Technology Risk Vice President
Doha, Doha Municipality, Qatar · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 4 weeks ago
- Work mode
- In office
- Education
- Bachelor or Master degree in Computer Science, IT or related fields
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Lesha Aviation Capital is seeking a Technology Risk Vice President to advance and bolster the organization's cybersecurity risk management and assurance practices across their technology landscape. This senior position involves performing and supervising cyber risk assessments, evaluating security controls effectiveness, managing compliance and assurance reviews, and identifying and remediating vulnerabilities and emerging threats. The role will also enhance cybersecurity governance and support regulatory conformity.
Key Responsibilities
- Conduct comprehensive security evaluations of enterprise infrastructure, applications, clouds (Microsoft Azure, Google Cloud Platform, Oracle Cloud Infrastructure), networks, databases, middleware, and security mechanisms.
- Review and evaluate new technology architectures to embed security requirements from the design phase.
- Perform threat modeling and risk assessments for business innovations and emerging technologies including AI, Generative AI, and Machine Learning.
- Define security baselines and configuration standards for IT environments.
- Provide security guidance for enterprise architecture and digital transformation initiatives.
- Lead application security efforts throughout software development lifecycles, integrating SAST, DAST, SCA, penetration tests, and DevSecOps practices into CI/CD pipelines.
- Manage enterprise vulnerability programs including risk-based remediation and penetration testing coordination for applications and infrastructure.
- Govern security monitoring and incident response activities, collaborating with SOC teams to enhance detection and remediation workflows.
- Support major cybersecurity incident investigations and incorporate lessons learned into ongoing risk management processes.
- Act as deputy to the Information Security Officer, supporting governance forums, audits, compliance activities, and preparing metrics and reports to inform executive leadership.
Preferred Certifications
- Offensive Security Certified Professional (OSCP)
- Certified Ethical Hacker (CEH)
- Computer Hacking Forensic Investigator (CHFI)
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
Educational Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Technology, or a closely related discipline.
Experience Required
- Over 10 years of experience in cybersecurity or technology risk assessment and assurance roles.
- Proven experience in applying frameworks and regulations like ISO 27001, NIST, NIA, QCSF, PCI DSS, GDPR, PDPL, or equivalents.
- Demonstrated expertise in cybersecurity risk assessments, control evaluations, and assurance within complex technology environments.
- Hands-on skills in security architecture, cloud security, AI and emerging tech security, application security, DevSecOps methodologies, vulnerability management, penetration testing, security operations, and incident handling.
Technical and Professional Skills
- Enterprise security architecture evaluation and design
- Cybersecurity risk assessment methods
- Cloud platform security (Azure, GCP, OCI)
- Security risk evaluation for AI and emerging technologies
- Application security testing techniques and DevSecOps practices
- Penetration testing coordination and vulnerability management
- Threat modeling and mitigation strategies
- Security information and event management (SIEM) and monitoring
- Executive reporting and engagement with diverse stakeholders
Key Competencies
- Strong analytical skills and risk-based decision-making
- Ability to translate technical cyber issues into business impact
- Comprehensive knowledge of regulatory and compliance adherence
- Leadership and influence across cross-functional teams
- Excellent communication skills with executives and stakeholders
- Balance between governance requirements and business/technology realities
- Proven problem-solving and innovative thinking
Minimum education
Master's Degree