Primary Purpose of the Job
QatarEnergy is looking to recruit a Senior Systems Engineer (Systems Security) that will join a team responsible for overall protection, confidentiality, integrity, and availability of the ICT systems that supports business operations. The new member is required to support and maintain the day-to-day security operations and system change lifecycle of critical security systems and devices, tools & services. The new member is also required to provide senior technical support for all systems security whilst providing leadership & mentoring to junior team members. The role will be an enabler to the company’s success through development and implementation of security practices that create a secure working environment.
Required Experience and Skills
- Proficiency in written and spoken English.
- 8 or more years of demonstrated experience in IT of which minimal 5 years of experience in systems security operations function.
- Design, deploy, and manage application system security controls such as application whitelisting.
- Design, deploy and manage Advanced Threat Prevention, Antivirus, host-based firewall/IPS, application control, security scanning for file servers, encryption and device controls.
- Design, deploy, and manage cloud security function such as Multi Factor Authentication, Key Vaults, Defender for Microsoft Azure and implement the same controls in Amazon AWS and Google GCP.
- Efficient threat management by integration using visibility from EDR (Endpoint Detection and Response) tools and endpoint posture status with remediation.
- Design, deploy, and manage Public Key Infrastructure and HSM solutions.
- Design and manage all data plane operations on Key Vaults and all objects in it.
- Design, design and deploy Privileged Access Management Services which includes management of privileged accounts, secure access to resources (on premise and in the cloud).
- Strong troubleshooting skills in network, software configuration, log interpretation, etc.
- Develop and create processes and procedures in compliance with QatarEnergy security policies and internationally recognized security frameworks and standards such as ISO and NIST.
- Develop, review, and maintain technical documentation (High-Level Designs) for security systems.
- Identify security controls to mitigate newly identified vulnerabilities and risks; and recommend control changes or improvements as needed.
- Analyze requests and incidents from QatarEnergy staff and provide solution based on the QatarEnergy Cyber Information Security Framework.
- Ability to provide information security guidance and counsel to QatarEnergy lines of business in the assessment and development of new business process and related IT processes.
- Has presentation skills that will gain acceptance of proposed solution from impacted stakeholders.
- Extensive technical knowledge with the latest security solutions and threat vectors.
- Has multitasking, problem solving, and strong analytics skills.
- Demonstrate commitment to quality and continuous improvement.
- Attains risk management skills in providing security reports and escalating critical security threats.
- Attains solid project management skills that will lead to serving security requirements and obtain information about solutions and successful delivery.
Educational Qualifications
- Bachelor’s degree in a relevant field.
- Recognized information security certification such as CISSP or CCIE.
- Certification in Microsoft Azure and AWS security is a plus.