Cytomate

Information Security Consultant

Cytomate

Doha, Doha Municipality, Qatar · Full Time

Be the first to apply

Experience
5–10 yrs
Salary
Openings
1
Posted
1 week ago
Work mode
In office
Education
Bachelor’s degree
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Cytomate

Cytomate is a leading cybersecurity firm based in Doha, Qatar, specializing in developing innovative offensive security technologies across the MENA region. Their comprehensive product suite includes Red Teaming, Penetration Testing, and Reverse Engineering services that help organizations identify security vulnerabilities. Among its proprietary platforms are Breach+, a Breach and Attack Simulation tool for exposing network weaknesses; Sarab, a deception-based product leveraging honey tokens to monitor attacker activity with minimal noise; and SnipeX, an AI-driven system designed to create and modify payloads for bypassing WAFs and other controls. Cytomate is dedicated to enhancing organizational security through dependable and efficient security solutions.

Role Overview

As an Information Security Consultant in the Cybersecurity, Risk and Compliance Advisory team, you will engage directly with clients to deliver services involving information security, cyber risk, regulatory compliance, data privacy, and AI governance across various industries. This role demands collaboration with senior leadership, business units, and technical teams to assess risks, refine governance frameworks, and implement actionable solutions based on recognized standards and regulatory frameworks. This position suits candidates with a strong technical foundation and excellent skills in analysis, documentation, stakeholder communication, and project management.

Key Responsibilities

  • Lead and contribute to cybersecurity governance, risk, compliance, and assurance assignments, including gap and maturity assessments, risk evaluations, internal audits, and preparation for certifications.
  • Design and continuously enhance Information Security Management Systems (ISMS) aligned with ISO/IEC 27001 and other relevant standards such as NIA, QCSF, NIST CSF, CIS Controls, ISO 22301, and PCI DSS.
  • Create and review security policies, procedures, standards, and governance materials like risk registers, risk treatment plans, Statements of Applicability, compliance matrices, and remediation plans.
  • Evaluate the design and functional effectiveness of security controls in domains such as access management, cloud security, vulnerability management, incident response, third-party risk, security operations, business continuity, and disaster recovery.
  • Assist with data privacy compliance initiatives, including privacy gap assessments, data mapping and classification, Records of Processing Activities, Data Protection Impact Assessments, rights management for data subjects, data retention policies, cross-border data transfers, and privacy-by-design implementations.
  • Support AI governance efforts and the implementation of ISO/IEC 42001 standards, including creating AI inventories, risk classification, impact assessments, formulating responsible-use policies, lifecycle management, human oversight, and governance of generative and third-party AI technologies.
  • Coordinate internal, regulatory, and certification audits by overseeing evidence collection, stakeholder interviews, findings management, corrective actions, and audit closure.
  • Conduct client workshops, interviews, awareness sessions, and deliver management presentations, translating complex technical and regulatory requirements into clear, actionable insights.
  • Manage project workstreams, timelines, risks, interdependencies, and client deliverables while preparing detailed reports, executive summaries, proposals, and presentations.
  • Build and maintain trusted client relationships, mentor junior consultants, and contribute to business growth through solution design and proposal development.

Essential Skills and Attributes

  • In-depth understanding of information security governance, risk management, compliance, and assurance.
  • Hands-on experience conducting risk and gap assessments, control audits, internal audits, or preparing for certifications.
  • Proficient knowledge of ISO/IEC 27001 standard and its real-world implementation in complex environments.
  • Familiarity with data privacy principles, privacy risk management, and regulatory compliance requirements.
  • Understanding of AI governance frameworks, responsible AI use, AI risk management, and familiarity with evolving AI regulations.
  • Ability to interpret and apply regulatory and standards-based mandates into feasible controls and implementation steps.
  • Strong analytical thinking, problem-solving skills, and professional judgment.
  • Excellent skills in policy development, report writing, presentations, and detailed documentation.
  • Confident facilitation of workshops and engagement with both technical and non-technical stakeholders.
  • Competence in managing multiple priorities and delivering quality results within deadlines.
  • Meticulous attention to detail and dedication to high-quality delivery.
  • Collaborative mindset with effective teamwork across multidisciplinary groups.
  • Fluency in English, with Arabic language skills considered a plus.

Educational Background and Experience

  • Bachelor’s degree in cybersecurity, information technology, computer science, engineering, risk management, business administration, or allied fields.
  • Between 5 to 10 years of relevant experience in information security, cybersecurity, IT risk, audit, GRC, data privacy, or advisory roles.
  • Proven track record working with ISO/IEC 27001 and other cybersecurity or compliance frameworks.
  • Experience managing client interactions or independently leading consulting projects.
  • Preference given to candidates with prior experience in cybersecurity, technology-risk, audit, or GRC consultancy.
  • Exposure to sectors such as government, financial services, energy, telecommunications, maritime, or regulated industries is advantageous.

Preferred Certifications

  • CISA, CISM, CISSP, CRISC, or CDPSE certifications.
  • ISO/IEC 27001 Lead Auditor or Lead Implementer credentials.
  • ISO/IEC 27701 Lead Auditor or Lead Implementer certifications.
  • ISO/IEC 42001 Lead Auditor or Lead Implementer.
  • CIPP/E, CIPM, or other recognized data privacy qualifications.
  • Certifications in ISO 22301, PCI DSS, cloud security, or related domains.
  • Project management certifications such as PMP or PRINCE2.

Desired Professional Qualities

Cytomate values professionals who demonstrate curiosity, commercial awareness, and a dedication to delivering impactful client outcomes. Candidates should be comfortable navigating the intersection of cybersecurity, privacy, and emerging technology risks while maintaining a pragmatic and risk-based perspective. Working at Cytomate offers a chance to participate in diverse advisory assignments, expand expertise in cybersecurity governance, data privacy, and responsible AI, and contribute to the company’s expanding service offerings.

Minimum education

Bachelor's Degree

Industry

Cybersecurity

How they work

Communication Teamwork & Collaboration Problem Solving Attention to Detail Customer Focus

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer