Information Security & Cybersecurity Risk Manager

🏢 SSC HR Solutions
📍 Cairo, EgyptOn-site
📅 Posted: 3w ago🔄 Updated: 3w ago
CV%
✨ AI Summary
The Information Security & Risk Manager will lead the organization's cybersecurity and risk function, responsible for designing, implementing, and maintaining the cybersecurity program. This role involves managing enterprise information security risks, ensuring compliance with Saudi regulatory and industry requirements, and fostering a security-aware culture. Key accountabilities include developing and improving Information Security Strategy, policies, ISMS, risk registers, and compliance reports. The manager will oversee GRC, Security Operations, Incident Response, Data Protection, and Security Awareness programs, ensuring alignment with business objectives and regulatory standards.
Required Skills
Information Technology
CybersecurityISO 27001NOC OperationsSIEMMicrosoft SentinelVulnerability ManagementPenetration TestingIncident ResponseData GovernanceSecurity Architecture
Other
NCAPDPLNDMOSplunkdata classificationsecurity controlsKRIsregulatory assessmentArabicEnglish
Finance, Legal & Governance
Data Protection & PrivacyIT GovernanceAuditing
Business, Sales & Management
HR ManagementProgress Reporting
Soft Skills & Professional Competencies
Strategic ThinkingLeadershipPeople ManagementStakeholder ManagementCommunicationPresentation Skills
Nice to have:
Information Technology
ISO 27001
Description
Information Security & Risk Manager1. Job DetailsPosition Title: Information Security & Risk ManagerDepartment: Technology Services / ITReports To: Information Security / CTOEmployment Type: PermanentLocation: Maadi, Degla – On-siteGrade: As per organizational structureDirect Reports: As per approved organizational structure2. Job PurposeThe Information Security & Risk Manager is responsible for leading the organization’s Information Security and Cyber Risk function. The role will design, implement, and maintain the cybersecurity program, manage enterprise information security risks, ensure compliance with applicable Saudi regulatory and industry requirements, and promote a strong security-aware culture across the organization.The role provides strategic and operational leadership across Information Security Governance, Risk & Compliance (GRC), Security Operations, Incident Response, Data Protection, and Security Awareness.3. Key Accountabilities & DeliverablesThe role will be accountable for the development, implementation, and continuous improvement of:Information Security Strategy and Cybersecurity RoadmapInformation Security policies, standards, procedures, and guidelinesInformation Security Management System (ISMS)Enterprise IT and Cybersecurity Risk RegisterInformation Security Risk Assessment ReportsRisk Treatment and Remediation PlansSecurity Compliance Reports, including ISO 27001 and applicable regulatory requirementsCybersecurity Control Framework and Control Effectiveness ReportsVulnerability Assessment and Penetration Testing (VAPT) ReportsCybersecurity Incident Reports and Root Cause Analysis (RCA)Security Monitoring and Threat DashboardsCybersecurity KPI and KRI DashboardsIdentity and Access Management (IAM) Policies, Models, and Access MatricesData Classification and Data Protection FrameworkInternal and External Audit Reports and Evidence RepositoryAudit Findings and Remediation TrackingBusiness Continuity and Disaster Recovery (BCP/DR) Security AlignmentSecurity Awareness and Training Programs and ReportsRegulatory Assessments, submissions, and compliance evidence4. Key ResponsibilitiesA. Information Security Strategy & GovernanceDefine, develop, and execute the organization’s Information Security Strategy and cybersecurity roadmap.Own and continuously improve the Information Security Management System (ISMS).Develop and maintain information security policies, standards, procedures, and guidelines.Establish effective cybersecurity governance frameworks aligned with business objectives.Provide regular reporting on cybersecurity posture, risk exposure, compliance, and security program performance to the CTO and executive leadership.Establish and monitor security KPIs, KRIs, and performance metrics.Ensure information security requirements are incorporated into technology initiatives, projects, and business processes.B. Information Security Risk ManagementLead regular information security and cybersecurity risk assessments across the organization.Own and maintain the enterprise IT and cybersecurity risk register.Identify, assess, prioritize, and communicate information security risks.Develop and manage risk treatment plans and ensure remediation activities are tracked through to closure.Work closely with business units, IT, and other stakeholders to establish appropriate risk mitigation strategies.Translate technical cybersecurity risks into business impact and communicate them effectively to senior management.Monitor the organization’s overall cyber risk profile and provide recommendations for risk reduction.C. Security Operations & SOCOversee Security Operations Centre (SOC) activities, including SOC Analysts and Security Engineers.Ensure effective security monitoring, threat detection, investigation, and response capabilities.Oversee SIEM operations and security monitoring platforms such as Microsoft Sentinel, Splunk, or equivalent technologies.Establish and monitor security incident management processes.Review security alerts, incidents, trends, and threat intelligence.Ensure appropriate escalation and response mechanisms are in place for critical security events.Monitor and improve the effectiveness of security controls and operational processes.D. Cybersecurity Incident ResponseLead the organization’s cybersecurity incident response capability.Ensure effective detection, containment, eradication, recovery, and post-incident activities.Develop, maintain, and continuously improve the Cybersecurity Incident Response Plan (CIRP).Conduct regular incident response exercises and simulations.Lead investigations into significant security incidents and ensure Root Cause Analysis (RCA) is completed.Track corrective and preventive actions resulting from security incidents.Ensure lessons learned are incorporated into security controls and processes.E. Governance, Risk & ComplianceLead Information Security Governance, Risk, and Compliance (GRC) activities.Ensure compliance with applicable regulatory and industry requirements, including:National Cybersecurity Authority (NCA) requirementsSaudi Personal Data Protection Law (PDPL)National Data Management Office (NDMO) requirements, where applicableISO/IEC 27001Other applicable cybersecurity and data protection regulationsCoordinate internal and external security audits and assessments.Manage audit evidence collection and maintain an organized security evidence repository.Track audit findings, remediation plans, and closure status.Prepare management and regulatory compliance reports.Support regulatory assessments, reviews, and submissions as required.F. Data Protection & PrivacyEstablish and maintain data protection and information classification frameworks.Ensure appropriate security controls are implemented for sensitive and personal data.Work with relevant stakeholders to support compliance with PDPL and applicable data protection requirements.Establish appropriate data access, handling, retention, and protection controls.Support privacy and data protection risk assessments where required.G. Vulnerability & Security TestingOversee vulnerability management activities across IT environments.Coordinate Vulnerability Assessments and Penetration Testing (VAPT).Review vulnerability and penetration testing reports.Ensure security vulnerabilities are appropriately prioritized based on business risk.Track remediation activities and validate closure of critical and high-risk vulnerabilities.Ensure security testing is incorporated into relevant technology projects and systems.H. Identity & Access ManagementEstablish and maintain IAM policies, standards, and access control frameworks.Ensure appropriate access governance and segregation of duties.Review privileged access and high-risk accounts.Support periodic user access reviews and access recertification.Ensure access controls align with business requirements and security policies.I. Security Awareness & CultureDevelop and implement an organization-wide security awareness program.Lead cybersecurity awareness campaigns and security training.Implement phishing simulation and social engineering awareness programs.Monitor employee security awareness performance and identify improvement areas.Promote a strong cybersecurity culture across all business functions.J. Business Continuity & Disaster RecoveryEnsure cybersecurity requirements are incorporated into Business Continuity and Disaster Recovery plans.Participate in BCP/DR risk assessments and exercises.Ensure critical systems have appropriate security, recovery, and resilience controls.Support testing and continuous improvement of security-related recovery procedures.5. Qualifications & ExperienceMinimum QualificationsBachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Security, or a related discipline.CISSP or CISM certification – Mandatory.ISO/IEC 27001 Lead Implementer or Lead Auditor certification preferred.NCA-related cybersecurity accreditation or certification is preferred.Minimum Experience8–10 years of professional experience in Information Security / Cybersecurity.At least 3 years of experience in a cybersecurity or information security management/leadership role.Proven experience managing enterprise cybersecurity programs and security teams.Proven experience in GRC, risk management, security operations, and incident response.Proven experience working with regulatory compliance, audits, and cybersecurity frameworks.6. Technical & Professional SkillsThe successful candidate should demonstrate:Strong knowledge of cybersecurity frameworks, standards, and best practices.Deep understanding of NCA, PDPL, NDMO, ISO 27001, and applicable data protection requirements.Strong expertise in Governance, Risk, and Compliance (GRC).Experience with SOC operations and SIEM platforms such as Microsoft Sentinel, Splunk, or equivalent.Strong understanding of vulnerability management and penetration testing.Strong knowledge of Incident Response and Cybersecurity Incident Response Plans (CIRP).Strong understanding of IAM and access governance.Knowledge of data protection, data classification, and data governance.Strong understanding of secure architecture and security controls.Ability to develop and monitor cybersecurity KPIs and KRIs.Strong audit and regulatory assessment experience.Ability to assess and communicate cybersecurity risks in terms of business impact.Strong strategic thinking and high-level decision-making capability.Excellent leadership and people-management skills.Ability to manage cross-functional teams and stakeholders under pressure.Strong communication, presentation, and reporting skills.Bilingual proficiency in Arabic and English.7. Leadership CompetenciesStrategic ThinkingCybersecurity LeadershipRisk-Based Decision MakingStakeholder ManagementExecutive CommunicationTeam Leadership & DevelopmentProblem SolvingCrisis and Incident ManagementGovernance & AccountabilityContinuous ImprovementBusiness AcumenChange ManagementSpecial RequirementsAbility to work effectively in a fast-paced and dynamic environment.Ability to manage cybersecurity incidents and critical security situations.Willingness to participate in security incident response and escalation activities when required.Strong confidentiality and professional integrity.Ability to work collaboratively with executive leadership, IT, business functions, auditors, and regulatory stakeholders.
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00