Information Security (InfoSec) Specialist
- Vulnerability Management
- Risk Management
- Incident Response
- Penetration Testing
- Incident Management
- ISO 27001
- NIST
- CIS Controls
- SIEM
- EDR
- IAM
- DLP
- RBAC
- Oracle Cloud
- Azure
- AWS
- Network Security
- PKI
- CISSP
- CISM
- CompTIA Security+
- CEH
- CRISC
Job Description – Information Security Specialist
Job Title: Information Security Specialist
Experience: 6–8 Years
Location: Qatar
Employment Type: 3 months contract then it can be extendable
Department: Information Security / IT
Reporting To: Information Security Manager / CISO
Job Summary
We are looking for an experiencedInformation Security Specialist with6–8 years of relevant experience to support and strengthen the organization’s information security posture. The role will be responsible for implementing and monitoring security controls, identifying and mitigating security risks, supporting security assessments and audits, managing security incidents, and ensuring compliance with applicable information security standards and regulatory requirements.
The ideal candidate should have strong hands-on experience acrossinformation security, vulnerability management, security monitoring, risk management, incident response, security governance, and compliance.
Key Responsibilities
1. Information Security Operations
- Monitor and manage information security controls across IT infrastructure, applications, cloud environments, and endpoints.
- Identify security vulnerabilities, threats, and potential areas of exposure.
- Support implementation and continuous improvement of security policies, procedures, and technical controls.
- Review security s and coordinate investigation and remediation activities.
- Work closely with IT, infrastructure, application, cloud, and network teams to address security issues.
2. Vulnerability & Risk Management
- Conduct vulnerability assessments and coordinate remediation of identified vulnerabilities.
- Review vulnerability scan and penetration testing reports and track corrective actions.
- Perform information security risk assessments and maintain risk registers.
- Support security risk identification for new applications, infrastructure, vendors, and technology initiatives.
- Follow up with stakeholders to ensure timely closure of security findings.
3. Security Incident Management
- Support detection, investigation, containment, and resolution of information security incidents.
- Participate in incident response activities and root-cause analysis.
- Maintain incident records, investigation reports, and lessons-learned documentation.
- Coordinate with internal teams and external security service providers during major security incidents.
4. Security Governance & Compliance
- Support implementation and maintenance of security controls aligned with standards such asISO 27001, NIST, CIS Controls, and applicable regulatory requirements.
- Support internal and external information security audits.
- Prepare evidence and documentation required for security and compliance assessments.
- Maintain security policies, standards, procedures, guidelines, and control documentation.
- Track audit observations and ensure timely remediation.
5. Security Monitoring & Technologies
- Work withSIEM, EDR/XDR, vulnerability management, firewall, IAM, DLP, email security, and endpoint security solutions.
- Review security logs and s and coordinate appropriate response actions.
- Support security monitoring and threat detection activities.
- Assist in tuning security tools and improving detection and response capabilities.
6. Identity & Access Security
- Support access reviews and user entitlement assessments.
- Monitor privileged and administrative access.
- Support implementation ofMFA, RBAC, least-privilege access, and access governance controls.
- Coordinate periodic user and privileged-access reviews with application and infrastructure teams.
7. Security Architecture & Projects
- Participate in security reviews for new applications, infrastructure, cloud solutions, integrations, and technology projects.
- Review security requirements for proposed solutions and provide recommendations.
- Support secure configuration and security-by-design initiatives.
- Participate in cloud security assessments across platforms such asOracle Cloud, Azure, AWS, or Microsoft 365, as applicable.
Required Skills & Experience
- 6–8 years of experience in Information Security, Cybersecurity, IT Security, or a related discipline.
- Strong understanding ofinformation security principles, risk management, vulnerability management, incident response, and security governance.
- Hands-on experience with security tools such as:
- SIEM
- EDR/XDR
- Vulnerability scanners
- Firewalls
- DLP
- IAM/PAM
- Endpoint and email security solutions
- Good knowledge ofnetwork security, endpoint security, identity and access management, cloud security, and application security fundamentals.
- Experience supportingISO 27001 / NIST / CIS security frameworks.
- Experience with security audits, compliance assessments, risk registers, and remediation tracking.
- Good understanding of security concepts includingMFA, encryption, PKI, certificates, authentication, authorization, logging, and security monitoring.
- Ability to analyze security incidents and coordinate remediation with technical teams.
- Strong documentation, communication, analytical, and stakeholder-management skills.
Preferred Certifications
One or more of the following certifications would be preferred:
- CISSP
- CISM
- ISO 27001 Lead Implementer / Lead Auditor
- CompTIA Security+
- CEH
- CRISC
- GIAC certifications
- Relevant cloud security certifications such asAzure Security, AWS Security, or Oracle Cloud Security
Education
- Bachelor's degree inComputer Science, Information Technology, Cybersecurity, Information Security, or a related field.
- Relevant professional certifications will be an added advantage.
Key Competencies
- Information Security & Cybersecurity
- Security Risk Management
- Vulnerability Management
- Security Incident Response
- SIEM / SOC Operations
- IAM & Privileged Access Management
- Network & Endpoint Security
- Cloud Security
- Security Governance & Compliance
- ISO 27001 / NIST
- Security Audits
- Security Policies & Procedures
- Third-Party / Vendor Security
- Security Awareness
- Strong analytical and problem-solving skills
- Excellent communication and stakeholder-management skills
Key Performance Areas
- Timely identification and remediation of security vulnerabilities
- Security incident response and closure
- Security compliance and audit readiness
- Security risk reduction
- Effectiveness of security monitoring and controls
- Timely closure of audit and security findings
- Security governance and documentation
- Continuous improvement of the organization's security posture
Information Security (InfoSec) Specialist · Bahwan CyberTek