• Working with application development and maintenance teams to ensure that the application security coverage from the requirement gathering level, SDLC, application implementation and after implementation.
• Coordinate with vendors and conduct vulnerability assessments and penetration testing for applications (web, on premises, mobile, public facing)
• Managing Oracle database security project, including overseeing timelines and collaborating with development and maintenance teams to develop effective solutions for clients.
• Part of Identity and Access Management (IAM) project, collaborating with cross-functional teams to ensure timely delivery of IAM solutions as per client requirements.
• Managed Dynatrace project, coordinating with development teams and successfully implemented Dynatrace for monitoring the performance of applications and infrastructure, resulting in improved system performance and increased client satisfaction, in addition to Application security module.
• Successfully implemented ISO 27001 certified information security systems, ensuring compliance with industry standards and promoting a culture of maintaining confidentiality, integrity and availability of information. Obtained ISO 27001:2013 certification through rigorous auditing and adherence to best practices in information security management.
• Conduct security static and dynamic testing through the provided tools - before go-live (new or changes)
• Coordinate with Cybersecurity Engineer - governance and risk management to maintain application security management policies/ procedures and risk management.
• Assist to develop, implement, and manage the overall application enterprise process for information security and associated architecture standards such as ISO 27001, NIA, cyber security law, privacy management law and Qatar 2022 cyber security requirement.
• Evaluate suspected security breaches and recommend corrective actions (including incidents involving outside vendors).
• Work with IT Security lead to coordinate with MOI security shield and maintain the NCSOC onboarding and continuity of connectivity
• Follow cyber security incident management and incident response plan.
• Serve as the part of the security incident response planning and execution.
• Assist Risk Management, Internal Audit and IT department in the development of appropriate criteria needed to assess the level of new/existing applications and / or technology infrastructure elements for compliance with enterprise security standards.
• Assist in the review of application and/or technology environments during the development or acquisition process to assure compliance with corporate security policies and directions and assist in the overall integration process regarding client's own technology environment.
• Maintenance of Application layer to support the organization's information security/privacy policies and procedures and ensure timely updating thereof in light of changing circumstances/ best practices/ regulatory directives.
• Work with IT Security lead to coordinate with MPTO team and maintain Qatar 2022 implementations based on the agreed roadmap
• Provide daily, weekly and monthly reports to Information Security Lead related environment application level changes,
• incidents, problems, service operation and critical area.
- Company industry:
- IT Services
- Job role:
-
Security