Senior Cybersecurity Certification & QMS Specialist (Common Criteria)
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Education
- Master's degree
- Resume
- Required to apply
Where you'll work
Job description
Position Overview
The Senior Cybersecurity Certification & Quality Management System (QMS) Specialist plays a crucial role in managing and refining the QMS that supports cybersecurity certification frameworks, ensuring these processes meet international standards and applicable regulations. This role emphasizes enhancing the efficiency, consistency, and reliability of certification activities.
Core Duties
- Lead planning, execution, monitoring, and continuous improvement of the QMS across various schemes within NISCF.
- Ensure internal processes align with national and international regulatory standards and guidelines.
- Evaluate and confirm the quality and accuracy of technical content related to certification.
- Regularly assess the certification procedures to boost their effectiveness and efficiency.
- Manage documentation and record-keeping to guarantee completeness, accuracy, and ease of access, keeping QMS documents current.
- Organize and perform internal audits and reviews to verify compliance and identify opportunities for improvement within the certification process.
- Coordinate scheme management review meetings to discuss system and process status.
- Review all scheme-related documents such as manuals, policies, procedures, forms, and templates to ensure quality standards.
- Implement and track corrective and preventive measures to address and resolve non-conformities promptly.
- Monitor updates and changes in applicable standards, including various ISO standards (ISO17021, 17024, 17065, 17025, 27006, 9001) and relevant national standards.
- Support the development of policies, standards, procedures, and guidance materials based on audit outcomes.
- Maintain high competence and impartiality standards, promoting consistency across all evaluations and certification activities.
- Possess comprehensive knowledge of Common Criteria standards, Protection Profiles, Security Targets, and Evaluation Assurance Levels (EALs), providing expert guidance on related documentation.
- Provide mentoring and guidance to certification body team members, including certifiers and evaluators, particularly on complex assessments.
- Make informed recommendations on certificate issuance for specific EALs leveraging extensive evaluation experience.
- Stay abreast of evolving security threats, technological advances, and standards to ensure certification relevance.
Required Qualifications and Experience
- Master’s degree in IT, information security, or a related discipline, preferably with a security focus.
- Certification from a recognized Common Criteria certification body; experience as a Certifier is highly desirable.
- Completion of IT Security Overview Training and Common Criteria for IT Security Evaluation Training and certifications.
- At least 10 years of professional work experience.
- Minimum 5 years in senior roles related to IT, Information Security, Cybersecurity auditing, Risk Management, or Cybersecurity/Information Security management.
- Proficiency in both Arabic and English in written and spoken forms is preferred.
Additional Competencies
- Analytical thinking and strong problem-solving capabilities.
- Experience in IT and Information Security assessment and auditing.
- Practical knowledge in risk assessment and management, including GAP analysis.
- Hands-on experience with information security, cybersecurity, and quality management systems.
- Understanding of ISO27001 certification audit requirements.
- Excellent communication skills, including documentation and technical report writing.
- Ability to objectively assess formal assessment schemes and reach firm conclusions.
- Planning and delivering training sessions and workshops in government and private sectors.
- Experience briefing senior-level executives.
- Working knowledge of auditing and information assurance standards such as ISA, ITAF, ISO17021, and ISO19011.
- Familiarity with third-party, certification, and cybersecurity audits.
- Ability to multitask, work autonomously, and collaborate effectively with diverse project teams and stakeholders.
- Strong attention to detail, ability to meet deadlines, and perform under pressure.
- Skilled in interpreting certification criteria in accordance with ISO/IEC standards (17021, 17024, 27006, 17065).