Senior IT Governance, Risk & Compliance (GRC) Specialist

  • Qatar

Qatar Engineering & Construction Company (Qcon)

Qatar Engineering & Construction Company (Qcon), established in 1975, is a leading National EPC and Maintenance Contractor serving the Oil & Gas, Petrochemical, Fertilizer, and Power industries in Qatar. With over 5,000 skilled personnel, Qcon delivers EPC projects, construction, maintenance, commissioning, and heavy steel fabrication. Qcon is committed to Safety, Health, Environment, and Quality (SHEQ) and holds international certifications including ISO 9001, OHSAS 18001, and ISO 14001

Role Description

We are seeking a Senior IT Governance, Risk & Compliance (GRC) Specialist based in Doha, Qatar. This role focuses on IT department-specific governance, risk, compliance, and ITDR/BCP activities. The specialist will ensure IT policies, procedures, and systems comply with internal controls and regulatory standards, coordinate IT audits, manage IT risks, and support IT teams in maintaining secure, resilient, and compliant operations.

Key Responsibilities

  • Develop, implement, and maintain IT policies, standards, and procedures (access management, change management, patching, backup, IT security, and ITSM processes).
  • Conduct IT risk assessments and maintain a centralized IT risk register with mitigation tracking.
  • Support internal and external IT audits, including evidence collection, findings remediation, and documentation.
  • Lead IT department-focused Business Continuity and Disaster Recovery planning, including BIA, RTO/RPO definition, DR testing, and reporting.
  • Monitor IT compliance with policies and regulatory requirements, coordinating with Infrastructure, Security, Network, and Helpdesk teams.
  • Maintain IT compliance documentation and contribute to continual service improvement initiatives within IT.

Qualifications & Skills

  • Bachelor’s degree in Information Technology, Computer Science, or related field.
  • Professional certifications preferred: CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or CISSP.
  • 5–8 years of IT experience, with 3–5 years in IT governance, risk, compliance, or audit-focused roles.
  • Strong knowledge of IT risk frameworks, ITSM, and IT security controls.
  • Excellent analytical, documentation, and stakeholder communication skills.
  • Experience in Oil & Gas or EPC industries is a plus, but not required.

Contact Details

Academic Record

Highest Academic

Certifications

Previous Employer

Attachments

Upload your CV/Resume
Upload your Certificates.