Cyber Security Engineer Jobs in Egypt
15328 Jobs Found
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>Manage and maintain IT infrastructure including servers, storage systems, virtualization platforms (VMware vSphere), network equipment, and end-user devices to ensure reliable operations. Administer Microsoft Active Directory, Group Policies, DNS, DHCP, File Services, and Microsoft 365 services to support organizational IT needs. Monitor system performance, availability, backups, and security events; implement and maintain cybersecurity best practices, endpoint protection, and access management controls to ensure business continuity. Install, configure, and troubleshoot network equipment including switches, wireless networks, and IP telephony solutions to maintain seamless connectivity. Coordinate and execute backup procedures, disaster recovery protocols, and business continuity initiatives to protect critical business operations. Support and manage cloud-based services and hybrid infrastructure environments while managing incidents, service requests, and problem resolution through IT Service Management (ITSM) processes. Develop and maintain technical documentation, operational procedures, and knowledge base articles; prepare regular reports on system health, infrastructure status, asset management, and operational KPIs; participate in IT projects, infrastructure upgrades, system implementations, and process improvement initiatives; and provide technical guidance and training to end-users as required.</p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><p>Bachelor's Degree in Computer Engineering, Computer Science or Information Technology. +3 years of experience in IT Infrastructure, IT Operations, or System Administration. Strong expertise in IT infrastructure management, including Windows Server, Active Directory, DNS, DHCP, Microsoft 365 Administration, VMware vSphere, storage systems, and backup solutions. Solid understanding of networking fundamentals (TCP/IP, VLANs, Routing, Switching, Wireless Networks) with hands-on experience in Cisco networking equipment, IP Telephony systems, and cloud technologies such as Microsoft Azure. Excellent troubleshooting, analytical, and problem-solving capabilities with knowledge of ITSM frameworks and ITIL best practices.</p><p></p></section>
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>Join Us</p><p>At Vodafone, we re not just shaping the future of connectivity for our customers we re shaping the future for everyone who joins our team. When you work with us, you re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact. Role Purpose</p><p>About the Role We are looking for a Cyber Security Assurance Senior Specialist to join our team and play a key role in ensuring the security of Vodafone s digital environment. This role is responsible for conducting penetration testing, vulnerability analysis, and security assurance activities across web applications, mobile platforms, networks, and cloud environments. As a Cyber Security Assurance Senior Specialist, you will work closely with technical teams and business stakeholders to identify, assess, and mitigate security risks while ensuring compliance with Vodafone s cyber security policies and standards.</p><p>Job Responsibilities</p><ul><li>Conduct penetration testing on web applications, networks, mobile applications, and cloud environments to identify vulnerabilities and security weaknesses.</li><li>Perform vulnerability analysis and provide remediation recommendations to enhance security posture.</li><li>Ensure secure acceptance of new nodes and technologies by validating compliance with Vodafone s security policies and industry standards.</li><li>Perform regular security assurance activities on existing systems and applications to maintain continuous compliance and protection against emerging threats.</li><li>Participate in risk assessments for new projects, providing a security assurance perspective to ensure risks are identified and mitigated early in the development cycle.</li><li>Collaborate with Vodafone technical teams and business units to address and remediate penetration testing findings effectively.</li><li>Stay up to date with emerging security threats, vulnerabilities, and industry best practices, applying them to improve security assurance processes.</li></ul><p>Not a perfect fit?</p><p>Worried that you don t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you re excited about this role but your experience doesn t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.</p><p>Core competencies, knowledge, and experience</p><p>Key activities</p><ul><li>Follow internal delivery processes to deliver cyber security programs requirements in alignment with global/local policies.</li><li>Ensure delivery of projects on time and within allocated budget.</li><li>Ensure that all streams running on the right track and fulfilling their main objectives.</li><li>Issue reports for running streams to Cyber Security and Technology Management</li><li>Manages building proper interface with different vendors.</li><li>Ensure projects and activities delivery with vendors on time and within allocated budget</li></ul><p>Strong knowledge of security frameworks such as MITRE ATT&CK , NIST and CIS.</p><p>Familiarity with hardening configurations for different environments (servers, databases, applications, etc.).</p><p>Experience in risk assessment and providing security recommendations in line with business requirements.</p><p>Ability to work collaboratively with cross-functional teams to address and mitigate security vulnerabilities.</p><p>Strong analytical and problem-solving skills, with the ability to communicate complex security issues to technical and non-technical stakeholders.</p><p>Relevant certifications are a plus ( OSCP, eWPTX, eCPPT, or similar ).</p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><ul><li>Conduct penetration testing on web applications, networks, mobile applications, and cloud environments to identify vulnerabilities and security weaknesses.</li><li>Perform vulnerability analysis and provide remediation recommendations to enhance security posture.</li><li>Ensure secure acceptance of new nodes and technologies by validating compliance with Vodafone s security policies and industry standards.</li><li>Perform regular security assurance activities on existing systems and applications to maintain continuous compliance and protection against emerging threats.</li><li>Participate in risk assessments for new projects, providing a security assurance perspective to ensure risks are identified and mitigated early in the development cycle.</li><li>Collaborate with Vodafone technical teams and business units to address and remediate penetration testing findings effectively.</li><li>Stay up to date with emerging security threats, vulnerabilities, and industry best practices, applying them to improve security assurance processes.</li><li>Follow internal delivery processes to deliver cyber security programs requirements in alignment with global/local policies.</li><li>Ensure delivery of projects on time and within allocated budget.</li><li>Ensure that all streams running on the right track and fulfilling their main objectives.</li><li>Issue reports for running streams to Cyber Security and Technology Management</li><li>Manages building proper interface with different vendors.</li><li>Ensure projects and activities delivery with vendors on time and within allocated budget</li><li>Strong knowledge of security frameworks such as MITRE ATT&CK , NIST and CIS.</li><li>Familiarity with hardening configurations for different environments (servers, databases, applications, etc.).</li><li>Experience in risk assessment and providing security recommendations in line with business requirements.</li><li>Ability to work collaboratively with cross-functional teams to address and mitigate security vulnerabilities.</li><li>Strong analytical and problem-solving skills, with the ability to communicate complex security issues to technical and non-technical stakeholders.</li><li>Relevant certifications are a plus ( OSCP, eWPTX, eCPPT, or similar ).</li></ul><p></p></section>
<p><h4>Join us</h4>
<p>At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.</p>
<h4>Role purpose</h4>
<p>Design, plan, deploy and manage network infrastructure, including switches, routers, and wireless systems, to ensure seamless connectivity.</p>
<h4>Key accountabilities</h4>
<ul>
<li>Develop, implement and maintain network policies, standards and procedures in alignment with industry best practices and compliance requirements for the customers.</li>
<li>Design and implement LAN, WAN, SD-WAN, and data center networks.</li>
<li>Configure and support routing, switching, wireless, and VPN solutions.</li>
<li>Define standards and requirements to manage and monitor network performance and resolve incidents.</li>
<li>Support network security integration with firewalls and other security solutions.</li>
<li>Maintain network documentation and diagrams.</li>
<li>Ensure compliance with network security and operational standards.</li>
<li>Configure and install network hardware and software.</li>
<li>Troubleshoot connectivity issues and monitor network performance.</li>
<li>Perform regular maintenance and firmware updates on network devices.</li>
</ul>
<h4>Project management</h4>
<ul>
<li>Ability to manage other partners and provide advice and recommendations to ensure projects are delivered with required quality.</li>
<li>Proactively identify opportunities for continuous improvement in service delivery processes.</li>
<li>Ensure that networking solutions adhere to regulatory requirements, industry standards, and organizational policies.</li>
<li>Identify and mitigate risks throughout the delivery lifecycle.</li>
</ul>
<h4>Stakeholder management</h4>
<ul>
<li>Collaborate with internal teams and customer teams to ensure relations and teamwork is achieved.</li>
<li>Drive innovation by exploring and adopting cutting-edge networking tools and methodologies.</li>
</ul>
<h4>Risk management</h4>
<ul>
<li>Oversee the establishment and implementation of contingency plans.</li>
<li>Track service performance using key performance indicators (KPIs) and service level agreements (SLAs), providing regular reports to clients and senior management.</li>
<li>Continuously assess security delivery processes and implement improvements to increase efficiency, reduce costs, and enhance customer satisfaction.</li>
<li>Oversee the resolution of service issues and escalate complex problems as needed, ensuring swift resolution and minimal impact on clients.</li>
<li>Identify potential risks to project delivery and implement mitigation strategies to minimize disruption.</li>
<li>Collaborate with other departments (e.g. sales, IT, product development) to introduce innovative solutions and services that add value to clients.</li>
</ul>
<h4>Compliance & auditing</h4>
<ul>
<li>Ensure the networks delivery aligns with the relevant regulations, compliance frameworks and industry standards.</li>
<li>Oversee internal and external security audits to assess compliance and identify areas for improvement.</li>
</ul>
<h4>Core competencies, knowledge and experience</h4>
<ul>
<li>4 to 8 years experience in network solutions and devices implementations.</li>
<li>Bachelor’s degree in computer science, information technology, engineering, or a related field.</li>
<li>Strong communication, interpersonal and presentation skills.</li>
<li>Proven teamwork skills, with the ability to work and influence others.</li>
<li>Excellent command of Arabic and English.</li>
<li>Experience in large-scale networking projects across diverse environments.</li>
<li>Demonstrated expertise in areas such as strong understanding of TCP/IP, routing, and switching.</li>
<li>Ability to troubleshoot complex network issues.</li>
<li>Must have technical or professional qualifications:
<ul>
<li>CCNA / CCNP or equivalent certifications.</li>
<li>Understanding of network security fundamentals.</li>
<li>Experience with Cisco, Fortinet, Juniper, F5, Trend Micro, Huawei, or similar platforms.</li>
<li>Strong understanding of ICT systems integration methodologies.</li>
<li>Relevant certifications such as CISSP, CISM, PMP, or ITIL are highly a nice to have.</li>
</ul>
</li>
