Senior Analyst/Specialist in Governance, Risk, and Compliance (GRC) Cybersecurity
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Education
- Bachelor's or Master's degree in Cybersecurity or related field
- Resume
- Required to apply
Where you'll work
Job description
Job Overview
This role focuses on supporting the governance, risk, and compliance framework within the cybersecurity domain to ensure adherence to national cyber regulations, organizational security policies, and government assurance standards. The analyst is responsible for identifying, evaluating, and managing information security risks across systems and business operations, maintaining risk registers, and tracking remediation for vulnerabilities and control gaps.
Key Responsibilities
- Act as a subject matter expert providing governance, risk, and compliance consultation in cybersecurity.
- Review and enhance enterprise cybersecurity architecture to align with business objectives and security requirements.
- Perform assessments against the Qatar Cyber Security Framework (QCSF) and recommend compliance improvements.
- Deliver practical cybersecurity advice and solutions to internal stakeholders.
- Identify cybersecurity risks and propose mitigation strategies to reduce exposure.
- Support policy implementation, standards adherence, and best practice frameworks within the organization.
- Collaborate with technical and business teams to improve overall cybersecurity posture.
- Prepare comprehensive reports, assessments, and strategic recommendations for senior management.
- Support cybersecurity audits and accreditation efforts to ensure regulatory alignment.
- Mentor stakeholders on cybersecurity governance, risk, and compliance best practices when needed.
Required Qualifications and Experience
- Bachelor’s or Master’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related fields.
- At least 10 years of professional experience in cybersecurity focusing on governance, risk management, compliance, enterprise cybersecurity architecture, and regulatory adherence.
- Mandatory certifications include CIIP (Certified Information Infrastructure Professional) and CISM (Certified Information Security Manager).
Preferred Certifications
- GICSP (Global Industrial Cyber Security Professional)
- CCISO (Certified Chief Information Security Officer)
Skills and Competencies
- Extensive knowledge of governance, risk, and compliance frameworks applicable to cybersecurity.
- Expertise in enterprise cybersecurity architecture design and review.
- In-depth understanding of the Qatar Cyber Security Framework.
- Strong analytical, problem-solving, and consulting skills in cybersecurity advisory.
- Capability to assess risks and devise effective security controls and solutions.
- Excellent communication, report-writing, and stakeholder engagement abilities.
- Ability to independently manage tasks and collaborate within multidisciplinary teams.
- Familiarity with international cybersecurity standards and industry best practices.
Language Proficiency
Fluency in both English and Arabic is essential for this role.