Technology Risk Vice President

🏢 lesha aviation capital
📍 Doha, QatarFull-timeOn-site
📅 Posted: 4d ago🔄 Updated: 4d ago
CV%
✨ AI Summary
Lesha Bank LLC is seeking an experienced Technology Risk Vice President to enhance its cybersecurity risk management and assurance capabilities. This role involves conducting cybersecurity risk assessments, evaluating security controls, monitoring risk exposure, and supporting remediation efforts across business entities and technology environments. The Vice President will also contribute to the Group's cybersecurity governance, risk management, and regulatory compliance framework. Key responsibilities include conducting security reviews of enterprise infrastructure, applications, cloud environments, and emerging technologies like AI. The role also entails leading application security assessments, overseeing vulnerability management and penetration testing, and providing governance for security operations and incident response. A strong analytical and risk-based decision-making capability, excellent communication skills, and the ability to translate technical cybersecurity issues into business risks are crucial.
Required Skills
Information Technology
CybersecurityThreat ModelingAI SecuritySecurity ArchitectureIncident ResponseSIEM
Soft Skills & Professional Competencies
Stakeholder Management
Requirements
The Technology Risk Vice President will be responsible for conducting and overseeing cybersecurity risk assessments, evaluating security controls, performing cybersecurity assurance and compliance reviews, monitoring technology and cyber risk exposure, and supporting the remediation of identified vulnerabilities. The role requires a strong blend of cybersecurity risk management, security assurance, and technical security expertise, with the ability to assess complex technology environments and engage effectively with stakeholders. Experience with enterprise security architecture, cloud security, AI security, application security, DevSecOps, vulnerability management, penetration testing, security operations, and incident response is essential. Experience supporting compliance with frameworks like ISO 27001, NIST, and GDPR is also required.
Description
Full TimeDoha, QatarPosted 2 weeks agoLesha Bank LLC (Public)Job SummaryWe are seeking an experienced Technology Risk Vice President to strengthen and enhance Lesha Group's cybersecurity risk management and assurance capabilities across its business entities and technology environments.The role will be responsible for conducting and overseeing cybersecurity risk assessments, evaluating the effectiveness of security controls, performing cybersecurity assurance and compliance reviews, monitoring technology and cyber risk exposure, and supporting the remediation of identified vulnerabilities, control deficiencies, and emerging threats. The position will also contribute to the ongoing enhancement of the Group's cybersecurity governance, risk management, and regulatory compliance framework.The successful candidate will possess a strong blend of cybersecurity risk management, security assurance, and technical security expertise, with the ability to assess complex technology environments and engage effectively with business stakeholders, technology teams, project managers, third-party service providers, auditors, and regulatory authorities to strengthen the Group's overall cyber resilience and risk posture.Key ResponsibilitiesSecurity Architecture & Technology RiskConduct security reviews of enterprise infrastructure, applications, cloud environments, networks, databases, middleware, and security solutions.Review proposed technology solutions and architectures to ensure security requirements are incorporated by design.Perform threat modelling and security risk assessments for new technologies and business initiatives.Define and assess security baselines and configuration standards.Provide security recommendations for enterprise architecture and technology transformation initiatives.Cloud, AI & Emerging Technology SecurityAssess and strengthen security controls across Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure environments.Conduct cloud security assessments covering identity, network security, workloads, containers, data protection, logging, and monitoring.Support security governance for container environments.Conduct security and risk assessments of AI, Generative AI, Machine Learning, and emerging technology solutions.Assess security controls and compliance requirements for AI-powered applications and third-party AI service providers.Establish appropriate security controls for cloud-native, AI-enabled, and emerging technology environments.Application Security & DevSecOpsLead application security assessments throughout the software development lifecycle.Establish and enhance secure SDLC and DevSecOps practices.Integrate security testing and controls into CI/CD pipelines.Oversee SAST, DAST, SCA, penetration testing, and