Data Analyst
Qureos IncDoha, QatarAnalyze metering data from Advanced Metering Infrastructure (AMI) and related systems to identify consumption patterns, trends, anomalies, and operational insights.Prepare analytical reports, dashb... أظهر المزيد
Job Description
The Application Security and Data Protection Lead is responsible for establishing, governing, and continuously improving application security and data protection capabilities across the organisation. The role ensures that applications, APIs, databases, integrations, and sensitive data assets are protected through secure design, secure development practices, risk-based vulnerability management, privacy-by-design, data classification, encryption, access governance, and data loss prevention controls. The lead ensures all security assessments are conducted systematically and documented thoroughly. This includes maintaining evidence integrity, preparing comprehensive reports, recommending corrective actions, and enhancing the organization’s capabilities to prevent and respond to data breaches and application vulnerabilities.
Requirements
Strong knowledge of secure SDLC, DevSecOps, application security governance, secure architecture principles, threat modelling, OWASP Top 10, OWASP ASVS, OWASP API Security Top 10, CWE/SANS Top 25, and risk-based vulnerability remediation. Good working knowledge of web, mobile, API, microservices, database, container, and cloud-native application architectures, including authentication, authorisation, session management, secrets management, input validation, logging, and secure configuration controls. Knowledge of data protection frameworks, data lifecycle management, data classification, encryption, key management, DLP, database activity monitoring, access control, privileged access, identity governance, privacy impact assessments, and regulatory control mapping. Experience using application security and DevSecOps tooling such as SAST, DAST, IAST, SCA, secrets scanning, container image scanning, IaC scanning, API security testing, vulnerability-management, SIEM, SOAR, ticketing, GRC, and case management platforms. Ability to translate application and data protection risks into pragmatic engineering requirements, security acceptance criteria, remediation plans, exception decisions, and executive-level risk summaries. Ability to use or govern tools and platforms such as SAST/DAST/SCA scanners, API testing tools, code repositories, CI/CD pipelines, DLP, CASB, DSPM, SIEM, EDR/XDR, cloud-native security controls, database security tools, and vulnerability management solutions. Equivalent practical experience is acceptable. Basic to intermediate skills in PowerShell, Python, Bash, Java, JavaScript, .NET, SQL, KQL, SPL, or similar scripting, query, and development languages to support secure code review, automation, investigation, and control validation. Ability to define application security standards, secure coding guidelines, data protection procedures, control baselines, metrics, dashboards, and management reports for technical teams and senior stakeholders. Good stakeholder management, communication, coaching, and presentation skills, with the ability to influence developers, architects, platform teams, data owners, legal, compliance, audit, and senior management. Strong analytical thinking, attention to detail, sound judgement, and ability to prioritise application and data risks based on business impact, exploitability, regulatory exposure, and operational urgency. High level of integrity and discretion. The candidate must handle confidential data, sensitive application findings, credentials, customer information, regulated data, and investigation material in a secure and ethical manner. Ability to support urgent application security, data breach, vulnerability disclosure, audit, and regulatory response activities outside normal working hours through an approved on-call or escalation arrangement, when required.
Application Security and Data Protection Lead • Doha, DA, qa