Intrinsic Security
Doha, QatarPosted today
Role Overview We are looking for an experienced Cybersecurity / GRC Consultant to support the implementation of Qatar’s National Data Classification Policy (NDCP) and NIAS v2.1 for Qatar. The consultant will work closely with business, technology, cybersecurity and compliance stakeholders to assess the current environment, identify gaps, develop the required security and data-classification frameworks, support implementation, and prepare the organisation for NCSA certification and audit readiness. The role requires a combination of cybersecurity governance, regulatory compliance, data classification, information security risk management and hands-on Microsoft Purview/DLP experience. Key Responsibilities The consultant will support the project across the full implementation lifecycle, including: • Review existing ISMS documentation, data classification policies, procedures and security strategies. • Conduct assessments and gap analysis against NIAS v2.1, NDCP, NIAP, QCSF, ISO 27001:2022, NIST and Qatar Data Privacy Law. • Conduct stakeholder interviews and workshops across business and technology functions. • Perform information security risk and control assessments and develop appropriate treatment plans. • Assess the organisation's Microsoft 365 E5 / Microsoft Purview environment and identify opportunities to improve data classification, labelling and DLP capabilities. • Develop and enhance the Data Classification & Labelling Strategy and associated governance framework. • Develop information asset register templates and support the identification and classification of information assets. • Define data criticality, CIA ratings, classification taxonomy and labelling criteria. • Develop data classification and DLP use cases and support their implementation. • Configure and fine-tune Microsoft Purview DLP policies and classification capabilities. • Support implementation of applicable NIAP, NDCP and NIAS governance controls and maintain implementation evidence. • Develop security baselines for critical technologies and classification criteria for VLANs, tape drives and removable media. • Develop and maintain cybersecurity policies, procedures, risk registers and risk treatment plans. • Support the development and finalisation of the Statement of Applicability (SOA). • Prepare audit documentation, evidence packs and control testing results for NCSA certification readiness. • Support internal audit activities and remediation/closure of audit findings. • Support the review and enhancement of Business Continuity and Disaster Recovery plans and participate in tabletop exercises. • Develop data-security-related incident response documentation and playbooks. • Conduct data classification, Purview and DLP awareness/training sessions for business and technical stakeholders. • Support end-user adoption of data classification and labelling. • Prepare project status reports, deliverable documentation, evidence packs and project closure materials. • Participate in knowledge-transfer sessions and ensure effective handover to the client's internal teams. Required Experience • 8+ years of overall experience in cybersecurity, information security, GRC or related areas. • Strong hands-on experience with NIAS / NIAP / NDCP / QCSF or comparable cybersecurity regulatory frameworks. • Strong understanding of ISO 27001, NIST and information security risk management. • Practical experience in data classification, information asset management and data protection. • Hands-on experience with Microsoft Purview, Microsoft 365 E5 and DLP. • Experience developing DLP policies, classification rules, use cases and implementation documentation. • Experience conducting cybersecurity assessments, gap assessments and control maturity assessments. • Experience developing cybersecurity policies, procedures, frameworks, risk registers and treatment plans. • Experience supporting NCSA or equivalent regulatory audits/certification activities. • Strong experience in audit evidence preparation, control testing and remediation tracking. • Experience working with enterprise stakeholders across business, IT, cybersecurity and compliance teams. • Strong documentation and report-writing skills. Preferred Qualifications • CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Lead Auditor or equivalent certification. • Microsoft security certifications, particularly those related to Purview, Information Protection and Compliance. • Experience working in the Qatar / GCC cybersecurity regulatory environment. • Previous experience in the energy, utilities or critical infrastructure sector. • Arabic language capability would be an advantage. Key Competencies • Strong understanding of cybersecurity governance and regulatory requirements. • Ability to translate regulatory requirements into practical controls and implementation activities. • Strong analytical and problem-solving skills. • Excellent stakeholder management and communication skills. • Strong workshop facilitation and presentation skills. • Ability to work independently with limited supervision. • Strong documentation, reporting and evidence-management capabilities. • Ability to operate comfortably between business/GRC requirements and technical implementation teams. Engagement Location: Qatar Engagement: Project-based consultancy Project Duration: Approximately 6 months Focus: NDCP, NIAS v2.1, data classification, Microsoft Purview/DLP, cybersecurity governance and NCSA certification readiness. Languages: Arabic and English Show more Show less
8+ years of overall experience in cybersecurity, information security, GRC or related areas. Strong hands-on experience with NIAS / NIAP / NDCP / QCSF or comparable cybersecurity regulatory frameworks. Strong understanding of ISO 27001, NIST and information security risk management. Practical experience in data classification, information asset management and data protection. Hands-on experience with Microsoft Purview, Microsoft 365 E5 and DLP. Experience developing DLP policies, classification rules, use cases and implementation documentation. Experience conducting cybersecurity assessments, gap assessments and control maturity assessments. Experience developing cybersecurity policies, procedures, frameworks, risk registers and treatment plans. Experience supporting NCSA or equivalent regulatory audits/certification activities. Strong experience in audit evidence preparation, control testing and remediation tracking. Experience working with enterprise stakeholders across business, IT, cybersecurity and compliance teams. Strong documentation and report-writing skills.
Review existing ISMS documentation, data classification policies, procedures and security strategies. Conduct assessments and gap analysis against NIAS v2.1, NDCP, NIAP, QCSF, ISO 27001:2022, NIST and Qatar Data Privacy Law. Conduct stakeholder interviews and workshops across business and technology functions. Perform information security risk and control assessments and develop appropriate treatment plans. Assess the organisation's Microsoft 365 E5 / Microsoft Purview environment and identify opportunities to improve data classification, labelling and DLP capabilities. Develop and enhance the Data Classification & Labelling Strategy and associated governance framework. Develop information asset register templates and support the identification and classification of information assets. Define data criticality, CIA ratings, classification taxonomy and labelling criteria. Develop data classification and DLP use cases and support their implementation. Configure and fine-tune Microsoft Purview DLP policies and classification capabilities. Support implementation of applicable NIAP, NDCP and NIAS governance controls and maintain implementation evidence. Develop security baselines for critical technologies and classification criteria for VLANs, tape drives and removable media. Develop and maintain cybersecurity policies, procedures, risk registers and risk treatment plans. Support the development and finalisation of the Statement of Applicability (SOA). Prepare audit documentation, evidence packs and control testing results for NCSA certification readiness. Support internal audit activities and remediation/closure of audit findings. Support the review and enhancement of Business Continuity and Disaster Recovery plans and participate in tabletop exercises. Develop data-security-related incident response documentation and playbooks. Conduct data classification, Purview and DLP awareness/training sessions for business and technical stakeholders. Support end-user adoption of data classification and labelling. Prepare project status reports, deliverable documentation, evidence packs and project closure materials. Participate in knowledge-transfer sessions and ensure effective handover to the client's internal teams.
Not sure you fit this role?
Upload your CV and see how you score against Intrinsic Security and every other live job. It's free.
Get my free matchesAED 12k–18k a month· est.