GRC Lead managing security compliance and risk governance in Egypt. Driving initiatives for ISO 27001 alignment and overseeing security audits and policies.
Responsibilities
● Maintain an enterprise-wide information security governance & ISMS framework that aligns with business objectives, regulatory requirements, and industry best practices.
● Develop, maintain, and enforce security policies, standards, and procedures.
● Lead strategic planning initiatives for security risk management, ensuring alignment with ISO 27001 requirements.
● Design, implement, and manage a security risk management framework that includes risk assessments, control evaluations, and mitigation strategies.
● Oversee and continuously improve the processes for vendor security risk assessments, ensuring third-party risks are effectively managed.
● Develop and monitor key risk indicators (KRIs) and performance metrics to evaluate the effectiveness of security controls and risk mitigation efforts.
● Oversee the development, implementation, and ongoing management of the organization’s security policies.
● Prepare and lead the organization’s readiness for external and internal security audits, including ISO 27001 certification audits.
● Build and run security awareness and phishing simulation programs and promote an organization-wide culture of security accountability.
● Ensure ongoing compliance with local regulatory frameworks, including those issued by CBE, FRA, and related bodies.
Requirements
● At least 4 years of experience in GRC, information security risk management or security compliance roles.
● Certifications: Relevant certifications such as CISSP, CISM, CRISC, or CISA are preferred.
● Demonstrated experience with ISO 27001 implementation, security audits, and vendor security risk assessments.
● Solid understanding of cloud architectures and security controls across AWS and Google Cloud Platform (GCP).
● Familiarity with regulatory requirements in Egypt and international data protection laws.
● University/college degree in a relevant professional field.
● Excellent communication skills in English, both written and spoken.
Technical support intern assisting clients and monitoring backup systems. Involves client interaction, system maintenance, and adherence to legal standards.
Cybersecurity Engineer responsible for safeguarding information systems and developing cyber security capabilities. Involves project management and collaboration through all phases of software development lifecycle.
Health and Safety Coordinator managing safety programs and practices in Brazil's largest pet ecosystem, Petz. Ensuring compliance and leading safety initiatives across various facilities.
Senior Industrial Security Specialist at Boeing conducting program assessments and managing compliance. Overseeing audits and supporting internal investigations while protecting sensitive information.
Senior/Lead Product Cybersecurity Engineer at Boeing ensuring the security and resilience of digital airplane systems. Leading risk assessments, technical solutions, and stakeholder coordination.
Senior Information Security Analyst at Banco ABC Brasil securing digital assets and ensuring compliance with industry standards. Collaborating with teams to enhance cybersecurity measures and manage incidents.
Security Engineer focused on enhancing cloud security at Ramp, ensuring safe management of financial data. Collaborating with cross - functional teams to remediate security issues and deploy secure solutions.
Sales Enablement Manager at Upwind Security crafting compelling narratives for technical audiences. Collaborating across teams to enhance market readiness and impact through influential content.
Talent Acquisition Partner owning recruitment cycles and enhancing Upwind's culture through AI - driven strategies in a fast - growing startup. Proactively sourcing global Go - To - Market roles while partnering closely with hiring managers.
Principal Associate in Capital One’s Cyber Division managing Information Security for Financial Services. Supporting stakeholders with analysis, reporting, and execution of cyber initiatives within the FS ISO Command Center.