Jobs Companies SSC HR Solutions Information Security and Risk Manager

Sobre este puesto de Information Security and Risk Manager en SSC HR Solutions

SSC HR Solutions · Presencial · Cairo, Cairo Governorate, Egypt

Information Security & Risk Manager

1. Job Details

Position Title: Information Security & Risk Manager
Department: Technology Services / IT
Reports To: Information Security / CTO
Employment Type: Permanent
Location: Maadi, Degla – On-site
Grade: As per organizational structure
Direct Reports: As per approved organizational structure

2. Job Purpose

The Information Security & Risk Manager is responsible for leading the organization’s Information Security and Cyber Risk function. The role will design, implement, and maintain the cybersecurity program, manage enterprise information security risks, ensure compliance with applicable Saudi regulatory and industry requirements, and promote a strong security-aware culture across the organization.

The role provides strategic and operational leadership across Information Security Governance, Risk & Compliance (GRC), Security Operations, Incident Response, Data Protection, and Security Awareness.

3. Key Accountabilities & Deliverables

The role will be accountable for the development, implementation, and continuous improvement of:

  • Information Security Strategy and Cybersecurity Roadmap
  • Information Security policies, standards, procedures, and guidelines
  • Information Security Management System (ISMS)
  • Enterprise IT and Cybersecurity Risk Register
  • Information Security Risk Assessment Reports
  • Risk Treatment and Remediation Plans
  • Security Compliance Reports, including ISO 27001 and applicable regulatory requirements
  • Cybersecurity Control Framework and Control Effectiveness Reports
  • Vulnerability Assessment and Penetration Testing (VAPT) Reports
  • Cybersecurity Incident Reports and Root Cause Analysis (RCA)
  • Security Monitoring and Threat Dashboards
  • Cybersecurity KPI and KRI Dashboards
  • Identity and Access Management (IAM) Policies, Models, and Access Matrices
  • Data Classification and Data Protection Framework
  • Internal and External Audit Reports and Evidence Repository
  • Audit Findings and Remediation Tracking
  • Business Continuity and Disaster Recovery (BCP/DR) Security Alignment
  • Security Awareness and Training Programs and Reports
  • Regulatory Assessments, submissions, and compliance evidence

4. Key Responsibilities

A. Information Security Strategy & Governance

  • Define, develop, and execute the organization’s Information Security Strategy and cybersecurity roadmap.
  • Own and continuously improve the Information Security Management System (ISMS).
  • Develop and maintain information security policies, standards, procedures, and guidelines.
  • Establish effective cybersecurity governance frameworks aligned with business objectives.
  • Provide regular reporting on cybersecurity posture, risk exposure, compliance, and security program performance to the CTO and executive leadership.
  • Establish and monitor security KPIs, KRIs, and performance metrics.
  • Ensure information security requirements are incorporated into technology initiatives, projects, and business processes.

B. Information Security Risk Management

  • Lead regular information security and cybersecurity risk assessments across the organization.
  • Own and maintain the enterprise IT and cybersecurity risk register.
  • Identify, assess, prioritize, and communicate information security risks.
  • Develop and manage risk treatment plans and ensure remediation activities are tracked through to closure.
  • Work closely with business units, IT, and other stakeholders to establish appropriate risk mitigation strategies.
  • Translate technical cybersecurity risks into business impact and communicate them effectively to senior management.
  • Monitor the organization’s overall cyber risk profile and provide recommendations for risk reduction.

C. Security Operations & SOC

  • Oversee Security Operations Centre (SOC) activities, including SOC Analysts and Security Engineers.
  • Ensure effective security monitoring, threat detection, investigation, and response capabilities.
  • Oversee SIEM operations and security monitoring platforms such as Microsoft Sentinel, Splunk, or equivalent technologies.
  • Establish and monitor security incident management processes.
  • Review security alerts, incidents, trends, and threat intelligence.
  • Ensure appropriate escalation and response mechanisms are in place for critical security events.
  • Monitor and improve the effectiveness of security controls and operational processes.

D. Cybersecurity Incident Response

  • Lead the organization’s cybersecurity incident response capability.
  • Ensure effective detection, containment, eradication, recovery, and post-incident activities.
  • Develop, maintain, and continuously improve the Cybersecurity Incident Response Plan (CIRP).
  • Conduct regular incident response exercises and simulations.
  • Lead investigations into significant security incidents and ensure Root Cause Analysis (RCA) is completed.
  • Track corrective and preventive actions resulting from security incidents.
  • Ensure lessons learned are incorporated into security controls and processes.

E. Governance, Risk & Compliance

  • Lead Information Security Governance, Risk, and Compliance (GRC) activities.
  • Ensure compliance with applicable regulatory and industry requirements, including:
    • National Cybersecurity Authority (NCA) requirements
    • Saudi Personal Data Protection Law (PDPL)
    • National Data Management Office (NDMO) requirements, where applicable
    • ISO/IEC 27001
    • Other applicable cybersecurity and data protection regulations
  • Coordinate internal and external security audits and assessments.
  • Manage audit evidence collection and maintain an organized security evidence repository.
  • Track audit findings, remediation plans, and closure status.
  • Prepare management and regulatory compliance reports.
  • Support regulatory assessments, reviews, and submissions as required.

