Introduction

Information Security Program is to ensure that the information security governance and controls are implemented effectively, in line with COMPANY strategic business objectives, regulatory compliance requirements and the region threat landscape context.

COMPANY is seeking to contract a mature experienced organization to perform information protection enterprise-wide rollout.

What are you going to do 

The CONTRACTOR shall ensure that as a minimum the following is captured:

  • Information Asset criticality (CIA);
  • Sensitivity Data Classification;
  • Identity Access Management requirements (Access Model, Segregation of Duty, Application/Data ownership, Privilege Access Management);
  • Information/data privacy requirements;
  • Integrity requirements.

Based on the information asset classification the CONTRACTOR shall ensure that as a minimum the following requirements are captured:

  • The confidentiality, integrity, and availability requirements;
  • The identity access management requirements;
  • The data sensitivity classification and information protection requirements;
  • The data privacy requirements of the information.
  • The CONTRACTOR will use the existing Business Impact analysis conducted by COMPANY Business Continuity team and conduct information classification exercise for 05 departments.

CONTRACTOR shall conduct interviews and workshops with the business to perform Information Classification (CIA) considering the following:

  • COMPANY risk matrix and Information Classification Standard;
  • Business Impact analysis conducted by COMPANY Business Continuity function for those departments;
  • Where possible CONTRACTOR shall leverage outputs from other initiatives conducted by the COMPANY.

CONTRACTOR shall use the already developed templates and information available and provided by the COMPANY and ensure that as part of the Information Classification Matrix the following information is captured:

  • Identification of Information Assets’ Owners;
  • Identification of Information with Privacy Data;
  • Group of Information Assets into Information Types.

Essential skills and knowledge

  • Relevant experience in Information Security with at least five (5) years in an Information Protection and privacy role;
  • Confirmed experience in implementing end-to-end Information Protection enterprise-wide in well-established organizations;
  • Hands-on experience in Information Protection and Privacy built by design controls definition and implementation;
  • Confirmed experience in Microsoft Information Protection enterprise-wide implementation in well-established organizations;
  • Confirmed experience in assessing, defining, and implementing DLP rules;
  • Confirmed experience in local and international privacy laws. Hand-on experience in establishing GDPR or other privacy laws;
  • Expertise in implementing information protection and privacy security controls from technological and administrative aspect;
  • Experience in implementing information protection, privacy procedures and gap assessments;
  • Experience and knowledge of ISO/IEC 27001:2013, GDPR, NIST CSF, DLP & other Information Protection technologies;
  • The following certification in good standing is mandatory for the personnel assigned to providing the SERVICES as per this document:
  • Certified Information Privacy Manager (CIPM); Certified Information Systems Security Professional (CISSP), Project Management certification;
  • Minimum 5-year experience in project management activities;
  • Good understanding of cloud solution (focus on Azure) and digital transformation process;
  • CONTRACTOR PERSONNEL shall demonstrate understanding of the organization culture and clear understanding of overcoming these challenges prior engaging.

What we offer 

Salary:

Day Rate in USD Plus Allowance

Work Schedule:

9 Hours / 6 Days

Duration:

12 months with possible extension

Location:

Qatar

Are you the perfect match for this vacancy? Apply in 5 minutes and let's get in touch!

your-application-process[1]

Process of your application

Application process & contact

We will now begin examining your application: We will take a close look at your application documents and ask you for additional information if necessary. If your qualifications match our requirements, we will invite you to meet us for the first time.

Project discussion with our customer

If the introductory meeting goes well for you and us, we will arrange a meeting with the customer who has the perfect project for you. This gives you the opportunity to find out more about the customer and the project.

The decision

If you enjoyed the project discussion and the customer is also convinced of your expertise, we will ask you the final and decisive question: Do you want to get started at Brunel?

Introductory conversation with Brunel

In an introductory meeting, we would like to find out more about your interests, ambitions and professional developments. At the same time, we report on working at Brunel and provide information about all career opportunities and prospects.

Welcome to Brunel

Now great times are beginning! With Brunel you have countless opportunities to help shape technological progress. You decide how your career path goes. We support you in every phase of your career. You always have security behind you: Brunel!