{bc}
linkedin

Information Security Consultant

Cytomate
Baladiyat ad Dawhah, QAT
Full-time
Mid-Senior
Onsite
Discovered 3 days ago
Information security governance, risk, compliance, and assuranceCybersecurity risk assessmentsGap assessments and control reviewsISO/IEC 27001NIAQCSF
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Information security governance, risk, compliance, and assuranceCybersecurity risk assessmentsGap assessments and control reviews
Smart Apply

Full Job Posting

Company Description

Cytomate is a cybersecurity company headquartered in Doha, Qatar, focused on offensive security technologies and services.

Its offerings include red teaming, penetration testing, reverse engineering, breach and attack simulation, deception, and AI-based payload generation tools.

Role Description

The company is hiring an experienced Information Security Consultant for its Cybersecurity, Risk and Compliance Advisory team.

The client-facing role delivers information security, cyber risk, regulatory compliance, data privacy, and AI governance engagements across industries.

The consultant will work with senior management, business functions, and technical teams to assess risk, strengthen governance, and implement practical solutions.

Key Roles and Responsibilities

  • Lead and support governance, risk, compliance, assurance, gap assessment, maturity assessment, risk assessment, audit, and certification-readiness engagements.
  • Design and improve Information Security Management Systems aligned with ISO/IEC 27001, NIA, QCSF, NIST CSF, CIS Controls, ISO 22301, and PCI DSS.
  • Develop security policies, procedures, standards, risk registers, treatment plans, Statements of Applicability, compliance matrices, and remediation roadmaps.
  • Assess controls across access management, cloud security, vulnerabilities, incident response, third-party risk, security operations, continuity, and disaster recovery.
  • Support privacy compliance, including data mapping, classification, processing records, impact assessments, data-subject rights, retention, transfers, and privacy-by-design.
  • Support AI governance and ISO/IEC 42001 implementation through inventories, risk classification, impact assessments, lifecycle controls, and human oversight.
  • Coordinate internal, regulatory, and certification audits, including evidence collection, interviews, findings, corrective actions, and closure.
  • Facilitate workshops, interviews, awareness sessions, and management presentations for technical and non-technical stakeholders.
  • Manage workstreams, timelines, risks, dependencies, client expectations, reports, proposals, presentations, and executive summaries.
  • Build client relationships, mentor junior consultants, and support business development through solution design, estimation, and proposal preparation.

Skills and Attributes

  • Strong knowledge of information security governance, risk management, compliance, and assurance is required.
  • Practical experience with risk assessments, gap assessments, control reviews, internal audits, or certification-readiness engagements is required.
  • The role requires sound understanding of ISO/IEC 27001, data privacy, AI governance, responsible AI, and emerging AI regulatory expectations.
  • The consultant must translate regulatory and standards-based requirements into practical controls and implementation actions.
  • Strong analytical, problem-solving, professional judgment, documentation, presentation, stakeholder engagement, and delivery skills are required.
  • English communication skills are required; Arabic would be an advantage.

Qualifications and Experience

  • A bachelor’s degree in cybersecurity, information technology, computer science, engineering, risk management, business administration, or a related discipline is required.
  • Approximately 5–10 years of relevant experience in information security, cybersecurity, IT risk, audit, GRC, data privacy, or related advisory services is required.
  • Experience with ISO/IEC 27001 and one or more recognized cybersecurity or compliance frameworks is required.
  • Client-facing activity management or independent delivery of defined consulting workstreams is required.
  • Cybersecurity, technology-risk, audit, or GRC consulting experience is preferred.
  • Experience in government, financial services, energy, telecommunications, maritime, or other regulated sectors is advantageous.

Preferred Certifications

  • Certifications such as CISA, CISM, CISSP, CRISC, CDPSE, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001, CIPP/E, CIPM, ISO 22301, PCI DSS, cloud security, PMP, or PRINCE2 are advantageous.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today