Senior Manager, Offensive Cyber Security
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- 8+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 hour ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Job description
About QNB Group
Founded in 1964 as Qatar's first Qatari-owned commercial bank, QNB Group has grown into the largest bank within the Middle East and Africa region, operating in over 31 countries on three continents. With over 28,000 employees, it serves approximately 20 million customers through around 1,000 branches and 4,300 ATMs. The bank holds top credit ratings by agencies like Standard & Poor’s (A), Moody’s (Aa3), and Fitch (A+) and is recognized as the most valuable bank brand in the region.
Role Summary
This senior role involves evaluating the Group’s IT applications and infrastructure to identify vulnerabilities relative to IT Security Policies and Standards. The incumbent will perform vulnerability scanning, participate in Red Team offensive simulation exercises, and manage external penetration testing vendors. An ethical hacking expertise and technical background are essential.
Main Responsibilities
- Ensure compliance with divisional KPIs to monitor performance and quality in Offensive Cyber Security.
- Promote cost efficiency and productivity to optimize benefits and reduce waste.
- Conduct security assessments of QNB systems, reviewing architecture design and policy adherence.
- Develop strong partnerships with IT and business units to understand and manage GIS risk service requirements.
- Provide advisory support on risks from emerging technologies, suggesting potential solutions.
- Identify improvement opportunities and adapt strategies to meet objectives.
- Analyze complex issues and determine effective solutions considering risk and business impact.
- Collaborate with external consultants for assessing information security effectiveness.
- Respond to customer queries on banking products and ensure solutions are provided.
- Maintain service standards per SLAs with internal teams to improve turnaround times.
- Build and sustain strong relationships across departments to meet Group objectives.
- Provide accurate information to auditors, compliance, financial control, and risk teams as required.
- Set ambitious targets and take initiative to exceed performance norms.
- Seek guidance as needed to perform tasks effectively and contribute constructively within teams.
- Assess security systems, network topologies, and overall security posture.
- Support enforcement of organizational security policies.
- Stay updated on security trends and vulnerabilities, keeping information security management informed.
- Maintain thorough understanding of business processes and controls in relevant areas.
- Commit to continuous professional development and staying current in security field advancements.
- Comply with legal, regulatory, and internal compliance frameworks including AML, CTF, sanctions, data protection, fraud control, whistleblowing, conflict of interest, and insider dealing policies.
- Operate within the Three Lines of Defense framework to identify and manage risks.
- Ensure client outcomes align with Conduct Risk policies.
- Support risk and control self-assessment (RCSA), key risk indicators (KRI), incident reporting, and remediation consistent with operational risk management.
- Complete mandatory trainings and attend internal and external seminars as required.
Qualifications & Experience
- Bachelor's degree preferably in Marketing, Banking, Finance, Accounting, Economics, Business Administration, or IT-related fields; Master's degree preferred.
- Minimum 8 years technical experience in security assessments of complex IT solutions, including penetration testing, ideally within a highly rated international bank.
- Experience in red team activities is advantageous.
- Professional offensive cybersecurity certifications (e.g., SANS, Offensive Security).
- Mandatory certifications including CISSP, CISM, or CISA.
- Previous experience in Banking or Big 4 Consultancy is required.
- Excellent verbal and written communication skills in English and Arabic, including report writing.
- Strong interpersonal and presentation capabilities.
- Knowledgeable on relevant laws, regulations, and compliance practices.
- Sound judgment and decision-making skills with integrity and self-management.
- Strong planning, organizing, analytical abilities, and result orientation.
- Deep expertise with penetration testing tools and techniques for both application and infrastructure layers.
- Knowledgeable in network architectures, access controls, and firewall technologies.
- Proficient with operating systems including Windows (Wintel), Solaris, and Linux.
- Experience or understanding of zero-day exploit identification.
- Experience designing and risk-assessing complex multi-forest Active Directory domains.
- Programming skills in languages such as Python, Golang, Rust, PowerShell, or C#.
- Capability to operate effectively under pressure.
Application Requirements
- Applicants must attach their Resume/CV, Copy of Passport or Qatar ID, and Educational Certificates as part of the application process.