Information Security Security Operations Officer Security Assessment & Assurance Specialist
Job Summary
Preferred Arabic Speaking
The Information Security Officer is responsible for leading and executing end-to-end security assurance activities across the client’s technology landscape including applications cloud infrastructure identity and third-party environments.
The role ensures security controls are properly designed implemented validated and continuously enforced including the definition and verification of secure configuration baselines across the enterprise in alignment with ISMS NCSA (Qatar NIA/QCSF) ISO 27001 and NIST CSF.
- Lead security assessments architecture reviews vulnerability management and assurance activities.
- Establish and operate a structured Security Assurance Framework covering control validation coverage tracking and continuous assurance.
- Manage the full security lifecycle from risk identification through remediation and validation.
- Translate technical findings into business-level risk statements and remediation plans.
- Perform in-depth security assessments of web applications APIs mobile applications cloud platforms containers and infrastructure.
- Identify advanced security risks such as business logic flaws authentication weaknesses privilege abuse and modern attack techniques.
- Validate secure architectures configuration baselines and cloud-native security controls.
- Support secure SDLC and DevSecOps practices including security testing and release controls.
- Define and maintain secure configuration baselines across the enterprise technology stack (OS databases network devices cloud services identity platforms and security tools).
- Align baselines with industry standards (e.g. CIS Benchmarks) and organizational risk requirements.
- Implement automated configuration compliance checks and continuous monitoring mechanisms.
- Conduct periodic reviews and validation of configurations to detect drift misconfigurations and unauthorized changes.
- Work with engineering and operations teams to enforce hardening standards and remediate deviations.
- Lead security architecture and design reviews across applications platforms and integrations.
- Conduct threat modeling to identify attack paths risks and mitigation strategies.
- Ensure alignment with enterprise security architecture and Zero Trust principles.
- Conduct security assessments of vendors SaaS providers and external integrations.
- Validate data protection encryption and privacy controls for sensitive and regulated data.
- Support cyber resilience activities including OT/ICS security reviews red team exercises and incident response simulations.
- Ensure continuous alignment with regulatory and framework requirements (ISO 27001 NIST CSF Qatar NIA QCSF).
- Support internal and external audits with defensible evidence-based controls.
- Define and report on security metrics KPIs and executive dashboards.
- 8 years of experience in information security assessments and assurance.
- Strong expertise in application API mobile and cloud security.
- Hands-on experience in penetration testing vulnerability management and security architecture reviews.
- Practical experience in system hardening configuration baselines and security control validation.
- Deep understanding of modern attack techniques and identity/authentication mechanisms.
- Proven ability to communicate technical risks to business stakeholders.
- OSCP / OSEP / OSWE
- CISSP
- Cloud Security Certifications (Azure / GCP)
- IEC 62443
Required Skills:
Information security assessments Security assurance Security controls design Security controls implementation Security controls validation Security controls enforcement Secure configuration baselines ISMS NCSA Qatar NIA QCSF ISO 27001 NIST CSF Security assessments Architecture reviews Vulnerability management Security lifecycle management Risk identification Remediation Business risk communication Application security API security Mobile application security Cloud platform security Container security Infrastructure security Business logic flaw identification Authentication security Privilege abuse prevention Modern attack techniques knowledge Secure architecture validation Configuration baselines validation Cloud-native security controls Secure SDLC DevSecOps Security testing Release controls Secure configuration baselines definition OS security Database security Network device security Cloud services security Identity platform security Security tools security CIS Benchmarks adherence Automated configuration compliance Continuous monitoring Configuration review Drift detection Misconfiguration detection Unauthorized change detection Engineering collaboration Operations collaboration Hardening standards enforcement Security architecture review Secure design review Threat modeling Attack path identification Risk mitigation strategies Enterprise security architecture alignment Zero Trust principles Third-party security assessments Vendor security assessment SaaS provider security assessment External integrations security assessment Data protection Encryption Privacy controls Sensitive data protection Regulated data protection Cyber resilience OT/ICS security Red team exercises Incident response simulations Governance Compliance Regulatory alignment Internal audits support External audits support Security metrics definition KPI reporting Executive dashboards Penetration testing Security architecture reviews System hardening Security control validation Identity mechanisms