
EY
Director - Tech Consulting - Cybersecurity
- Permanent
- Doha, Qatar
- Experience 5 - 10 yrs
- Urgent
Job expiry date: 18/11/2025
Job overview
Date posted
04/10/2025
Location
Doha, Qatar
Salary
QAR 50,000 - 60,000 per month
Compensation
Comprehensive package + relocation
Experience
5 - 10 yrs
Seniority
Director
Qualification
Bachelors degree
Expiration date
18/11/2025
Job description
Join EYâs world-leading practice protecting mission critical systems and national critical infrastructure across the GCC and wider MENA region. The role reports to MENA Cyber Security leadership, contributes as a subject matter resource for OT/ICS Cyber Security topics within EYâs Cyber Security Strategy, and entails extensive client travel of 50â80% across GCC/MENA. As a consulting leader, the director supports executives in business development by preparing presentations and designing proposals and solutions for moderately complex projects (and elements of highly complex projects), provides subject matter insight to bids and proposals, creates innovative commercial insights, adapts methods and practices to operational team and cultural needs, contributes to thought leadership, and packages overall project findings into clear, concise, high-quality work products. Engagement delivery responsibilities include leading and delivering DPP and cybersecurity engagements with very minimal supervision; ensuring delivery and quality of final reports; communicating effectively with engagement partners and managers; and building, managing, and motivating high-performing teams. The domain requires solid knowledge of OT and ICS security, strong understanding of the complex and sensitive nature of ICS/SCADA environments, and capability to evaluate cyber risks to SCADA, DCS, Smart Grids, DMS, and ECS system architectures. Technical scope spans ICS/OT products and technologies (including Honeywell, GE, Siemens, ABB), industrial networking protocol security (DNP3, Modbus, Profinet, ZigBee), endpoint OS and Server OS knowledge, OT-capable SIEM and logging/monitoring platforms (Splunk, ArcSight, QRadar), deployment of unidirectional firewalls, host-based firewalls, Anti-Malware, and HIDS in plant/operational environments, awareness of network monitoring platforms (Fidelis XPS, RSA), and endpoint protection tools and hardening (Carbon Black, Symantec, McAfee). The director applies applicable best practices and security standards (NERC-CIP, ISA99/IEC 62443, NIST 800-82, Qatarâs National ICS security standard) and understands plant process systems, plant safety, and plant integrity systems and solutions.
Required skills
Key responsibilities
- Lead and deliver DPP and cybersecurity engagements with very minimal supervision and ensure the delivery and quality of final reports to clients
- Prepare and design proposals, presentations, and solutions for moderately complex projects (and elements of highly complex projects) and provide subject matter insight to bids and proposals
- Evaluate cyber risks to SCADA, DCS, Smart Grids, DMS, and ECS architectures and recommend OT/ICS security controls and architectures
- Direct OT/ICS security solutioning across ICS/OT products and technologies including Honeywell, GE, Siemens, and ABB platforms
- Implement and oversee OT-capable SIEM, security event logging, and monitoring using platforms such as Splunk, ArcSight, and QRadar
- Deploy unidirectional firewalls, host-based firewalls, Anti-Malware, and HIDS within plant and operational environments and verify effectiveness
- Apply industrial networking protocol security for DNP3, Modbus, Profinet, and ZigBee and document compliance requirements
- Align engagements with applicable standards and best practices including NERC-CIP, ISA99 (IEC 62443), NIST 800-82, and Qatarâs National ICS security standard
- Collaborate with engagement partners and managers, build, manage, and motivate high-performing teams, and communicate status and risks
- Support executives in business development, account management, and pipeline activities across the GCC and MENA region
- Create innovative commercial insights for clients, adapt methods to operational team and cultural needs, and contribute to thought leadership
- Package overall project findings into clear, concise, high-quality work products for executive and board-level stakeholders
- Travel extensively (50â80%) for client delivery and business development across GCC and other parts of MENA
Experience & skills
- Possess at least 6+ years of sound industry experience in cyber security and a minimum of 4 years of experience in Information security and OT/ICS cyber security, preferably within Oil and Gas and Power and Utilities
- Demonstrate solid knowledge of the OT and ICS security domain and a strong understanding of ICS/SCADA environments
- Show solid experience with ICS/OT products and technologies including Honeywell, GE, Siemens, and ABB product families and platforms
- Be capable of evaluating cyber risks to SCADA, DCS, Smart Grids, DMS, and ECS system architectures
- Demonstrate solid knowledge of industrial networking protocol security such as DNP3, Modbus, Profinet, and ZigBee
- Hold in-depth endpoint OS and Server OS knowledge applicable to plant and operational environments
- Demonstrate knowledge of OT-capable SIEM, security events logging and monitoring platforms such as Splunk, ArcSight, and QRadar
- Have experience deploying unidirectional firewalls, host-based firewalls, Anti-Malware, and HIDS in plant and operational environments
- Maintain awareness of network monitoring platforms such as Fidelis XPS and RSA and endpoint protection tools and hardening techniques including Carbon Black, Symantec, and McAfee
- Apply applicable best practices and security standards including NERC-CIP, ISA99 (IEC 62443), NIST 800-82, and Qatarâs National ICS security standard
- Hold a Bachelorâs degree in Electronics Technology, Computer Engineering, Electrical engineering, mechatronics or a similar specialization in electronics, PLC, wireless (radio), networking, and/or ICS technology
- Possess internationally recognized technical certifications such as CISSP, GICSP, ISA99, ISO 27001, CCSA, CCSE, CCSP, and EC-Council Ethical Hacker
- Demonstrate an existing track record of successful engagement delivery in data protection & privacy and cyber security, ideally with Big 4 or comparable consulting experience
- Show demonstrated experience in business development and account management and experience managing professional service project teams
- Exhibit excellent command in written and spoken English and willingness to travel extensively (50â80%)