Назад
Company hidden
5 часов назад

GRC Lead (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Egypt
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Lead (Cybersecurity): Managing enterprise information security governance, risk, compliance, and ISMS activities in a hybrid Cairo-based role with an accent on ISO 27001 alignment, security audits, vendor risk assessments, and regulatory compliance. Focus on designing risk management frameworks, evaluating security controls, leading audit readiness, and building organization-wide security awareness programs.

Location: Cairo, Cairo Governorate, Egypt; hybrid

Company

hirify.global operates a technology organization requiring enterprise-wide information security governance, risk management, and regulatory compliance.

What you will do

  • Maintain the enterprise information security governance and ISMS framework in alignment with business objectives, regulations, and industry standards.
  • Develop, maintain, and enforce security policies, standards, and procedures.
  • Design and manage security risk processes covering risk assessments, control evaluations, mitigation strategies, and key risk indicators.
  • Oversee vendor security risk assessments and third-party risk management.
  • Lead internal and external audit readiness, including ISO 27001 certification audits.
  • Run security awareness and phishing simulation programs while partnering with engineering, product, and legal teams.

Requirements

  • At least 4 years of experience in GRC, information security risk management, or security compliance.
  • Experience implementing ISO 27001, conducting security audits, and managing vendor security risk assessments.
  • Solid understanding of cloud architectures and security controls across AWS and Google Cloud Platform.
  • Familiarity with Egyptian regulatory requirements, including CBE and FRA frameworks, and international data protection laws.
  • University or college degree in a relevant professional field.
  • Excellent written and spoken English.

Nice to have

  • CISSP, CISM, CRISC, or CISA certification.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →