وصف الوظيفة
الموقع: القاهرة، مصر (100% داخلي)
نوع العمل: عقد
عنّا:
حين يلتقي نخبة المواهب التقنية بفرص عالمية المستوى!
في Xenon7، نعمل مع شركات رائدة وشركات ناشئة مبتكرة في مشاريع شيّقة ومتطورة تستفيد من أحدث التقنيات عبر مجالات متعددة من تكنولوجيا المعلومات بما في ذلك البيانات، الويب، البنية التحتية، الذكاء الاصطناعي وغيرها الكثير. خبرتنا في تطوير حلول تكنولوجيا المعلومات وتوفير الموارد عند الطلب تتيح لنا الشراكة مع العملاء في مبادرات تحوّلية، مما يدفع الابتكار ونمو الأعمال. سواء كان ذلك تمكين المؤسسات العالمية أو التعاون مع شركات ناشئة رائدة، نحن ملتزمون بتقديم حلول متقدمة وذات تأثير يلبي التحديات الأكثر تعقيداً في اليوم.
عن العميل:
انضم إلى إحدى المؤسسات المالية الرائدة في مصر، المعروفة بمجموعة خدماتها المصرفية الشاملة، بما في ذلك الخدمات المصرفية المؤسسية والشخصية المصرفية والإسلامية. مع حضور عالمي من خلال أكثر من 50 فرعاً ومراسلين، نخدم عملاء متنوعين وديناميين. مع بدء رحلة التحول الرقمي الثوري، نلتزم باستغلال أحدث التقنيات لإنشاء بنية بيانات حديثة تعيد تعريف أدائنا وخدمتنا المقدمة.
ملخص الوظيفة:
توجد هذه الدور لتعجيل وضع الامتثال لأمن المعلومات عبر تقنية المعلومات والتحول الرقمي. يعمل المختص كذراع امتثال تقني لوظيفة InfoSec يتتبّع التزام، وتوثيق، وتقرير عن التقدم في التصحيح مقابل متطلبات إطار عمل الأمن السيبراني لـ CBE، والتزامات PCI DSS، والالتزامات الرقابية الداخلية. كما يقود ويلتزم بتمارين التأكيد، إما بشكل مباشر أو عبر تحديد ون إدارة مشاريع التقييم الأمني من طرف ثالث.
المسؤوليات الرئيسية:
أ. متابعة امتثال تكنولوجيا المعلومات والتحول الرقمي
• الحفاظ على متعقب امتثال حي عبر جميع مجالات ضوابط إطار الأمن السيبراني لـ CBE النشطة (IAM،
PAM، GRC، أمان الحاويات، وغيرها).
• إجراء جولات فنية منتظمة مع فرق تكنولوجيا المعلومات والتحول الرقمي للتحقق من حالة التنفيذ وإغلاق فجوات الدليل.
• تصعيد المخاطر والمعرقلات لرئيس GRC وCISO بلغة مخاطر مُقاسة مناسبة لتقرير لجنة المخاطر.
• ربط إجراءات التصحيح بنتائج OKR وتتبع التسليم وفق الجداول الزمنية المتفق عليها.
• إعداد تقارير حالة الامتثال بصيغة مناسبة للإدارة العليا والجمهور التنظيمي.
ب. قيادة تعامل PCI DSS
• امتلاك دورة تفاعل PCI DSS بالكامل - تحديد النطاق، وتقييم الفجوات، وتتبع التصحيح، وتنسيق QSA، وتقرير الامتثال (RoC) أو جاهزية استبيان التقييم الذاتي (SAQ).
• التنسيق عبر IT والعمليات والتحول الرقمي لضمان تطبيق ضوابط بيئة بيانات صاحب البطاقة (CDE)، وتوثيقها وصيانتها.
• إدارة العلاقة مع مقدِّر الأمن المؤهل (QSA) المعين والعمل كنقطة اتصال داخلية طوال دورة التقييم.
• قيادة إغلاق نتائج PCI DSS وبناء سجل ضوابط تعويضية حيث لا تكون الضوابط الفنية قابلة للتنفيذ بعد.
• الحفاظ على مكتبة وثائق PCI DSS بما في ذلك مخططات الشبكة، ومخططات تدفق البيانات، وقاعدة بيانات الأصول، والسياسات ذات الصلة بـ CDE.
ج. تمارين ضمان InfoSec
• تخطيط وتنفيذ أنشطة التأكيد بما في ذلك اختبار الضوابط، ومراجعات التكوين، ومراجعات الوصول، وفحوصات الالتزام بالسياسة.
• نطاق، شراء، وإدارة بائعي تقييم أمني من قبل طرف ثالث حيث تكون القدرة التقييمية المتخصصة مطلوبة (مثلاً اختبارات الاختراق، تمارين الفريق الأحمر، مراجعات أمان السحابة).
• إنتاج تقارير تأكيد واضحة تتضمن نتائج مخاطر وتوضيح التأثير التجاري وتوصيات التصحيح ذات الأولوية.
• تتبع تصحيح النتائج حتى الإغلاق والتحقق من فاعلية الإجراءات التصحيحية.
• التنسيق مع مدير تحقق ضوابط InfoSec لمواءمة مخرجات التأكيد مع برنامج تحقق التحكم الأوسع.
المتطلبات
• خبرة لا تقل عن 7 سنوات في أمن المعلومات، مع وجود 3 سنوات على الأقل في بنك أو مؤسسة مالية.
