Description:
The Sr Cybersecurity Engineer role will be responsible for ensuring the protection of the organizations computer systems and cloud infrastructure through the detection of threats and the response to any threats and attacks. It includes evaluating Information Security and Privacy risk leading to an iterative process for the development and implementation of technical controls, security policies, protocols, procedures, and security training for the organization with the objective to protect corporate systems and other assets and the data stored on those corporate systems and assets. This role also works with the business to ensure all global audit and compliance requirements needed for the business are met and works with audit functions, government, and regulatory agencies to provide supportive documentation as applicable.
General Duties and Responsibilities:
Assess risks and develops security standards, procedures, and controls to manage risks.
Improves companys security positioning through process improvement, policy, automation, and the continuous evolution of capabilities.
Updates security controls and provides support to all stakeholders on security controls covering internal assessments, regulations, protecting Personally Identifying Information (PII) data, and Payment Card Industry Data Security Standards (PCI DSS) and others as necessary.
Performs and investigates internal and external information security risk and exceptions assessments. Assess incidents, vulnerability management, scans, patching status, secure baselines, penetration test result, phishing, and social engineering tests and attacks.
Documents and reports control failures and gaps to manager and relevant stakeholders. Provides remediation guidance and prepares management reports to track remediation activities.
Collaborate with peers on Information Technology team to implement security and data protection controls and continually improve processes.
Define risk and compliance metrics and provide frequent reporting to management, including gaps in policy and proposed resolutions to measure against those metrics.
Remains current and stays informed on security best practices, changing landscape, relevant frameworks and standards and acts as the resource for security assessment and regulatory compliance.
Leads the IT efforts to promote and remain passionate about identifying, assessing, and mitigating security and privacy risk.
Ensure any external and internal data centers within company remain compliant with SOC, data privacy and any other relevant compliance standards.
Trains, guides, and acts as a resource on security assessment functions to other departments. Provide leadership, coaching and training programs for Compliance and Information Security to all employees.
Performs other related duties as assigned.
Required Knowledge, Skills, and Abilities:
Knowledge of functions and capabilities of firewalls on-premises and cloud based.
Experience with SIEM products (log collectors, data lakes) playbook creation, rules management, and threat hunting.
Knowledge of security control frameworks and standards such as NIST-171, 800-53, CSF, and ISO 27000 Series.
Information technology systems and processes, network infrastructure, data architecture, data processes, and protocols.
Development of IT security best practices and policies.
Hands-on experiences with firewalls, IDS/IPS, SIEM, antivirus, and vulnerability scanning tools.
Experience in technical concepts: cloud computing environments: logical access control, agile development process, secure coding principles, security architecture, information security, network security, and privacy.
Experience with Microsoft stack of technologies, Defender for Identity, endpoint, cloud, and office.
Microsoft Azure experience with Security, Networks, Conditional Access, Identity, and MFA.
Information systems auditing, monitoring, controlling, and assessment process.
Incident response investigations, management, and practices.
Threat Identify tools, investigate IOCs, APTs and recommend protections.
Experience overseeing and managing vendors and managed service providers.
Apply a risk-based approach to planning, executing, and reporting on audit engagements and auditing process.
Evaluate and update and/or revise program materials.
Handle sensitive and confidential matters, situations, and data.
Work independently and prioritize multiple tasks and adapt to needed changes.
Remain calm under high pressure/difficult situations.
Personal Traits and Characteristics:
Strong communication, reporting skills and presentation skills
Reliable, dependable, diligent Highly organized with good time management skills.
The successful candidate shall exhibit a sense of ownership, urgency, be solution orientated, collaborative and accountable.
Self-motivated professional able to work in a fast-paced and constantly changing environment.
Experienced and capable of being the lead on implementations and projects.
A focus on customer satisfaction, with strong interpersonal skills and responsiveness.
Ability to communicate with all levels of organization and capable of working with various teams.
Effectively communicate technical issues to diverse audiences, both in writing and verbally.
Education and Training:
Bachelors degree or higher required in computer science preferably in an IT Security and Compliance discipline or equivalent experience.
10+ years of experience in information security/cybersecurity programs, compliance, audit and/or risk management in a technology environment
Preferred Security Certifications: Certified Information Systems Security Professional (CISSP), CompTIA Security+, Systems Security Certified Practitioner (SSCP).
Accommodation:
Candidates for the position should be able to perform essential job duties in the work environment described with or without accommodation. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.
Equal Employment Opportunity:
Infinite Electronics is proud to be an Equal Employment Opportunity and Affirmative Action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, gender expression, marital status, age, national origin, disability status, protected veteran status, or any other characteristic protected by law. We are committed to building a diverse workforce and we actively encourage women, minorities, people with disabilities, and veterans to apply.
Job Types: Full-time, Contract
Contract length: 72 months
Pay: QAR7,
- 00 - QAR10,000.00 per month
Education: - Bachelor's (Preferred)
Application Deadline: 29/08/2024