Rejobs
Iberdrola Renewables

Cybersecurity Operations

成为Iberdrola Renewables在卡塔尔多哈的网络安全运营专家。定义并改善Google Cloud、AWS和Azure的云安全策略。与团队合作,确保安全的产品设计和事件响应。期待在动态的工作环境中塑造数字能源解决方案的未来。
Iberdrola Renewables
Iberdrola Renewables
多哈,卡塔尔   现场   全职  UTC+03:00

Iberdrola Renewables

公司简介

伊比德罗拉可再生能源(伊比德罗拉旗下)

西班牙比尔巴鄂

1992年

约43,000名员工(来源:linkedin.com)。2023年收入为493.3亿欧元(来源:technologymagazine.com)。

业务范围

伊比德罗拉通过其可再生能源部门,已成为全球最大的风能生产商,同时在光伏太阳能、水电、储能和新兴网络技术领域也有业务。自2001年转型为清洁能源以来,公司开发了许多标志性项目,如苏格兰的卡兰德十字风电场和西班牙的马兰琼风电场。伊比德罗拉通过陆上和海上风能、光伏太阳能电站和水电系统,生成、分配和供应电力,目标是电气化和能源转型市场(来源:iberdrola.com)。

项目与成就

伊比德罗拉的重点项目包括位于墨西哥的拉文塔三号风电场、西班牙的圣埃斯特沃水电扩建项目,以及位于西班牙巴达霍斯的努涅斯·德·巴尔博亚太阳能电站,装机容量超过500兆瓦。公司还在卡斯蒂利亚和莱昂启动了总计350兆瓦的太阳能电站项目。目前,伊比德罗拉专注于海上风能、太阳能的扩展以及电网现代化,支持2023-2025年470亿欧元的投资计划(来源:iberdrola.com)。

近期发展

在2023年,伊比德罗拉宣布了以可持续性和数字化为重点的品牌演变,成功将其标志的能耗减少了50%。此外,公司与欧洲投资银行达成了6.9亿欧元的协议,用于巴西的可再生能源项目和西班牙的电网数字化。公司还继续推进750亿欧元的投资计划,该计划在COP27上得到了强调,并保持对清洁能源发电能力扩展的关注(来源:iberdrola.com)。

在这里工作

伊比德罗拉提供多种职位,包括工程、建设、运营、创新和管理,所有职位都集中在向清洁能源的转型上。公司的文化强调创新和团队的福祉,促进协作和全球化的工作环境。就业机会在多个关键地点提供,包括比尔巴鄂总部,以及在瓦伦西亚、马德里和美国、英国、巴西和墨西哥等国际市场的办公室(来源:technologymagazine.com)。

联系方式


最后更新于 2025-12-27 | 报告问题

Job Description

East-West Digital (EWD) is seeking a highly skilled Cybersecurity Operations expert to define, implement, and continuously strengthen the company's cloud security strategy across Google Cloud, AWS, and Azure. This role serves as the central reference point for all matters related to cloud privacy, data protection, defensive security, and secure solution design.

Working side-by-side with architecture, development, and product teams, the Cybersecurity Operations expert ensures that all cloud-based products are designed and delivered following a rigorous Privacy & Security by Design approach. The position includes responsibilities across threat modelling, internal security assessments, incident response, automation of controls, and continuous posture management.

This is a senior, high-impact role within EWD's cloud platform domain.

Jobs to Be Done

  1. Define and govern EWD's cloud security framework:
    • Establish best practices for cloud security and privacy across all EWD products.
    • Maintain and enhance the organization's cloud security posture.
    • Develop policies, automated controls, and preventive guardrails across cloud environments.
  2. Guide architecture and development teams:
    • Ensure Security by Design principles are applied throughout the full product lifecycle.
    • Provide expert guidance, architectural reviews, and periodic internal audits.
    • Contribute to secure architecture patterns, design decisions, and implementation strategies.
  3. Perform continuous security evaluation:
    • Identify, analyze, and remediate vulnerabilities across projects.
    • Conduct advanced threat modelling and risk assessments.
    • Perform internal ethical hacking when needed to validate security controls.
  4. Lead detection and incident response operations:
    • Design and implement logging, monitoring, and alerting strategies.
    • Detect threats using native cloud security services.
    • Lead incident response, recovery, and post-incident forensics.
  5. Ensure governance, compliance, and architectural robustness
    • Ensure compliance with internal standards, regulatory requirements, and cloud benchmarks.
    • Conduct architectural reviews to identify gaps and optimize cost-security-complexity trade-offs.
    • Support centralized management of GCP projects, AWS accounts, and Azure subscriptions.

