Ref: SP889-10

Job description / Role

Employment: Full Time

Position: Information Security Officer
Section: Human Resources
Company : Nakilat Keppel Offshore & Marine (NKOM)
Location : Ras Laffan / Qatar

Job Summary and Purpose
• Drive a strong and robust information security management system in the organization through threat/vulnerability detection, security scanning, penetration testing, security monitoring, identifying IT/OT security risks and other related information security activities.
• Ensure adherence to the various internal and international information security standards and also to provide technical consultation on multiple information security issues.

Key Accountabilities
• Information Security Management (Nakilat Shipyard Joint Ventures):
• Identify information security vulnerabilities and threats in the company IT/OT technology network and infrastructure using various techniques e.g. penetration testing and vulnerability assessment.
• Collate information from the conducted assessments and recommend appropriate remedial steps.
• Coordinate the development of the organization’s disaster recovery and business continuity plans for information security, and tests readiness.
• Develop, review improve and update information security policies, procedures, guidelines and other related documents.
• Provide support to build the organization wide information security awareness and training programs. Contribute and provide contents for its awareness activities.
• Monitor, evaluate and ensure the segregation of duties on all systems in order to mitigate the risk of unintentional and/or deliberate system misuse.
• Ensure compliance with the applicable internal and international information security standards (NIA, ISO27001).
• Monitor changes in legislation and accreditation standards that affect information security, notify the concerned parties and assists other departments to ensure regulatory compliance.
• Ensure appropriate administrative, physical and technical safeguards are in place to protect information assets from internal and external threats.
• Liaise and maintain contact with law enforcement authorities, regulatory bodies, security groups and industry forums in the field of Information Security.
• Prepare security baselines and safeguard applications, operating systems and infrastructure devices by adopting the latest standards.
• Resolve information security issues and improve the information security performance by providing technical consultation in system development, acquisition, procurement, implementation, change management, operation/support, and architectural and other ad-hoc projects.
• Assist in operation areas related to information security and follow the related processes to provide support in information security initiatives.
• Work with the concerned parties on the security incidents and vulnerability management processes from design to implementation and beyond.
• Review technical information in the requirements statements, feasibility analysis, operating procedure manuals, and other documents produced in the process of system development.
• Monitor and assess the system security, system audit trails/logs and the veracity of system configurations whenever required.
• Assist in performing on-going security monitoring of information systems including assessing information security risk, conducting functional and gap analyses to determine the extent to which key business areas and infrastructure comply with statutory and regulatory requirements.
• Evaluate and recommend new information security technologies and countermeasures against threats to information or privacy and developing security reports and dashboards.
• Provide assistance in identifying, recording, reporting and resolving the various security violations.
• Support and assist the other activities linked with Enterprise Risk and Business Continuity Management such as Risk Assessments and Business Impact Analysis.

Key Result Areas
• Contribute to the development and management of policies and procedures for Information Security Management.
• Develop and contribute organization wide information security awareness programs and training.
• Prepare Information Security related risk assessments, reports and other relevant documentation.
• Conduct the required tests to identify threats and vulnerabilities for IT and OT infrastructure.


• Bachelor's Degree in Computer Science or any other equivalent field.
• Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH) and Certified ISO27001 Lead implementer are required.
• Globally recognized credential certification is preferred in Information Security domain for example, CISM, ISO27001LA.

• Minimum of 4 years of Information Security experience. IT background is preferred.

About the Company

N-KOM is one of Middle East's leading shipyards, offering a comprehensive range of marine services as well as solutions for the oil and gas industry.

Strategically located at the heart of oil and gas activities in the Arabian Gulf, Nakilat-Keppel Offshore & Marine (N-KOM) combines a wealth of experience and expertise from its parent companies Qatar Gas Transport Company (Nakilat) and Keppel Offshore & Marine (KOM), to provide repair, conversion and construction services for marine vessels, offshore and onshore structures.

Spanning over 50 hectares, the comprehensive facility is equipped with two graving docks and a floating dock that can easily accommodate VLCCs, quays and piers offering a total berthage capacity of 3,150m, a range of workshops ideally situated in front of the drydocks, more than 500,000sqm of fabrication area and sub-contractor facilities on-site, thus enhancing the shipyard's flexibility and capabilities.

With a team of experienced industry professionals, extensive infrastructure and track record of safe, quality and timely project executions, N-KOM has rapidly established itself as the preferred shipyard in the Middle East.

Get personalised updates on latest vacancies
Job Alerts by Email
  • Personalised updates on latest career opportunities
  • Insights on hiring and employment activity in your industry
  • Typically sent twice a month