Security inspector Jobs in Qatar
4070 Jobs Found
The Senior Cybersecurity Certification Consultant is responsible for leading and executing certification assessment activities to evaluate organizations’ compliance with national and international cybersecurity and information security standards. The role ensures fair, consistent, and objective certification decisions while overseeing assessment teams, managing certification cases, and maintaining the integrity of the certification process. It also contributes to developing certification methodologies, tools, and frameworks aligned with regulatory and accreditation requirements.<br><br>Key Responsibilities<br><br> Delivery of certification services Senior Information Security / Cyber Security Assessor is responsible for the day to day certification application assessment review, validation Manage the team and assign the cases Maintain detailed and organize records of the certification process, ensuring accuracy and completeness Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across certification activities Review different organizations’ Information Security / Cyber Security compliance to national or international standards and best practices in Information Security / Cyber Security Evaluate the design and operating effectiveness of Information Security / Cyber Security controls Document observations/findings in such a manner that they are clearly understandable and traceable and are based on objective evidence Develop and maintain certification procedures and required tools based on National Information Security Compliance framework Maintain impartiality, confidentiality and to declare any potential conflicts of interest that might jeopardize an objective assessment as required Develop measurement and compliance mechanisms & tools to monitor improvements Provide a recommendation on the outcome of an assessment Stay up to date with the latest developments in security, emerging threats, and evolving technology to ensure the certification process remains relevant Conduct efficient and effective Cyber Security risk assessments and Information Security / Cyber Security audit procedures Develop and deliver internal training and workshop to upscale and build Information Security / Cyber Security, compliance, assurance and audit capabilities within the team. Manage the external communication during the audit: from the application till the issue of decision<br><br>Requirements<br><br>Education & Experience<br><br>Bachelor’s degree in Information Technology, Computer Information Systems, Cyber Security, or equivalent. Minimum 20 years of professional experience in IT / Information Security / Cyber Security. At least 4 years of experience as a senior auditor, assessor, or in cybersecurity risk/security management roles. Experience in cybersecurity consulting or implementation aligned with national/international standards is an advantage.<br><br>Certifications (Preferred)<br><br>CISSP, CISA, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or equivalent certifications.<br><br>Technical Skills<br><br>Strong knowledge of cybersecurity risk assessment and audit methodologies. Expertise in security frameworks and standards (ISO 27001, NIST, NIA, CSF, etc.). Understanding of certification and accreditation standards (ISO/IEC 17021, 17024, 17065, 17006, ISO 19011, ISA, ITAF). Hands-on experience in information security auditing and assurance. Strong awareness of evolving cybersecurity threats and technologies.<br><br>Core Skills<br><br>Excellent analytical, evaluation, and problem-solving abilities. Strong technical report writing and documentation skills. Ability to interpret compliance frameworks and certification criteria objectively. Excellent communication and presentation skills in English (written and verbal). Experience delivering training and workshops across government and private sectors.<br><br>Behavioral Competencies<br><br>High attention to detail and ability to work under pressure and tight deadlines. Strong interpersonal and stakeholder management skills. Ability to work independently with high levels of professionalism and integrity. Capability to manage multiple assignments and cross-functional teams effectively. Commitment to impartiality, confidentiality, and ethical assessment practices.<br><br>Language: English (required)<br><br>Availability: As soon as possible<br><br>The contract duration is 12 months, with the possibility of extension based on departmental requirements.
The Senior Cybersecurity Certification Consultant is responsible for leading and executing certification assessment activities to evaluate organizations’ compliance with national and international cybersecurity and information security standards. The role ensures fair, consistent, and objective certification decisions while overseeing assessment teams, managing certification cases, and maintaining the integrity of the certification process. It also contributes to developing certification methodologies, tools, and frameworks aligned with regulatory and accreditation requirements.<br><br>Key Responsibilities<br><br> Delivery of certification services Senior Information Security / Cyber Security Assessor is responsible for the day to day certification application assessment review, validation Manage the team and assign the cases Maintain detailed and organize records of the certification process, ensuring accuracy and completeness Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across certification activities Review different organizations’ Information Security / Cyber Security compliance to national or international standards and best practices in Information Security / Cyber Security Evaluate the design and operating effectiveness of Information Security / Cyber Security controls Document observations/findings in such a manner that they are clearly understandable and traceable and are based on objective evidence Develop and maintain certification procedures and required tools based on National Information Security Compliance framework Maintain impartiality, confidentiality and to declare any potential conflicts of interest that might jeopardize an objective assessment as required Develop measurement and compliance mechanisms & tools to monitor improvements Provide a recommendation on the outcome of an assessment Stay up to date with the latest developments in security, emerging threats, and evolving technology to ensure the certification process remains relevant Conduct efficient and effective Cyber Security risk assessments and Information Security / Cyber Security audit procedures Develop and deliver internal training and workshop to upscale and build Information Security / Cyber Security, compliance, assurance and audit capabilities within the team. Manage the external communication during the audit: from the application till the issue of decision<br><br>Requirements<br><br>Education & Experience<br><br>Bachelor’s degree in Information Technology, Computer Information Systems, Cyber Security, or equivalent. Minimum 20 years of professional experience in IT / Information Security / Cyber Security. At least 4 years of experience as a senior auditor, assessor, or in cybersecurity risk/security management roles. Experience in cybersecurity consulting or implementation aligned with national/international standards is an advantage.<br><br>Certifications (Preferred)<br><br>CISSP, CISA, CISM, CRISC, ISO 27001 Lead Auditor/Implementer, or equivalent certifications.<br><br>Technical Skills<br><br>Strong knowledge of cybersecurity risk assessment and audit methodologies. Expertise in security frameworks and standards (ISO 27001, NIST, NIA, CSF, etc.). Understanding of certification and accreditation standards (ISO/IEC 17021, 17024, 17065, 17006, ISO 19011, ISA, ITAF). Hands-on experience in information security auditing and assurance. Strong awareness of evolving cybersecurity threats and technologies.<br><br>Core Skills<br><br>Excellent analytical, evaluation, and problem-solving abilities. Strong technical report writing and documentation skills. Ability to interpret compliance frameworks and certification criteria objectively. Excellent communication and presentation skills in English (written and verbal). Experience delivering training and workshops across government and private sectors.<br><br>Behavioral Competencies<br><br>High attention to detail and ability to work under pressure and tight deadlines. Strong interpersonal and stakeholder management skills. Ability to work independently with high levels of professionalism and integrity. Capability to manage multiple assignments and cross-functional teams effectively. Commitment to impartiality, confidentiality, and ethical assessment practices.<br><br>Language: English (required)<br><br>Availability: As soon as possible<br><br>The contract duration is 12 months, with the possibility of extension based on departmental requirements.
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<ul>
<li>Commissions the preparation and the implementation of necessary operational security software updates, firewall installation, hardware additions, and any authorized technical changes related to the security functions to ensure compliance both with internal security policies etc. and applicable laws and regulations required security levels.</li>
<li>Design and manage processes for detection, investigation, correction, and/or prosecution of operational security breaches, violations, and incidents.</li>
<li>Benchmark, analyze report on, and make recommendations for the improvement of Operational Technology (OT) security infrastructure.</li>
<li>Works with management to ensure that as new equipment, facilities, services, and systems are installed that the OT security issues are addressed.</li>
<li>Typically, a background in technical Operational Technology (OT) roles such as architecture, security program development or operations, with a clear and abiding interest in operational security.</li>
<li>Liaison with and offers technical direction to related operational security governance functions (such as Physical Security/Facilities, Risk Management, Legal and Compliance) plus senior and middle managers throughout the organization as necessary, on information security matters such as routine security activities plus emerging security risks and control technologies.</li>
<li>Plan, implement and upgrade security measures and controls.</li>
<li>Protect digital files and operational security systems against unauthorized access, modification, or destruction.</li>
<li>Maintain data and monitor/review security access authorizations.</li>
<li>Manage network, intrusion detection and prevention systems.</li>
<li>Work out on the security tools such as security asset inventory management and risk management reporting to security information and event management system (SIEM).</li>
<li>Define, implement, and maintain corporate security manuals, policies, procedures & instructions.</li>
<li>Coordinate further security plans, awareness received from vendors and take required actions.</li>
<li>Security assessments of network infrastructure, hosts and applications.</li>
<li>Work out on ICS security related audit findings and maintain corrective actions.</li>
<li>Download, validate and apply the latest Antivirus DAT file to AV server and ensure published to all ICS machines by continuously monitor the AV server dashboard.</li>
<li>Asset identification, monitoring and analysis using supportive tools (IPS, firewall log, system events and antivirus reports.</li>
<li>ICS Firewall Events log, DNS, Router, and switches Events log analysis.</li>
<li>Validation and deployment of firmware and software updates, deactivate of unnecessary software's or access.</li>
<li>Define and implement backup schedule for all ICS assets, System configuration backups, Machines image backups, Router and switches backups, FW backups.</li>
<li>Manage User accounts ICS, network, and security equipment.</li>
<li>Support Project execution team to integrate new Operational Technology (OT) system in Plant security framework.</li>
<li>Work out on Audit findings and observations.</li>
<li>Work out with ICS modifications as requested.</li>
<li>Collect and archive system logs, events, change logs, failure events etc. To support audit and forensic analysis.</li>
<li>Ensure that all implementation activities are complied with published ICS policies, instructions, procedures,</li>
</ul><br><ul>
<li>Bachelor's Degree in Information security Technology, Computer Science or Electronic/Electrical Engineer.</li>
<li>Must be ICS certified from SANS, however following certificates will be great additional advantage for the candidate: - <ul>
<li>GIAC GICSP (Global Industrial Cybersecurity Professional).</li>
<li>ISA CAP (Certified Automation Professional).</li>
<li>Cybersecurity for Automation, Control, and SCADA Systems (ISA-99/IEC-62443) - ISA</li>
<li>Advanced SCADA Security - Red Tiger/ any other vendor.</li>
<li>Industrial Cybersecurity for OPC - Matrikon/any other vendor.</li>
<li>OPC-UA Hands-on Training Level-3 - OPCTI.</li>
</ul>
</li>
<li>3-5 years at least of field experience in OT Cybersecurity domain in Oil & gas & petrochemical industry.</li>
<li>Excellent knowledge of common IT/OT ICS specialization areas related to PLC's, DCS's, PDCS, Firewalls, networks, and switches.</li>
<li>Knowledge of international & national standards frameworks such as ISA99, IEC62433, IEC61511, IEC62351, IEC62591 ISO27001, 27002, 27005 Compliance regulations.</li>
<li>Strong understanding of core operations and of the information security requirements.</li>
<li>Extensive knowledge of several ICS DCS/PDCS/PLC/ESD/Servers, routers, switches & firewalls technologies within several OEM technologies such as, Siemens, HIMA, TRICONEX, HONEYWELL, GE, Allan Bradley, CISCO, MacAfee.</li>
</ul><br><ul>
<li><strong>Salary:</strong><ul>
<li>Monthly Rate in QAR Plus allowance</li>
</ul></li>
<li><strong>Work Schedule:</strong><ul>
<li>8 Hours / 5 Days</li>
</ul></li>
</ul>
<ul>
<li><strong>Duration:</strong>
<ul>
<li>2 years with possible extension</li>
</ul>
</li>
<li><strong>Location:</strong>
<ul>
<li>Qatar</li>
</ul>
</li>
</ul> </div>
The Senior Common Criteria Certification Specialist is responsible for leading and executing cybersecurity product and system certification activities in alignment with internationally recognized standards, particularly Common Criteria. The role involves evaluating security documentation, conducting technical risk assessments, overseeing testing processes, and providing expert recommendations on certification decisions (e.g., EAL levels).<br><br>This position plays a critical role in ensuring the integrity, consistency, and credibility of the certification process, while collaborating with developers, evaluators, and regulatory stakeholders. The specialist also contributes to the development of certification policies and stays current with emerging cybersecurity threats, technologies, and standards.<br><br>Key Responsibilities<br><br>Senior Certifier is responsible for the conduct of the day to day certification, validation, oversight, certificate maintenance and mutual recognition with the common criteria standards. Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across all evaluation and certification activities;Possess a deep understanding of Common Criteria standards, Protection Profiles, Security Targets, Evaluation Assurance Levels (EALs), and related documentation Provide guidance and mentorship to CB team members Certifiers and evaluators, ensuring their understanding of the certification process and helping them with complex evaluations. Lead and oversee the review and assessment of documentation submitted by product developers, including Security Target documents, design specifications, and test plans. Conduct advanced technical risk assessments, identifying potential security weaknesses or flaws in products or systems and providing expert guidance for mitigation. Oversee and manage the testing phase, ensuring that security testing is conducted rigorously and accurately. Conduct of day-to-day certification, certificate maintenance and mutual recognition projects and in compliance with scheme documentations. Assisting with the development of policies, standards, procedures and guidelines. Make recommendations regarding certification at specific Evaluation Assurance Levels (EALs) based on extensive evaluation expertise and knowledge of the certification process. Stay up-to-date with the latest developments in security, emerging threats, and evolving technology to ensure the certification process remains relevant. Collaborate with stakeholders, such as developers, evaluators, and national certification authorities, to ensure a consistent and accurate evaluation process.<br><br>Requirements<br><br>A university degree-level qualification in IT, information security or a related field. ideally with a focus on security domains. Certification from a recognized Common Criteria certification body and previous experience as a Certifier is desired IT Security Overview Training and certification Common Criteria for IT Security Evaluation Training and certification Minimum 8 years Minimum 4 years of work experience as a Senior IT / Information Security / Cyber Security Auditor and/or Risk Management and/or Cyber Security/Information Security Management. Proficiency in Arabic and English (spoken and written) is preferred<br><br>General<br><br>Other Required Qualifications:<br><br>Analytical and problem-solving skills Proven experience in IT and Information Security Assessment Common Criteria for IT Security Evaluation Training Experience in Risk Assessment and management. Should have hands on experience in information security Understanding of ISO27001 certification audit requirements Excellent communication, documentation, and report-writing skills. In-depth knowledge of security testing methodologies and tools. Have analytical & assessment experience of formal schemes and can assess a situation in a fair and objective manner in order to arrive at a firm conclusion. Have training, workshops planning and delivery experience across Government & private sector.<br><br>Technical<br><br>Experience in Risk Assessment and management including audit methodologies and risk assessment methodologies. Understanding of NIA controls and implementation requirements Proficiency in security frameworks and standards like NIST, ISO27001, NIA. Strong awareness of Information Security / Cyber Security trends.<br><br>Behavioural<br><br>Ability to multitask and work effectively with multiple project teams, sponsors, and customers. Ability to pay close attention to detail, meet deadlines and work under pressure. Interpersonal skills Work autonomously with a high degree of enthusiasm<br><br>Specific<br><br>Excellent technical report writing skills. Have capabilities to understand and interpret the Certification Criteria (ISO/ IEC 17021, ISO/ IEC 17024, ISO/ IEC 27006 and ISO/IEC 17065). Knowledge of auditing and information assurance standards like ISA, ITAF, ISO17021, ISO19011. Proficiency in security frameworks and standards like, ISO27001, NIA, CSF Q2022. Familiarity with third-party audit, Certification and Information Security / Cyber Security audits. Proven, hands on, experience in Information Security Audit or Information Security Management.
The Senior Common Criteria Certification Specialist is responsible for leading and executing cybersecurity product and system certification activities in alignment with internationally recognized standards, particularly Common Criteria. The role involves evaluating security documentation, conducting technical risk assessments, overseeing testing processes, and providing expert recommendations on certification decisions (e.g., EAL levels).<br><br>This position plays a critical role in ensuring the integrity, consistency, and credibility of the certification process, while collaborating with developers, evaluators, and regulatory stakeholders. The specialist also contributes to the development of certification policies and stays current with emerging cybersecurity threats, technologies, and standards.<br><br>Key Responsibilities<br><br>Senior Certifier is responsible for the conduct of the day to day certification, validation, oversight, certificate maintenance and mutual recognition with the common criteria standards. Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across all evaluation and certification activities;Possess a deep understanding of Common Criteria standards, Protection Profiles, Security Targets, Evaluation Assurance Levels (EALs), and related documentation Provide guidance and mentorship to CB team members Certifiers and evaluators, ensuring their understanding of the certification process and helping them with complex evaluations. Lead and oversee the review and assessment of documentation submitted by product developers, including Security Target documents, design specifications, and test plans. Conduct advanced technical risk assessments, identifying potential security weaknesses or flaws in products or systems and providing expert guidance for mitigation. Oversee and manage the testing phase, ensuring that security testing is conducted rigorously and accurately. Conduct of day-to-day certification, certificate maintenance and mutual recognition projects and in compliance with scheme documentations. Assisting with the development of policies, standards, procedures and guidelines. Make recommendations regarding certification at specific Evaluation Assurance Levels (EALs) based on extensive evaluation expertise and knowledge of the certification process. Stay up-to-date with the latest developments in security, emerging threats, and evolving technology to ensure the certification process remains relevant. Collaborate with stakeholders, such as developers, evaluators, and national certification authorities, to ensure a consistent and accurate evaluation process.<br><br>Requirements<br><br>A university degree-level qualification in IT, information security or a related field. ideally with a focus on security domains. Certification from a recognized Common Criteria certification body and previous experience as a Certifier is desired IT Security Overview Training and certification Common Criteria for IT Security Evaluation Training and certification Minimum 8 years Minimum 4 years of work experience as a Senior IT / Information Security / Cyber Security Auditor and/or Risk Management and/or Cyber Security/Information Security Management. Proficiency in Arabic and English (spoken and written) is preferred<br><br>General<br><br>Other Required Qualifications:<br><br>Analytical and problem-solving skills Proven experience in IT and Information Security Assessment Common Criteria for IT Security Evaluation Training Experience in Risk Assessment and management. Should have hands on experience in information security Understanding of ISO27001 certification audit requirements Excellent communication, documentation, and report-writing skills. In-depth knowledge of security testing methodologies and tools. Have analytical & assessment experience of formal schemes and can assess a situation in a fair and objective manner in order to arrive at a firm conclusion. Have training, workshops planning and delivery experience across Government & private sector.<br><br>Technical<br><br>Experience in Risk Assessment and management including audit methodologies and risk assessment methodologies. Understanding of NIA controls and implementation requirements Proficiency in security frameworks and standards like NIST, ISO27001, NIA. Strong awareness of Information Security / Cyber Security trends.<br><br>Behavioural<br><br>Ability to multitask and work effectively with multiple project teams, sponsors, and customers. Ability to pay close attention to detail, meet deadlines and work under pressure. Interpersonal skills Work autonomously with a high degree of enthusiasm<br><br>Specific<br><br>Excellent technical report writing skills. Have capabilities to understand and interpret the Certification Criteria (ISO/ IEC 17021, ISO/ IEC 17024, ISO/ IEC 27006 and ISO/IEC 17065). Knowledge of auditing and information assurance standards like ISA, ITAF, ISO17021, ISO19011. Proficiency in security frameworks and standards like, ISO27001, NIA, CSF Q2022. Familiarity with third-party audit, Certification and Information Security / Cyber Security audits. Proven, hands on, experience in Information Security Audit or Information Security Management.
<p>ob Overview:</p><p>The Senior Information Security Specialist is responsible for overseeing the governance,</p><p>risk management, and compliance aspects of information security within the organization.</p><p>This role involves developing and implementing security strategies, ensuring adherence to</p><p>regulatory requirements, and managing risks to safeguard the organization's information</p><p>assets.</p><p>Key Responsibilities:</p><ul><li><p>Develop and maintain information security governance frameworks and policies aligned with organizational goals and regulatory requirements.</p></li><li><p>Integrate security governance practices into the organization’s risk management and compliance strategies.</p></li><li><p>Develop, implement, and review information security policies and procedures to ensure they meet regulatory requirements and industry best practices.</p></li><li><p>Ensure effective communication and adherence to these policies across the organization.</p></li><li><p>Conduct regular risk assessments to identify, assess, and mitigate information security risks.</p></li><li><p>Ensure compliance with local and international information security regulations and standards (e.g., Qatar National Information Assurance</p></li><li><p>Policy, ISO/IEC 27001, and Qatar Cybersecurity Framework CSF).</p></li><li><p>Monitor changes in regulations and update policies and procedures as needed.</p></li><li><p>Manage internal and external audits related to information security and compliance.</p></li><li><p>Prepare and present detailed reports on security status, risk assessments, and audit findings to senior management and regulatory bodies.</p></li><li><p>Support information security incident management from a compliance and risk perspective, including documentation, reporting, and adherence to incident response procedures.</p></li><li><p>Develop and deliver training and awareness programs focused on information security governance and risk management.</p></li><li><p>Act as a liaison between IT, legal, compliance, and business units to ensure alignment on security and risk management initiatives.</p></li><li><p>Address information security concerns raised by internal and external stakeholders.</p></li></ul><p><strong>Desired Candidate Profile</strong></p><p>Qualifications:</p><ul><li><p>Education:</p></li><li><p>Bachelor’s degree in Information Security, Cybersecurity, or a related field.</p></li><li><p>Advanced degrees or certifications (e.g., CISSP, CISM, CRISC, CISA) are highly desirable.</p></li><li><p>Experience:</p></li><li><p>Minimum of 8 years of experience in information security with a focus on governance, risk management, and compliance.</p></li><li><p>Proven experience in developing and implementing security frameworks and managing compliance programs.</p></li><li><p>Skills:</p></li><li><p>In-depth knowledge of information security principles, practices, and regulations.</p></li><li><p>Experience with security frameworks and standards (e.g., NIA, Qatar CSF, ISO/IEC 27001, NIST).</p></li><li><p>Strong analytical, organizational, and problem-solving skills.</p></li><li><p>Excellent communication skills, with the ability to effectively convey security concepts to various stakeholders.</p></li><li><p>Proficiency with compliance and risk management tools is advantageous.</p></li><li><p>Advanced level of Arabic and English language. Bi-lingual is preferred.</p></li></ul>
<strong>Job Description<br><br></strong>We are seeking a skilled <strong>Application Security Senior Engineer </strong>to join our Cybersecurity Practice. In this role, you will work closely with our application security, development, and QA teams to secure our clients’ applications across their entire lifecycle. You will conduct security testing, perform penetration tests, and assess vulnerabilities across web, mobile, API applications.<br><br>Your responsibilities will span application penetration testing, automated security scanning (SAST, DAST, SCA), threat modelling, secure code review, and developer enablement. You will embed security best practices throughout the software development lifecycle and ensure that applications are designed and built with robust security controls.<br><br>You will collaborate with development and DevOps teams to integrate security into CI/CD pipelines, triage and validate findings, and provide clear, actionable remediation guidance. The role requires hands-on technical expertise, strong analytical skills, and the ability to translate complex security findings into practical fixes that developers can implement.<br><br><strong>Responsibilities<br><br></strong><ul><li>Penetration Testing:Conduct penetration tests on web applications, mobile applications, APIs, and thick-client applications. Prepare detailed reports with clear risk ratings and actionable remediation recommendations.</li><li>Security Scanning:Implement, tune, and manage automated security scanning tools (SAST, DAST, SCA) to continuously identify vulnerabilities in code, configurations, and third-party dependencies across all application types.</li><li>Threat Modelling:Perform threat modelling to identify potential security risks and attack surfaces associated with applications early in the design process, and provide guidance on mitigating these risks.</li><li>Secure Code Review:Review application source code for security vulnerabilities across multiple platforms and languages, and offer practical, developer-friendly recommendations for remediation.</li><li>DevSecOps Integration:Integrate security testing and controls into CI/CD pipelines, enabling continuous and automated security validation as part of the development workflow.</li><li>Training & Awareness:Develop and deliver secure coding training sessions and workshops to raise application security awareness among development teams and other stakeholders.</li><li>Tool Evaluation:Assess and recommend tools and technologies to enhance application security testing and monitoring capabilities across various platforms.</li><li>Documentation:Create and maintain comprehensive documentation related to security assessments, vulnerability management, and application security standards and policies.<br><br></li></ul><strong>Qualifications<br><br></strong><ul><li>Education: Bachelor’s / college degree in Computer Science, Information Security, or a related field.</li><li>Experience: At least 4 years of experience in application security, secure software development, penetration testing, or a closely related field.</li><li>Certifications: Relevant professional certifications are highly desirable. These may include, but are not limited to:</li><ul><li>OffSec certifications (e.g., OSWA, OSWE)</li><li>eLearnSecurity (e.g., eWPT, eWPTX)</li><li>GIAC / SANS (e.g., SEC542, GWAPT)</li><li>BCSP or other application security certifications.</li></ul><li>Technical Skills: Proficiency with security testing tools such as Burp Suite (required), and familiarity with Snyk, HCL AppScan, Fority, and Postman (preferred). Strong understanding of secure coding practices and hands-on experience with at least one programming language. Familiarity with DevSecOps practices and CI/CD pipelines is preferred.</li><li>Knowledge: In-depth knowledge of application security principles and practices, with strong familiarity with security frameworks and guidelines (e.g., OWASP Top 10, ASVS, MASVS, WSTG, MSTG). Understanding of common vulnerability classes, exploitation techniques, and remediation strategies. Knowledge of Qatar National Information Assurance (NIA) is a plus.</li></ul>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
About the job Security Specialist "End Point, DLP and Data mgmt. (12 month contract)
<p>Security specialist Role Description- Endpoint Security and Data Leak Protection Analyst</p><br>
<p>Primary purpose of the role The Security specialist is responsible for the administration of the organization's information and data security policies and practices to ensure authorized users can readily access information and that the information is protected in terms of confidentiality, integrity and availability. Well follow security best practices guideline. In this role, need to handle all responsibility as following mentioned.</p><br>
<p>* Service Management and Service Operation</p><br>
<p>Drafts and maintains the policy, standards, procedures, and documentation for security. Monitors the application and compliance of security operations procedures and reviews information systems for actual or potential breaches in security. Ensures that all identified breaches in security are promptly and thoroughly investigated. Ensures that any system changes required to maintain security are implemented. Ensures that security records are accurate and complete.</p><br>
<p>* Strategy & Architecture and Information Strategy</p><br>
<p>Obtains and acts on vulnerability information and conducts security risk assessments for business applications and computer installations; provides authoritative advice and guidance on security strategies to manage the identified risk. Investigates major breaches of security and recommends appropriate control improvements. Interprets security policy and contributes to development of standards and guidelines that comply with this. Performs risk assessment, business impact analysis and accreditation for all major information systems within the organization. Ensures proportionate response to vulnerability information, including appropriate use of forensics.</p><br>
<p>* Plan and priorities, Think and Solve Problems</p><br>
<p>* Consider future aims and goals of the team/unit and organization when prioritizing own and others' work</p><br>
<p>* Initiate, priorities, consult on and develop team/unit goals, strategies, and plans</p><br>
<p>* Anticipate and assess the impact of changes, such as government policy/economic conditions, on team/unit objectives and initiate appropriate responses</p><br>
<p>* Ensure current work plans and activities support and are consistent with organizational change initiatives</p><br>
<p>* Evaluate achievements and adjust future accordingly</p><br>
<p>* Technology</p><br>
<p>* Demonstrate a sound understanding of technology relevant to the work unit, and identify and select the most appropriate technology for assigned tasks</p><br>
<p>* Identify opportunities to use a broad range of communications technologies to deliver effective messages</p><br>
<p>* Understand, act on and monitor compliance with information and communications security and use policies</p><br>
<p>* Identify ways to leverage the value of technology to achieve team/unit outcomes, using the existing technology of the business</p><br>
<p>* Support compliance with the records, information, and knowledge management requirements of the organization</p><br>
<p>* Key accountabilities and Responsibilities</p><br>
<p>* Develop, implement, and manage security policies and protocols for endpoint devices including desktops, laptops, mobile devices, and servers.</p><br>
<p>* Technical hands-on experience with endpoint security</p><br>
<p>* Understanding of operating system, networking protocols, security and Internet environments</p><br>
<p>* Experience with systems installation, configuration and administration of operating systems and applications</p><br>
<p>* Experience installing, configuring and integrating a security environment</p><br>
<p>* Experience using application firewalls, SIEM, IDS/IPS etc.</p><br>
<p>* Experience with common enterprise desktop software deployment methodologies</p><br>
<p>* Design and enforce strategies to prevent the unauthorized transmission of sensitive information. Monitor and analyze data flows to identify and mitigate potential data breaches.</p><br>
<p>* Act as a first responder to security incidents involving endpoint devices and data leaks. Conduct thorough investigations, document findings, and recommend remediation actions.</p><br>
<p>* Continuously monitor security threats and vulnerabilities related to endpoints. Stay</p><br>
<p>updated on the latest security trends and threat intelligence to proactively protect the</p><br>
<p>organization.</p><br>
<p>* Collaborate with IT and compliance teams to develop and maintain endpoint security</p><br>
<p>policies, standards, and guidelines. Ensure compliance with industry regulations and best</p><br>
<p>practices.</p><br>
<p>* Manage and optimize security tools and technologies such as antivirus software, EDR, XDR, encryption solutions, and DLP systems. Ensure they are effectively configured and updated.</p><br>
<p>* Generate regular reports on the status of endpoint security and data leak prevention efforts. Provide insights and recommendations based on analysis and findings.</p><br>
<p>* Experience with data analysis and data quality assessment techniques</p><br>
<p>* Possesses knowledge of data lifecycle activities such as data definitions, data lineage (data life cycle that includes the data's origins, what happens and where it moves over time) and data quality</p><br>
<p>* Understands how data is used within business processes and its impact on desired business process outcomes</p><br>
<p>* Experience with data analysis and data quality assessment techniques</p><br>
<p>* Possesses knowledge of data lifecycle activities such as data definitions, data lineage and data quality</p><br>
<p>* Responsible for conducting vulnerability assessments and penetration tests to identify</p><br>
<p>security weaknesses, evaluate risks, and recommend remediation measures.</p><br>
<p>* Following Products key responsibilities well know best practice security</p><br>
<p>* Minimum of 5-6 years of experience in cybersecurity, preferably within a SOC</p><br>
<p>environment.</p><br>
<p>* Experience in incident response, threat hunting, DLP, and vulnerability management.</p><br>
<p>* Hands-on experience with Endpoint security monitoring and DLP analysis tools.</p><br>
<p>* Experience with regulatory and compliance frameworks such as GDPR, HIPAA, NIA,</p><br>
<p>Qatar 2022 CSF, ISO 27001 is a plus.</p><br>
<p>* Strong knowledge of endpoint security solutions, DLP technologies, and antivirus software. Proficiency in security incident response and threat analysis.</p><br>
<p>* Excellent analytical and problem-solving skills. Ability to analyze complex security issues and develop effective solutions.</p><br>
<p>* High attention to detail to ensure accurate monitoring, analysis, and reporting.</p><br>
<p>* Strong verbal and written communication skills. Ability to clearly articulate security</p><br>
<p>concepts to technical and non-technical audiences.</p><br>
<p>* Ability to work collaboratively with cross-functional teams and demonstrate a proactive</p><br>
<p>approach to security challenges.</p><br>
<p>* Proven work experience with Microsoft Antivirus, Microsoft Defender XDR, Endgame EDR, Microsoft DLP, Microsoft Purview, Microsoft Insider Risk Management and Microsoft Priva is a must.</p><br>
<p>* Work experience with Vulnerability scanners like Tenable, Burp suite etc.</p><br>
<p>* Should have knowledge of data privacy and data protection.</p><br>
<br>
<br> </div>
Location: Doha, Qatar | <strong><em>Practice Area</em></strong>: Technology & Engineering | Type: Permanent<br><br><strong>The Role<br><br></strong>Capco is looking for an AI Security Consultant to help our clients identify, assess, and manage security risks associated with AI technologies and AI-enabled solutions. You’ll work across data, security, technology, risk, and business teams to embed appropriate security controls throughout the lifecycle of AI systems.<br><br>This is an opportunity to work at the intersection of AI, data, and cybersecurity within financial services, helping clients adopt AI securely while protecting sensitive information, strengthening governance, and managing emerging security risks.<br><br><strong>What You’ll Do<br><br></strong><ul><li>Assess security risks associated with AI systems, models, data pipelines, and supporting technology environments.</li><li>Conduct AI security assessments and secure AI architecture reviews.</li><li>Define and implement security controls, standards, and guardrails across the AI lifecycle, from design and development through deployment and ongoing operation.</li><li>Identify and assess AI-specific threats and vulnerabilities, including risks relating to data exposure, model access, prompt manipulation, and misuse.</li><li>Deliver cybersecurity advisory services supporting enterprise AI adoption.</li><li>Support clients in securing AI-enabled products, platforms and data ecosystems.</li><li>Work with data, security, architecture, engineering, risk, and business teams to embed security-by-design into AI solutions and delivery processes.</li><li>Support AI security governance, risk assessments, control testing, monitoring, incident response, and remediation activities.<br><br></li></ul><strong>What We’re Looking For<br><br></strong><ul><li>Strong experience in cybersecurity, information security, AI security, data security, or related technology risk disciplines.</li><li>Practical understanding of AI and machine learning environments and the security risks associated with models, data, applications, and supporting infrastructure.</li><li>Experience applying security controls, threat modelling, risk assessment, identity and access management, data protection, and secure architecture principles.</li><li>Strong understanding of security governance, responsible AI, regulatory requirements, and security-by-design principles.</li><li>Clear communication and stakeholder management skills, with the ability to translate technical AI security risks into practical business and risk considerations.<br><br></li></ul><strong>Bonus Points For<br><br></strong><ul><li>Experience delivering AI, data, or cybersecurity initiatives within banking, financial services, or another regulated environment.</li><li>Knowledge of AI security threats, responsible AI frameworks, model security, Generative AI, or emerging AI security practices.</li><li>Experience with cloud-based AI and machine learning platforms and their associated security controls.</li><li>Relevant cybersecurity, cloud, data, AI, or information security certifications.</li><li>Exposure to large-scale AI, data, cybersecurity, regulatory, or technology transformation programmes.<br><br></li></ul><strong>Why Join Capco<br><br></strong><ul><li>Deliver high-impact technology solutions for Tier 1 financial institutions</li><li>Work in a collaborative, flat, and entrepreneurial consulting culture</li><li>Access continuous learning, training, and industry certifications</li><li>Be part of a team shaping the future of digital financial services</li><li>Help shape the future of digital transformation across FS & Energy.<br><br></li></ul><strong>We offer a competitive, people-first benefits package designed to support every aspect of your life.<br><br></strong><strong>Inclusion at Capco<br><br></strong>We’re committed to making our recruitment process accessible and straightforward for everyone. If you need any adjustments at any stage, just let us know – we’ll be happy to help. We value each person’s unique perspective and contribution. At Capco, we believe that being yourself is your greatest strength. Our #BeYourselfAtWork culture encourages individuality and collaboration – a mindset that shapes how we work with clients and each other every day.
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><strong>JOB SUMMARY</strong></p><br><p>The Security Officer is responsible for maintaining a safe, secure, and welcoming environment for guests, team members and team members. The role provides a visible and professional security presence throughout the hotel while proactively identifying and mitigating risks.</p><br><p>The Security Officer conducts regular patrols, monitors security systems, responds to incidents and emergencies, enforces established hotel security procedures, and provides appropriate assistance to guests and team members. The position requires sound judgment, discretion, effective communication, and the ability to remain calm and professional in challenging situations.</p><br><p><strong>KEY RESPONSIBILITIES</strong></p><br><p><strong>Security Operations</strong></p><br><ul><li><p>Conduct regular and documented patrols of all designated areas, including guest floors, public areas, back-of-house areas, parking facilities, entrances, and hotel perimeter.</p><br></li><li><p>Maintain a visible, professional, and discreet security presence throughout the property.</p><br></li><li><p>Monitor CCTV, access control systems, alarm panels, radios, and other security-related systems and equipment.</p><br></li><li><p>Monitor and control access to restricted areas in accordance with hotel procedures.</p><br></li><li><p>Respond promptly and appropriately to security alarms, suspicious activity, disturbances, and reported incidents.</p><br></li><li><p>Enforce hotel security policies and procedures consistently and professionally.</p><br></li><li><p>Identify, assess, and report security risks, unsafe conditions, suspicious behaviour and potential vulnerabilities.</p><br></li><li><p>Conduct authorized bag inspections, vehicle inspections and other security checks in accordance with hotel policy and applicable requirements.</p><br></li><li><p>Maintain strict control and accountability of master keys, access cards and other security-sensitive items.</p><br></li></ul><p><strong>Incident & Emergency Response</strong></p><br><ul><li><p>Respond to medical, fire, evacuation, and other emergency situations within the scope of training and hotel procedures.</p><br></li><li><p>Provide appropriate initial assistance and coordinate with management and relevant emergency services when required.</p><br></li><li><p>Liaise with police, fire services, EMS, and other authorized agencies as directed or when circumstances require.</p><br></li><li><p>Complete clear, factual, timely, and confidential incident reports for all significant security incidents.</p><br></li><li><p>Maintain accurate security logs, occurrence books, shift reports and other required records.</p><br></li></ul><p><strong>Guest & Support</strong></p><br><ul><li><p>Provide courteous and professional assistance to guests, including directions, escorts, guest lockouts, and other appropriate security-related assistance.</p><br></li><li><p>Assist with lost and found procedures in accordance with hotel policy.</p><br></li><li><p>Support safe deposit box procedures and other security-sensitive guest services as assigned.</p><br></li><li><p>Handle guest, team members and hotel information with discretion and always maintain confidentiality.</p><br></li><li><p>Maintain a service-oriented approach while ensuring that security procedures and standards are upheld.</p><br></li></ul><p><strong>Safety, Compliance & Training</strong></p><br><ul><li><p>Identify and report safety hazards, maintenance concerns, security deficiencies, and other conditions that may present a risk to guests, team members, or hotel property.</p><br></li><li><p>Participate in emergency drills, security exercises, training programs, briefings, and departmental meetings.</p><br></li><li><p>Maintain knowledge of hotel emergency procedures, evacuation plans, security policies, and relevant operating procedures.</p><br></li><li><p>Ensure all security equipment issued or used during the shift is maintained, accounted for, and reported if defective or missing.</p><br></li><li><p>Comply with all hotel policies, procedures, standards, and applicable laws and regulations.</p><br></li><li><p>Perform any other reasonable duties and responsibilities as assigned by the Security Manager or authorized management.</p><br></li></ul> </div>
<p> </p>
<p>The candidate will be responsible for conducting comprehensive <b>Vulnerability Assessment and Penetration Testing (VAPT)</b> across enterprise IT environments, applications, networks, infrastructure, cloud platforms and security systems.</p>
Key Responsibilities<br>
<ul>
<li>Conduct internal and external <b>penetration testing</b> across networks, servers, firewalls, endpoints and infrastructure.</li>
<li>Perform <b>web application and API penetration testing</b>, including testing against OWASP vulnerabilities.</li>
<li>Conduct vulnerability assessments and manually validate identified vulnerabilities and false positives.</li>
<li>Perform controlled exploitation to determine the actual impact and severity of identified security weaknesses.</li>
<li>Conduct security testing of <b>network devices, firewalls, routers, switches, VPNs, load balancers and servers</b>.</li>
<li>Perform application security testing covering authentication, authorization, session management, input validation, encryption and business-logic vulnerabilities.</li>
<li>Conduct <b>source-code security reviews</b> and support <b>SAST/DAST</b> activities.</li>
<li>Assess security of <b>cloud environments and operating systems</b>.</li>
<li>Perform security assessments using tools such as <b>Burp Suite, Nmap, Nessus, Metasploit, Wireshark and Kali Linux</b>.</li>
<li>Develop or automate penetration-testing/security activities using <b>Python</b>.</li>
<li>Prepare detailed penetration-testing and vulnerability-assessment reports containing evidence, risk ratings, business impact and remediation recommendations.</li>
<li>Work with technical teams to remediate identified vulnerabilities.</li>
<li>Conduct <b>retesting and validation</b> after remediation.</li>
<li>Follow established penetration-testing methodologies and cybersecurity best practices.</li>
<li>Support security teams in identifying attack vectors and improving the organization s overall security posture.</li>
</ul>
Required Technical Skills<br>
<p>Strong hands-on knowledge of:</p>
<ul>
<li>Vulnerability Assessment & Penetration Testing (VAPT)</li>
<li>Network Penetration Testing</li>
<li>Web Application Penetration Testing</li>
<li>API Security Testing</li>
<li>Infrastructure Security Testing</li>
<li>Cloud Security Testing</li>
<li>Vulnerability Exploitation & Validation</li>
<li>OWASP Top 10</li>
<li>SAST & DAST</li>
<li>Source-Code Security Analysis</li>
<li>Secure Coding Practices</li>
<li>Network & Operating System Security</li>
<li>Python/Security Automation</li>
<li>Burp Suite</li>
<li>Nmap</li>
<li>Nessus</li>
<li>Metasploit</li>
<li>Wireshark</li>
<li>Kali Linux</li>
</ul>
<div> </div>
<p> <br> </p>
Requirements <br> Standards / Framework Knowledge<br>
<p>The candidate should have good knowledge of relevant cybersecurity standards and methodologies, including:</p>
<ul>
<li> <b>OWASP</b> </li>
<li> <b>NIST</b> </li>
<li> <b>ISO/IEC 27001</b> </li>
<li> <b>PCI DSS</b> </li>
<li>Penetration-testing methodologies and security best practices</li>
</ul>
<div> </div>
<p> </p>
<p>Nair Systems is currently looking Senior Active Directory & Identity Security Consultant our Qatar operations.</p><p><strong>Required Skills & Experience</strong></p><ul><li>Experience 10+ years of Active Directory administration experience.</li><li>5+ years of Active Directory security hardening experience.</li><li>Experience managing environments with:<ul><li>Multiple Forests</li><li>Multiple Domains</li><li>Complex Trust Relationships</li><li>Hybrid Identity Deployments</li></ul></li></ul><p><strong>Technical Skills</strong></p><ul><li>Expert-level knowledge of:<ul><li>Active Directory Domain Services</li><li>Group Policy Design and Administration</li><li>Loopback Processing</li><li>DNS Architecture and Security</li><li>Windows Server 2016/2019/2022/2025</li><li>Kerberos Authentication</li><li>LDAP Security</li><li>AD Replication</li><li>AD Certificate Services</li><li>PKI Infrastructure</li><li>PowerShell Automation</li><li>Microsoft Entra ID</li><li>Identity Governance</li><li>Security Expertise</li></ul></li><li>Hands-on experience with:<ul><li>Active Directory Hardening</li><li>Identity Threat Detection</li><li>Identity Security Posture Management</li><li>PAM Solutions</li><li>Tier-0 Security</li><li>Zero Trust Architecture</li><li>Security Assessments</li><li>Attack Path Remediation</li></ul></li></ul><p><strong>Preferred Certifications</strong></p><ul><li>Microsoft Certified: Identity and Access Administrator (SC-300)</li><li>Microsoft Certified: Cybersecurity Architect (SC-100)</li><li>Microsoft Security Operations Analyst (SC-200)</li><li>Microsoft Certified Windows Server Hybrid Administrator</li><li>CISSP</li><li>CISM</li></ul><p>Joining time frame: 2 weeks (maximum 1 month)</p><p><strong>Desired Candidate Profile</strong></p><p>Experience 10+ years of Active Directory administration experience. 