More stories

  • in

    Data Security protection, classification, and encryption Consultant: | Almawarid Group

    Employment:

    Full Time

    Identify and implement data protection controls and technologies to ensure the protection of the Company information. The consultant is responsible for ensuring the protection of confidential information to authorized personnel by implementing cryptographic controls. He/she evaluates the current cryptographic algorithms and encryption systems and develops new algorithms if required.Role: • Assess the effectiveness of the current data protection controls• Identify and implement mitigation controls / plans for the identified gaps• Assess the practices regarding data collection and data sharing . • Identify, design and implement data protection technologies such as DLP and DRM. • Implement data classification tools and data discovery tools. • Analyze and evaluate the data privacy incidents and report to the concerned team for response and remediation• Ensure the Company compliance with the data protection laws and regulations. Provide recommendations to improve the data protection compliance. • Create security systems / mechanisms that protect against any potential information disclosure or attacks. • Implement security controls to ensure the protection of data from any modification or deletion due to unauthorized access. • Implement new cryptographic algorithms. • Analyze existing encryption systems and cryptographic algorithms to identify weaknesses and vulnerabilities.• Suggest security solutions to eliminate the weaknesses. • Manage, and monitor the implementation of the recommended improvements. • Assist in solving any security issues that may emerge. • Review and analyze all the security incidents to identify the need for cryptographic controls.• Keep up to date with current research and trends for cryptography. • Develop policies, procedures and processes related to privacy and data protection.• Conduct a risk assessment to ensure that appropriate controls are in place to mitigate risk effectively. • Identify and implement technical measures for data protection in line with relevant laws and regulations. • Conduct Privacy Impact Assessments. • Ensure that all third-party services are compliant with data privacy and security requirements.• Liaise with the legal team to ensure the right contractual clauses are defined and embedded into all data processor contracts. • Monitor compliance with GDPR or other applicable data protection laws. • Identify and evaluate the Company data processing activities. • Maintain the records of data processing activities. • Stay updated about the changes in laws and provide recommendations to ensure data privacy compliance.• Act as point of contact with legal and regulatory authorities, and internal teams. • Develop training materials and conducts trainings for employees on best data privacy practices, privacy compliance and the consequences in case of non-compliance

    Knowledge: • Network components, their operation and appropriate network security controls and methods. • Understanding of risk assessment, mitigation and management methods. • Relevant cybersecurity aspects of legislative and regulatory requirements, relating to ethics and privacy. • Computer algorithms. • Cybersecurity considerations for database systems. • Installation, integration and optimization of system components. • Human-computer interaction principles. • IT security principles and methods. • Network access, identity and access management. • Operating systems. • Network traffic protocols, methods and management. • Telecommunications concepts relevant to role. • Network security architecture concepts including topology, protocols, components, and principles. • Network systems management principles, models, methods and tools.• Systems security testing and evaluation methods. • How threat intelligence sources collect intelligence. • Network protocols and directory services. • How to use network analysis tools to identify vulnerabilities. • Intrusion detection and prevention system tools and applications. • Network protocols and directory services• Knowledge and understanding of new technologies and solutions from a cybersecurity perspective. • Network components, their operation and appropriate network security controls and methods. • Cybersecurity authentication, authorization and access control methods. • Encryption algorithms, their relative strengths and weaknesses and appropriate selection criteria. • Cryptography and cryptographic key management concepts.• Cybersecurity assessment and authorization processes. • Cybersecurity controls and privacy requirements for the management of risks relating to data. • Low-level computer languages required for role. • Mathematics required for role. • Programming language structures and logic. • Key security management concepts. • National cybersecurity regulations and requirements relevant to the Company. • Encryption methodologies. • Industry standard security models and their effective application. • Confidentiality, integrity and availability requirements.• Knowledge of current and emerging data encryption security features in databases.• Complex data structures. • Implementing enterprise key escrow systems to support data-at-rest encryption.• Confidentiality, integrity and availability principles. • Asset availability, capabilities and limitations. • NCA ECC Standard. • NIST CSF Framework. • The principles of cybersecurity and data privacy.• Data classification standards and methodologies. • Operational impact on an organization due to cybersecurity breaches. • Relevant cybersecurity, ethics and privacy laws, regulations and standards. • Conducting privacy impact assessments. • Privacy enhancing technologies. • Digital evidence seizes and preservation. Qualifications: • Bachelor’s degree in computer science, information technology, or any other related field. • 7-15 years of experience in information security. • A minimum of 5 years of Data Protection or Data Privacy. • Experience conducting audits to ISO 27701, GDPR and HIPAA • CISA, CISM, IAPP, CIPP, or equivalent certifications. • ECES, CISSP, SANS Suite, or equal certifications

