security architecture reviews</p></li><li><p>Security design review reports</p></li><li><p>Threat models and risk assessments</p></li><li><p>Security control mapping and recommendations</p></li><li><p>Architecture patterns, baselines, and standards</p></li><li><p>Technical security advisory reports</p></li><li><p>Secure design recommendations for infrastructure, cloud, and applications</p></li><li><p>Security improvement roadmaps</p></li><li><p>Support for incident response, investigations, and technical analysis</p></li><li><p>Knowledge transfer sessions for CSEA members</p></li></ul><p><br></p><p><strong>Desired Candidate Profile</strong></p><p><strong>Requirements</strong></p><p><strong>Education:<br></strong></p><ul><li><p>Bachelor’s degree in a technology-related field, such as Cybersecurity, Computer Science, Computer Engineering, Information Security, Information Technology, or a related discipline. A higher degree or relevant professional certifications are preferred.</p></li></ul><p>Experience:</p><ul><li><p>Minimum of 10 years relevant experience in cybersecurity, information security, security engineering, or IT infrastructure security, with at least 3 years of hands-on experience in cybersecurity architecture, security engineering, or enterprise security architecture.</p></li></ul><p>Preferred Certifications:</p><ul><li><p>CISSP, CISM, SABSA, or TOGAF certifications preferred.</p></li><li><p>Cloud security certifications such as CCSP, Azure Security Engineer, or AWS Security Specialty preferred.</p></li><li><p>Cybersecurity certifications such as GCIH, GCIA, GSEC, or Security+ preferred.</p></li><li><p>Other relevant cybersecurity, cloud security, or architecture certifications considered.<br></p></li></ul><p><strong><em>Proficiency in English & Arabic is required.</em></strong></p><p><br></p>