5+ years of Active Directory security hardening experience. Experience managing environments with: Multiple Forests Multiple Domains Complex Trust Relationships Hybrid Identity Deployments Technical Skills Expert-level knowledge of: Active Directory Domain Services Group Policy Design and Administration Loopback Processing DNS Architecture and Security Windows Server 2016/2019/2022/2025 Kerberos Authentication LDAP Security AD Replication AD Certificate Services PKI Infrastructure PowerShell Automation Microsoft Entra ID Identity Governance Security Expertise Hands-on experience with: Active Directory Hardening Identity Threat Detection Identity Security Posture Management PAM Solutions Tier-0 Security Zero Trust Architecture Security Assessments Attack Path Remediation Preferred Certifications Microsoft Certified: Identity and Access Administrator (SC-300) Microsoft Certified: Cybersecurity Architect (SC-100) Microsoft Security Operations Analyst (SC-200) Microsoft Certified Windows Server Hybrid Administrator CISSP CISM Joining time frame: 2 weeks (maximum 1 month)</p>
<p>JOB SUMMARY The Security Officer is responsible for maintaining a safe, secure, and welcoming environment for guests, team members and team members. The role provides a visible and professional security presence throughout the hotel while proactively identifying and mitigating risks. The Security Officer conducts regular patrols, monitors security systems, responds to incidents and emergencies, enforces established hotel security procedures, and provides appropriate assistance to guests and team members. The position requires sound judgment, discretion, effective communication, and the ability to remain calm and professional in challenging situations.</p>
<h3>KEY RESPONSIBILITIES</h3>
<h4>Security Operations</h4>
<ul>
<li>Conduct regular and documented patrols of all designated areas, including guest floors, public areas, back-of-house areas, parking facilities, entrances, and hotel perimeter.</li>
<li>Maintain a visible, professional, and discreet security presence throughout the property.</li>
<li>Monitor CCTV, access control systems, alarm panels, radios, and other security-related systems and equipment.</li>
<li>Monitor and control access to restricted areas in accordance with hotel procedures.</li>
<li>Respond promptly and appropriately to security alarms, suspicious activity, disturbances, and reported incidents.</li>
<li>Enforce hotel security policies and procedures consistently and professionally.</li>
<li>Identify, assess, and report security risks, unsafe conditions, suspicious behaviour and potential vulnerabilities.</li>
<li>Conduct authorized bag inspections, vehicle inspections and other security checks in accordance with hotel policy and applicable requirements.</li>
<li>Maintain strict control and accountability of master keys, access cards and other security-sensitive items.</li>
</ul>
<h4>Incident & Emergency Response</h4>
<ul>
<li>Respond to medical, fire, evacuation, and other emergency situations within the scope of training and hotel procedures.</li>
<li>Provide appropriate initial assistance and coordinate with management and relevant emergency services when required.</li>
<li>Liaise with police, fire services, EMS, and other authorized agencies as directed or when circumstances require.</li>
<li>Complete clear, factual, timely, and confidential incident reports for all significant security incidents.</li>
<li>Maintain accurate security logs, occurrence books, shift reports and other required records.</li>
</ul>
<h4>Guest & Support</h4>
<ul>
<li>Provide courteous and professional assistance to guests, including directions, escorts, guest lockouts, and other appropriate security-related assistance.</li>
<li>Assist with lost and found procedures in accordance with hotel policy.</li>
<li>Support safe deposit box procedures and other security-sensitive guest services as assigned.</li>
<li>Handle guest, team members and hotel information with discretion and always maintain confidentiality.</li>
<li>Maintain a service-oriented approach while ensuring that security procedures and standards are upheld.</li>
</ul>
<h4>Safety, Compliance & Training</h4>
<ul>
<li>Identify and report safety hazards, maintenance concerns, security deficiencies, and other conditions that may present a risk to guests, team members, or hotel property.</li>
<li>Participate in emergency drills, security exercises, training programs, briefings, and departmental meetings.</li>
<li>Maintain knowledge of hotel emergency procedures, evacuation plans, security policies, and relevant operating procedures.</li>
<li>Ensure all security equipment issued or used during the shift is maintained, accounted for, and reported if defective or missing.</li>
<li>Comply with all hotel policies, procedures, standards, and applicable laws and regulations.</li>
<li>Perform any other reasonable duties and responsibilities as assigned by the Security Manager or authorized management.</li>
</ul><p><strong>Desired Candidate Profile</strong></p><h4>QUALIFICATIONS & REQUIREMENTS</h4>
<h4>Education</h4>
<ul>
<li>High school diploma or equivalent.</li>
<li>Additional security, law enforcement, hospitality, or safety-related training is preferred.</li>
</ul>
<h4>Experience</h4>
<ul>
<li>Minimum 1 2 years of experience in hotel security, security services, law enforcement, military, emergency response, or a related field is preferred.</li>
<li>Previous experience in a hotel or hospitality environment is an advantage.</li>
</ul>
<h4>Physical Requirements</h4>
<ul>
<li>Ability to stand and walk for extended periods, including during an 8 12 hour shift where operationally required.</li>
<li>Ability to climb stairs and access different areas of the hotel during patrols and emergencies.</li>
<li>Ability to work indoors and outdoors and in varying weather conditions.</li>
<li>Ability to respond quickly to emergency situations, subject to applicable safety requirements and reasonable accommodation.</li>
</ul>
<p>Alongside these key competencies, the incumbent of the role will be required to demonstrate the fundamentals of the company s Count on Me! service culture to be responsive, respectful and deliver a great experience.</p>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span><span></span><br><br><span>SECURITY ANALYST</span><br><span>Responsibilities</span><br></span><ul><li><span>Monitor, assess, and improve the organization’s overall cybersecurity posture.</span><br></li><li><span>Conduct security risk assessments, vulnerability assessments, and compliance reviews.</span><br></li><li><span>Investigate security incidents, identify root causes, and coordinate containment and remediation activities.</span><br></li><li><span>Manage and monitor security technologies, including SIEM, firewalls, endpoint protection, IDS/IPS, and vulnerability management tools.</span><br></li><li><span>Develop and maintain cybersecurity policies, procedures, standards, and incident-response plans.</span><br></li><li><span>Perform threat analysis and recommend appropriate security controls.</span><br></li><li><span>Coordinate penetration testing, security audits, and remediation tracking.</span><br></li><li><span>Prepare security reports, risk registers, and management-level presentations.</span><br></li><li><span>Support security awareness programmes and provide technical guidance to internal teams.</span><br></li><li><span>Ensure compliance with applicable cybersecurity frameworks and regulatory requirements.</span><br></li></ul><span></span>INTERESTED CANDIDATES CAN SEND CV TO 31313903/ bency@madre-me.com<br><br><br><span>Requirements<span>Requirements</span><br></span><ul><li><span>Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.</span><br></li><li><span>Minimum 10 years of relevant experience in cybersecurity or information security.</span><br></li><li><span>Strong experience in security risk management, vulnerability management, and incident response.</span><br></li><li><span>In-depth knowledge of SIEM, EDR, IDS/IPS, firewalls, and other security technologies.</span><br></li><li><span>Strong understanding of network security, cloud security, identity management, and data protection.</span><br></li><li><span>Knowledge of frameworks such as ISO 27001, NIST, CIS Controls, and applicable regulatory standards.</span><br></li><li><span>Professional certifications such as CISSP, CISM, CEH, CompTIA Security+, or equivalent are preferred.</span><br></li><li><span>Strong analytical, problem-solving, reporting, and communication skills.</span><br></li></ul><br> </div>
<p>Support the implementation of ICS Security engineering specifications and related procedures, work practices, manuals, and development of equipment strategies for new projects. Identify limitations of existing systems, recommend best practices and upgrades.</p><p>Review the design such as System Architecture, Network Architecture, Functional Design Specifications, Detailed Design Specifications, Interface Agreements and ensure compliance to ICS Security engineering specifications.</p><p>Participate, review the ICS risk assessments, technology evaluations, and deviation requests, DRP (Disaster Recovery Plan) simulations.</p><p>Validate the system built through FAT and SAT for the department.</p><p>Coordinate and ensure deliverables as per the Operational Readiness Procedure to ensure smooth handover to ICS Security Operations.</p><p>Participate in ICS Security incident investigations or Root Cause Failure Analysis, continuous improvement and productivity enhancement initiatives.</p><p>Serve as focal point to ICS Security Custodians and ICSE Technicians to ensure alignment with the ICS Security Policy & Specifications.</p><p>Provide technical support for clarifying, following and implementing ICS Security Policy requirements across engineering sections, development teams, expansion teams, and operations.</p><p>Support in planning and conducting periodic ICS Security self-assessments to evaluate compliance with the ICS Security Policy.</p><p>Participate in life cycle management review of ICS in scope inventory and update inventory periodically.</p><p><strong>Desired Candidate Profile</strong></p><ul><li>Bachelor's degree in Engineering (Instrumentation & Control, Electrical, Electronic, Computer) or Computer Science.</li><li>6 years' experience in Oil and Gas Industry operations, technical, engineering with ICS Security Experience.</li><li>Experience of implementing security controls within an OT environment.</li><li>Understanding of different Industrial Control Systems environments.</li><li>ICS System Security Experience, Knowledge of Networking, Security tools, Knowledge of ICS Security monitoring like IDS/IPS, SIEM etc.,</li><li>Proficient in written and spoken English.</li><li>Computer Literate.</li><li>Excellent interpersonal skills, highly proficient in handling personnel, administrative, organizational and logistical issues.</li><li>Solve issues associated with ICS Security design, sustainment.</li><li>Lead ownership of issues related to ICS Security to support and drive continuous improvement.</li></ul>
<strong>About Accenture<br><br></strong>Accenture helps the world’s leading enterprises reinvent by building their digital core and unleashing the power of AI to create value at speed for organizations across industries. Our strategy is to be the reinvention partner of choice for our clients and lead in the safe, widespread adoption of AI, and to be the most client-focused, AI-enabled, great place to work in the world. We bring together the talent of our approximately 786,000 people with proprietary assets and platforms, deep process and industry expertise, and leading ecosystem relationships to deliver end-to-end solutions and measurable outcomes at scale. Through our Reinvention Services, we offer broad expertise across Cybersecurity, Digital Core, Finance, Industry and Enterprise, Song, Supply Chain and Engineering, and Talent, with advanced capabilities in AI and Data, Industry and Process, and Technology. We serve approximately 9,000 clients and generated approximately $70 billion in FY25 revenue. Visit us at accenture.com.<br><br><strong>About Accenture Security<br><br></strong>Accenture Security helps organizations prepare for, prevent, detect, respond to, and recover from cyber threats. We bring together deep industry knowledge, advanced security capabilities, and cutting-edge technology to help our clients protect their most critical assets, comply with regulatory requirements, and build resilient security programs.<br><br><strong>Role Overview<br><br></strong>We are looking for a <strong>Cloud Security Specialist</strong> to strengthen the security posture of our cloud environments, with a strong focus on <strong>Google Cloud Platform (GCP)</strong> and exposure to <strong>AWS and Azure</strong>. You will work closely with engineering, DevOps, and security teams to design, implement, and operate secure cloud‑native solutions while ensuring compliance with industry and regulatory standards.<br><br><strong>Key Functions<br><br><br></strong><li>Design and implement security controls across multi‑cloud environments, with primary focus on GCP<br></li><li>Secure cloud‑native services including Google Kubernetes Engine (GKE), Compute Engine, and Cloud Storage<br></li><li>Implement and manage identity, access, and network security controls across cloud platforms<br></li><li>Embed security into CI/CD pipelines and DevOps workflows, enabling secure‑by‑design cloud solutions<br><br><br></li><strong>Responsibilities<br><br><br></strong><li>Design, deploy, and maintain cloud security architectures aligned with best practices and the shared responsibility model<br></li><li>Implement Identity and Access Management (IAM) and Identity‑Aware Proxy (IAP) to enforce least‑privilege access<br></li><li>Configure and enforce network security controls using VPCs, Cloud Armor, Cloud VPN, and firewall rules<br></li><li>Implement data protection mechanisms including encryption, key management, and data loss prevention using Cloud KMS and Secret Manager<br></li><li>Monitor, detect, and respond to cloud security events leveraging Security Command Center, Cloud Logging, and Cloud Monitoring<br></li><li>Perform cloud security assessments, vulnerability analysis, and misconfiguration reviews<br></li><li>Support cloud‑related incident response and forensic activities<br></li><li>Integrate security controls into Infrastructure as Code (Terraform or similar)<br></li><li>Ensure compliance with frameworks such as ISO 27001, NIST, and National Cybersecurity Authority (NCA / ECC)<br></li><li>Develop and maintain cloud security policies, standards, and hardening guidelines<br></li><li>Partner with engineering teams to remediate findings and continuously improve security posture<br><br><br></li><strong>Qualifications<br><br><br></strong><li>3–6 years of experience in cloud security, cybersecurity, or infrastructure security<br></li><li>Hands‑on experience securing at least one major cloud platform (GCP preferred)<br></li><li>Strong understanding of cloud architecture and the shared responsibility model<br></li><li>Solid knowledge of:<br></li><li>Identity and Access Management<br></li><li>Network security, segmentation, firewalls, and private connectivity<br></li><li>Data protection and encryption practices<br></li><li>Experience with cloud security services such as:<br></li><li>Security Command Center<br></li><li>Cloud KMS<br></li><li>Cloud Armor<br></li><li>Ability to identify, analyze, and remediate cloud misconfigurations and vulnerabilities<br></li><li>Familiarity with Infrastructure as Code (Terraform or similar)<br></li><li>Experience integrating security into CI/CD pipelines<br></li><li>Understanding of compliance frameworks (ISO 27001, NIST, NCA/ECC preferred)<br></li><li>Strong troubleshooting, documentation, and communication skills<br></li><li>Ability to work independently and proactively drive security initiatives<br><br></li>To learn more about life @AccentureMiddleEast, follow us on social media and keep up with our latest news .Accenture Middle East Africa : LinkedIn, Instagram, Facebook, Twitter, YouTube<strong>.<br><br></strong>
