GRC Lead managing security compliance and risk governance in Egypt. Driving initiatives for ISO 27001 alignment and overseeing security audits and policies.
Responsibilities
● Maintain an enterprise-wide information security governance & ISMS framework that aligns with business objectives, regulatory requirements, and industry best practices.
● Develop, maintain, and enforce security policies, standards, and procedures.
● Lead strategic planning initiatives for security risk management, ensuring alignment with ISO 27001 requirements.
● Design, implement, and manage a security risk management framework that includes risk assessments, control evaluations, and mitigation strategies.
● Oversee and continuously improve the processes for vendor security risk assessments, ensuring third-party risks are effectively managed.
● Develop and monitor key risk indicators (KRIs) and performance metrics to evaluate the effectiveness of security controls and risk mitigation efforts.
● Oversee the development, implementation, and ongoing management of the organization’s security policies.
● Prepare and lead the organization’s readiness for external and internal security audits, including ISO 27001 certification audits.
● Build and run security awareness and phishing simulation programs and promote an organization-wide culture of security accountability.
● Ensure ongoing compliance with local regulatory frameworks, including those issued by CBE, FRA, and related bodies.
Requirements
● At least 4 years of experience in GRC, information security risk management or security compliance roles.
● Certifications: Relevant certifications such as CISSP, CISM, CRISC, or CISA are preferred.
● Demonstrated experience with ISO 27001 implementation, security audits, and vendor security risk assessments.
● Solid understanding of cloud architectures and security controls across AWS and Google Cloud Platform (GCP).
● Familiarity with regulatory requirements in Egypt and international data protection laws.
● University/college degree in a relevant professional field.
● Excellent communication skills in English, both written and spoken.
Cybersecurity Engineer advancing security posture with real - time threat monitoring using SIEM tools like Splunk. Managing incident response and vulnerability management lifecycle across networks and applications.
Senior Network Security Engineer focusing on MFA services for Verizon's Global Network & Technology team. Collaborating on technical implementation and providing ongoing operational support.
Director managing strategic stakeholder engagement for cyber security initiatives in Australia. Collaborating across governments and industry to drive national cyber preparedness and awareness.
Information Systems Security Officer ensuring operational security for information systems. Collaborating with ISSM and ISO while managing security operations and compliance.
Cybersecurity Engineer Principal at GDIT leads enterprise initiatives for improving identity and access security. Collaborates with leadership to architect modern IAM solutions per Zero Trust Principles.
Manager role supporting Cybersecurity and Technology Risk Oversight Center of Excellence. Leading regulatory exams and audits while collaborating with cross - functional risk management teams.
Cybersecurity Specialist protecting DSV Contract Logistics IT platforms. Manage cybersecurity risks and embed security into IT solutions while ensuring operational continuity.
Regional Security Manager responsible for security operations at EMEA Data Centers. Collaborating with cross - functional teams for compliance and incident management.
Chargé.e d’Etudes et Travaux en systèmes électromécaniques de sécurité at RATP Infrastructures. Responsible for ensuring technical compliance and supervising project activities on - site.