• خبرة PCI DSS عملية - يجب أن تكون قد شاركت في أو بقيت على رأس دورة RoC كاملة أو SAQ-D على الأقل.
• معرفة عميقة بمتطلبات إطار عمل الأمن السيبراني لـ CBE والسياق التنظيمي المصري.
• خبرة في إجراء تقييمات فجوات التوافق التقنية عبر بنية IT التحتية، الشبكة، وطبقة التطبيقات.
• مهارات تواصل كتابية وشفوية قوية بالعربية والإنجليزية.
الشهادات المفضلة
• CISA - مُدقق أنظمة معلومات معتمد
• PCIP أو PCI ISA - مُقيِّم أمني داخلي PCI
• ISO 27001 Lead Auditor
• CISM - مدير أمن معلومات معتمد
الخبرة المفضلة
• خبرة سابقة في بنك مصري أو مؤسسة مالية تعمل تحت إشراف البنك المركزي المصري.
• الإلمام بأدوات GRC (RSA Archer، ServiceNow GRC، أو ما يعادلها).
• خبرة في العمل مع مدققين خارجيين، QSA، والجهات التنظيمية.
المزايا
- حزمة رواتب جذابة وقائدة في السوق
- مسار واضح للترقية المهنية مع فرص التطوير المهني
Job description
Location: Cairo, Egypt (100% On-Premise)
Employment Type: Contract
About us:
Where elite tech talent meets world-class opportunities!
At Xenon7, we work with leading enterprises and innovative startups on exciting, cutting-edge projects that leverage the latest technologies across various domains of IT including Data, Web, Infrastructure, AI, and many others. Our expertise in IT solutions development and on-demand resources allows us to partner with clients on transformative initiatives, driving innovation and business growth. Whether it's empowering global organizations or collaborating with trailblazing startups, we are committed to delivering advanced, impactful solutions that meet today's most complex challenges.
About the Client:
Join one of Egypt's premier financial institutions, renowned for its extensive suite of banking services, including Institutional Banking, Personal Banking, and Islamic Banking. With a global presence through over 50 branches and correspondents, we serve a diverse and dynamic clientele. As we embark on a groundbreaking digital transformation journey, we are committed to leveraging the latest technologies to establish a state-of-the-art data architecture that will redefine our performance and service delivery.
Job Summary:
This role exists to accelerate the information security compliance posture across IT and Digital Transformation. The specialist acts as the InfoSec function's technical compliance arm-tracking, evidencing, and reporting on remediation progress against CBE Cybersecurity Framework requirements, PCI DSS obligations, and internal control commitments. The role also leads and executes assurance exercises, either directly or by scoping and managing third-party security assessment engagements.
Key Responsibilities:
A. IT & Digital Transformation Compliance Follow-Up
• Maintain a live compliance tracker across all active CBE Cybersecurity Framework control domains (IAM,
PAM, GRC, Container Security, and others).
• Conduct regular technical walk-throughs with IT and Digital Transformation teams to validate
implementation status and close evidence gaps.
• Escalate risks and blockers to the Head of GRC and CISO with clear risk-quantified language suitable for
Risk Committee reporting.
• Map remediation actions to OKR key results and track delivery against agreed timelines.
• Prepare compliance status reports in a format suitable for senior management and regulatory audiences.
B. PCI DSS Engagement Lead
• Own the end-to-end PCI DSS engagement cycle - scoping, gap assessment, remediation tracking, QSA
coordination, and Report on Compliance (RoC) or Self-Assessment Questionnaire (SAQ) readiness.
• Coordinate across IT, Operations, and Digital to ensure cardholder data environment (CDE) controls are
implemented, evidenced, and maintained.
• Manage the relationship with the appointed Qualified Security Assessor (QSA) and act as the internal
point of contact throughout the assessment cycle.
• Drive closure of PCI DSS findings and build a compensating controls register where technical controls are
not yet feasible.
• Maintain PCI DSS documentation library including network diagrams, data flow diagrams, asset inventory,
and policies relevant to the CDE.
C. InfoSec Assurance Exercises
• Plan and execute assurance activities including control testing, configuration reviews, access reviews,
and policy compliance spot checks.
• Scope, procure, and manage third-party security assessment vendors where specialized assessment
capability is required (e.g., penetration testing, red team exercises, cloud security reviews).
• Produce clear assurance reports with risk-rated findings, business impact statements, and prioritized
remediation recommendations.
• Track finding remediation to closure and validate effectiveness of corrective actions.
• Coordinate with the InfoSec Control Validation Manager to align assurance outputs with
broader control validation programme.
Requirements
• Minimum 7 years of information security experience, with at least 3 years in a banking or financial
institution.
• Hands-on PCI DSS experience - must have participated in or led at least one full RoC or SAQ-D
assessment cycle.
• Deep knowledge of CBE Cybersecurity Framework requirements and Egyptian regulatory context.
• Experience conducting technical compliance gap assessments across IT infrastructure, network, and
application layers.
• Strong written and verbal communication skills in both Arabic and English.
Preferred Certifications
• CISA - Certified Information Systems Auditor
• PCIP or PCI ISA - PCI Internal Security Assessor
• ISO 27001 Lead Auditor
• CISM - Certified Information Security Manager
Preferred Experience
• Prior experience in an Egyptian bank or financial institution operating under CBE oversight.
• Familiarity with GRC tooling (RSA Archer, ServiceNow GRC, or equivalent).
• Experience working with external auditors, QSAs, and regulators.
Benefits
- Attractive, market-leading salary package
- Clear career advancement path with professional development opportunities