<p><strong>Location:</strong> Onsite – Doha, Qatar<br><strong>Experience:</strong> 5+ Years<br><strong>Employment Type:</strong> Full-Time</p><span><strong>About the Role</strong></span><p>KalSoft is looking for a <strong>Lead SOC Analyst</strong> to lead security monitoring, threat detection, investigation, and incident response for AI agents and agentic platforms across the Microsoft ecosystem. The role focuses on securing Microsoft 365, Microsoft Purview, Microsoft Defender, Microsoft Entra ID, Microsoft Sentinel, and Azure AI Foundry. The candidate will oversee AI security monitoring, incident response, compliance, and containment activities while collaborating with security, identity, governance, and business teams in a 24/7 SOC environment.</p><span><strong>Key Responsibilities</strong></span><ul><li>Monitor AI agents and agentic platforms across Microsoft 365 Agents, Microsoft Purview, Microsoft Defender XDR, Microsoft Entra ID, Microsoft Sentinel, and Azure AI Foundry</li><li>Detect, investigate, and respond to AI-related security threats, including:<ul><li>Agent takeover and account compromise</li><li>Privilege drift and excessive permissions</li><li>Prompt injection attacks and data poisoning</li><li>Shadow or unauthorized AI agents</li><li>Suspicious agent behaviour and anomalous activity</li></ul></li><li>Conduct security incident triage, investigation, and escalation in accordance with SOC procedures</li><li>Execute approved containment and remediation actions, including access token revocation, Conditional Access enforcement, agent suspension or quarantine, and privileged access restrictions</li><li>Develop, maintain, and fine-tune detection use cases, analytics rules, and monitoring content in Microsoft Sentinel and Defender XDR</li><li>Manage agent risk classifications, security certifications, evidence repositories, audit records, and compliance documentation</li><li>Conduct recurring assurance reviews, security validations, and control testing to ensure agents comply with governance requirements</li><li>Track and report detection, response, and containment SLAs, KPIs, and KRIs</li><li>Collaborate with client security teams, identity administrators, governance and compliance teams, Microsoft support, and AI agent owners to coordinate threat response and risk mitigation</li><li>Support threat hunting and continuous improvement of AI security monitoring capabilities</li><li>Develop and maintain playbooks, incident response procedures, and operational runbooks for AI-related security events</li><li>Participate in a 24/7 operational rota and on-call support for continuous security monitoring and incident response</li></ul><span><strong>Requirements</strong></span><ul><li>Bachelor's degree in a relevant discipline</li><li>5+ years of experience in SOC, Security Operations, Managed Security Services (MSSP), Cyber Defence, or Incident Response environments</li><li>Hands-on experience with:<ul><li>Microsoft Sentinel and Microsoft Defender XDR</li><li>Microsoft Purview and Microsoft Entra ID</li><li>Conditional Access and Continuous Access Evaluation (CAE)</li><li>Privileged Identity Management (PIM)</li></ul></li><li>Experience investigating identity-based attacks, authorization issues, insider threats, and cloud security incidents</li><li>Practical experience creating, tuning, and maintaining detection rules, alerts, and investigation workflows</li><li>Experience supporting security monitoring in cloud-native and Microsoft security environments</li><li>Experience working in a 24/7 security operations environment</li><li>Strong proficiency in <strong>Kusto Query Language (KQL)</strong> for threat hunting, monitoring, and investigation</li><li>Strong understanding of Role-Based Access Control (RBAC), Privileged Access Management (PAM), least privilege principles, and identity and access governance</li><li>Knowledge of AI security technologies and platforms, including:<ul><li>Microsoft Copilot Studio</li><li>Microsoft 365 Agents (Agent 365)</li><li>Azure AI Foundry</li><li>Agent governance and lifecycle management</li></ul></li><li>Familiarity with AI and agentic security frameworks and standards, including:<ul><li>OWASP Top 10 for LLM Applications and Agentic Security</li><li>MITRE ATLAS</li><li>NIST AI Risk Management Framework (AI RMF)</li></ul></li><li>Strong understanding of cloud security, threat detection methodologies, and incident response best practices</li><li>Excellent analytical, problem-solving, and decision-making skills, particularly during active security incidents</li><li>Strong documentation, evidence collection, audit support, and reporting skills</li><li>Excellent verbal and written communication skills, with the ability to engage technical and non-technical stakeholders</li><li>Ability to manage priorities and respond effectively in high-pressure operational environments</li><li>Commitment to continuous learning in AI security and cyber defence</li><li>Willingness to participate in a 24/7 operational support model and on-call rota</li></ul>
We are looking for an experienced Red Team Operations Specialist with deep hands-on expertise in adversary simulation and advanced offensive security operations. This is not a traditional Penetration Testing role. We are specifically looking for professionals who have led real-world Red Team engagements and can demonstrate advanced offensive security capabilities.<br>Key Requirements• 7+ years of relevant cybersecurity / offensive security experience• Bachelor’s degree in Information Security, Computer Science or related field• Proven experience leading end-to-end Red Team engagements• Adversary simulation & attack scenario development• Strong Operational Security (OpSec) knowledge• Hands-on initial access techniques• Security control / detection bypass development• Hands-on experience with Command & Control (C2) frameworks• Developed at least one offensive security / Red Team tool• Demonstrated at least one original Red Team research technique• Delivered at least one Red Team / offensive security training<br>Mandatory Certification CRTO II – Certified Red Team Operator II<br>Shortlisted candidates should be able to provide:• CV and Red Team engagement portfolio/list• Details or evidence of a tool developed• Evidence of original security research/technique• Details of Red Team/offensive security training delivered• CRTO II certification copy<br>Important: Candidates whose experience is primarily vulnerability assessment or traditional penetration testing, without hands-on Red Team/adversary simulation experience, will not meet the requirement.<br>Interested Red Team professionals are welcome to apply or connect directly.
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span></span><ul><li><b>Firewall & Threat Protection</b>: Architect and oversee deployment of FortiGate, Palo Alto, Cisco ASA5500, F5 BIG‑IP ASM, HP Tipping Point (IPS), FireEye APT, and BlueCoat Proxy solutions.<br></li><li><b>Network Security Architecture</b>: Design secure VPN solutions (AnyConnect), ACS/ISE, DNS security, and enterprise network segmentation.<br></li><li><b>Information Security Design</b>: Develop system security frameworks, apply cryptography (DES, RSA), and implement risk management strategies.<br></li><li><b>Cloud Security</b>: Integrate Azure and GCP cloud environments into enterprise security architecture, ensuring compliance and resilience.<br></li><li><b>Business Alignment</b>: Align security initiatives with organizational goals, balancing risk reduction with operational efficiency.<br></li><li><b>Incident Response & Governance</b>: Provide architectural support for incident response, audits, and compliance programs.<br></li><li><b>Documentation & Standards</b>: Maintain security architecture blueprints, policies, and procedures.<br></li><li><b>Mentoring & Leadership</b>: Guide security engineers, review designs, and ensure best practices are followed.<br></li></ul><br><span>Requirements</span><p><b>Qualifications</b><br></p><br><ul><li>Bachelor’s degree in Computer Science, Information Technology, or related discipline.<br></li><li>Minimum <b>10+ years of experience</b> in IT and cybersecurity architecture.<br></li><li>Strong knowledge of enterprise and cloud security frameworks.<br></li></ul><p><b>Certifications</b><br></p><br><ul><li>Fortinet NSE, Palo Alto PCNSE, F5 ASM, Azure Security, Cisco ASA, FireEye APT, HP Tipping Point IPS, BlueCoat Proxy.<br></li><li><b>CCIE Security preferred</b>.<br></li></ul><br> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span></span><ul><li><b>Firewall & Security Management</b>: Configure, monitor, and troubleshoot FortiGate, Palo Alto, Cisco ASA, F5 BIG‑IP ASM, HP Tipping Point, and FireEye APT systems.<br></li><li><b>Network Security</b>: Manage VPN solutions (AnyConnect), ACS/ISE, DNS security, and secure remote access.<br></li><li><b>Information Security</b>: Design system security, apply cryptography (DES, RSA), and implement risk management strategies.<br></li><li><b>Cloud Security</b>: Support Azure and GCP environments, ensuring secure integration with business processes.<br></li><li><b>Incident Response</b>: Investigate and resolve advanced threats, including APTs, intrusions, and malware.<br></li><li><b>Documentation & Compliance</b>: Maintain security policies, procedures, and audit records.<br></li><li><b>Collaboration</b>: Work with IT, cloud, and business teams to align security with organizational goals.<br></li></ul><br><span>Requirements</span><p><b>Qualifications</b><br></p><br><ul><li>Bachelor’s degree in Computer Science, Information Technology, or related discipline.<br></li><li>Minimum <b>8+ years of experience</b> in network and security engineering.<br></li><li>Hands‑on expertise with Fortinet, Palo Alto, Cisco ASA, F5 BIG‑IP ASM, HP Tipping Point, FireEye APT.<br></li><li>Strong knowledge of VPN, ACS/ISE, DNS security, and advanced InfoSec concepts.<br></li></ul><p><b>Certifications</b><br></p><br><ul><li>Fortinet NSE, Palo Alto PCNSE, F5 ASM, Azure Security, HP Tipping Point IPS, FireEye APT.<br></li><li>Cisco ASA5500 expertise; <b>CCIE Security preferred</b>.<br></li><li>BlueCoat Proxy certification desirable.<br></li></ul><br> </div>