Starlink Qatar

Governance, Risk, and Compliance (GRC) Specialist

Starlink Qatar

Doha, Doha Municipality, Qatar · Full Time

Be the first to apply

Experience
5–8 yrs
Salary
Openings
1
Posted
2 weeks ago
Work mode
In office
Education
Bachelor’s degree
Eligibility
Experienced professionals with a bachelor’s degree in a relevant discipline and a background in information security governance, audit, compliance, risk, or cybersecurity can apply. Candidates with direct exposure to ISO 27001, Qatar NIA, PCI-DSS, privacy compliance, cloud security, IAM/PAM, and au…
Resume
Required to apply

Where you'll work

Job description

About the Role

This position focuses on IT security audits, compliance oversight, cybersecurity governance, and risk management across the organization. The selected professional will help ensure that security practices align with regulatory obligations, internal policies, data protection requirements, and established governance frameworks.

The role also involves shaping audit approaches, carrying out security assessments, tracking compliance maturity, spotting risks and control gaps, and working with stakeholders to improve the organization’s cybersecurity resilience.

Security Audit and Compliance

  • Create, improve, and manage end-to-end IT security audit and compliance programs.
  • Organize, schedule, and run information security audit engagements.
  • Set the audit scope, goals, methods, and execution plans.
  • Design and apply audit test plans for systems, applications, infrastructure, and cloud setups.
  • Perform compliance reviews for high-priority systems, networks, and applications.
  • Keep audit calendars, records, evidence files, and reporting workflows current.
  • Drive closure of audit observations, non-compliance items, and remediation actions in a timely manner.

Cybersecurity Governance and Risk

  • Verify adherence to internal policies, legal and regulatory requirements, contract terms, and security standards.
  • Track cybersecurity maturity and overall compliance status across technical and operational areas.
  • Maintain control matrices mapped to multiple governance, risk, and compliance frameworks.
  • Detect security risks, weaknesses, and compliance shortcomings, then propose corrective measures.
  • Carry out vulnerability and compliance assessments and follow up on remediation work.
  • Support governance activities involving security policies, standards, and operating procedures.

Security Operations and Technical Oversight

  • Review security and compliance controls for cloud environments, Identity and Access Management (IAM), Privileged Access Management (PAM), Data Loss Prevention (DLP), and productivity/collaboration tools.
  • Work with IT operations and business stakeholders to address identified vulnerabilities and compliance issues.
  • Contribute to technical hardening requirements and baseline security documentation.
  • Confirm compliance for critical infrastructure, applications, systems, and cloud services.

Reporting and Documentation

  • Draft audit reports, compliance summaries, and progress updates for management and stakeholders.
  • Present findings, recommendations, and remediation plans to leadership.
  • Maintain thorough and accurate audit evidence and documentation records.
  • Monitor remediation progress and verify completion of earlier audit recommendations.

Stakeholder Coordination and Support

  • Coordinate with internal and external auditors to support reviews and evidence gathering.
  • Partner with business, HR, finance, operations, and project teams during audit and compliance activities.
  • Support business initiatives by identifying related cybersecurity and compliance risks.
  • Help create and deliver security awareness and compliance programs.
  • Handle related tasks and special assignments as required.

Qualifications and Experience

A bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Security, Risk Management, or a related field is required.

The role calls for 5–8 years of experience in information security governance, risk management, compliance, internal controls, audit, or cybersecurity.

Practical experience is needed in managing or supporting an Information Security Management System (ISMS) aligned to ISO/IEC 27001. Experience with Qatar National Information Assurance (NIA) implementation, compliance tracking, control assessment, and audit readiness is also required.

Applicants should have hands-on exposure to PCI-DSS compliance and certification activities, including gap analysis, control validation, remediation tracking, and audit support. Familiarity with data privacy and protection requirements, privacy risk reviews, and personal data handling controls is expected.

Experience in security risk assessments, risk treatment plans, and risk register maintenance is important, along with experience supporting ICOFR reviews, audits, control testing, and remediation. Prior involvement in internal audits, external audits, certification audits, and regulatory assessments will be valuable.

The role also requires the ability to assess audit evidence from technology platforms, security tools, infrastructure, cloud services, applications, and business systems to determine whether controls are effective and compliant. Experience with GRC platforms, risk tools, and compliance monitoring solutions is an advantage.

Strong analytical ability, clear documentation, report writing, communication, presentation, and stakeholder management skills are essential. The candidate should also be able to prepare executive dashboards, compliance reports, risk reports, and management presentations.

Technical Knowledge

A strong grasp of information security frameworks and standards, cybersecurity governance, risk management, vulnerability management, security assessments, cloud security controls, and IAM concepts is required.

Knowledge of ISO 27001, ISO 27002, NIST, and CIS Benchmarks is expected. Practical hands-on experience with cloud security environments, IAM and PAM technologies, DLP tools, and enterprise productivity and collaboration platforms is mandatory.

Preferred Certifications

  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified in Governance of Enterprise IT (CGEIT)
  • Cloud security certifications such as cloud security administration or governance credentials
  • ISO 27001 Lead Auditor or an equivalent qualification

Additional Skills

  • Strong analytical and problem-solving ability
  • Excellent audit, reporting, and record-keeping skills
  • Effective stakeholder coordination and communication
  • Comfort working with multicultural and cross-functional teams
  • Ability to develop security policies, standards, and governance models
  • Solid understanding of security compliance and operational best practices

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help