Senior Information Security Analyst
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 hour ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Primary Responsibilities
- Lead the governance and implementation of the Information Security Management System (ISMS), including the creation of policies, standards, and procedures for corporate information security across IT and Operational Technology (OT) domains.
- Develop and enforce security policies and raise organizational awareness regarding these policies and standards within operational areas.
- Ensure robust IT controls are in place to comply with current and anticipated security requirements, conducting compliance and operational maturity assessments for IT and OT environments under ISMS guidelines.
- Create and maintain metrics, dashboards, and documentation to demonstrate compliance activities effectively.
- Collaborate with IT stakeholders, project managers, and business owners to perform vendor risk assessments, due diligence reviews, and define security requirements; manage third-party assessment records.
- Keep abreast of the latest security trends, emerging threats, and best practices to enhance the organization’s security posture continuously.
- Work closely with cross-functional teams, including AI and digital units, to align security governance with emerging technologies and intelligence initiatives.
- Perform additional security-related tasks as assigned by the team lead.
Required Qualifications and Experience
- Bachelor’s degree in information security, computer science, or engineering.
- Professional certifications in information security management and compliance such as CISSP, CISM, CRISC, GIAC, or ISO27001, along with experience in control frameworks like NIST Cybersecurity Framework.
- Minimum of 10 years’ relevant professional experience.
- Hands-on experience with extensive Industrial Control Systems (ICS) and Information and Communications Technology (ICT) environments within the energy sector, ideally Oil & Gas.
- Proven expertise in designing custom information security management systems.
- Experience establishing Governance, Risk, and Compliance (GRC) processes and utilizing industry-standard GRC tools and solutions.
- Thorough knowledge of information security capability assessments and requirements analysis.
- Familiarity with applicable national laws, industry regulations, and security standards.
- Excellent skills in written, verbal, and presentation communication.
Skills
How they work
Communication