    We are a national group formed on the foundations of social responsibility and building the acquired value with hard work and quality of outputs that contribute to creating a fertile production environment for our esteemed customers so that they can present their work in accordance with standards of balanced performance that ensures continuity and reduces the expected risk. More

  • in

    Cyber Governance – Cloud Security Consultant: | Almawarid Group

    Employment:

    Full Time

    Design, deploy and manage the solutions in the cloud environment. Provide guidance on cloud security to identify, detect, analyze and mitigate any threats or vulnerabilities. • Design and develop the cloud security architecture. • Develop and maintain a reference cloud security architecture.• Evaluate the effectiveness of current security architectures and designs with the IT team• Conduct cloud security risk assessments. • Develop and implement secure cloud strategy, policies and procedures. • Identify the company data stored within cloud environments. • Act as a subject matter expert for security cloud architecture. • Build and implement security controls to prevent unauthorized access to, alteration and disclosure of cloud data, software and systems. • Test software systems to ensure the security of the cloud-based platforms. • Assist the Intelligence team in monitoring and responding to cloud security events and incidents. • Develop and conduct awareness sessions on the cloud security.

    Knowledge:• NCA ECC Standard. • NIST CSF Framework.• The principles of cybersecurity and privacy.• Cloud-based knowledge management technologies and concepts. • Cloud service models and effect on incident response. • Cybersecurity incident response in cloud environment. • Network components, security measures and methods. • Cross-platform collaboration and content synchronization. • Virtualization technologies. • Network Infrastructure cybersecurity communication methods, principles and concepts. • IT security solutions (e.g. SIEM, CASB, DLP, MFA etc.) • Cloud security alliance cloud controls matrix • Relevant cybersecurity, ethics and privacy laws, regulations and standardsQualifications: • Bachelor’s degree in computer science, information systems, software engineering, data science, or related field. • 7- 15 years of experience in information security. • 7+ years of experience in cloud security. • Experience working with standard concepts, practices, and procedures of cloud technology and public cloud environments. • CISSP, CISM, CISA, CCSP, CCSK, CompTIA Cloud+, AWS cloud certifications, Azure cloud certification or equal certifications

    We are a national group formed on the foundations of social responsibility and building the acquired value with hard work and quality of outputs that contribute to creating a fertile production environment for our esteemed customers so that they can present their work in accordance with standards of balanced performance that ensures continuity and reduces the expected risk. More

  • in

    Application security Consultant: | Almawarid Group

    Employment:

    Full Time

    The systems security development specialist is responsible for evaluating the security of the software and applications. He/she should be involved in the complete software development lifecycle.• Determine the required security controls. • Assist in software design reviews. • Identify functional and/or performance test cases. • Conduct a risk assessment when a system, software or application undergoes a change. • Conduct secure code reviews. • Identify and implement security mechanisms to resolve issues in software development. • Perform software quality assurance testing. • Implement security measures for solving issues identified during software acceptance phase. • Conduct vulnerability assessment activities prior to deploying the application. • Evaluate and communicate the software testing results with the design team and stakeholders. • Develop documentation for software programming and development, and secure software / system testing and validation. • Develop and implement an application security program across the organization with periodic reviews to assess effectiveness. • Develop secure coding standards and procedures, derived from leading security practices and industry standards, across all platforms. • Develop a process for project risk rating to drive and inform SDLC rigor (e.g. threat modelling), which will be part of the SDLC process. • Conduct security assessments on applications when in staging mode and provide risk assessment report for application owners before deploying them in production.• Define an IT/OT application testing framework where regular reviews and mandatory checkpoints are conducted against defined standards prior to design completion.• Develop a code integrity process where code signing is performed consistently & integrated in SDLC process and code obfuscation is applied wherever applicable. • Conduct security assessments on applications in production. • Review the IT/OT security controls for applications targeted with cyber threats. • Maintain a centralized repository for SDLC processes integrated with regular tracking processes. • Document a list of requirements where all intellectual property and production code are held in escrow. • Develop guidelines to include application security testing and for mobile applications.• Train testers on coding process using security test cases. • Identify and assign personnel responsible for application security. • Develop a process for conducting SAST and DAST activities on all developed applications• Implement Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools to identify vulnerabilities and weaknesses in applications before deploying into production. • Develop a platform to allow users to report bugs/issues in the applications. • Implement a WAF to ensure protection of critical and externally facing the company applications. • Ensure WAF logs are captured, archived and integrated to the SIEM solution. • Create and maintain an inventory of all IT/OT applications including criticality and sensitivity ratings, reviewed at least once a year. • Maintain a whitelist of IT/OT applications and application components authorized to be active on a host along with a list of trusted applications from vendors. • Perform periodic scans to detect deviations from the baseline configuration standards.• Develop schedule to periodically review Web Application Firewall (WAF) signatures based on the changes to application use cases and design changes. • Develop training materials and implement training on application hardening relevant to all stakeholders.

    Knowledge: • Network components, their operation and appropriate network security controls and methods. • Cybersecurity and privacy principles as they apply to software development. • Programming language structures and logic. • Interpreted and compiled computer languages. • Critical information systems that were designed with limited technical cybersecurity controls. • Data security standards relating to the sector in which the company operates. • Embedded systems and how cybersecurity controls can be applied to them. • Intrusion detection and prevention system tools and applications. • Complex data structures. • Local and wide area networking principles and concepts including bandwidth management.• Secure configuration management techniques. • Software debugging principles. • Software development models.• Software engineering. • System design tools, methods and techniques, including automated systems analysis and design tools. • Knowledge of web services. • Secure coding techniques. • Software quality assurance process. • Developing software in high-level languages.• Developing software for UNIX or Linux.Qualifications: • Bachelor’s degree in computer science, information systems, or related field. • 10+ years of experience in information security. • 7+ years of experience in security testing of software. • ISTQB certifications, or equal certifications• Bachelor’s degree in computer science, information systems, or related field. • 10+ years of experience in information security. • 7+ years of experience in security testing of software. • ISTQB certifications, or equal

    We are a national group formed on the foundations of social responsibility and building the acquired value with hard work and quality of outputs that contribute to creating a fertile production environment for our esteemed customers so that they can present their work in accordance with standards of balanced performance that ensures continuity and reduces the expected risk. More

  • in

    Microsoft Infrastructure Consultant | Qatar Datamation Systems (QDS)

    Employment:

    Full Time

    As a Microsoft Infrastructure Consultant, you will be responsible to design and develop the infrastructure technical aspects for the deployment for different customer and also work with Microsoft closely.Description: • Act as the infrastructure expert for supporting different customers in the transformation of various services from on-premises solutions to Cloud technologies.• Plan, design, configure and deploy large scale cloud infrastructure on-premises or on Azure for different customers.• Produce end-to-end solution designs, putting together technologies from multiple IT systems and departments across either the application or infrastructure domains.• Must have detailed knowledge and experience of one or more application or infrastructure domains and can clearly document and communicate the domain architecture.• Ensures technical quality and assurance by participating in Governance and Technical Design peer review processes, working closely with customer and internal stakeholders as appropriate.• Oversees coordination of the Solution Manager/Solution Architect, and teams up with other Functional or Technical Architects.• Experience and working knowledge with Microsoft Azure with IaaS & PaaS / Microsoft 365 with Security, including planning, configuration, optimization and deployment. • Strong practical Windows-based systems administration skills in a Cloud or Virtualized environment. • Proficiency in Windows / Active Directory / Exchange / Azure and Microsoft 365 technologies. • Large scale migration experience Data Centre to Data Centre and/or Data Centre to Cloud. • Demonstrated ability to think strategically about business, product, and technical challenges. • Experience planning and developing support processes and adhering to best practices.• Strong written and oral communication skills, and the ability to effectively communicate with technical and non-technical audiences. • Experience managing cloud/data center operations, including governance, monitoring, alerting and notifications.