application security reviews.Work closely with development teams to identify and remediate application security vulnerabilities.Promote security-by-design principles across application development and technology projects.Vulnerability & Security TestingOversee enterprise vulnerability management and risk-based vulnerability remediation.Manage penetration testing activities for applications, infrastructure, and external-facing systems.Coordinate internal and external penetration testing engagements and track remediation.Establish vulnerability management KPIs, KRIs, risk acceptance processes, and remediation timelines.Chair or facilitate vulnerability remediation governance forums where required.Identify recurring vulnerabilities and drive improvements to the organization's overall security posture.Security Operations & Incident ManagementProvide governance and oversight of security monitoring and incident response capabilities.Work with SOC and security operations teams to improve detection, response, and remediation processes.Review SIEM use cases, security monitoring requirements, and incident management processes.Support major cybersecurity incident investigations and post-incident improvement activities.Ensure lessons learned from incidents are incorporated into security controls and risk management processes.Cybersecurity Governance, Risk & Compliance SupportAct as a deputy to the Information Security Officer when required, ensuring business continuity and ongoing execution of cybersecurity governance, risk management, compliance, and assurance activities.Provide analytical and administrative support to cybersecurity governance forums, risk committees, and management review meetings, including the preparation of presentations, reports, and action tracking.Support internal, external, and regulatory audits through evidence collection, stakeholder coordination, tracking of findings, and monitoring of remediation activities.Prepare and maintain cybersecurity metrics, dashboards, risk reports, KPIs, KRIs, and management reporting materials for governance and oversight purposes.Perform cybersecurity assurance activities and control effectiveness reviews to support the evaluation of the Group's cybersecurity maturity and control environment.Preferred CertificationsOSCP – Offensive Security Certified ProfessionalCEH – Certified Ethical HackerCHFI – Computer Hacking Forensic InvestigatorCISSP – Certified Information Systems Security ProfessionalCISM – Certified Information Security ManagerEducational Qualifications RequiredBachelor or Master degree in Computer or IT or any related fieldsExperience RequirementsMore than 10 years of experience in Cybersecurity / Technology Risk Assessment and AssuranceExperience supporting compliance with recognized frameworks and regulations such as ISO 27001, NIST, NIA, QCSF, PCI DSS, GDPR, PDPL, or similar standards.Hands-on experience conducting cybersecurity risk assessments, control reviews, and security assurance activities.Skilled in enterprise security architecture reviews, cloud, AI, emerging technologies security reviews, application security reviews, DevSecOps, vulnerability assessment, penetration testing, security operations and information security incident management.Technical And Professional Skills RequiredEnterprise Security ArchitectureCybersecurity Risk AssessmentsCloud SecurityAI SecurityApplication SecurityDevSecOpsVulnerability ManagementPenetration TestingThreat ModellingSecurity Operations & Incident ResponseSIEM and Security MonitoringExecutive Reporting and Stakeholder ManagementKey CompetenciesStrong analytical and risk-based decision-making capability.Ability to translate technical cybersecurity issues into business risks.Strong understanding of regulatory and compliance requirements.Ability to lead cybersecurity initiatives across multiple business and technology functions.Excellent stakeholder and executive communication skills.Ability to balance governance requirements with practical technology and business needs.Strong leadership, influencing, and problem-solving capabilities.First NameLast Name (optional)Country (optional)Email addressMessageUpload CVUpload your CV/resume or any other relevant file. Max. file size: 256 MB.Key ResponsibilitiesSecurity Architecture & Technology RiskConduct security reviews of enterprise infrastructure, applications, cloud environments, networks, databases, middleware, and security solutions.Review proposed technology solutions and architectures to ensure security requirements are incorporated by design.Perform threat modelling and security risk assessments for new technologies and business initiatives.Define and assess security baselines and configuration standards.Provide security recommendations for enterprise architecture and technology transformation initiatives.Cloud, AI & Emerging Technology SecurityAssess and strengthen security controls across Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure environments.Conduct cloud security assessments covering identity, network security, workloads, containers, data protection, logging, and monitoring.Support security governance for container environments.Conduct security and risk assessments of AI, Generative AI, Machine Learning, and emerging technology solutions.Assess security controls and compliance requirements for AI-powered applications and third-party AI service providers.Establish appropriate security controls for cloud-native, AI-enabled, and emerging technology environments.Application Security & DevSecOpsLead application security assessments throughout the software development lifecycle.Establish and enhance secure SDLC and DevSecOps practices.Integrate security testing and controls into CI/CD pipelines.Oversee SAST, DAST, SCA, penetration testing, and application security reviews.Work closely with development teams to identify and remediate application security vulnerabilities.Promote security-by-design principles across application development and technology projects.Vulnerability & Security TestingOversee enterprise vulnerability management and risk-based vulnerability remediation.Manage penetration testing activities for applications, infrastructure, and external-facing systems.Coordinate internal and external penetration testing engagements and track remediation.Establish vulnerability management KPIs, KRIs, risk acceptance processes, and remediation timelines.Chair or facilitate vulnerability remediation governance forums where required.Identify recurring vulnerabilities and drive improvements to the organization's overall security posture.Security Operations & Incident ManagementProvide governance and oversight of security monitoring and incident response capabilities.Work with SOC and security operations teams to improve detection, response, and remediation processes.Review SIEM use cases, security monitoring requirements, and incident management processes.Support major cybersecurity incident investigations and post-incident improvement activities.Ensure lessons learned from incidents are incorporated into security controls and risk management processes.Cybersecurity Governance, Risk & Compliance SupportAct as a deputy to the Information Security Officer when required, ensuring business continuity and ongoing execution of cybersecurity governance, risk management, compliance, and assurance activities.Provide analytical and administrative support to cybersecurity governance forums, risk committees, and management review meetings, including the preparation of presentations, reports, and action tracking.Support internal, external, and regulatory audits through evidence collection, stakeholder coordination, tracking of findings, and monitoring of remediation activities.Prepare and maintain cybersecurity metrics, dashboards, risk reports, KPIs, KRIs, and management reporting materials for governance and oversight purposes.Perform cybersecurity assurance activities and control effectiveness reviews to support the evaluation of the Group's cybersecurity maturity and control environment.Preferred CertificationsOSCP – Offensive Security Certified ProfessionalCEH – Certified Ethical HackerCHFI – Computer Hacking Forensic InvestigatorCISSP – Certified Information Systems Security ProfessionalCISM – Certified Information Security ManagerEducational Qualifications RequiredBachelor or Master degree in Computer or IT or any related fieldsExperience RequirementsMore than 10 years of experience in Cybersecurity / Technology Risk Assessment and AssuranceExperience supporting compliance with recognized frameworks and regulations such as ISO 27001, NIST, NIA, QCSF, PCI DSS, GDPR, PDPL, or similar standards.Hands-on experience conducting cybersecurity risk assessments, control reviews, and security assurance activities.Skilled in enterprise security architecture reviews, cloud, AI, emerging technologies security reviews, application security reviews, DevSecOps, vulnerability assessment, penetration testing, security operations and information security incident management.Technical And Professional Skills RequiredEnterprise Security ArchitectureCybersecurity Risk AssessmentsCloud SecurityAI SecurityApplication SecurityDevSecOpsVulnerability ManagementPenetration TestingThreat ModellingSecurity Operations & Incident ResponseSIEM and Security MonitoringExecutive Reporting and Stakeholder ManagementKey CompetenciesStrong analytical and risk-based decision-making capability.Ability to translate technical cybersecurity issues into business risks.Strong understanding of regulatory and compliance requirements.Ability to lead cybersecurity initiatives across multiple business and technology functions.Excellent stakeholder and executive communication skills.Ability to balance governance requirements with practical technology and business needs.Strong leadership, influencing, and problem-solving capabilities.
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00