وصف الوظيفة
Grow with us
حول هذه الفرصة:
في إريكسون، الأمن هو أساسي لتمكين أعمالنا وثقة العملاء والمرونة التشغيلية. نحن نبحث عن مدير أمن معلومات متمرس ومتحفز للانضمام إلى مؤسسة أمان المؤسسة في منطقة EMEA، بالتقارير إلى رئيس أمان المعلومات، BCM وأمان تكنولوجيا المعلومات، EMEA.
هذه فرصة مثيرة لمحترف أمني شغوف بإدارة المخاطر والحوكمة وبناء شراكات قوية عبر بيئة متعددة الجنسيات متنوعة. ستلعب دوراً رئيسياً في تعزيز موقف أمان إريكسون عبر منطقة أوروبا والشرق الأوسط وأفريقيا من خلال قيادة مجال إدارة مخاطر الأمن من طرف ثالث (TPSRM) مع المساهمة في نظام إدارة أمن المعلومات (ISMS)، وإدارة مخاطر أمن المعلومات (ISRM)، وبيان القابلية (SoA)، والتوعية الأمنية، وأنشطة الامتثال التنظيمي.
الموقع: هذا المنصب مفتوح للمرشحين المؤهلين القاطنين في أي مكان داخل منطقة EMEA.
ما ستقوم به:
- قيادة برنامج إدارة مخاطر الأمن من الطرف الثالث عبر EMEA، لضمان التقييم والمراقبة والإدارة الفعالة لمخاطر الأمن المتعلقة بالمزودين.
- تطوير وتنفيذ خطط TPSRM التشغيلية، خرائط الطريق، مؤشرات الأداء الرئيسية، وتقارير الإدارة.
- دعم والإشراف على أنشطة معالجة مخاطر المزودين بالتعاون مع الأطراف الداخلية والخارجية.
- مراقبة التهديدات الناشئة لسلسة التوريد، واتجاهات الأمن السيبراني، وأفضل الممارسات الصناعية لتعزيز إطار TPSRM باستمرار.
- دعم تنفيذ وصيانة وتحسين مستمر لنظام إدارة أمن المعلومات (ISMS) بما يتوافق مع ISO/IEC 27001:2022.
- قيادة تقييمات مخاطر أمن المعلومات (ISRAs) ودعم تخطيط المعالجة والمتابعة للمؤسسات التنظيمية المعينة.
- دعم تطوير وصيانة بيانات القابلية (SoA)، بما في ذلك مراجعات قابلية الضبط وتقييم الفجوات وتخطيط المعالجة.
- العمل كمستشار أمني موثوق لقادة الأعمال، وتقديم إرشادات قائمة على المخاطر وتمكين اتخاذ قرارات مستنيرة.
- المساهمة في التوعية الأمنية وتطوير الكفاءات والمبادرات التي تعزز ثقافة أمان قوية عبر EMEA.
- دعم التدقيقات الداخلية والخارجية، وأنشطة الامتثال التنظيمي، ومبادرات التحسين المستمر.
- توفير خبرة موضوعية للتحاليل الأمنية، وإدارة الحوادث، ومراجعات ما بعد الحادث.
- دعم الامتثال للوائح الأمن السيبراني عبر منطقة EMEA.
المهارات التي تجلبها:
- خبرة لا تقل عن 5 سنوات في أمن المعلومات، إدارة مخاطر الأمن السيبراني، إدارة مخاطر الأمن من الطرف الثالث، حوكمة/مخاطر والامتثال (GRC)، أو مجالات ذات صلة.
- خبرة في العمل ضمن منظمات متعددة الجنسيات كبيرة وهياكل مصفوفة معقدة.
- خبرة مثبتة في إجراء تقييمات مخاطر الأمن وتقييمات المزودين وتخطيط معالجة المخاطر والامتثال.
- فهم قوي لأنظمة إدارة أمن المعلومات (ISMS)، وإدارة مخاطر أمن المعلومات (ISRM)، وممارسات إدارة مخاطر المزودين.
- فهم راسخ لـ ISO/IEC 27001:2022، إطار عمل NIST للأمن السيبراني (CSF)، وNIST SP 800-53، والمتطلبات التنظيمية للأمن السيبراني بما في ذلك NIS2 وGDPR وغيرها من القوانين المعنية بأمن المعلومات في EMEA.
- يفضل وجود خبرة في دعم وصيانة بيئة حاصلة على اعتماد ISO/IEC 27001.
- خبرة في التعامل مع كبار أصحاب المصلحة وتأثير القرارات المعتمدة على المخاطر.
- فهم جيد لأدوات الذكاء الاصطناعي والذكاء الاصطناعي التوليدي، بما في ذلك الآثار الأمنية والخصوصية والحوكمة والامتثال. يفضل خبرة عملية في استخدام GenAI لتبسيط العمليات وتحسين الكفاءة ودعم اتخاذ قرارات مستنيرة.
- درجة البكالوريوس في تكنولوجيا المعلومات، الأمن السيبراني، الهندسة، علوم الحاسوب، أو مجال ذو صلة.
- الشهادات المفضلة تشمل CISSP، CISM، CRISC، ISO/IEC 27001 Lead Implementer/Auditor، CTPRP، أو شهادات أخرى مكافئة في الأمن السيبراني، إدارة المخاطر، الحوكمة، أو الامتثال.
- يجيد اللغة الإنجليزية كتابة وتحدثاً.
لماذا تنضم إلينا؟
- صغِ وضع الأمن لشركة تقنية رائدة من بين الشركات.
- اعمل مع أصحاب مصلحة متنوعين عبر أوروبا والشرق الأوسط وأفريقيا.
- اثر قرارات استراتيجية في أمان الموردين، وإدارة المخاطر، وحوكمة الأمن المعلوماتي.
- كن جزءاً من فريق تعاوني يكرس حماية أشخاص إريكسون ومعلوماته وعملائه.
لماذا الانضمام إلى إريكسون؟في إريكسون، ستتاح لك فرصة استثنائية. فرصة لاستخدام مهاراتك وخيالك لدفع حدود الممكن وبناء حلول لم تُرَ من قبل لمواجهة بعض من أصعب المشكلات في العالم. ستواجه التحدي، ولكنك لن تكون بمفردك. ستنضم إلى فريق من المبتكرين المتنوعين الذين يسعون إلى تجاوز الوضع الراهن لصياغة ما سيأتي بعد ذلك.
ماذا يحدث عند تقديمك الطلب؟انقر هنا لمعرفة كل ما تحتاج إلى معرفته حول ما يبدو عليه عملية التوظيف النموذجية لدينا. تشجع Ericsson على وجود منظمة متنوعة وشاملة كجزء من قيمنا، ولهذا نرعى ذلك في كل ما نقوم به. نؤمن حقاً أنه من خلال التعاون مع أشخاص لديهم تجارب مختلفة ندفع الابتكار، وهو أمر أساسي لنمونا المستقبلي. نشجع الأشخاص من جميع الخلفيات على التقديم وتحقيق كامل إمكاناتهم كجزء من فريق Ericsson. تفخر Ericsson بأنها صاحب عمل يقدم فرص متكافئة. تعلم المزيد.
البلد والمدin']}
Job description
Grow with us
About this opportunity:
At Ericsson, security is a fundamental enabler of our business, customer trust, and operational resilience. We are looking for an experienced and motivated Information Security Manager to join the EMEA Enterprise Security organization, reporting to the Head of Information Security, BCM & IT Security, EMEA.
This is an exciting opportunity for a security professional who is passionate about risk management, governance, and building strong partnerships across a diverse multinational environment. You will play a key role in strengthening Ericsson's security posture across Market Area Europe, Middle East, and Africa (EMEA) by leading the Third-Party Security Risk Management (TPSRM) domain while contributing to the region's Information Security Management System (ISMS), Information Security Risk Management (ISRM), Statement of Applicability (SoA), security awareness, and regulatory compliance activities.
Location: This position is open to qualified candidates located anywhere within the EMEA region.
What you will do:
- Lead the Third-Party Security Risk Management program across EMEA, ensuring effective assessment, monitoring, and management of supplier-related security risks.
- Develop and execute TPSRM operational plans, roadmaps, KPIs, and management reporting.
- Support and oversee supplier risk treatment activities in collaboration with internal and external stakeholders.
- Monitor emerging supply chain threats, cybersecurity trends, and industry best practices to continuously enhance the TPSRM framework.
- Support the implementation, maintenance, and continual improvement of the Information Security Management System (ISMS) in alignment with ISO/IEC 27001:2022.
- Lead Information Security Risk Assessments (ISRAs) and support risk treatment planning and follow-up for assigned organizational units.
- Support the development and maintenance of Statements of Applicability (SoA), including control applicability reviews, gap assessments, and remediation planning.
- Act as a trusted security advisor to business leaders, providing risk-based guidance and enabling informed decision-making.
- Contribute to security awareness, competence development, and initiatives that promote a strong security culture across EMEA.
- Support internal and external audits, regulatory compliance activities, and continuous improvement initiatives.
- Provide subject matter expertise for security investigations, incident management, and post-incident reviews.
- Support compliance with cybersecurity regulations across the EMEA region.
The skills you bring:
- Minimum 5 years of experience in Information Security, Cybersecurity Risk Management, Third-Party Security Risk Management, Governance Risk & Compliance (GRC), or related domains.
- Experience working within large multinational organizations and complex matrix environments.
- Demonstrated experience performing security risk assessments, supplier assessments, risk treatment planning, and compliance activities.
- Strong understanding of Information Security Management Systems (ISMS), Information Security Risk Management (ISRM), and supplier risk management practices.
- Solid understanding of ISO/IEC 27001:2022, NIST Cybersecurity Framework (CSF), NIST SP 800-53, and cybersecurity regulatory requirements including NIS2, GDPR, and other EMEA relevant cybersecurity regulations.
- Experience supporting and maintaining an ISO/IEC 27001-certified environment is highly desirable.
- Experience engaging with senior stakeholders and influencing risk-based decisions.
- Good understanding of AI and Generative AI tools, including security, privacy, governance, and compliance implications. Practical experience leveraging GenAI to streamline processes, improve efficiency, and support informed decision-making is highly desirable.
- Bachelor's degree in Information Technology, Cybersecurity, Engineering, Computer Science, or a related field.
- Preferred certifications include CISSP, CISM, CRISC, ISO/IEC 27001 Lead Implementer/Auditor, CTPRP, or equivalent cybersecurity, risk management, governance, or compliance certifications.
- Fluent in English, both written and spoken.
Why Join Us?
- Shape the security posture of one of the world's leading technology companies.
- Work with diverse stakeholders across Europe, the Middle East, and Africa.
- Influence strategic decisions in supplier security, risk management, and information security governance.
- Be part of a collaborative team dedicated to protecting Ericsson's people, information, and customers.
Why join Ericsson?At Ericsson, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build solutions never seen before to some of the world’s toughest problems. You´ll be challenged, but you won’t be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
What happens once you apply?Click Here to find all you need to know about what our typical hiring process looks like.Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we champion it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity Employer. learn more.
Primary country and city: Egypt (EG) || Cairo
Req ID: 788422