Requirements

Education:

  • Bachelor's degree in Computer Science, Engineering, or a related field.
  • A Master's degree is a plus.

Experience:

  • More than 5 years of experience in cloud security, cloud engineering, or related roles.
  • Extensive hands-on experience with Google Cloud and AWS; Azure experience is a plus.
  • Proven track record implementing DevSecOps, security automation, CI/CD pipelines, and incident response.
  • Previous experience in the energy or utilities sector is advantageous.

Skills and Competencies

Cloud Security & Privacy

  • Strong understanding of data classification, privacy, and protection mechanisms.
  • Expertise in encryption (in transit and at rest), key management, and secret protection.
  • Understanding of secure internet protocols and security operations.
  • Ability to balance cost, security, and deployment complexity.
  • Deep knowledge of the Cloud Shared Responsibility Model.

Identity & Access Management

  • Experience designing and implementing authentication and authorization for cloud resources.
  • Advanced familiarity with:
    • (MUST) Google Cloud: IAM, IAM Conditions, Cloud Identity, Access Context Manager
    • (NICE TO HAVE) AWS: Identity Center, Directory Service, IAM Roles, Permission Sets, Control Tower
    • (NICE TO HAVE) Azure: Entra ID, Conditional Access, PIM, RBAC

Detection, Monitoring & Incident Response

  • Proficiency with tools such as SCC, Chronicle, Cloud Logging & Monitoring, GuardDuty, Security Hub, Inspector, Sentinel, Azure Monitor, etc. (at least one of them)
  • Ability to design logging architectures, dashboarding, alerts, and anomaly detection.
  • Strong incident response and threat-mitigation skills.

Network & Application Security

  • Experience with edge and application protection (e.g. Cloud Armor, IAP, AWS WAF, AWS Network Firewall, Azure Front Door, etc.).
  • Understanding of Zero-Trust principles and secure connectivity patterns.

Data Protection

  • Experience with tools such us Cloud KMS, Secret Manager, CMEK, AWS KMS/CloudHSM, Azure Key Vault, VPC-SC, DLP frameworks, and confidential computing (at least one of them).

Governance & Compliance

  • Knowledge of posture management, CIS benchmarks, regulatory frameworks, SCPs, Assured Workloads, Blueprints, etc.
  • Ability to perform end-to-end architecture reviews with a security focus.

Soft Skills

  • Structured and innovative mindset.
  • Strong team spirit and relationship-building skills.
  • Ability to manage complex situations with sound judgment.
  • Resilience and composure under pressure.
  • Entrepreneurial, proactive, and highly collaborative.

Key Performance Indicators (KPIs)

  • Compliance level with EWD's cloud security framework across all products.
  • Reduction of vulnerabilities and security findings over time.
  • Mean Time to Detect (MTTD) and Mean Time to Resolve (MTTR) for security incidents.
  • Adoption rate of automated security controls across teams.
  • Quality and frequency of internal security audits.
  • Improvement of EWD's cloud security posture metrics (SCC scores, CIS benchmarks, etc.).

Why Join Us?

At East-West Digital, you will help shape the security foundation of a next-generation, cloud-native platform serving real-world energy applications and global customers. You will work with cutting-edge cloud and AI technologies, drive high-impact decisions, and collaborate with multidisciplinary teams in a dynamic, multicultural environment.

East-West Digital is building the future of digital energy solutions from Doha, and this role places you at the core of that transformation-combining innovation, technical excellence, and meaningful impact across the entire organization.

Please note that any applicant who is not a citizen of the country of the vacancy will be subject to compliance with the applicable immigration requirements to legally work in that country.

获取工作提醒

获取多哈,卡塔尔地区职位机会的工作提醒

关于这个角色

2025年12月23日

全职

公司

2026年1月9日

现场

Iberdrola Renewables

iberdrola.com

  •  多哈,卡塔尔

More than 5 years

UTC+03:00

立即申请

工作已过期?

请告知 Iberdrola Renewables 您是在 Rejobs 上找到这份工作的。这将帮助我们成长,并让更多人投身于可再生能源工作!

如何连接

查看您的连接

在 LinkedIn 上查看您在 Iberdrola Renewables 的联系人,在申请此职位时充分利用您的人际网络