Security inspector Jobs in Qatar
4070 Jobs Found
The CSEA Contractor is expected to provide hands-on support to the Cyber Security Engineering and Architecture section by contributing to security architecture activities, technical security reviews, control implementation, risk assessments and advisory services across enterprise systems, infrastructure, cloud environments and applications.<br><br>The Contractor Is Expected To Have<br><br>Hands-on experience with Enterprise Security Architecture methodologies and modern security technologies, including IAM, SIEM, EDR/XDR, WAF, SASE, Zero Trust, cloud security, and security automation tools. Strong knowledge of IT infrastructure security, including network security, cloud security, endpoint security, identity security, and secure architecture design principles. Strong knowledge of application security, including secure SDLC, Dev Sec Ops, API security, secure coding practices, and application threat modeling. Experience implementing, validating, and reviewing security controls across IT infrastructure, cloud platforms such as AWS, Azure, and GCP, and enterprise applications. Experience developing, maintaining, and enhancing security control libraries, security patterns, baselines, and architecture standards, while ensuring their integration into security architecture and engineering activities. Strong understanding of cybersecurity standards, laws, and frameworks, including NIST, ISO/IEC 27001, CIS Controls, GDPR, PCI-DSS, and other relevant regulatory or compliance requirements. Strong understanding of cybersecurity best practices, including secure network architecture, endpoint protection, identity and access management, cloud security, Dev Sec Ops, and defense-in-depth design. Experience conducting security design reviews, architecture assessments, threat modeling, technical risk assessments, and security gap assessments. Ability to support business units, project teams, IT teams, and security stakeholders in selecting, designing, and implementing secure information systems and technology solutions. Experience with security automation and scripting using tools and languages such as Python, Power Shell, Bash, Terraform, Ansible, or similar technologies. Ability to support security investigations, incident response activities, forensic analysis, root cause analysis, and post-incident improvement recommendations when required. Experience providing technical consultation and advisory support on CSEA-related projects, initiatives, and engagements as requested by the CSEA Section Head. Excellent ability to translate technical cybersecurity concepts, risks, and recommendations into clear business language for both technical and non-technical stakeholders. Experience participating in cybersecurity committees, technical working groups, architecture review boards, project meetings, and cross-functional security discussions. Strong problem-solving, analytical, and decision-support skills, with the ability to assess complex technical environments and recommend practical security solutions. Ability to work independently while also collaborating effectively with security architects, SOC analysts, IT teams, application teams, project managers, and business stakeholders. Excellent verbal and written communication skills, with the ability to document security findings, architecture recommendations, risks, and remediation actions clearly and professionally. Ability to mentor and support CSEA team members as needed by transferring knowledge, sharing technical expertise, and contributing to the development of internal cybersecurity engineering and architecture capabilities.<br><br>Key Deliverables<br><br>The contractor may be expected to support or deliver:<br><br>Security architecture reviews Security design review reports Threat models and risk assessments Security control mapping and recommendations Architecture patterns, baselines, and standards Technical security advisory reports Secure design recommendations for infrastructure, cloud, and applications Security improvement roadmaps Support for incident response, investigations, and technical analysis Knowledge transfer sessions for CSEA members<br><br>Requirements<br><br>Education:<br><br>Bachelor’s degree in a technology-related field, such as Cybersecurity, Computer Science, Computer Engineering, Information Security, Information Technology, or a related discipline. A higher degree or relevant professional certifications are preferred.<br><br>Experience<br><br>Minimum of 10 years relevant experience in cybersecurity, information security, security engineering, or IT infrastructure security, with at least 3 years of hands-on experience in cybersecurity architecture, security engineering, or enterprise security architecture.<br><br>Preferred Certifications<br><br>CISSP, CISM, SABSA, or TOGAF certifications preferred. Cloud security certifications such as CCSP, Azure Security Engineer, or AWS Security Specialty preferred. Cybersecurity certifications such as GCIH, GCIA, GSEC, or Security+ preferred. Other relevant cybersecurity, cloud security, or architecture certifications considered.
The CSEA Contractor is expected to provide hands-on support to the Cyber Security<br><br>Engineering and Architecture section by contributing to security architecture<br><br>activities, technical security reviews, control implementation, risk<br><br>assessments and advisory services across enterprise systems, infrastructure,<br><br>cloud environments and applications.<br><br>The<br><br>Contractor Is Expected To Have<br><br>Hands-on experience with Enterprise Security Architecture methodologies and modern security technologies, including IAM, SIEM, EDR/XDR, WAF, SASE, Zero Trust, cloud security, and security automation tools. Strong knowledge of IT infrastructure security, including network security, cloud security, endpoint security, identity security, and secure architecture design principles. Strong knowledge of application security, including secure SDLC, Dev Sec Ops, API security, secure coding practices, and application threat modeling. Experience implementing, validating, and reviewing security controls across IT infrastructure, cloud platforms such as AWS, Azure, and GCP, and enterprise applications. Experience developing, maintaining, and enhancing security control libraries, security patterns, baselines, and architecture standards, while ensuring their integration into security architecture and engineering activities. Strong understanding of cybersecurity standards, laws, and frameworks, including NIST, ISO/IEC 27001, CIS Controls, GDPR, PCI-DSS, and other relevant regulatory or compliance requirements. Strong understanding of cybersecurity best practices, including secure network architecture, endpoint protection, identity and access management, cloud security, Dev Sec Ops, and defense-in-depth design. Experience conducting security design reviews, architecture assessments, threat modeling, technical risk assessments, and security gap assessments. Ability to support business units, project teams, IT teams, and security stakeholders in selecting, designing, and implementing secure information systems and technology solutions. Experience with security automation and scripting using tools and languages such as Python, Power Shell, Bash, Terraform, Ansible, or similar technologies. Ability to support security investigations, incident response activities, forensic analysis, root cause analysis, and post-incident improvement recommendations when required. Experience providing technical consultation and advisory support on CSEA-related projects, initiatives, and engagements as requested by the CSEA Section Head. Excellent ability to translate technical cybersecurity concepts, risks, and recommendations into clear business language for both technical and non-technical stakeholders. Experience participating in cybersecurity committees, technical working groups, architecture review boards, project meetings, and cross-functional security discussions. Strong problem-solving, analytical, and decision-support skills, with the ability to assess complex technical environments and recommend practical security solutions. Ability to work independently while also collaborating effectively with security architects, SOC analysts, IT teams, application teams, project managers, and business stakeholders. Excellent verbal and written communication skills, with the ability to document security findings, architecture recommendations, risks, and remediation actions clearly and professionally. Ability to mentor and support CSEA team members as needed by transferring knowledge, sharing technical expertise, and contributing to the development of internal cybersecurity engineering and architecture capabilities.<br><br>Key<br><br>Deliverables<br><br>The<br><br>Contractor May Be Expected To Support Or Deliver<br><br>Security architecture reviews Security design review reports Threat models and risk assessments Security control mapping and recommendations Architecture patterns, baselines, and standards Technical security advisory reports Secure design recommendations for infrastructure, cloud, and applications Security improvement roadmaps Support for incident response, investigations, and technical analysis Knowledge transfer sessions for CSEA members<br><br>Requirements<br><br>Education:<br><br>Bachelor’s degree in a technology-related field, such as Cybersecurity, Computer Science, Computer Engineering, Information Security, Information Technology, or a related discipline. A higher degree or relevant professional certifications are preferred.<br><br>Experience<br><br>Minimum of 10 years relevant experience in cybersecurity, information security, security engineering, or IT infrastructure security, with at least 3 years of hands-on experience in cybersecurity architecture, security engineering, or enterprise security architecture.<br><br>Preferred Certifications<br><br>CISSP, CISM, SABSA, or TOGAF certifications preferred. Cloud security certifications such as CCSP, Azure Security Engineer, or AWS Security Specialty preferred. Cybersecurity certifications such as GCIH, GCIA, GSEC, or Security+ preferred. Other relevant cybersecurity, cloud security, or architecture certifications considered.<br><br>Proficiency in English & Arabic is<br><br>required.
Full Time Doha, Qatar Posted 18 hours ago<br><br>Website Lesha Bank LLC (Public) Lesha Bank LLC (Public)<br><br>Lesha Bank is searching for the greatest talent and brightest minds to contribute to the current growth phase at our bank. We are looking for top-tier individuals who are passionate and hungry to add value from day one. Every day at Lesha is different, presenting a new challenge with the opportunity to contribute and grow. We are looking for an<br><br>Job Summary<br><br>We are seeking an experienced Technology Risk Associate to strengthen and enhance Lesha Group’s cybersecurity risk management and assurance capabilities across its business entities and technology environments.<br><br>The role will be responsible for conducting and overseeing cybersecurity risk assessments, evaluating the effectiveness of security controls, performing cybersecurity assurance and compliance reviews, monitoring technology and cyber risk exposure, and supporting the remediation of identified vulnerabilities, control deficiencies, and emerging threats. The position will also contribute to the ongoing enhancement of the Group’s cybersecurity governance, risk management, and regulatory compliance framework.<br><br>The successful candidate will possess a strong blend of cybersecurity risk management, security assurance, and technical security expertise, with the ability to assess complex technology environments and engage effectively with business stakeholders, technology teams, project managers, third-party service providers, auditors, and regulatory authorities to strengthen the Group’s overall cyber resilience and risk posture.<br><br>Key Responsibilities<br><br>Security Architecture & Technology Risk<br><br>Conduct security reviews of enterprise infrastructure, applications, cloud environments, networks, databases, middleware, and security solutions. Review proposed technology solutions and architectures to ensure security requirements are incorporated by design. Perform threat modelling and security risk assessments for new technologies and business initiatives. Define and assess security baselines and configuration standards. Provide security recommendations for enterprise architecture and technology transformation initiatives.<br><br>Cloud, AI & Emerging Technology Security<br><br>Assess and strengthen security controls across Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure environments. Conduct cloud security assessments covering identity, network security, workloads, containers, data protection, logging, and monitoring. Support security governance for container environments. Conduct security and risk assessments of AI, Generative AI, Machine Learning, and emerging technology solutions. Assess security controls and compliance requirements for AI-powered applications and third-party AI service providers. Establish appropriate security controls for cloud-native, AI-enabled, and emerging technology environments.<br><br>Application Security & Dev Sec Ops<br><br>Lead application security assessments throughout the software development lifecycle. Establish and enhance secure SDLC and Dev Sec Ops practices. Integrate security testing and controls into CI/CD pipelines. Oversee SAST, DAST, SCA, penetration testing, and application security reviews. Work closely with development teams to identify and remediate application security vulnerabilities. Promote security-by-design principles across application development and technology projects.<br><br>Vulnerability & Security Testing<br><br>Oversee enterprise vulnerability management and risk-based vulnerability remediation. Manage penetration testing activities for applications, infrastructure, and external-facing systems. Coordinate internal and external penetration testing engagements and track remediation. Establish vulnerability management KPIs, KRIs, risk acceptance processes, and remediation timelines. Chair or facilitate vulnerability remediation governance forums where required. Identify recurring vulnerabilities and drive improvements to the organization’s overall security posture.<br><br>Security Operations & Incident Management<br><br>Provide governance and oversight of security monitoring and incident response capabilities. Work with SOC and security operations teams to improve detection, response, and remediation processes. Review SIEM use cases, security monitoring requirements, and incident management processes. Support major cybersecurity incident investigations and post-incident improvement activities. Ensure lessons learned from incidents are incorporated into security controls and risk management processes.<br><br>Cybersecurity Governance, Risk & Compliance Support<br><br>Act as a deputy to the Information Security Officer when required, ensuring business continuity and ongoing execution of cybersecurity governance, risk management, compliance, and assurance activities. Provide analytical and administrative support to cybersecurity governance forums, risk committees, and management review meetings, including the preparation of presentations, reports, and action tracking. Support internal, external, and regulatory audits through evidence collection, stakeholder coordination, tracking of findings, and monitoring of remediation activities. Prepare and maintain cybersecurity metrics, dashboards, risk reports, KPIs, KRIs, and management reporting materials for governance and oversight purposes. Perform cybersecurity assurance activities and control effectiveness reviews to support the evaluation of the Group’s cybersecurity maturity and control environment.<br><br>Preferred Certifications<br><br>OSCP – Offensive Security Certified Professional CEH – Certified Ethical Hacker CHFI – Computer Hacking Forensic Investigator CISSP – Certified Information Systems Security Professional CISM – Certified Information Security Manager<br><br>Educational Qualifications Required<br><br>Bachelor or Master degree in Computer or IT or any related fields<br><br>Experience Requirements<br><br>More than 10 years of experience in Cybersecurity / Technology Risk Assessment and Assurance Experience supporting compliance with recognized frameworks and regulations such as ISO 27001, NIST, NIA, QCSF, PCI DSS, GDPR, PDPL, or similar standards. Hands-on experience conducting cybersecurity risk assessments, control reviews, and security assurance activities. Skilled in enterprise security architecture reviews, cloud, AI, emerging technologies security reviews, application security reviews, Dev Sec Ops, vulnerability assessment, penetration testing, security operations and information security incident management.<br><br>Technical And Professional Skills Required<br><br>Enterprise Security Architecture Cybersecurity Risk Assessments Cloud Security AI Security Application Security Dev Sec Ops Vulnerability Management Penetration Testing Threat Modelling Security Operations & Incident Response SIEM and Security Monitoring Executive Reporting and Stakeholder Management<br><br>Key Competencies<br><br>Strong analytical and risk-based decision-making capability. Ability to translate technical cybersecurity issues into business risks. Strong understanding of regulatory and compliance requirements. Ability to lead cybersecurity initiatives across multiple business and technology functions. Excellent stakeholder and executive communication skills. Ability to balance governance requirements with practical technology and business needs. Strong leadership, influencing, and problem-solving capabilities.<br><br>First Name<br><br>Last Name (optional)<br><br>Country (optional)<br><br>Email address<br><br>Message<br><br>Upload CV<br><br>Upload your CV/resume or any other relevant file. Max. file size: 256 MB.<br><br>Lesha Bank is searching for the greatest talent and brightest minds to contribute to the current growth phase at our bank. We are looking for top-tier individuals who are passionate and hungry to add value from day one. Every day at Lesha is different, presenting a new challenge with the opportunity to contribute and grow. We are looking for an<br><br>Key Responsibilities<br><br>Security Architecture & Technology Risk<br><br>Conduct security reviews of enterprise infrastructure, applications, cloud environments, networks, databases, middleware, and security solutions. Review proposed technology solutions and architectures to ensure security requirements are incorporated by design. Perform threat modelling and security risk assessments for new technologies and business initiatives. Define and assess security baselines and configuration standards. Provide security recommendations for enterprise architecture and technology transformation initiatives.<br><br>Cloud, AI & Emerging Technology Security<br><br>Assess and strengthen security controls across Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure environments. Conduct cloud security assessments covering identity, network security, workloads, containers, data protection, logging, and monitoring. Support security governance for container environments. Conduct security and risk assessments of AI, Generative AI, Machine Learning, and emerging technology solutions. Assess security controls and compliance requirements for AI-powered applications and third-party AI service providers. Establish appropriate security controls for cloud-native, AI-enabled, and emerging technology environments.<br><br>Application Security & Dev Sec Ops<br><br>Lead application security assessments throughout the software development lifecycle. Establish and enhance secure SDLC and Dev Sec Ops practices. Integrate security testing and controls into CI/CD pipelines. Oversee SAST, DAST, SCA, penetration testing, and application security reviews. Work closely with development teams to identify and remediate application security vulnerabilities. Promote security-by-design principles across application development and technology projects.<br><br>Vulnerability & Security Testing<br><br>Oversee enterprise vulnerability management and risk-based vulnerability remediation. Manage penetration testing activities for applications, infrastructure, and external-facing systems. Coordinate internal and external penetration testing engagements and track remediation. Establish vulnerability management KPIs, KRIs, risk acceptance processes, and remediation timelines. Chair or facilitate vulnerability remediation governance forums where required. Identify recurring vulnerabilities and drive improvements to the organization’s overall security posture.<br><br>Security Operations & Incident Management<br><br>Provide governance and oversight of security monitoring and incident response capabilities. Work with SOC and security operations teams to improve detection, response, and remediation processes. Review SIEM use cases, security monitoring requirements, and incident management processes. Support major cybersecurity incident investigations and post-incident improvement activities. Ensure lessons learned from incidents are incorporated into security controls and risk management processes.<br><br>Cybersecurity Governance, Risk & Compliance Support<br><br>Act as a deputy to the Information Security Officer when required, ensuring business continuity and ongoing execution of cybersecurity governance, risk management, compliance, and assurance activities. Provide analytical and administrative support to cybersecurity governance forums, risk committees, and management review meetings, including the preparation of presentations, reports, and action tracking. Support internal, external, and regulatory audits through evidence collection, stakeholder coordination, tracking of findings, and monitoring of remediation activities. Prepare and maintain cybersecurity metrics, dashboards, risk reports, KPIs, KRIs, and management reporting materials for governance and oversight purposes. Perform cybersecurity assurance activities and control effectiveness reviews to support the evaluation of the Group’s cybersecurity maturity and control environment.<br><br>Preferred Certifications<br><br>OSCP – Offensive Security Certified Professional CEH – Certified Ethical Hacker CHFI – Computer Hacking Forensic Investigator CISSP – Certified Information Systems Security Professional CISM – Certified Information Security Manager<br><br>Educational Qualifications Required<br><br>Bachelor or Master degree in Computer or IT or any related fields<br><br>Experience Requirements<br><br>More than 10 years of experience in Cybersecurity / Technology Risk Assessment and Assurance Experience supporting compliance with recognized frameworks and regulations such as ISO 27001, NIST, NIA, QCSF, PCI DSS, GDPR, PDPL, or similar standards. Hands-on experience conducting cybersecurity risk assessments, control reviews, and security assurance activities. Skilled in enterprise security architecture reviews, cloud, AI, emerging technologies security reviews, application security reviews, Dev Sec Ops, vulnerability assessment, penetration testing, security operations and information security incident management.<br><br>Technical And Professional Skills Required<br><br>Enterprise Security Architecture Cybersecurity Risk Assessments Cloud Security AI Security Application Security Dev Sec Ops Vulnerability Management Penetration Testing Threat Modelling Security Operations & Incident Response SIEM and Security Monitoring Executive Reporting and Stakeholder Management<br><br>Key Competencies<br><br>Strong analytical and risk-based decision-making capability. Ability to translate technical cybersecurity issues into business risks. Strong understanding of regulatory and compliance requirements. Ability to lead cybersecurity initiatives across multiple business and technology functions. Excellent stakeholder and executive communication skills. Ability to balance governance requirements with practical technology and business needs. Strong leadership, influencing, and problem-solving capabilities.
<p>The CSEA Contractor is expected to provide hands-on support to the Cyber Security Engineering and Architecture section by contributing to security architecture activities, technical security reviews, control implementation, risk assessments and advisory services across enterprise systems, infrastructure, cloud environments and applications.</p><p><strong>Desired Candidate Profile</strong></p><ul><li>Hands-on experience with Enterprise Security Architecture methodologies and modern security technologies, including IAM, SIEM, EDR/XDR, WAF, SASE, Zero Trust, cloud security, and security automation tools.</li><li>Strong knowledge of IT infrastructure security, including network security, cloud security, endpoint security, identity security, and secure architecture design principles.</li><li>Strong knowledge of application security, including secure SDLC, DevSecOps, API security, secure coding practices, and application threat modeling.</li><li>Experience implementing, validating, and reviewing security controls across IT infrastructure, cloud platforms such as AWS, Azure, and GCP, and enterprise applications.</li><li>Experience developing, maintaining, and enhancing security control libraries, security patterns, baselines, and architecture standards, while ensuring their integration into security architecture and engineering activities.</li><li>Strong understanding of cybersecurity standards, laws, and frameworks, including NIST, ISO/IEC 27001, CIS Controls, GDPR, PCI-DSS, and other relevant regulatory or compliance requirements.</li><li>Strong understanding of cybersecurity best practices, including secure network architecture, endpoint protection, identity and access management, cloud security, DevSecOps, and defense-in-depth design.</li><li>Experience conducting security design reviews, architecture assessments, threat modeling, technical risk assessments, and security gap assessments.</li><li>Ability to support business units, project teams, IT teams, and security stakeholders in selecting, designing, and implementing secure information systems and technology solutions.</li><li>Experience with security automation and scripting using tools and languages such as Python, PowerShell, Bash, Terraform, Ansible, or similar technologies.</li><li>Ability to support security investigations, incident response activities, forensic analysis, root cause analysis, and post-incident improvement recommendations when required.</li><li>Experience providing technical consultation and advisory support on CSEA-related projects, initiatives, and engagements as requested by the CSEA Section Head.</li><li>Excellent ability to translate technical cybersecurity concepts, risks, and recommendations into clear business language for both technical and non-technical stakeholders.</li><li>Experience participating in cybersecurity committees, technical working groups, architecture review boards, project meetings, and cross-functional security discussions.</li><li>Strong problem-solving, analytical, and decision-support skills, with the ability to assess complex technical environments and recommend practical security solutions.</li><li>Ability to work independently while also collaborating effectively with security architects, SOC analysts, IT teams, application teams, project managers, and business stakeholders.</li><li>Excellent verbal and written communication skills, with the ability to document security findings, architecture recommendations, risks, and remediation actions clearly and professionally.</li><li>Ability to mentor and support CSEA team members as needed by transferring knowledge, sharing technical expertise, and contributing to the development of internal cybersecurity engineering and architecture capabilities.</li><li><strong>Key Deliverables:</strong> The contractor may be expected to support or deliver: Security architecture reviews, Security design review reports, Threat models and risk assessments, Security control mapping and recommendations, Architecture patterns, baselines, and standards, Technical security advisory reports, Secure design recommendations for infrastructure, cloud, and applications, Security improvement roadmaps, Support for incident response, investigations, and technical analysis, Knowledge transfer sessions for CSEA members</li><li><strong>Requirements</strong></li><li><strong>Education:</strong> Bachelor s degree in a technology-related field, such as Cybersecurity, Computer Science, Computer Engineering, Information Security, Information Technology, or a related discipline. A higher degree or relevant professional certifications are preferred.</li><li><strong>Experience:</strong> Minimum of 10 years relevant experience in cybersecurity, information security, security engineering, or IT infrastructure security, with at least 3 years of hands-on experience in cybersecurity architecture, security engineering, or enterprise security architecture.</li><li><strong>Preferred Certifications:</strong> CISSP, CISM, SABSA, or TOGAF certifications preferred. Cloud security certifications such as CCSP, Azure Security Engineer, or AWS Security Specialty preferred. Cybersecurity certifications such as GCIH, GCIA, GSEC, or Security+ preferred. Other relevant cybersecurity, cloud security, or architecture certifications considered.</li><li>Proficiency in English & Arabic is required.</li></ul>
<p>Maintain launch/recover UC-35 Cessna Citation aircraft. Troubleshoot malfunctions in aircraft structure, landing gear, flight surfaces and controls, anti-icing, pneudraulic, engines, auxiliary power unit, and ventilation and heating systems.</p><p>Principal Accountabilities:</p><ul><li>Operationally checks repaired or modified systems for proper operation.</li><li>Performs quality maintenance on assigned aircraft in accordance with federal aviation regulations, original equipment manufacturers, or military technical orders as specified in the statement of work instructions.</li><li>Repair and replace aircraft structures, such as wings and fuselage, and functional components including rigging, surface controls, and plumbing and hydraulic units, using hand tools, power tools, machines, and associated equipment.</li><li>Read and interpret manufacturers' and maintenance manuals, service bulletins, and other specifications to determine feasibility and method of repairing or replacing malfunctioning or damaged components.</li><li>Examine engines for oil leaks, and listens to operating engine to detect and diagnose malfunctions.</li><li>Inspect turbine blades to detect cracks or breaks.</li><li>Test engine operation, using troubleshooting procedures and diagnostic test equipment, to identify source of malfunction.</li><li>Replace or repair worn or damaged components using hand tools, gauges, and test equipment.</li><li>Remove and install engine from aircraft.</li><li>Disassemble and inspect parts for wear, warping, or other defects.</li><li>Repair or replace defective engine parts and reassembles and installs engine in aircraft.</li><li>Perform miscellaneous duties to service aircraft, including flushing crankcase, cleaning screens, greasing moving parts, and checking brakes.</li><li>May service engines and airframe components at line station making repairs, short of overhaul, required to keep aircraft in safe operating condition.</li><li>May specialize in work, repair and modification of structural, precision, and functional spare parts and assemblies.</li><li>May specialize in engine repair.</li><li>Perform other qualified duties as assigned.</li></ul><p>Knowledge & Skills</p><ul><li>Knowledge of aircraft sub-systems, including maintenance parameter, systems operation, limitations, and technical orders.</li><li>Ability to become qualified and perform engine runs for the aircraft type they are assigned to support.</li><li>Ability to read, write, and interpret technical duties is required.</li><li>Ability to communicate effectively with all levels of employees throughout the organization.</li><li>Proven track record demonstrating adaptability to change and the ability to respond to challenges in a changing environment.</li></ul><p>Minimum Qualifications:</p><ul><li>Valid FAA A&P Certificate Required.</li><li>All mechanics assigned to perform maintenance on FAA certified aircraft must meet FAA requirements.</li><li>Recent full-time experience in aviation maintenance with the assigned aircraft during the past 12 months.</li><li>Three (3) or more years aircraft mechanic experience as an aircraft mechanic on assigned aircraft required, five (5) years preferred.</li><li>Six (6) months of flight line and overhaul & inspection experience</li><li>Completion of formal maintenance training on assigned aircraft is desired.</li><li>Qualified by the appropriate USG armed forces aircraft mechanic maintenance course or civilian equivalent training.</li><li>High school diploma or equivalent.</li><li>Tools are provided by Amentum.</li></ul><p>Security Clearance Requirements:</p><ul><li>Must be able to obtain and maintain a US Govt DoW Secret Security Clearance. Must be able to obtain and maintain facility credentials and authorization. US Citizenship is Required to hold a US Govt Secret Clearance, and facility credentials and authorization to work at this facility.</li></ul><p>Physical Requirements/Working Environment</p><ul><li>Must be able to walk and stand on level and/or inclined surfaces for extended periods throughout the day.</li><li>Must be able to climb stairs, ramps, ladders and work stands.</li><li>Must be able to crouch, crawl, grasp or handle objects, use finger dexterity, bend elbow/knee and reach above/below shoulders.</li><li>May be required to carry, push or pull up to and may exceed 50 pounds.</li><li>May be required to lift up to 50 pounds to height of four feet and be required to lift up to 35 pounds to height of 7 feet.</li><li>May be required to see aircraft in flight, read dials/gauges, identify small objects and hand tools.</li><li>Must be able to type using a standard keyboard to communicate through e-mail and various software applications.</li><li>Must be able to see imperfections, micrometer readings and other small scales.</li><li>Must be able to read and interpret newspaper and typewritten print.</li><li>Must be able to communicate by voice and detect sounds by ear over telephone.</li><li>Must be able to distinguish color and judge three dimensional depths.</li><li>May be required to operate power vehicles, machinery, hand tools, ground support equipment, fork lift, APU, etc.</li><li>Must have minimum 20/100 near and far vision, correctable to 20/20.</li><li>Must be capable of living and working in a potentially hostile environment for an extended period.</li><li>May be required to respond to a wide variety of operational circumstances, including extreme weather conditions and rudimentary infrastructure.</li><li>May be exposed to extreme noise from turbine and jet engine aircraft.</li><li>May be exposed to fumes or airborne particles. May be exposed to electrical shock hazards or work near moving mechanical parts, vehicles, or aircraft.</li><li>Must be able to travel internationally to and between remote locations in austere and/or hostile environments.</li></ul><p><strong>Desired Candidate Profile</strong></p><ul><li>Valid FAA A&P Certificate Required.</li><li>All mechanics assigned to perform maintenance on FAA certified aircraft must meet FAA requirements.</li><li>Recent full-time experience in aviation maintenance with the assigned aircraft during the past 12 months.</li><li>Three (3) or more years aircraft mechanic experience as an aircraft mechanic on assigned aircraft required, five (5) years preferred.</li><li>Six (6) months of flight line and overhaul & inspection experience</li><li>Completion of formal maintenance training on assigned aircraft is desired.</li><li>Qualified by the appropriate USG armed forces aircraft mechanic maintenance course or civilian equivalent training.</li><li>High school diploma or equivalent.</li><li>Tools are provided by Amentum.</li><li>Must be able to obtain and maintain a US Govt DoW Secret Security Clearance. Must be able to obtain and maintain facility credentials and authorization. US Citizenship is Required to hold a US Govt Secret Clearance, and facility credentials and authorization to work at this facility.</li><li>Must be able to walk and stand on level and/or inclined surfaces for extended periods throughout the day.</li><li>Must be able to climb stairs, ramps, ladders and work stands.</li><li>Must be able to crouch, crawl, grasp or handle objects, use finger dexterity, bend elbow/knee and reach above/below shoulders.</li><li>May be required to carry, push or pull up to and may exceed 50 pounds.</li><li>May be required to lift up to 50 pounds to height of four feet and be required to lift up to 35 pounds to height of 7 feet.</li><li>May be required to see aircraft in flight, read dials/gauges, identify small objects and hand tools.</li><li>Must be able to type using a standard keyboard to communicate through e-mail and various software applications.</li><li>Must be able to see imperfections, micrometer readings and other small scales.</li><li>Must be able to read and interpret newspaper and typewritten print.</li><li>Must be able to communicate by voice and detect sounds by ear over telephone.</li><li>Must be able to distinguish color and judge three dimensional depths.</li><li>May be required to operate power vehicles, machinery, hand tools, ground support equipment, fork lift, APU, etc.</li><li>Must have minimum 20/100 near and far vision, correctable to 20/20.</li><li>Must be capable of living and working in a potentially hostile environment for an extended period.</li><li>May be required to respond to a wide variety of operational circumstances, including extreme weather conditions and rudimentary infrastructure.</li><li>May be exposed to extreme noise from turbine and jet engine aircraft.</li><li>May be exposed to fumes or airborne particles. May be exposed to electrical shock hazards or work near moving mechanical parts, vehicles, or aircraft.</li><li>Must be able to travel internationally to and between remote locations in austere and/or hostile environments.</li></ul>
<p>The Role Capco is looking for a Security Architect to help our clients design and deliver secure, resilient cloud environments. You ll work across business, security, architecture, engineering, risk, and technology teams to embed security into cloud transformation programmes from the outset. This is an opportunity to tackle complex security challenges within financial services, helping clients adopt cloud technologies confidently while maintaining strong governance, regulatory compliance, and security controls. What You ll Do Designing and implementing cloud security strategies and policies that meet an organisation's specific needs. Design secure architectures and security patterns across public, private, and hybrid cloud environments. Define and implement cloud security controls, standards, guardrails, and architecture principles aligned with business and regulatory requirements. Work with engineering and platform teams to embed security throughout cloud infrastructure, applications, and delivery pipelines. Conducting regular security assessments and audits to identify vulnerabilities and develop plans to address them. Assess cloud security risks, identify control gaps, and provide practical recommendations that balance security, resilience, and business requirements. Collaborate with security, risk, architecture, and technology stakeholders to support secure cloud adoption and transformation.</p><p><strong>Desired Candidate Profile</strong></p><p>What We re Looking For Strong experience in cloud security architecture, cybersecurity architecture, or cloud infrastructure security. Practical knowledge of security architecture principles, identity and access management, encryption, network security, logging, monitoring, and cloud-native security controls. Experience designing security solutions across major cloud platforms such as AWS, Microsoft Azure, or Google Cloud Platform. Strong understanding of security frameworks, governance, risk management, regulatory requirements, and security-by-design principles. Knowledge of recognised cybersecurity frameworks and industry security standards. Experience with DevSecOps, infrastructure as code, container security, Kubernetes, or cloud security posture management.Clear communication and stakeholder management skills, with the ability to translate complex security requirements into practical architecture and engineering outcomes. Bonus Points For Experience delivering cloud security solutions within banking, financial services, or another regulated environment. Relevant cloud or security certifications. Exposure to large-scale cloud migration, modernisation, cybersecurity, or technology transformation programmes.</p>
???? Welcome to Your Next Adventure! The Cybersecurity Manager is responsible for the day-to-day management and execution of Snoonu's cybersecurity operations, translating the strategy, policies, and priorities set by the Head of Cybersecurity into consistent, well-run security capabilities across security operations, vulnerability management, incident response, application and cloud security oversight, identity security, and governance execution. The role operates as the operational backbone of the cybersecurity function, managing security engineers, analysts, and specialists on a day-to-day basis, ensuring controls are implemented correctly, risks are tracked and remediated on schedule, and security processes run reliably and efficiently. Working closely with the Head of Cybersecurity, and in regular contact with Technology, Product, IT, Data, and business stakeholders, the Cybersecurity Manager ensures that security initiatives are delivered on time, that operational risk is visible and managed, and that the team executes against the priorities defined by cybersecurity leadership. The role combines hands-on technical oversight with team leadership, acting as the primary point of escalation for operational security matters and freeing the Head of Cybersecurity to focus on strategy, governance, and executive-level risk management.???? What You’ll Get Your Hands OnOperational Leadership & Program Execution Translate the cybersecurity strategy and roadmap set by the Head of Cybersecurity into operational plans, priorities, and day-to-day execution schedules. Coordinate execution across security operations, vulnerability management, application security, cloud security, and identity security workstreams. Track progress of security initiatives, projects, and remediation activities, and escalate delays, resourcing gaps, or emerging risks to the Head of Cybersecurity. Ensure security processes, runbooks, and procedures are documented, current, and consistently followed by the team. Support planning and reporting on cybersecurity capacity, workload, and resourcing needs. Security Operations & Incident Response Manage day-to-day security monitoring and detection activities, ensuring alerts are triaged, investigated, and resolved within agreed timelines. Act as the operational incident commander for security incidents, coordinating containment, investigation, and remediation, and escalating significant or high-severity incidents to the Head of Cybersecurity promptly. Ensure incident documentation, timelines, and lessons-learned reports are completed for all incidents. Coordinate and participate in incident-response tabletop exercises and technical simulations. Vulnerability & Exposure Management Manage the day-to-day vulnerability management program across applications, infrastructure, cloud, and endpoints. Ensure vulnerabilities are triaged, prioritized, assigned, and tracked to remediation against agreed SLAs. Coordinate with engineering, infrastructure, and platform teams to drive timely remediation of critical and high-risk findings. Monitor overdue items, recurring weaknesses, and exceptions, and escalate material or stalled risks to the Head of Cybersecurity. Support coordination of penetration tests, scans, and security assessments, and track resulting findings to closure. Application, Cloud & Dev Sec Ops Security Oversight Oversee day-to-day implementation of application security and Dev Sec Ops practices, including code scanning, dependency checks, and secure release gates. Monitor cloud security posture and coordinate remediation of misconfigurations, excessive permissions, and exposed assets with infrastructure and platform teams. Support engineering and product teams with practical security guidance during design and development, escalating architecture-level or higher-risk decisions to the Head of Cybersecurity. Track adoption and effectiveness of security tooling embedded in CI/CD pipelines and development workflows Identity, Access & Data Security Oversee operational execution of access reviews, joiner/mover/leaver processes, and privileged-access controls. Monitor for dormant accounts, excessive privileges, and access-control weaknesses, and drive remediation with system and application owners. Support implementation of data-security controls, including access control, encryption, and data-loss-prevention monitoring. Support investigation of suspected data-exposure or unauthorized-access incidents. Governance, Compliance & Third-Party Security Execution Support execution of the security governance framework, ensuring policies, standards, and procedures defined by the Head of Cybersecurity are implemented and followed operationally. Coordinate evidence collection, audits, and assessments related to ISO/IEC 27001, PCI DSS, and other applicable frameworks. Track findings from audits and assessments through to remediation, and maintain accurate compliance records. Coordinate day-to-day third-party security assessments and monitor remediation of vendor-related risks. Security Awareness & Reporting Coordinate delivery of security awareness training, phishing simulations, and role-specific enablement programs. Track behavioral metrics and awareness-program effectiveness, and report trends to the Head of Cybersecurity. Prepare regular operational reporting on security metrics, KPIs, incidents, vulnerabilities, and remediation status for the Head of Cybersecurity and relevant stakeholders. Team Leadership & Development Directly manage and coach a team of security analysts, engineers, and specialists across security operations, vulnerability management, and related functions. Set clear day-to-day expectations, priorities, and performance objectives for the team, aligned with direction from the Head of Cybersecurity. Conduct performance reviews, identify development needs, and support career growth for team members. Support hiring, onboarding, and knowledge continuity within the team. Foster a culture of ownership, technical excellence, and collaboration within the operational security team.???? ♂️ The Magic You Bring Bachelor's / Master’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related discipline, or equivalent relevant professional experience.4-7 years of experience in the cybersecurity field, including prior experience leading or coordinating a team or workstream. Hands-on experience across several security domains such as security operations, vulnerability management, incident response, application security, cloud security, or identity and access management. Practical experience managing security tools, processes, and day-to-day operations in a technology-driven organization. Working knowledge of cloud environments, modern software-development practices, CI/CD, and enterprise application architectures. Experience supporting security governance, audits, or compliance activities. Strong organizational, coordination, and problem-solving skills, with the ability to manage multiple priorities under time pressure. Good communication skills, with the ability to work effectively with technical teams and non-technical stakeholders. Technical & Functional Competencies Security operations and incident response management. Vulnerability and exposure management. Application, cloud, and Dev Sec Ops security oversight. Identity and privileged-access security. Data security and data-loss prevention. Security governance, audit, and compliance support (ISO 27001, PCI DSS). Third-party security assessment coordination. Security awareness program management. Security metrics, reporting, and KPI tracking. Team leadership and operational management.
<h3>Job Summary</h3>We are seeking an experienced Technology Risk Vice President to strengthen and enhance Lesha Group s cybersecurity risk management and assurance capabilities across its business entities and technology environments. The role will be responsible for conducting and overseeing cybersecurity risk assessments, evaluating the effectiveness of security controls, performing cybersecurity assurance and compliance reviews, monitoring technology and cyber risk exposure, and supporting the remediation of identified vulnerabilities, control deficiencies, and emerging threats. The position will also contribute to the ongoing enhancement of the Group s cybersecurity governance, risk management, and regulatory compliance framework. The successful candidate will possess a strong blend of cybersecurity risk management, security assurance, and technical security expertise, with the ability to assess complex technology environments and engage effectively with business stakeholders, technology teams, project managers, third-party service providers, auditors, and regulatory authorities to strengthen the Group s overall cyber resilience and risk posture. <h3>Key Responsibilities</h3><strong>Security Architecture & Technology Risk</strong> Conduct security reviews of enterprise infrastructure, applications, cloud environments, networks, databases, middleware, and security solutions. Review proposed technology solutions and architectures to ensure security requirements are incorporated by design. Perform threat modelling and security risk assessments for new technologies and business initiatives. Define and assess security baselines and configuration standards. Provide security recommendations for enterprise architecture and technology transformation initiatives. <strong>Cloud, AI & Emerging Technology Security</strong> Assess and strengthen security controls across Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure environments. Conduct cloud security assessments covering identity, network security, workloads, containers, data protection, logging, and monitoring. Support security governance for container environments. Conduct security and risk assessments of AI, Generative AI, Machine Learning, and emerging technology solutions. Assess security controls and compliance requirements for AI-powered applications and third-party AI service providers. Establish appropriate security controls for cloud-native, AI-enabled, and emerging technology environments. <strong>Application Security & DevSecOps</strong> Lead application security assessments throughout the software development lifecycle. Establish and enhance secure SDLC and DevSecOps practices. Integrate security testing and controls into CI/CD pipelines. Oversee SAST, DAST, SCA, penetration testing, and application security reviews. Work closely with development teams to identify and remediate application security vulnerabilities. Promote security-by-design principles across application development and technology projects. <strong>Vulnerability & Security Testing</strong> Oversee enterprise vulnerability management and risk-based vulnerability remediation. Manage penetration testing activities for applications, infrastructure, and external-facing systems. Coordinate internal and external penetration testing engagements and track remediation. Establish vulnerability management KPIs, KRIs, risk acceptance processes, and remediation timelines. Chair or facilitate vulnerability remediation governance forums where required. Identify recurring vulnerabilities and drive improvements to the organization s overall security posture. <strong>Security Operations & Incident Management</strong> Provide governance and oversight of security monitoring and incident response capabilities. Work with SOC and security operations teams to improve detection, response, and remediation processes. Review SIEM use cases, security monitoring requirements, and incident management processes. Support major cybersecurity incident investigations and post-incident improvement activities. Ensure lessons learned from incidents are incorporated into security controls and risk management processes. <strong>Cybersecurity Governance, Risk & Compliance Support</strong> Act as a deputy to the Information Security Officer when required, ensuring business continuity and ongoing execution of cybersecurity governance, risk management, compliance, and assurance activities. Provide analytical and administrative support to cybersecurity governance forums, risk committees, and management review meetings, including the preparation of presentations, reports, and action tracking. Support internal, external, and regulatory audits through evidence collection, stakeholder coordination, tracking of findings, and monitoring of remediation activities. Prepare and maintain cybersecurity metrics, dashboards, risk reports, KPIs, KRIs, and management reporting materials for governance and oversight purposes. Perform cybersecurity assurance activities and control effectiveness reviews to support the evaluation of the Group s cybersecurity maturity and control environment. <strong>Preferred Certifications</strong> OSCP Offensive Security Certified Professional CEH Certified Ethical Hacker CHFI Computer Hacking Forensic Investigator CISSP Certified Information Systems Security Professional CISM Certified Information Security Manager <strong>Technical and Professional Skills Required</strong> Enterprise Security Architecture Cybersecurity Risk Assessments Cloud Security AI Security Application Security DevSecOps Vulnerability Management Penetration Testing Threat Modelling Security Operations & Incident Response SIEM and Security Monitoring Executive Reporting and Stakeholder Management <strong>Key Competencies</strong> Strong analytical and risk-based decision-making capability. Ability to translate technical cybersecurity issues into business risks. Strong understanding of regulatory and compliance requirements. Ability to lead cybersecurity initiatives across multiple business and technology functions. Excellent stakeholder and executive communication skills. Ability to balance governance requirements with practical technology and business needs. Strong leadership, influencing, and problem-solving capabilities.<p><strong>Desired Candidate Profile</strong></p><h3>Educational Qualifications Required</h3>Bachelor or Master degree in Computer or IT or any related fields <h3>Experience Requirements</h3>More than 10 years of experience in Cybersecurity / Technology Risk Assessment and Assurance Experience supporting compliance with recognized frameworks and regulations such as ISO 27001, NIST, NIA, QCSF, PCI DSS, GDPR, PDPL, or similar standards. Hands-on experience conducting cybersecurity risk assessments, control reviews, and security assurance activities. Skilled in enterprise security architecture reviews, cloud, AI, emerging technologies security reviews, application security reviews, DevSecOps, vulnerability assessment, penetration testing, security operations and information security incident management.
<p>Lesha Bank is searching for the greatest talent and brightest minds to contribute to the current growth phase at our bank. We are looking for top-tier individuals who are passionate and hungry to add value from day one. Every day at Lesha is different, presenting a new challenge with the opportunity to contribute and grow. We are looking for an Job Summary We are seeking an experienced Technology Risk Associate to strengthen and enhance Lesha Group s cybersecurity risk management and assurance capabilities across its business entities and technology environments. The role will be responsible for conducting and overseeing cybersecurity risk assessments, evaluating the effectiveness of security controls, performing cybersecurity assurance and compliance reviews, monitoring technology and cyber risk exposure, and supporting the remediation of identified vulnerabilities, control deficiencies, and emerging threats. The position will also contribute to the ongoing enhancement of the Group s cybersecurity governance, risk management, and regulatory compliance framework. The successful candidate will possess a strong blend of cybersecurity risk management, security assurance, and technical security expertise, with the ability to assess complex technology environments and engage effectively with business stakeholders, technology teams, project managers, third-party service providers, auditors, and regulatory authorities to strengthen the Group s overall cyber resilience and risk posture.</p><p>Key Responsibilities</p><ul><li><strong>Security Architecture & Technology Risk</strong> Conduct security reviews of enterprise infrastructure, applications, cloud environments, networks, databases, middleware, and security solutions. Review proposed technology solutions and architectures to ensure security requirements are incorporated by design. Perform threat modelling and security risk assessments for new technologies and business initiatives. Define and assess security baselines and configuration standards. Provide security recommendations for enterprise architecture and technology transformation initiatives.</li><li><strong>Cloud, AI & Emerging Technology Security</strong> Assess and strengthen security controls across Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure environments. Conduct cloud security assessments covering identity, network security, workloads, containers, data protection, logging, and monitoring. Support security governance for container environments. Conduct security and risk assessments of AI, Generative AI, Machine Learning, and emerging technology solutions. Assess security controls and compliance requirements for AI-powered applications and third-party AI service providers. Establish appropriate security controls for cloud-native, AI-enabled, and emerging technology environments.</li><li><strong>Application Security & DevSecOps</strong> Lead application security assessments throughout the software development lifecycle. Establish and enhance secure SDLC and DevSecOps practices. Integrate security testing and controls into CI/CD pipelines. Oversee SAST, DAST, SCA, penetration testing, and application security reviews. Work closely with development teams to identify and remediate application security vulnerabilities. Promote security-by-design principles across application development and technology projects.</li><li><strong>Vulnerability & Security Testing</strong> Oversee enterprise vulnerability management and risk-based vulnerability remediation. Manage penetration testing activities for applications, infrastructure, and external-facing systems. Coordinate internal and external penetration testing engagements and track remediation. Establish vulnerability management KPIs, KRIs, risk acceptance processes, and remediation timelines. Chair or facilitate vulnerability remediation governance forums where required. Identify recurring vulnerabilities and drive improvements to the organization s overall security posture.</li><li><strong>Security Operations & Incident Management</strong> Provide governance and oversight of security monitoring and incident response capabilities. Work with SOC and security operations teams to improve detection, response, and remediation processes. Review SIEM use cases, security monitoring requirements, and incident management processes. Support major cybersecurity incident investigations and post-incident improvement activities. Ensure lessons learned from incidents are incorporated into security controls and risk management processes.</li><li><strong>Cybersecurity Governance, Risk & Compliance Support</strong> Act as a deputy to the Information Security Officer when required, ensuring business continuity and ongoing execution of cybersecurity governance, risk management, compliance, and assurance activities. Provide analytical and administrative support to cybersecurity governance forums, risk committees, and management review meetings, including the preparation of presentations, reports, and action tracking. Support internal, external, and regulatory audits through evidence collection, stakeholder coordination, tracking of findings, and monitoring of remediation activities. Prepare and maintain cybersecurity metrics, dashboards, risk reports, KPIs, KRIs, and management reporting materials for governance and oversight purposes. Perform cybersecurity assurance activities and control effectiveness reviews to support the evaluation of the Group s cybersecurity maturity and control environment.</li></ul><p><strong>Desired Candidate Profile</strong></p><ul><li><strong>Preferred Certifications</strong> OSCP Offensive Security Certified Professional CEH Certified Ethical Hacker CHFI Computer Hacking Forensic Investigator CISSP Certified Information Systems Security Professional CISM Certified Information Security Manager</li><li><strong>Educational Qualifications Required</strong> Bachelor or Master degree in Computer or IT or any related fields</li><li><strong>Experience Requirements</strong> More than 10 years of experience in Cybersecurity / Technology Risk Assessment and Assurance Experience supporting compliance with recognized frameworks and regulations such as ISO 27001, NIST, NIA, QCSF, PCI DSS, GDPR, PDPL, or similar standards. Hands-on experience conducting cybersecurity risk assessments, control reviews, and security assurance activities. Skilled in enterprise security architecture reviews, cloud, AI, emerging technologies security reviews, application security reviews, DevSecOps, vulnerability assessment, penetration testing, security operations and information security incident management.</li><li><strong>Technical and Professional Skills Required</strong> Enterprise Security Architecture Cybersecurity Risk Assessments Cloud Security AI Security Application Security DevSecOps Vulnerability Management Penetration Testing Threat Modelling Security Operations & Incident Response SIEM and Security Monitoring Executive Reporting and Stakeholder Management</li><li><strong>Key Competencies</strong> Strong analytical and risk-based decision-making capability. Ability to translate technical cybersecurity issues into business risks. Strong understanding of regulatory and compliance requirements. Ability to lead cybersecurity initiatives across multiple business and technology functions. Excellent stakeholder and executive communication skills. Ability to balance governance requirements with practical technology and business needs. Strong leadership, influencing, and problem-solving capabilities.</li></ul>
<p>A leading organization in Qatar is seeking a <strong>Manager – Security & Compliance</strong> to lead cybersecurity governance, information security, risk management, and regulatory compliance initiatives across the organization. The successful candidate will be responsible for strengthening security controls, ensuring compliance with applicable standards and regulations, managing security risks, overseeing audits and assessments, and fostering a strong security culture across the business.</p><p><br></p><p><strong>Key Responsibilities</strong></p><ul><li>Lead the implementation and continuous improvement of information security and compliance frameworks.</li><li>Develop and maintain security policies, standards, procedures, and controls.</li><li>Conduct risk assessments and drive mitigation plans for identified security risks.</li><li>Manage internal and external security audits, assessments, and compliance reviews.</li><li>Oversee vulnerability management, security monitoring, and incident response activities.</li><li>Ensure third-party vendors meet security and compliance requirements.</li><li>Partner with business and technology teams to embed security and risk management practices.</li><li>Deliver security awareness and training initiatives across the organization.</li><li>Provide regular reporting to senior management on security risks, compliance status, and remediation activities.</li><li>Lead, mentor, and develop a high-performing security and compliance team.</li></ul><p><br></p><p><strong>Requirements</strong></p><ul><li>Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field.</li><li>Minimum 8-10 years of experience in cybersecurity, information security, risk management, or compliance.</li><li>At least 3 years of leadership experience managing security or compliance functions.</li><li>Strong knowledge of information security frameworks, risk management, governance, and regulatory compliance.</li><li>Experience managing audits, security assessments, and third-party risk reviews.</li><li>Professional certifications such as <strong>CISSP, CISM, CRISC, CISA, CEH, Security+, or ISO 27001</strong> are highly desirable.</li></ul><p><br></p><p>Interested candidates are encouraged to apply in confidence. All applications will be treated with strict confidentiality.</p>
<strong>Location: Doha | <em>Practice Area</em>: Technology & Engineering | Type: Permanent<br><br></strong><strong>The Role<br><br></strong>Capco is looking for a Security Architect to help our clients design and deliver secure, resilient cloud environments. You’ll work across business, security, architecture, engineering, risk, and technology teams to embed security into cloud transformation programmes from the outset.<br><br>This is an opportunity to tackle complex security challenges within financial services, helping clients adopt cloud technologies confidently while maintaining strong governance, regulatory compliance, and security controls.<br><br><strong>What You’ll Do<br><br></strong><ul><li>Designing and implementing cloud security strategies and policies that meet an organisation's specific needs.</li><li>Design secure architectures and security patterns across public, private, and hybrid cloud environments.</li><li>Define and implement cloud security controls, standards, guardrails, and architecture principles aligned with business and regulatory requirements.</li><li>Work with engineering and platform teams to embed security throughout cloud infrastructure, applications, and delivery pipelines.</li><li>Conducting regular security assessments and audits to identify vulnerabilities and develop plans to address them.</li><li>Assess cloud security risks, identify control gaps, and provide practical recommendations that balance security, resilience, and business requirements.</li><li>Collaborate with security, risk, architecture, and technology stakeholders to support secure cloud adoption and transformation.<br><br></li></ul><strong>What We’re Looking For<br><br></strong><ul><li>Strong experience in cloud security architecture, cybersecurity architecture, or cloud infrastructure security.</li><li>Practical knowledge of security architecture principles, identity and access management, encryption, network security, logging, monitoring, and cloud-native security controls.</li><li>Experience designing security solutions across major cloud platforms such as AWS, Microsoft Azure, or Google Cloud Platform.</li><li>Strong understanding of security frameworks, governance, risk management, regulatory requirements, and security-by-design principles.</li><li>Knowledge of recognised cybersecurity frameworks and industry security standards.</li><li>Experience with DevSecOps, infrastructure as code, container security, Kubernetes, or cloud security posture management.Clear communication and stakeholder management skills, with the ability to translate complex security requirements into practical architecture and engineering outcomes.<br><br></li></ul><strong>Bonus Points For<br><br></strong><ul><li>Experience delivering cloud security solutions within banking, financial services, or another regulated environment.</li><li>Relevant cloud or security certifications.</li><li>Exposure to large-scale cloud migration, modernisation, cybersecurity, or technology transformation programmes.<br><br></li></ul><strong>Why Join Capco<br><br></strong><ul><li>Deliver high-impact technology solutions for Tier 1 financial institutions</li><li>Work in a collaborative, flat, and entrepreneurial consulting culture</li><li>Access continuous learning, training, and industry certifications</li><li>Be part of a team shaping the future of digital financial services</li><li>Help shape the future of digital transformation across FS & Energy.<br><br></li></ul><strong>We offer a competitive, people-first benefits package designed to support every aspect of your life.<br><br></strong><strong>Inclusion at Capco<br><br></strong>We’re committed to making our recruitment process accessible and straightforward for everyone. If you need any adjustments at any stage, just let us know – we’ll be happy to help. We value each person’s unique perspective and contribution. At Capco, we believe that being yourself is your greatest strength. Our #BeYourselfAtWork culture encourages individuality and collaboration – a mindset that shapes how we work with clients and each other every day.
<strong>Job Description<br><br></strong>We are seeking an experienced Cloud Security Engineer to join our Cybersecurity Practice. In this role, you will work closely with our cloud, infrastructure, and security teams to design, implement, and maintain security controls that protect our clients’ cloud environments.<br><br>Your responsibilities will include assessing cloud architectures, identifying security risks, implementing security best practices, and continuously monitoring cloud platforms to ensure confidentiality, integrity, and availability of systems and data. You will support secure adoption of cloud services across public, private, and hybrid environments, ensuring compliance with organizational policies, industry standards, and Qatari regulatory requirements.<br><br>You will collaborate with cloud architects, DevOps teams, and application teams to embed security controls throughout the cloud lifecycle, including design, deployment, and operations. The role requires hands-on technical expertise, strong analytical skills, and the ability to translate security requirements into practical, scalable cloud security solutions.<br><br><strong>Responsibilities<br><br></strong><ul><li>Cloud Security Architecture and Assessment:Assess cloud architectures and environments across public, private, and hybrid cloud platforms to identify security risks and design appropriate security controls. Conduct security reviews of cloud services, configurations, and deployments, including compute, storage, networking, identity, and platform services. Provide detailed assessment reports with clear, actionable remediation recommendations aligned with industry best practices.</li><li>Cloud Security Governance:Define, implement, and maintain cloud security governance frameworks, including security policies, standards, baselines, and control frameworks aligned with organizational and regulatory requirements. Establish clear roles and responsibilities through RACI models and support the development of cloud security operating procedures to ensure consistent, repeatable, and auditable security practices across cloud environments.</li><li>Security Monitoring and Threat Detection:Implement and support cloud security monitoring solutions to detect misconfigurations, vulnerabilities, and suspicious activities. Analyze security alerts and events, investigate potential incidents, and support timely remediation to maintain the confidentiality, integrity, and availability of cloud environments.</li><li>Identity and Access Management:Review and support secure implementation of identity and access controls, including role-based access control, least privilege, authentication, and authorization mechanisms across cloud platforms and services.</li><li>Cloud Security Compliance:Ensure cloud environments comply with organizational security policies, regulatory requirements, and applicable security standards. Support continuous compliance monitoring and remediation of configuration gaps and policy violations.</li><li>DevSecOps and Automation Support:Collaborate with DevOps and cloud engineering teams to integrate security controls into CI/CD pipelines and infrastructure-as-code workflows. Promote automation to improve security consistency, visibility, and scalability across cloud environments.</li><li>Security Tools and Technologies:Evaluate, implement, and manage Cloud-Native Application Protection Platform (CNAPP) solutions to enhance cloud security posture, visibility, and threat detection. This includes third-party platforms such as Palo Alto Prisma Cloud as well as native cloud security solutions such as Microsoft Defender, covering posture management, workload protection, identity security, and runtime threat detection.</li><li>Documentation and Reporting:Create and maintain comprehensive documentation related to cloud security architectures, assessments, controls, and operational procedures. Prepare security reports and dashboards for internal stakeholders and clients as required.</li><li>Training and Awareness:Support security awareness initiatives by providing guidance and knowledge-sharing sessions to cloud, infrastructure, and development teams on secure cloud practices and emerging cloud security threats.<br><br></li></ul><strong>Qualifications<br><br></strong><ul><li>Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field.</li><li>Experience: At least 3 years of experience in cloud security, cloud infrastructure, cybersecurity operations, or a closely related role.</li><li>Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:</li><ul><li>Oracle Cloud Infrastructure Security Professional (highly desirable)</li><li>Microsoft Azure Security Engineer Associate (AZ-500) (highly desirable)</li><li>Other Cloud Service Providers (AWS, GCP, etc.)</li><li>Vendor agnostic cloud security (CSA, GIAC, etc.).</li><li>General cybersecurity (CompTIA, ISC2, etc.).</li></ul><li>Technical Skills: Proficiency with cloud security and monitoring tools such as Microsoft Defender for Cloud, Azure Policy, Entra ID, and OCI Cloud Guard, including hands-on experience with IAM configuration, network security controls (NSGs/route controls/security lists), encryption & key management (Azure Key Vault / OCI Vault), and logging/monitoring (Azure Monitor/Log Analytics, OCI Logging). Familiarity with Infrastructure as Code (IaC) (e.g., Terraform, ARM/Bicep) and integrating security checks into automation and deployment workflows is preferred.</li><li>Knowledge: In-depth knowledge of cloud security principles and practices, including shared responsibility, identity governance, segmentation, hardening, vulnerability management, and incident response in cloud environments. Familiar with security frameworks and guidelines (e.g., CIS Benchmarks, NIST, ISO 27001, CSA Cloud Controls Matrix) and general compliance/security governance concepts. Familiarity with DevSecOps practices and CI/CD pipelines, Qatar National Information Assurance (NIA) is a plus.<br></li></ul><strong>About Malomatia<br><br></strong><strong> ABOUT US <br><br></strong>malomatia is a leading Qatar-based IT services and solutions provider, bringing together top Qatari and international talent to deliver innovative, end-to-end technology solutions that empower clients to achieve their strategic goals.<br><br><strong>Our mission<br><br></strong>Empowering Qatar’s businesses and governments to leap into the digital future with agile, knowledge-driven solutions.<br><br><strong>Our vision<br><br></strong>To become Qatar’s trusted knowledge partner in digital transformation, disrupting industries, shaping the future, and building a world-class tech ecosystem.<br><br><strong>Driving change that makes a real impact<br><br></strong>Since 2008, malomatia has been driving Qatar’s digital transformation through innovative, ISO-certified IT solutions. With expertise across key public and private sectors, we empower the nation’s vision with advanced services in cloud, cybersecurity, AI, and contact center excellence, elevating the role of technology in shaping Qatar’s sustainable future.<br><br><strong>About The Team<br><br></strong>Established in 2008, malomatia is a Qatari leader in IT services and digital transformation. We serve key sectors including Government, Healthcare, Education, Customs, and Transportation, delivering impactful solutions that support national development goals. Powered by a diverse team of skilled Qatari and international IT professionals, we deliver innovative, high-value digital solutions tailored to the unique needs of our clients.<br><br>Our mission is to inspire customers to thrive through digital excellence, and we envision becoming the trusted partner of choice in building a smarter society through technology and talent. We are driven by core values that define our culture and approach: ownership, integrity, empathy, teamwork, transparency, agility, excellence, trust, and innovation.<br><br>Join us in shaping the future of technology in Qatar
Job Description<br><br>We are seeking a skilled Senior Cybersecurity Consultant to join our Cybersecurity Practice. In this role, you will work closely with cloud, infrastructure, network, endpoint, and application teams to design, implement, and maintain enterprise security controls that protect our digital environments.<br><br>Your responsibilities will span Identity & Access Management (IAM), Data Security, Cloud Security, Endpoint Security, and Network Security. You will support the implementation of security best practices, monitor security posture, identify risks, and contribute to improving the overall security architecture across hybrid IT environments.<br><br>You will assist in assessing security architectures, identifying vulnerabilities, implementing security solutions, and supporting incident response activities to ensure confidentiality, integrity, and availability of systems and data. The role requires hands-on technical expertise, strong analytical capabilities, and the ability to translate security requirements into practical and scalable security solutions.<br><br>Responsibilities<br><br>Enterprise Security Architecture and Risk Assessment:Support the assessment of enterprise IT and cloud environments to identify security risks and recommend appropriate controls across identity, data, network, endpoint, and cloud domains. Conduct security reviews of infrastructure, configurations, and deployments and provide actionable remediation recommendations aligned with industry best practices. Identity and Access Management (IAM):Implement and support secure identity and access controls, including role-based access control (RBAC), least privilege, multi-factor authentication (MFA), privileged access management (PAM), and identity governance practices across enterprise and cloud environments. Data Security:Assist in implementing data protection controls including data classification, encryption at rest and in transit, key management, data loss prevention (DLP), and secure data handling practices to ensure regulatory and organizational compliance. Cloud Security:Support secure configuration and monitoring of public, private, and hybrid cloud platforms. Implement security controls related to IAM, network segmentation, workload protection, encryption, logging, and compliance monitoring. Contribute to cloud security posture management and vulnerability remediation efforts. Endpoint Security:Support deployment and management of endpoint protection solutions including EDR/XDR platforms, antivirus, device control, patch management, and hardening baselines. Monitor endpoint security alerts and assist in incident investigation and response. Security Technology Stack:Support the implementation and management of security platforms and monitoring tools to strengthen security posture, improve visibility, and enhance threat detection across enterprise and cloud environments. Documentation and Reporting:Prepare and maintain documentation related to security configurations, risk assessments, incident reports, and operational procedures. Provide regular security posture updates to internal stakeholders and clients as required.<br><br>Qualifications<br><br>Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field. Experience: At least 8 years of experience in cloud security, cloud infrastructure, cybersecurity operations, or a closely related role. Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:Microsoft Azure Security Engineer Associate (AZ-500) Comp TIA Security+, CySA+, or similar ISC2 (e.g., CC or SSCP) CSA or other cloud security certifications.). Technical Skills: Hands-on experience with security technologies including identity platforms (such as Entra ID and Active Directory), cloud-native security tools, endpoint protection solutions (EDR/XDR), network security technologies (firewalls, IDS/IPS, VPN), SIEM and log monitoring solutions, encryption and key management systems, and vulnerability management tools. Familiarity with integrating security controls across enterprise and cloud environments is preferred. Knowledge: Strong understanding of cybersecurity principles including defense-in-depth, zero trust, least privilege, segmentation, encryption, vulnerability management, and incident response. Familiarity with security frameworks and guidelines (e.g., CIS Benchmarks, NIST, ISO 27001) and general compliance/governance concepts. Knowledge of Qatar National Information Assurance (NIA) is a plus.<br>About Malomatia<br><br> ABOUT US <br><br>malomatia is a leading Qatar-based IT services and solutions provider, bringing together top Qatari and international talent to deliver innovative, end-to-end technology solutions that empower clients to achieve their strategic goals.<br><br>Our mission<br><br>Empowering Qatar’s businesses and governments to leap into the digital future with agile, knowledge-driven solutions.<br><br>Our vision<br><br>To become Qatar’s trusted knowledge partner in digital transformation, disrupting industries, shaping the future, and building a world-class tech ecosystem.<br><br>Driving change that makes a real impact<br><br>Since 2008, malomatia has been driving Qatar’s digital transformation through innovative, ISO-certified IT solutions. With expertise across key public and private sectors, we empower the nation’s vision with advanced services in cloud, cybersecurity, AI, and contact center excellence, elevating the role of technology in shaping Qatar’s sustainable future.<br><br>About The Team<br><br>Established in 2008, malomatia is a Qatari leader in IT services and digital transformation. We serve key sectors including Government, Healthcare, Education, Customs, and Transportation, delivering impactful solutions that support national development goals. Powered by a diverse team of skilled Qatari and international IT professionals, we deliver innovative, high-value digital solutions tailored to the unique needs of our clients.<br><br>Our mission is to inspire customers to thrive through digital excellence, and we envision becoming the trusted partner of choice in building a smarter society through technology and talent. We are driven by core values that define our culture and approach: ownership, integrity, empathy, teamwork, transparency, agility, excellence, trust, and innovation.<br><br>Join us in shaping the future of technology in Qatar
