jobholds
SENIOR INFORMATION SECURITY RISK ANALYST (Governance, Risk & Compliance)
قطر
•
تاريخ النشر: 2024-05-01
•
1,209 مشاهدة
تفاصيل ومتطلبات الوظيفة
<p><b>Department</b><br />
INFORMATION SECURITY INFORMATION & COMMUNICATION TECHNOLOGY<br />
<br />
<b>Title</b><br />
SENIOR INFORMATION SECURITY RISK ANALYST (Governance, Risk & Compliance)<br />
<br />
<b>Primary Purpose of Job</b><br />
The Senior Information Security Risk Analyst is tasked with enhancing the information security posture of QatarEnergy in both IT and OT environments by assessing and managing cyber and information security risks. He/She actively participates in projects during all phases of implementation and operation, provides expert technical and procedural direction to identify and manage cyber and information security risks, and monitors progress of activities to manage and report identified risks.<br />
<br />
<b>Education</b><br />
• Bachelor degree in information security, computer science, or systems engineering. • Professional certifications related to Information security (e.g., ISO27001, ISO27005, CISSP, GICSP, CISA, GIAC, CEH, etc.)<br />
<br />
<b>Experience & Skills</b><br />
• Knowledge of fundamental security principles and challenges in their practical application • 10+ years of relevant professional experience • Experience with large ICS & ICT environments in the Energy sector, preferably in Oil & Gas • Knowledge of information security capabilities and requirements analysis • Perform periodic risk management activities in IT and OT during the phases of project lifecycle, communicate risks and mitigation actions to stakeholders, and support the business in defining cyber and information security requirements • Identify critical information systems and supporting systems for business processes and projects • Evaluate effectiveness of existing information security controls • Propose cost effective information security controls for the remediation of risk • Manage information security risk register, including the development of risks acceptance reports, and communicate risks to the business as required • Maintain security controls framework in compliance with state law, international standards and best practices • Define and evaluate metrics for reporting information security control effectiveness • Communicate the urgency and severity of complex risk scenarios in simple, effective language • Excellent written and verbal business communication skills<br />
</p>
INFORMATION SECURITY INFORMATION & COMMUNICATION TECHNOLOGY<br />
<br />
<b>Title</b><br />
SENIOR INFORMATION SECURITY RISK ANALYST (Governance, Risk & Compliance)<br />
<br />
<b>Primary Purpose of Job</b><br />
The Senior Information Security Risk Analyst is tasked with enhancing the information security posture of QatarEnergy in both IT and OT environments by assessing and managing cyber and information security risks. He/She actively participates in projects during all phases of implementation and operation, provides expert technical and procedural direction to identify and manage cyber and information security risks, and monitors progress of activities to manage and report identified risks.<br />
<br />
<b>Education</b><br />
• Bachelor degree in information security, computer science, or systems engineering. • Professional certifications related to Information security (e.g., ISO27001, ISO27005, CISSP, GICSP, CISA, GIAC, CEH, etc.)<br />
<br />
<b>Experience & Skills</b><br />
• Knowledge of fundamental security principles and challenges in their practical application • 10+ years of relevant professional experience • Experience with large ICS & ICT environments in the Energy sector, preferably in Oil & Gas • Knowledge of information security capabilities and requirements analysis • Perform periodic risk management activities in IT and OT during the phases of project lifecycle, communicate risks and mitigation actions to stakeholders, and support the business in defining cyber and information security requirements • Identify critical information systems and supporting systems for business processes and projects • Evaluate effectiveness of existing information security controls • Propose cost effective information security controls for the remediation of risk • Manage information security risk register, including the development of risks acceptance reports, and communicate risks to the business as required • Maintain security controls framework in compliance with state law, international standards and best practices • Define and evaluate metrics for reporting information security control effectiveness • Communicate the urgency and severity of complex risk scenarios in simple, effective language • Excellent written and verbal business communication skills<br />
</p>
وظائف مشابهة قد تهمك
ViiV (GSK) US Competitive Intelligence & Market Research Lead
الولايات المتحدة
عرض →
Remote Support Engineer – Night Shift
المملكة المتحدة
عرض →
Primary Technical Support Engineer
الفلبين
عرض →
Services Partner Deployment Specialist
الفلبين
عرض →
Senior IT Project Manager
قطر
عرض →
Senior Manager Quality Assurance
قطر
عرض →
IT Project Manager - Consultant
قطر
عرض →
D&it Affiliates Advisor
السعودية
عرض →
Þmo Site Engineer
المملكة المتحدة
عرض →
Principal Software Engineer
الولايات المتحدة
عرض →
ملخص الوظيفة
المجال / التصنيف
تكنولوجيا المعلومات
الدولة
قطر
نوع الدوام
دوام كامل
إعلان وظيفة موثوق ومعتمد
تم التحقق من بيانات الإعلان لضمان تجربة تقديم آمنة ومباشرة للباحثين عن عمل.