    Candidate should have relevant experience of deployment/migration/configuration on the below technologies and platforms:• Active Directory• Exchange Server• Microsoft Azure Cloud (IaaS/PaaS)• Microsoft 365 (Office 365/Enterprise Mobility + Security/Windows 10)• System Center Suite• SQL Server

    QDS has strengthened its play and expanded its presence in the regional IT solutions, services and support market by building long-term relationships with customers and principals.

    Since its inception in 1983, QDS has been growing from strength to strength blending the latest of technology with impeccable business acumen and meeting the most challenging requirements of a fastevolving IT landscape through strategic joint ventures, world class vendor alliances, extensive and strategic vertical focus and a well trained and talented workforce of over 150 professionals.

    Today, QDS provides a wide range of fully integrated IT based business solutions that addresses almost the entire market spectrum, spanning various verticals like Banking and Finance, Healthcare, Government, Education, Oil and Gas, Telecommunication and Private sectors backed by high quality customer Support. More

  • in

    Strategic Client Services Director – Telco Sector | Oracle

    Employment:

    Full Time

    Strategic Client Services Director – Telco Sector Emerging technologies are disrupting old paradigms and unleashing new opportunities, and Oracle are using those emerging technologies along with 40 years of experience to lead the way in modernising the enterprise for their customers. We are transforming the world of business, empowering nearly half a million businesses across the globe to turn untapped potential into real business value with our full stack of SaaS, PaaS, IaaS, with Professional and Managed Services on offer to our customers. We enable companies to reimagine their businesses, processes, and experiences to outpace change. Role Purpose The Strategic Client Services Director role is one of influence and leadership, responsible for providing Oracle’s strategic customers with the guidance and support needed for successful and effective use of Oracles products and services. This role requires thought leadership in the customer’s industry, matching Oracle’s products and services to meet the changing landscape within this industry, and ensuring our customers have the support they need from Oracle to achieve their strategic goals. We are looking after industry experience in the key industries such as telecommunications or government, but strong business acumen in general is required. The successful candidate will work closely with the Strategic Client Director who has accountability for the end to end Oracle service and sales for the customer. The Strategic Client Services Director will drive a high degree of customer satisfaction, referenceability and protect / enhance revenue streams with their assigned customers. You will lead and coordinate activities with the Strategic Client Director and other Oracle stakeholders to support the implementation of the Oracle account strategy for the customer. Key responsibilities PARTNERSHIP : Build significant, value-based relationships with key customer contacts, that results in a partnership of collaboration and business growth for both Oracle and our customersLEADERSHIP : Together with the Strategic Client Director, provide the account team with leadership and guidance to deliver results. The account team represents multiple lines of business. The Strategic Client Service Director will inspire this team of highly skilled people to deliver services that have the customer at the centre of all the decisions we make. BUSINESS INSIGHT: Provide industry and customer insight to the wider Oracle team. Drive forward Oracle’s best practices, and support implementation of recommendations across the customer’s Oracle landscape by working with customer stakeholders to ensure appropriate levels of sponsorship and prioritization.CUSTOMER ADVOCACY: Have a thorough understanding of the customers’ current Oracle landscape and their requirements from Oracle in the future. Working in collaboration with the Strategic Client Director, Account team members, Oracle Support, Oracle Development and Cloud Operations to ensure the best solutions and outcomes for the customer are met.MASTERING COMPLEXITY: Work within this role is non-routine and complex, involving the application of advanced technical/business skills in areas of specialization, using the Oracle network to drive forward solutions, at pace, in demanding situations. GOVERNANCE: Participate in Account Planning and Account Reviews, track and communicate status on complex projects including risk identification and mitigation recommendations. Establishing joint governance plans with the customer and participating in those governance forums wherein Oracle technologies are being deployed / utilised. SUPPORT SERVICES: Have a strong understanding of the IT life cycle management, experience in managing major incidents that require executive level communication. Ensuring that the customer and Oracle are aligned and prepared to manage reactive situations such as incidents and escalated problems. Maintain detailed knowledge and demonstrated execution of Oracle support services and cloud operations to ensure the best possible service is received by the customer

