Senior Manager, Information Security & Data Risk
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 કલાક પેહલા
- Work mode
- In office
- Education
- Bachelor's degree in cybersecurity or related field
- Resume
- Required to apply
Where you'll work
Job description
Role Overview
The Senior Manager for Information Security & Data Risk spearheads consulting projects aimed at safeguarding client data across its entire lifecycle. This role is pivotal in helping clients identify their exposure to information security and data risks, translating various organizational and national standards into actionable controls, and embedding data classification, privacy, identity management, resilience, and assurance into data and IT programs.
Main Responsibilities
- Provide leadership over information security, data risk, privacy, classification, and resilience components during client projects.
- Evaluate security governance, policies, control frameworks, threat vulnerabilities, access controls, monitoring mechanisms, and operational evidence.
- Interpret and convert legal, regulatory, national, and client-specific requirements into explicit security and privacy mandates for data projects.
- Conceptualize or assess controls related to data classification, handling, access restrictions, encryption, logging, data retention, and secure disposal.
- Offer guidance to architecture and engineering teams on security by design for platforms, APIs, data pipelines, and analytics.
- Create and maintain risk registers, control matrices, remediation strategies, exception documentation, and evidence collection guidelines.
- Conduct risk workshops and present risk options, residual risk evaluations, and control recommendations to authorized decision-makers.
- Examine identity and access management practices including privileged access, segregation of duties, and lifecycle management controls such as joiner, mover, and leaver processes.
- Review incident response, data backup, disaster recovery, and business continuity plans related to client data.
- Collaborate with privacy officers, compliance teams, auditors, system owners, and technical teams for assurance and remediation efforts.
- Assure the quality of security assessments, architectural designs, testing evidence, and executive summaries prepared by delivery teams.
- Enhance client capabilities through control walkthroughs, training sessions, documentation, and seamless handover processes.
Qualifications and Experience
- Possession of a bachelor’s degree in cybersecurity, information security, computer science, or a related discipline; master’s degree is advantageous.
- Equivalent blend of related education and significant consulting or relevant implementation experience may be acceptable.
- Minimum of 10 years in information security or technology risk roles, including over 4 years in leadership capacities.
- Proven track record leading cybersecurity, data privacy, or technology risk projects.
- Experience providing advisory services to senior leaders within government, regulated industries, or complex organizations.
- Skilled in the design and evaluation of security controls for data platforms, integrations, and operational contexts.
- Effective communicator able to present residual risks and remediation priorities clearly to both technical staff and executives.
Technical Expertise
- Expertise with security governance, risk management, and control frameworks.
- Knowledge of data classification, privacy requirements, and lifecycle data protection techniques.
- Familiarity with identity and access controls including privileged accounts and segregation of duties.
- Understanding of security design principles for platforms, APIs, integrations, and analytics.
- Competence in logging, monitoring, vulnerability management, and incident response.
- Insight into backup, disaster recovery, resilience, and business continuity measures.
- Experience with compliance documentation, managing exceptions, and assurance testing.
- Awareness of unique security challenges in public sector and highly regulated environments.
Key Competencies
- Strong governance skills in security management.
- Ability to evaluate and manage risks effectively.
- Expertise in data classification principles.
- Proficiency in identity and access management practices.
- Resilience planning and implementation.
- Understanding of regulatory compliance.
- Capability for balanced risk judgement and discretion.
- Leadership in assurance and crisis communication.
- Facilitation of risk and control discussions with senior stakeholders.
- Clear writing of risk statements, control requirements, and remediation strategies.
- Articulate technical risks in terms understandable by business leaders.
- Professional handling of sensitive information with appropriate discretion.
- Coordination across security, privacy, legal, audit, and technology functions.
- Maintaining independence and providing objective challenge supported by evidence.
- Supporting client risk decisions without assuming formal risk approval authority.
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- IAPP CIPP or CIPM (Certification in Privacy and Data Protection)
Skills
Work styles they’re looking for
Leadership
Confidentiality
Crisis Communication
Facilitation
Discretion
Risk judgment