QNB3810 - Senior Manager, Offensive Cyber Security

  • Business Unit
    QNB - Qatar
  • Division
    Risk Management
  • Department
    Risk Management
  • Location
    Doha, Qatar
  • Closing Date
    22-Aug-2026
About QNB

Established in 1964 as the country’s first Qatari-owned commercial bank, QNB Group has steadily grown to become the largest bank in the Middle East and Africa (MEA) region.

QNB Group’s presence through its subsidiaries and associate companies extends to more than 31 countries across three continents providing a comprehensive range of advanced products and services. The total number of employees is more than 28,000 serving up to 20 million customers operating through 1,000 locations, with an ATM network of 4,300 machines.

QNB has maintained its position as one of the highest rated regional banks from leading credit rating agencies including Standard & Poor’s (A), Moody’s (Aa3) and Fitch (A+). The Bank has also been the recipient of many awards from leading international specialised financial publications.

Based on the Group’s consistent strong financial performance and its expanding international presence, QNB currently ranks as the most valuable bank brand in the Middle East and Africa, according to Brand Finance Magazine.

QNB Group has an active community support program and sponsors various social, educational and sporting events.

Job Summary

The incumbent will have the responsibility to assess the Information Technology applications and infrastructure in the Group for any gaps from IT Security Policies and Standards. The incumbent will be responsible for undertaking vulnerability scanning of IT assets, for participating in the QNB Red Team that conducts simulated offensive attack exercises and for managing the relationships with penetration testing vendors. This highly technical role must have an ethical hacking skillset and background.

Main Responsibilities

A. Shareholder & Financial:

  • Ability to adhere to divisional Key Performance Indicators (KPI’s) for performance monitoring and quality measurement purposes.

  • Implements KPI’s and best practices for Offensive Cyber Security.

  • Promote cost consciousness and efficiency and enhance productivity, to minimise cost, avoid waste, and optimise benefits for the bank.

  • Act within the limits of the powers delegated to the incumbent.

B. Customer (Internal & External):

  • Ability to perform security assessments of QNB systems. Assessing the effectiveness of the systems, the security architecture design, compliance to IT security policies and relevant standards.

  • Ability to develop close relationships with IT and business teams. Understand and manage their requirements for GIS risk services.

  • Ability to provide Ad-hoc consultancy for risks of new technologies and propose with potential solutions.

  • Ability to identify opportunities and develop new ideas that will lead to improvements.

  • Ability to adapt/change behavior or plans to better achieve the target/objective.

  • Ability to analyze a complex problem and identify potential solutions by exploring and analyzing diverse alternatives, including, where applicable, risks and potential business impact. Ability to make the right decisions based on the necessary information and to take measures accordingly.

  • Ability to liaise with external consultants appointed from time to time to assess the adequacy and effectiveness of the Group’s information security efforts.

  • To assist customers in all their queries on Bank’s product and seek solution to their requests.

  • Maintain activities in accordance with Service Level Agreements (SLAs) with internal departments/units to achieve improvements in turn-around time.

  • Build and maintain strong/effective relationships with related departments/units to achieve the Group’s objectives.

  • Provide timely/accurate data to external/internal Auditors, Compliance, Financial Control and Risk when required.

C. Internal (Processes, Products, Regulatory):

  • Ability to set high targets/objectives for self and department. Prefers to take the initiative than to stay passive if events happen. Committed to improving productivity. Unwilling to accept average performance. Tries to be above the requested performance.

  • Ability to identify own strengths and limitations. Seeks guidance and advice when appropriate to accomplish tasks and perform the role in an effective and efficient way.

  • Ability to play a constructive role as member of the team.

  • Ability to assess the effectiveness of the various information security systems and network topologies and evaluate security posture of QNB.

  • Ability to provide required support for enforcing the security policies of the organization.

  • Ability to build and maintain strong and effective relationship with all other related departments and units to achieve the Group’s goals/ objectives.

  • Ability to keep Group Information Security Management apprised of the latest security trends and vulnerabilities.

D. Learning & Knowledge:

  • Possess an understanding of business processes and controls in all related operational areas.

  • Must have an expert understanding of information security issues, best practices, and a working knowledge of IT systems.

  • Proactively identify areas for professional development of self and undertake development activities.

  • Seek out opportunities to remain current with all developments in professional field.

E. Legal, Regulatory, and Risk Framework Responsibilities:

  • Comply with all applicable legal, regulatory and internal compliance requirements including, but not limited to, Group Compliance Policies and Procedures (AML & CTF, Sanctions Policy, Data Protection Policy, Fraud Control Policy, Whistle Blowing Policy, Conflict of Interest and Insider Dealing Policy).

  • Understand and effectively perform your role under the Three Lines of Defense principle to identify measure, monitor, manage and report risks.

  • Ensure systematic good outcomes for clients in accordance with Conduct Risk policy.

  • Support the framework of RCSA, KRI, Incident reporting and remediation, as appropriate, in accordance with the Operational Risk Management requirements.

  • Maintain appropriate knowledge to ensure full qualification to undertake the role.

  • Complete all mandatory training provided by the Bank, attain, and maintain the required levels of competence.

  • Attend mandatory (internal and external) seminars as instructed by the Bank.

Education and Experience Requirements
  • Bachelor’s degree preferably with a Major in Marketing, Banking, Finance, Accounting, Economics, Business

  • Administration or Information Technology (related field of study), Masters preferred.

  • At least 8 years of experience in undertaking technical security assessments of complex IT solutions including penetration testing, preferably within a highly rated international bank.

  • Experience in undertaking red team activities is beneficial

  • Professional offensive cybersecurity certifications (SANS, Offensive Security, etc.)

  • Professional certification such as CISSP, CISM, CISA is mandatory.

  • Previous Banking or Big 4 Consultancy work experience is mandatory

  • Excellent oral and written communication skills (including report writing) in English and Arabic.

  • Good interpersonal and presentation skills.

  • Understanding of the relevant laws, regulations, and practices.

  • Ability to make decisions and follow through with initiatives.

  • Personal integrity and self-management.

  • Planning, organizing, and analytical ability.

  • Results oriented.

  • Strong analytical skills and the ability to communicate both verbally and in writing with all levels of management.

  • Strong knowledge of penetration testing tools and techniques of application and infrastructure components.

  • Strong knowledge of network topologies, logical access controls and firewalls technologies.

  • Strong knowledge of operating systems (Wintel, Solaris and Linux)

  • Having an understanding or experience in identifying zero day exploits

  • Having experience in designing and risk assessing multi-forest Active Directory domains

  • Programming experience (Python, Golang, Rust, PowerShell, C#, etc)Ability to work under pressure

Note: you will be required to attach the following:
  1. Resume/CV
  2. Copy of Passport or QID
  3. Copy of Education Certificate