<p>Location: Doha, Qatar | Practice Area : Technology & Engineering | Type: Permanent</p><p>The Role</p><p>Capco is looking for an AI Security Consultant to help our clients identify, assess, and manage security risks associated with AI technologies and AI-enabled solutions. You ll work across data, security, technology, risk, and business teams to embed appropriate security controls throughout the lifecycle of AI systems. This is an opportunity to work at the intersection of AI, data, and cybersecurity within financial services, helping clients adopt AI securely while protecting sensitive information, strengthening governance, and managing emerging security risks.</p><p>What You ll Do</p><ul><li>Assess security risks associated with AI systems, models, data pipelines, and supporting technology environments.</li><li>Conduct AI security assessments and secure AI architecture reviews.</li><li>Define and implement security controls, standards, and guardrails across the AI lifecycle, from design and development through deployment and ongoing operation.</li><li>Identify and assess AI-specific threats and vulnerabilities, including risks relating to data exposure, model access, prompt manipulation, and misuse.</li><li>Deliver cybersecurity advisory services supporting enterprise AI adoption.</li><li>Support clients in securing AI-enabled products, platforms and data ecosystems.</li><li>Work with data, security, architecture, engineering, risk, and business teams to embed security-by-design into AI solutions and delivery processes.</li><li>Support AI security governance, risk assessments, control testing, monitoring, incident response, and remediation activities.</li></ul><p><strong>Desired Candidate Profile</strong></p><p>What We re Looking For</p><ul><li>Strong experience in cybersecurity, information security, AI security, data security, or related technology risk disciplines.</li><li>Practical understanding of AI and machine learning environments and the security risks associated with models, data, applications, and supporting infrastructure.</li><li>Experience applying security controls, threat modelling, risk assessment, identity and access management, data protection, and secure architecture principles.</li><li>Strong understanding of security governance, responsible AI, regulatory requirements, and security-by-design principles.</li><li>Clear communication and stakeholder management skills, with the ability to translate technical AI security risks into practical business and risk considerations.</li></ul><p>Bonus Points For</p><ul><li>Experience delivering AI, data, or cybersecurity initiatives within banking, financial services, or another regulated environment.</li><li>Knowledge of AI security threats, responsible AI frameworks, model security, Generative AI, or emerging AI security practices.</li><li>Experience with cloud-based AI and machine learning platforms and their associated security controls.</li><li>Relevant cybersecurity, cloud, data, AI, or information security certifications.</li><li>Exposure to large-scale AI, data, cybersecurity, regulatory, or technology transformation programmes.</li></ul>
The IT Security Audit & Compliance Specialist is responsible for managing and overseeing information security audits, compliance programs, cybersecurity governance, and risk management initiatives across the organization. The role ensures compliance with security standards, regulatory requirements, data protection policies, and internal governance frameworks.<br>The position supports the development of audit frameworks, conducts security assessments, monitors compliance maturity, identifies security risks and vulnerabilities, and collaborates with stakeholders to strengthen the organization’s cybersecurity posture.<br>Key Responsibilities<br>Security Audit & Compliance Management<br>Develop and maintain comprehensive IT security audit and compliance programs Plan, coordinate, and execute information security audit activities Define audit scope, objectives, methodologies, and work plans Develop and implement audit test plans for systems, applications, infrastructure, and cloud environments Conduct security compliance audits for critical systems, networks, and applications Maintain audit schedules, documentation, evidence collection, and reporting processes Ensure timely closure of audit findings, non-compliance issues, and remediation activities<br>Cybersecurity Governance & Risk Management<br>Ensure compliance with organizational policies, regulatory requirements, contractual obligations, and security standards Monitor cybersecurity maturity and compliance posture across operational and technical environments Build and maintain controls matrices aligned with multiple security and compliance frameworks Identify security risks, vulnerabilities, and compliance gaps, and recommend corrective actions Conduct vulnerability and compliance assessments and coordinate remediation activities Support governance initiatives related to security standards, policies, and operating procedures<br>Security Operations & Technical Oversight<br>Monitor compliance and security controls related to cloud security environments, Identity and Access Management (IAM), Privileged Access Management (PAM), Data Loss Prevention (DLP), and enterprise productivity and collaboration platforms. Coordinate with IT operations and business teams to resolve identified vulnerabilities and compliance issues Support the development of technical hardening standards and security baseline documents Ensure compliance of critical infrastructure, systems, applications, and cloud services<br>Reporting & Documentation<br>Prepare audit reports, compliance reports, and status updates for management and stakeholders Communicate audit findings, recommendations, and remediation plans to leadership teams Maintain clear, accurate, and complete audit documentation and evidence records Track progress of remediation efforts and monitor implementation of previous audit recommendations<br>Stakeholder Coordination & Support<br>Liaise with internal and external audit teams to support audit activities and evidence collection Collaborate with business units, HR, finance, operations, and project teams during audit and compliance reviews Support key business initiatives by identifying cybersecurity and compliance-related risks Assist in developing and delivering security awareness and compliance initiatives Perform related duties and special projects as assigned<br>Qualifications & Experience<br>Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Security, Risk Management, or a related discipline.5–8 years of experience in Information Security Governance, Risk Management, Compliance, Internal Controls, Audit, or Cybersecurity. Hands-on experience in implementing, managing, or maintaining Information Security Management Systems (ISMS) based on ISO/IEC 27001. Experience in Qatar National Information Assurance (NIA) framework implementation, compliance monitoring, control assessment, and audit readiness activities Experience in PCI-DSS compliance and certification implementation, including control assessment, gap analysis, remediation tracking, and audit support. Knowledge of Data Privacy and Protection requirements, privacy risk assessments, personal data handling controls, and regulatory compliance. Proven experience conducting information security risk assessments, risk treatment planning, and maintaining risk registers. Experience supporting or coordinating ICOFR (Internal Controls over Financial Reporting) reviews, audits, control testing, and remediation activities. Experience coordinating internal audits, external audits, certification audits, and regulatory assessments. Knowledgeable in reviewing, validating, and assessing audit evidence generated from various technology platforms, security tools, infrastructure systems, cloud services, applications, and business systems to determine control effectiveness and compliance. Experience with governance, risk, and compliance (GRC) platforms, risk management tools, and compliance monitoring solutions is an advantage. Strong analytical, documentation, report writing, communication, presentation, and stakeholder management skills. Ability to prepare executive dashboards, compliance reports, risk reports, and management presentations.<br>Technical Knowledge<br>Strong understanding of information security frameworks and standards, cybersecurity governance and risk management, vulnerability management and security assessments, cloud security technologies and controls, and identity and access management concepts. Knowledge of industry frameworks and standards, including ISO 27001 / ISO 27002, NIST, and CIS Benchmarks. Mandatory hands-on knowledge of cloud security environments, IAM and PAM technologies, DLP solutions, and enterprise productivity and collaboration platforms.<br>Preferred Certifications<br>Certified Information Systems Auditor (CISA) Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) Certified in Governance of Enterprise IT (CGEIT) Cloud security certifications (e.g., cloud security administration or governance certifications) ISO 27001 Lead Auditor or equivalent certifications<br>Skills<br>Strong analytical and problem-solving abilities Excellent audit, reporting, and documentation skills Strong stakeholder management and communication skills Ability to work effectively with cross-functional and multicultural teams Experience developing security policies, standards, and governance frameworks Strong understanding of security compliance and operational best practices
<p>We are looking for an experienced and proactive <strong>Head of Security</strong> to lead and oversee security operations across our properties. The successful candidate will be responsible for maintaining a safe and secure environment for employees, guests, clients, contractors, visitors, company assets, and properties.</p><p><br></p><p>The role requires strong leadership, operational planning, risk management, incident handling, and the ability to manage both internal and outsourced security teams.</p><p><br></p><p><strong>Responsibilities</strong></p><ul><li>Lead and oversee security operations across multiple properties and locations, including manpower deployment, shift planning, operational discipline, and performance monitoring.</li><li>Develop, implement, and maintain security policies, procedures, operational standards, and emergency response plans in line with company requirements and applicable Qatar regulations.</li><li>Manage and monitor outsourced security service providers, ensuring compliance with contractual requirements, service standards, manpower deployment, and performance expectations.</li><li>Conduct regular security, safety, hazard, and risk assessments, identify vulnerabilities, and implement corrective actions and continuous security improvements.</li><li>Monitor and lead the response to security incidents, accidents, losses, breaches, and emergencies, including investigations, reporting, crisis management, evacuation procedures, and coordination with relevant authorities.</li><li>Oversee CCTV, access control, alarm systems, electronic key systems, visitor management, patrol procedures, and other security equipment, ensuring regular inspection, testing, and maintenance.</li><li>Lead loss prevention, security training, emergency drills, special security arrangements, and stakeholder coordination, while preparing security reports, risk assessments, and management updates.</li></ul><p><br></p><p><strong>Qualifications</strong></p><ul><li>Minimum 7 years of relevant experience in security, safety, loss prevention, or a related field, including previous experience in a senior security management or supervisory role.</li><li>Proven experience managing security operations across multiple properties or locations, including outsourced security companies and large security teams.</li><li>Strong knowledge of security operations, risk assessment, loss prevention, incident investigation, emergency response, and crisis management.</li><li>Knowledge of CCTV, access control, alarm systems, and other electronic security systems, with an understanding of Qatar’s applicable security, safety, labour, and regulatory requirements.</li><li>Minimum High School Diploma or equivalent. Relevant certifications in Security, Safety, Occupational Health & Safety, First Aid, or Emergency Management will be an advantage.</li><li>Strong leadership, communication, decision-making, problem-solving, planning, organization, and people-management skills, with the ability to work under pressure and manage multiple priorities.</li><li>Strong report-writing and computer skills. Arabic and English language proficiency is preferred.</li></ul>
<p>Responsibilities</p><ul><li>Develop, implement, and maintain the organization's Information Security strategy, policies, procedures, and controls.</li><li>Establish and continuously improve the Information Security Management System (ISMS) in accordance with ISO/IEC 27001.</li><li>Ensure compliance with QCB regulations, NCSA requirements, NIST Cybersecurity Framework, PCI DSS, and other applicable regulatory standards.</li><li>Identify, assess, and manage information security and cybersecurity risks and maintain the Information Security Risk Register.</li><li>Conduct and oversee security risk assessments, vulnerability assessments, penetration testing, and control reviews.</li><li>Lead and manage information security incidents, including investigation, response, reporting, and post-incident corrective actions.</li><li>Oversee security monitoring, logging, and cybersecurity controls, including SIEM, EDR/XDR, IAM/PAM, DLP, firewalls, IDS/IPS, and WAF.</li><li>Develop and maintain information security policies, standards, procedures, and security KPIs.</li><li>Manage third-party and vendor security risks, including security assessments and compliance reviews.</li><li>Coordinate internal and external security audits and regulatory examinations.</li><li>Provide regular information security reports, risk updates, KPIs, and recommendations to senior management and the Board.</li><li>Develop and deliver information security awareness and training programs across the organization.</li><li>Ensure information security requirements are incorporated into Business Continuity and Disaster Recovery plans.</li><li>Stay updated on emerging cybersecurity threats, regulatory requirements, and industry best practices.</li></ul><p><strong>Desired Candidate Profile</strong></p><p>Qualifications</p><ul><li>Bachelor's degree in information security, Cybersecurity, Computer Science, Information Technology, or a related field, master's degree is preferred.</li><li>10 15 years of experience in IT and Information Security, with 5 7 years in a senior or leadership security role.</li><li>Experience working within financial institutions, banking, or other highly regulated environments.</li><li>Strong knowledge and practical experience with QCB regulations, NCSA requirements, ISO/IEC 27001, PCI DSS, and NIST.</li><li>CISSP certification is mandatory or strongly preferred.</li><li>Additional certifications such as CISM, CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor, or PCI DSS certifications are an advantage.</li><li>Strong understanding of cybersecurity governance, risk management, compliance, and security controls.</li><li>Hands-on knowledge of enterprise security technologies, including SIEM, EDR/XDR, IAM/PAM, DLP, firewalls, IDS/IPS, and WAF.</li><li>Experience managing security incidents, audits, penetration testing, vulnerability assessments, and third-party security risks.</li><li>Strong leadership, communication, stakeholder management, and presentation skills.</li><li>Ability to communicate effectively with senior management and Board-level stakeholders.</li><li>High level of integrity, independence, analytical thinking, and professional judgment.</li></ul>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span><u><b>Job Summary</b></u>
<br></span><p>The Assistant Security Manager is responsible to support the Security Manager in overseeing and managing security operations within an organization. This role involves assisting in the development and implementation of security policies, procedures, and protocols to safeguard personnel, assets, and facilities. Additionally, Assistant Security Managers may be responsible for supervising security staff, conducting security assessments and audits, and coordinating security training programs. They play a vital role in ensuring compliance with security regulations, addressing security breaches or incidents, and maintaining a safe and secure environment for employees, customers, and visitors. </p><br>
<br><br><u><b>Job Responsibilities 1</b></u>
<br><p>Interact with Guests as well as individuals outside the Hotel including, but not limited to law Enforcement Agencies, Government Officials, other Chief Security Officers and members of the local community</p><br> <p>Direct and coordinate the activities of all security personnel</p><br> <p>Ensure that all Hotel areas and property are adequately secured at all times</p><br> <p>Coordinate outside police agencies in the investigation and handling of crimes, accidents, etc., involving the hotel, its colleagues, or guests</p><br> <p>Prepares daily incident reports, requisitions, and other inter office memos</p><br> <p>Ensure that all allegations of the crime and other incidents are investigated and recorded</p><br> <p>Prepare annual Security goals</p><br> <p>Liaise with department heads to ensure Hotel staff are adhering to established security procedures</p><br> <p>Become a member of the appropriate Hotel Security Officers Association</p><br> <p>Establishes comprehensive key controls</p><br> <p>Responsible for found property deposited with Security for safekeeping</p><br>
<br><br><u><b>Job Responsibilities 2</b></u>
<br><br><b>Additional Responsibilities 3</b>
<br><br><u><b>Job Knowledge & Skills</b></u>
<br><p>Comprehensive knowledge of security protocols, procedures, and best practices to effectively enforce safety and security measures.</p><br>
<p>Proficiency in operating surveillance cameras, alarm systems, and access control technology to monitor and identify security threats.</p><br>
<p> Ability to remain calm and take decisive action during emergencies, including medical incidents, fires, or security breaches, to ensure the safety of individuals and property.</p><br>
<p>Strong verbal and written communication skills to interact effectively with visitors, employees, and law enforcement personnel, and to prepare accurate incident reports.</p><br>
<p> Capacity to assess security risks, identify vulnerabilities, and implement appropriate solutions to mitigate threats and enhance overall security measures.</p><br><br><br><u><b>Job Experience</b></u>
<br><p>Minimum 8 year(s) working experience, 5 year(s) relevant working experience, 2 year (s) GCC is a plus</p><br><br><br><u><b>Competencies</b></u>
<br>Leadership_321977503<br>Resilience<br>Quality_321977507<br>Safety Management L3<br>Guest Relations L3<br>Regulatory Compliance L3<br>Hotel Management Standards and Procedures L3<br>Security Management L3<br>Agility<br>AI Fluency<br><br><br><u><b>Education</b></u>
<br>Diploma in any Related Technical Certificates<br><br><br><br>
</div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span><u><b>Job Summary</b></u>
<br></span><p>The Assistant Security Manager is responsible to support the Security Manager in overseeing and managing security operations within an organization. This role involves assisting in the development and implementation of security policies, procedures, and protocols to safeguard personnel, assets, and facilities. Additionally, Assistant Security Managers may be responsible for supervising security staff, conducting security assessments and audits, and coordinating security training programs. They play a vital role in ensuring compliance with security regulations, addressing security breaches or incidents, and maintaining a safe and secure environment for employees, customers, and visitors. </p><br>
<br><br><u><b>Job Responsibilities 1</b></u>
<br><p>Interact with Guests as well as individuals outside the Hotel including, but not limited to law Enforcement Agencies, Government Officials, other Chief Security Officers and members of the local community</p><br> <p>Direct and coordinate the activities of all security personnel</p><br> <p>Ensure that all Hotel areas and property are adequately secured at all times</p><br> <p>Coordinate outside police agencies in the investigation and handling of crimes, accidents, etc., involving the hotel, its colleagues, or guests</p><br> <p>Prepares daily incident reports, requisitions, and other inter office memos</p><br> <p>Ensure that all allegations of the crime and other incidents are investigated and recorded</p><br> <p>Prepare annual Security goals</p><br> <p>Liaise with department heads to ensure Hotel staff are adhering to established security procedures</p><br> <p>Become a member of the appropriate Hotel Security Officers Association</p><br> <p>Establishes comprehensive key controls</p><br> <p>Responsible for found property deposited with Security for safekeeping</p><br>
<br><br><u><b>Job Responsibilities 2</b></u>
<br><br><b>Additional Responsibilities 3</b>
<br><br><u><b>Job Knowledge & Skills</b></u>
<br><p>Comprehensive knowledge of security protocols, procedures, and best practices to effectively enforce safety and security measures.</p><br>
<p>Proficiency in operating surveillance cameras, alarm systems, and access control technology to monitor and identify security threats.</p><br>
<p> Ability to remain calm and take decisive action during emergencies, including medical incidents, fires, or security breaches, to ensure the safety of individuals and property.</p><br>
<p>Strong verbal and written communication skills to interact effectively with visitors, employees, and law enforcement personnel, and to prepare accurate incident reports.</p><br>
<p> Capacity to assess security risks, identify vulnerabilities, and implement appropriate solutions to mitigate threats and enhance overall security measures.</p><br><br><br><u><b>Job Experience</b></u>
<br><p>Minimum 8 year(s) working experience, 5 year(s) relevant working experience, 2 year (s) GCC is a plus</p><br><br><br><u><b>Competencies</b></u>
<br>Leadership_321977503<br>Resilience<br>Quality_321977507<br>Safety Management L3<br>Guest Relations L3<br>Regulatory Compliance L3<br>Hotel Management Standards and Procedures L3<br>Security Management L3<br>Agility<br>AI Fluency<br><br><br><u><b>Education</b></u>
<br>Diploma in any Related Technical Certificates<br><br><br><br>
</div>
The Information Security Engineer will<br><br>focus on ensuring the organization’s applications and data is secure and built<br><br>according to best security standards. This role will be the subject matter<br><br>expert on building secure code, application security, vulnerability testing,<br><br>and providing security validation to the organization’s environments.<br><br>Key Roles & Responsibilities<br><br>Perform scheduled penetration testing of the company’s applications Perform white, gray and black box security assessments. Support the organization, JVs and Subsidiaries in implementing Secure Software development lifecycle. Perform Mobile Services security Assessments. Support the organizations’ environment monitoring by using available tools or help build internal tools to enable advanced threat detection and response. Conduct Security Vulnerability Assessments and impact assessment on company’s electronic assets. Perform Security Assessments on ERP and other on-premise solutions.<br><br>Requirements<br><br>Skills,<br><br>Knowledge And Behaviors<br><br>Ability to lead direct and indirect resources Ability to communicate technical challenges to non-technical audiences Ability to quantify risk and impact vectors Certified Ethical Hacker OCSP level of technical expertise Strong Scripting capability Strong ISO 27000 understanding Strong Application security background Strong Infrastructure security Background Strong experience in open source security tools<br><br>Qualifications & Experience<br><br>Security Certification focusing on offensive or defensive practices Bachelor’s degree in Information Security or Computer Engineering10 + years in cybersecurity field System, network and/or application background<br><br>Preferred Experience<br><br>Product development experience