On-site
SSC Egypt -
Egypt , Cairo
--
SSC Egypt

Job Details


2. Job Purpose

The Information Security & Risk Manager is responsible for leading the organization s Information Security and Cyber Risk function. The role will design, implement, and maintain the cybersecurity program, manage enterprise information security risks, ensure compliance with applicable Saudi regulatory and industry requirements, and promote a strong security-aware culture across the organization.

The role provides strategic and operational leadership across Information Security Governance, Risk & Compliance (GRC), Security Operations, Incident Response, Data Protection, and Security Awareness.

3. Key Accountabilities & Deliverables

The role will be accountable for the development, implementation, and continuous improvement of:

  • Information Security Strategy and Cybersecurity Roadmap
  • Information Security policies, standards, procedures, and guidelines
  • Information Security Management System (ISMS)
  • Enterprise IT and Cybersecurity Risk Register
  • Information Security Risk Assessment Reports
  • Risk Treatment and Remediation Plans
  • Security Compliance Reports, including ISO 27001 and applicable regulatory requirements
  • Cybersecurity Control Framework and Control Effectiveness Reports
  • Vulnerability Assessment and Penetration Testing (VAPT) Reports
  • Cybersecurity Incident Reports and Root Cause Analysis (RCA)
  • Security Monitoring and Threat Dashboards
  • Cybersecurity KPI and KRI Dashboards
  • Identity and Access Management (IAM) Policies, Models, and Access Matrices
  • Data Classification and Data Protection Framework
  • Internal and External Audit Reports and Evidence Repository
  • Audit Findings and Remediation Tracking
  • Business Continuity and Disaster Recovery (BCP/DR) Security Alignment
  • Security Awareness and Training Programs and Reports
  • Regulatory Assessments, submissions, and compliance evidence

4. Key Responsibilities A. Information Security Strategy & Governance
  • Define, develop, and execute the organization s Information Security Strategy and cybersecurity roadmap.
  • Own and continuously improve the Information Security Management System (ISMS).
  • Develop and maintain information security policies, standards, procedures, and guidelines.
  • Establish effective cybersecurity governance frameworks aligned with business objectives.
  • Provide regular reporting on cybersecurity posture, risk exposure, compliance, and security program performance to the CTO and executive leadership.
  • Establish and monitor security KPIs, KRIs, and performance metrics.
  • Ensure information security requirements are incorporated into technology initiatives, projects, and business processes.

  • Support testing and continuous improvement of security-related recovery procedures.

5. Qualifications & Experience Minimum Qualifications
  • Bachelor s degree in Information Technology, Computer Science, Cybersecurity, Information Security, or a related discipline.
  • CISSP or CISM certification Mandatory.
  • ISO/IEC 27001 Lead Implementer or Lead Auditor certification preferred.
  • NCA-related cybersecurity accreditation or certification is preferred.
Minimum Experience
  • 8 10 years of professional experience in Information Security / Cybersecurity.
  • At least 3 years of experience in a cybersecurity or information security management/leadership role.
  • Proven experience managing enterprise cybersecurity programs and security teams.
  • Proven experience in GRC, risk management, security operations, and incident response.
  • Proven experience working with regulatory compliance, audits, and cybersecurity frameworks.

6. Technical & Professional Skills

The successful candidate should demonstrate:

  • Strong knowledge of cybersecurity frameworks, standards, and best practices.
  • Deep understanding of NCA, PDPL, NDMO, ISO 27001, and applicable data protection requirements.
  • Strong expertise in Governance, Risk, and Compliance (GRC).
  • Experience with SOC operations and SIEM platforms such as Microsoft Sentinel, Splunk, or equivalent.
  • Strong understanding of vulnerability management and penetration testing.
  • Strong knowledge of Incident Response and Cybersecurity Incident Response Plans (CIRP).
  • Strong understanding of IAM and access governance.
  • Knowledge of data protection, data classification, and data governance.
  • Strong understanding of secure architecture and security controls.
  • Ability to develop and monitor cybersecurity KPIs and KRIs.
  • Strong audit and regulatory assessment experience.
  • Ability to assess and communicate cybersecurity risks in terms of business impact.
  • Strong strategic thinking and high-level decision-making capability.
  • Excellent leadership and people-management skills.
  • Ability to manage cross-functional teams and stakeholders under pressure.
  • Strong communication, presentation, and reporting skills.
  • Bilingual proficiency in Arabic and English.

7. Leadership Competencies
  • Strategic Thinking
  • Cybersecurity Leadership
  • Risk-Based Decision Making
  • Stakeholder Management
  • Executive Communication
  • Team Leadership & Development
  • Problem Solving
  • Crisis and Incident Management
  • Governance & Accountability
  • Continuous Improvement
  • Business Acumen
  • Change Management

Special Requirements
  • Ability to work effectively in a fast-paced and dynamic environment.
  • Ability to manage cybersecurity incidents and critical security situations.
  • Willingness to participate in security incident response and escalation activities when required.
  • Strong confidentiality and professional integrity.
  • Ability to work collaboratively with executive leadership, IT, business functions, auditors, and regulatory stakeholders.

Desired Candidate Profile

Similar Jobs

About SSC Egypt
Egypt, Cairo