F. Data Protection & Privacy

  • Establish and maintain data protection and information classification frameworks.
  • Ensure appropriate security controls are implemented for sensitive and personal data.
  • Work with relevant stakeholders to support compliance with PDPL and applicable data protection requirements.
  • Establish appropriate data access, handling, retention, and protection controls.
  • Support privacy and data protection risk assessments where required.

G. Vulnerability & Security Testing

  • Oversee vulnerability management activities across IT environments.
  • Coordinate Vulnerability Assessments and Penetration Testing (VAPT).
  • Review vulnerability and penetration testing reports.
  • Ensure security vulnerabilities are appropriately prioritized based on business risk.
  • Track remediation activities and validate closure of critical and high-risk vulnerabilities.
  • Ensure security testing is incorporated into relevant technology projects and systems.

H. Identity & Access Management

  • Establish and maintain IAM policies, standards, and access control frameworks.
  • Ensure appropriate access governance and segregation of duties.
  • Review privileged access and high-risk accounts.
  • Support periodic user access reviews and access recertification.
  • Ensure access controls align with business requirements and security policies.

I. Security Awareness & Culture

  • Develop and implement an organization-wide security awareness program.
  • Lead cybersecurity awareness campaigns and security training.
  • Implement phishing simulation and social engineering awareness programs.
  • Monitor employee security awareness performance and identify improvement areas.
  • Promote a strong cybersecurity culture across all business functions.

J. Business Continuity & Disaster Recovery

  • Ensure cybersecurity requirements are incorporated into Business Continuity and Disaster Recovery plans.
  • Participate in BCP/DR risk assessments and exercises.
  • Ensure critical systems have appropriate security, recovery, and resilience controls.
  • Support testing and continuous improvement of security-related recovery procedures.

5. Qualifications & Experience

Minimum Qualifications

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Security, or a related discipline.
  • CISSP or CISM certification – Mandatory.
  • ISO/IEC 27001 Lead Implementer or Lead Auditor certification preferred.
  • NCA-related cybersecurity accreditation or certification is preferred.

Minimum Experience

  • 8–10 years of professional experience in Information Security / Cybersecurity.
  • At least 3 years of experience in a cybersecurity or information security management/leadership role.
  • Proven experience managing enterprise cybersecurity programs and security teams.
  • Proven experience in GRC, risk management, security operations, and incident response.
  • Proven experience working with regulatory compliance, audits, and cybersecurity frameworks.

6. Technical & Professional Skills

The successful candidate should demonstrate:

  • Strong knowledge of cybersecurity frameworks, standards, and best practices.
  • Deep understanding of NCA, PDPL, NDMO, ISO 27001, and applicable data protection requirements.
  • Strong expertise in Governance, Risk, and Compliance (GRC).
  • Experience with SOC operations and SIEM platforms such as Microsoft Sentinel, Splunk, or equivalent.
  • Strong understanding of vulnerability management and penetration testing.
  • Strong knowledge of Incident Response and Cybersecurity Incident Response Plans (CIRP).
  • Strong understanding of IAM and access governance.
  • Knowledge of data protection, data classification, and data governance.
  • Strong understanding of secure architecture and security controls.
  • Ability to develop and monitor cybersecurity KPIs and KRIs.
  • Strong audit and regulatory assessment experience.
  • Ability to assess and communicate cybersecurity risks in terms of business impact.
  • Strong strategic thinking and high-level decision-making capability.
  • Excellent leadership and people-management skills.
  • Ability to manage cross-functional teams and stakeholders under pressure.
  • Strong communication, presentation, and reporting skills.
  • Bilingual proficiency in Arabic and English.

7. Leadership Competencies

  • Strategic Thinking
  • Cybersecurity Leadership
  • Risk-Based Decision Making
  • Stakeholder Management
  • Executive Communication
  • Team Leadership & Development
  • Problem Solving
  • Crisis and Incident Management
  • Governance & Accountability
  • Continuous Improvement
  • Business Acumen
  • Change Management

Special Requirements

  • Ability to work effectively in a fast-paced and dynamic environment.
  • Ability to manage cybersecurity incidents and critical security situations.
  • Willingness to participate in security incident response and escalation activities when required.
  • Strong confidentiality and professional integrity.
  • Ability to work collaboratively with executive leadership, IT, business functions, auditors, and regulatory stakeholders.

Requirements

 

¿Listo para postularte en SSC HR Solutions?
Postúlate en SSC HR Solutions

Sobre SSC HR Solutions


SSC HR Solutions is specialized in BPO services with a primary focus on a recruitment and outsourcing services that supports businesses in their recruitment needs.

Serving over 80 companies worldwide prominently featured on the Fortune 500. With more than 5,000 successful hires, including 1,000 outsourced employees; SSC proactively seeks, nurtures, and cultivates talent within the corporate realm.

Our outsourcing services include but are not limited to: (i) Payroll, (ii) Social Insurance, (iii) Labor Law Consultation, (iv) Medical Insurance, (v) Recruitment Services and (vi) Fully Equipped Integrated Office Spaces.


Contact us if you are pursuing prospective talent for your business or are looking to expand your job search.


SSC Egypt looks forward to connecting you with your future. If you are interested or have any inquiries, please feel free to reach out to us.


- Email Contact: [email protected]

- Website: https://ssc-hr.com/

Ver todos los empleos en SSC HR Solutions →

Empleos similares

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en SSC HR Solutions

Ver todos los empleos en SSC HR Solutions →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis