About this role
<div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:24.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Job Specification</b></H2> </div><div><p style="margin:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Join our dedicated Cyber Assurance Team within the Information Risk Management Department. Reporting to the Cyber Assurance Lead, you will play a critical role in strengthening our organization's security posture.</span></p> <p style="margin:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">The Cyber Assurance team is responsible for proactively assessing and enhancing our security defenses. This involves conducting comprehensive ethical hacking activities and adversary simulations to identify potential vulnerabilities and control gaps. Your expertise will be vital in providing actionable recommendations to fortify our systems and ensure the resilience of our digital assets.</span></p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Job Purpose</H2> </div><div><ul> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Contribute to the effectiveness of the organization’s cyber defence by identifying risks, evaluating controls, and supporting the protection of information systems and data from cyber threats and vulnerabilities. Deliver and enhance key components of the cyber assurance program within QatarEnergy LNG’s Information Security organization. </span></li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Job Context & Major Challenge(s) - I</H2> </div><div><ul> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Major challenges: <br>(1) requires deep understanding of ethical hacking, penetration testing methodologies and offensive cybersecurity tactics <br>(2) supporting the Information Risk Management Division Manager in dealing with an increased cybersecurity risk due to the geopolitical situation <br>(3) contributing to the ongoing continuous improvement of SOC due to the current maturity level and the changing threat level <br>(4) keeping up to date with IT and OT Information Security and developments. <br>(5) keeping up to date with IT and OT Information Security regulatory requirements.</span></li> <li style="font-family:arial, helvetica, sans-serif"> </li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Key Job Accountabilities - I</H2> </div><div><ul style="margin-bottom:0.0cm;margin-top:0.0px" type="disc"> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Develop Attack Scenarios: Based on CTI and threat actor Tactics, Techniques, and Procedures (TTPs), create realistic and impactful threat simulation scenarios.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Configure and Deploy Security Tools: Set up, configure, and run automated security scanning tools, such as vulnerability scanners and web application security scanners.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Analyze Scan Results: Interpret findings from automated scans to identify potential vulnerabilities and weaknesses that could be exploited in a simulation.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Perform Phishing Simulations: Design, execute, and analyze targeted phishing campaigns to test the human element of security and measure employee awareness.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Collaborate for Defense Improvement: Work with blue teams to share insights on attack methodologies, improve detection capabilities, and enhance overall security posture.</span></li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:24.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px"><b>Person Specification - Minimum Requirement</b></H2> </div><div></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Qualifications</H2> </div><div><ul> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Bachelor’s degree level in information security, computer science or engineering.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Professional certifications in information security management and standards (e.g., OSCP, CRTP, CRTO, OSWE, etc.)</span></li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Knowledge and/or Experience - I</H2> </div><div><ul> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">5+ years of experience in <strong>Offensive Security / Red Teaming </strong></span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Broad knowledge of current techniques and practices associated with development and service provision and is a recognized specialist in at least one area.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Understands the main strategic and commercial issues facing IT and safety and availability expectations from OT and the Organization’s management and a good understanding of the principles of management and control.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Possesses good understanding of and practices according to a professional code of conduct and code of ethics.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Possesses a good understanding of IT/OT business applications.</span></li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Technical and Business Skills - I</H2> </div><div><ul> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Ability to assess and evaluate risk and the impact of legislation, and actively promotes compliance.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Builds a good rapport and strategic relations with the OT OEM community and QatarEnergy LNG Operation Leads.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Ability to deal effectively with stakeholders at all levels.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Demonstrates integrity, objectivity and impartiality.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Analytical skills.</span></li> <li style="margin-top:0.0cm;margin-right:0.0cm;margin-bottom:0.0cm;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-size:11.0pt;font-family:Calibri, sans-serif">Applies pragmatic judgement in the application of rules.</span></li> </ul></div></div></div>