    Key skills & Competencies Skills – Excellent communication and presentation skills; able to communicate and present at Exec C-Level- Strong business acumen – entrepreneurial approach- Strong networking and relationship building- Ability to lead & influence a geographically dispersed team without direct reporting lines at times- Understand the customer’s industry, as well as its technical and infrastructure environment, and translate it into Oracle solutions- Subject Matter expertise in industry and/or key Oracle product(s)- Expected travel 25 -50% of timeCompetencies – 10 or more years of experience in senior positions of professional Enterprise implementation experience, IT Service leadership, Program Management or Account Management experience- Demonstrated strong competency of interpersonal skills, team leadership, business acumen, relationship building and conflict management- Demonstrated expertise in large (multi-site or international) transformation projects- Experience working Globally with delivery and customer teams is preferred Education – Bachelor’s degree, Master’s degree or equivalent preferred- ITIL, PMP, Prince2 or equivalent certification preferred

    Oracle offers an integrated array of applications, databases, servers, storage, and cloud technologies to empower modern business. For most companies, flexibility is critical. Oracle provides a wide choice of software, systems, and cloud deployment models – including public, on-premises, and hybrid clouds – to ensure that technology flexes to the unique needs of a business.

    Oracle Cloud is a complete, integrated stack of platform, infrastructure, and application services. With advanced scalability and security, Oracle Cloud enables technical agility across the enterprise, connects people to information for clearer insights, and fosters efficiency through simplified workflows.

    More than 420,000 customers across 145 countries have harnessed Oracle technology to accelerate their digital transformation. More

  • in

    Cyber Governance – Security Architect Senior Consultant | Almawarid Group

    Employment:

    Full Time

    • Execute cybersecurity reviews and identify gaps in Company’s security architecture and generate cybersecurity risk management plans. • Apply secure configuration management processes. • Identify and prioritize Company’s critical business functions in collaboration with relevant company stakeholders. • Analyze candidate architectures, allocate security services, and select security mechanisms. • Define system security context, concept of operations and baseline requirements in line with Company applicable cybersecurity policies. • Design detailed functional specifications that document Company’s architecture development process. • Determine security controls for information systems and networks and document appropriately. • Define appropriate availability levels for critical system functions and disaster recovery and continuity of operations requirements. • Develop and integrate cybersecurity designs for systems and networks with multilevel security requirements. • Develop and address Company’s security architecture and systems security engineering requirements throughout the acquisition life cycle. • Guarantee that acquired or developed systems and architectures are consistent with Company’s cybersecurity architecture guidelines. • Read and translate technical diagrams, specifications, drawings, blueprints and schematics relating to systems and networks. • Detect and document security controls for Company systems and networks.

    Knowledge:• NCA ECC Standard. • NIST CSF Framework.• ITIL & COBIT Standards.• SABSA Framework. • Network access, identity and access management, and access authentication methods. • Operating systems, network traffic protocols, methods, management and systems testing and evaluation methods. • Application firewall concepts and functions. • Confidentiality, integrity and availability requirements and data security standards relating to personally identifiable information• Configuration management techniques, embedded systems and how cybersecurity controls can be applicable to them. • Network design processes, including security objectives, operational objectives and trade-offs. • Network hardware devices and functions, network technologies and multi-level security systems and cross domain solutions.Qualifications: • Bachelor’s degree in computer science, software engineering, information systems, or a related field. • 7-15 years of experience in information security and IT risk management. • Experience working with common information security standards, such as: ISO 27001/27002, NIST, PCI DSS, ITIL, COBIT • CISSP, CISM, CISA, CEH, SABSA Chartered Security Architect, CompTIA Security+ or equal certifications.

    We are a national group formed on the foundations of social responsibility and building the acquired value with hard work and quality of outputs that contribute to creating a fertile production environment for our esteemed customers so that they can present their work in accordance with standards of balanced performance that ensures continuity and reduces the expected risk. More

  • in

    Director Wealth Management | McGregor Boyall

    Employment:

    Full Time

    Our client, a multi-national bank is looking to appoint Director Wealth Management. UAE Nationals preferred. The role is a client facing role managing the Bank’s relationship with it’s highest value clients where professionalism, client focus and an expert understanding of financial planning and wealth products are critical to the success of the business. The role holder has a responsibility to acquire, develop and retain relationships with a portfolio of Wealth Premier clients.Requirement:Bachelor’s degree or equivalent experience.Candidates are required to complete the SCA requirements which are passing the 4 mandatory exams and obtaining University degree equalization from the Ministry of Education.ICWIM Level 3 qualificationMinimum of eight years proven and progressive financial services, and at least 3 years as Relationship Manager.Evidence of strong client recommendation and sales results in wealth products.Equivalent relationship management experience in managing high net worth client portfolios preferred.Expert knowledge in financial planning and wealth products.McGregor Boyall is an equal opportunity employer and do not discriminate on any grounds.

    Our client, a multi-national bank is looking to appoint Director Wealth Management. UAE Nationals preferred. The role is a client facing role managing the Bank’s relationship with it’s highest value clients where professionalism, client focus and an expert understanding of financial planning and wealth products are critical to the success of the business. The role holder has a responsibility to acquire, develop and retain relationships with a portfolio of Wealth Premier clients.Requirement:Bachelor’s degree or equivalent experience.Candidates are required to complete the SCA requirements which are passing the 4 mandatory exams and obtaining University degree equalization from the Ministry of Education.ICWIM Level 3 qualificationMinimum of eight years proven and progressive financial services, and at least 3 years as Relationship Manager.Evidence of strong client recommendation and sales results in wealth products.Equivalent relationship management experience in managing high net worth client portfolios preferred.Expert knowledge in financial planning and wealth products.

    Established in 1987, McGregor Boyall is a global recruitment consultancy providing permanent and contract / interim professionals across a wide variety of disciplines including Technology, Risk, Finance, Compliance, Legal, Marketing and HR & Talent Management. Since our inception, we have built an unrivalled reputation for helping organisations recruit the very best talent to ensure that they realise their business and operational objectives.

    Headquartered in the city of London, and with further offices throughout the UK (Manchester, Birmingham, Edinburgh and Glasgow) as well as globally in Dubai and Singapore, we are able to offer recruitment solutions throughout the UK & Europe, Middle East and Asia Pacific regions. More

  • in

    UAE National – Director of Recruitment | Michael Page

    Employment:

    Full Time

    We are recruiting for a UAE National – Director of Recruitment, that will report directly into the CHCO. The role holder will drive the entire recruitment function and lead the overall recruiting strategy across the UAE.Client DetailsOur client is a reputable semi-government entity based in Dubai.Description* Lead and manage the recruitment team and entire talent acquisition strategy* Design employer branding and proposition* Manage the end-to-end recruitment process for multiple, critical roles* Develop and preserve relationships with internal senior stakeholders, offering advise on recruitment solutions and process* Acquire the best talent to further develop the efficiency of the company as a whole* Build and maintain a robust pipeline of talent, billed ATS data integrity, and regularly share updates with internal stakeholders* Utilise innovative sourcing techniques and strategies to find, connect with and recruit top-tier talent* Recognise recruitment enhancement ideas to implement across the region* Support wider group within any recruitment and talent needsJob Offer* Huge exposure to C-Suite and wider group* Great opportunity to further build your team and for your own career development* Working for a cash rich, secure and established entity* Competitive salary and benefits* Education Allowance* Benefits* Furniture Allowance* Bonus

    * 8 + years of recruitment or talent experience, with a HR Operational background – full understanding of legislation* Data orientated, to utilise recruitment data, to influence and support stakeholders* Strong leadership skills* Fluent written and spoken English and Arabic is essential* Consultative recruitment approach with strong business acumen* Career driven, with a leading from the front and hands on approach – with 360 recruitment* Strong understanding of your recruitment metrics / ratios / numbers – time to hire, CVs to interviews, interviews to placements etc * Team management experience

    Michael Page is one of the world’s leading professional recruitment consultancies, specializing in the placement of candidates in permanent, contract, temporary and interim positions with clients around the world.

    The Group has operations in the UK, Continental Europe, Asia-Pacific and the Americas. In the Middle East we focus on the areas of:

    Finance & Accounting
    Banking & Financial Services
    Procurement
    Property & Construction
    Engineering & Supply Chain
    Oil & Gas Technical and Engineering
    Human Resources
    Sales
    Marketing
    Technology
    Secretarial
    Executive Search
    Legal

    The Group operates through 161 offices in 33 countries and employs over 5,000 employees worldwide. More