<li>Strong knowledge of network and security frameworks and standards (e.g., ISO 27001, NIST CSF, PCI-DSS).</li>
<li>Ability to understand and manage technical concepts and processes, bridging the gap between technical and non-technical stakeholders.</li>
<li>Familiarity with networks technologies and tools.</li>
<li>Knowledge of quality assurance processes and tools to ensure that deliverables meet specified requirements and quality standards.</li>
<li>Experience in managing changes to project scope, schedule, and requirements while minimizing disruption to project progress.</li>
</ul>
<h4>Not a perfect fit?</h4>
<p>Worried that you don’t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you’re excited about this role but your experience doesn’t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.</p>
<h4>Who we are</h4>
<p>We are a leading international telco, serving millions of customers. At Vodafone, we believe that connectivity is a force for good. If we use it for the things that really matter, it can improve people's lives and the world around us. Through our technology we empower people, connecting everyone regardless of who they are or where they live and we protect the planet, whilst helping our customers do the same.</p>
<p>Belonging at Vodafone isn't a concept; it's lived, breathed, and cultivated through everything we do. You'll be part of a global and diverse community, with many different minds, abilities, backgrounds and cultures. We're committed to increasing diversity, ensure equal representation, and make Vodafone a place everyone feels safe, valued and included.</p>
<p>If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, please refer to the company’s application adjustments guidance for support.</p>
<p>Together we can.</p></p><p></p>
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><br><ul><li><p>Deliver cybersecurity and technology risk consulting engagements across various industries.</p></li><li><p>Conduct cybersecurity and technology risk assessments covering applications, infrastructure, cloud environments, and business processes. Ability to develop risks, controls, compliance requirements and implementation guidance</p></li><li><p>Ability to review regulatory circulars, notices, standards and guidelines and identify applicable technology and cybersecurity obligations</p></li><li><p>Perform cybersecurity governance, compliance, maturity, and control effectiveness assessments against industry standards and regulatory requirements.</p></li><li><p>Assess and enhance governance structures, risk management frameworks, and cybersecurity operating models.</p></li><li><p>Develop and review cybersecurity policies, standards, procedures, and supporting governance documentation.</p></li><li><p>Support clients in establishing and improving compliance monitoring, risk management, and assurance programs.</p></li><li><p>Conduct gap assessments and develop remediation roadmaps aligned with leading frameworks and regulations.</p></li><li><p>Support resilience initiatives including business continuity, disaster recovery, and operational resilience assessments.</p></li><li><p>Identify risks, evaluate controls, analyze findings, and provide practical recommendations to improve security and risk posture.</p></li><li><p>Develop detailed reports, executive presentations, and management summaries tailored to both technical and business audiences.</p></li><li><p>Facilitate stakeholder workshops, interviews, and working sessions with technology, security, risk, and business teams.</p></li><li><p>Manage multiple engagements, ensuring timely delivery, quality assurance, and adherence to leading practices.</p></li><li><p>Mentor and coach junior team members, contributing to capability development and knowledge sharing across the practice.</p></li><li><p>Stay updated on emerging cyber threats, technology trends, regulatory changes, and industry best practices</p></li></ul><p><strong> </strong></p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><p>To qualify for the role, you must have</p><ul><li><p>A bachelor's or master’s degree in information technology, cyber security etc.</p></li><li><p>Excellent communication skills with a consulting mindset.</p></li><li><p>3-8 years of experience in cybersecurity, technology risk, IT risk, compliance, governance, resilience, or consulting services</p></li><li><p>A valid passport for travel.</p></li><li><p>Excellent communication skills with a consulting mindset.</p><br></li></ul><p>Ideally, you’ll also have</p><ul><li><p>Industry-recognized certifications such as CISSP, CRISC, CISM ISO 27001 LA/LI</p></li><li><p>Experience working with GRC platforms (e.g., Archer, ServiceNow GRC etc.).</p></li><li><p>Familiarity with cloud security, privacy, operational resilience, or third-party risk management programs</p></li><li><p>Experience supporting clients in highly regulated sectors such as financial services or government</p></li><li><p>Knowledge of regional frameworks and regulations within the Middle East</p></li></ul><p></p></section>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span><b>Shape & Create - And make it happen!</b></span><span>The Villeroy & Boch Group with its Ideal Standard brand is one of the world's leading manufacturers in the ceramics and lifestyle sector. With our innovative and stylish products from the Dining & Lifestyle and Bath & Wellness segments, we have been creating moments and rooms to feel good in since 1748. Our success is based on the passion, design expertise and innovative strength of our more than 13,000 employees in 42 countries. </span><span>Want to become part of us? #shapeandcreate</span><ul><li>Configuring, maintaining, and troubleshooting a wide range of network devices, including routers, switches, firewalls (e.g., Cisco ASA, Palo Alto, FortiGate), and load balancers, along with wireless access points.</li><li>Ensuring high network performance, security, and availability through continuous monitoring, proactive maintenance, and rapid incident response.</li><li>Managing VPN solutions, network access control (NAC) systems, and other network-centric security mechanisms to protect V&B's digital assets.</li><li>Utilizing network monitoring and management tools (e.g., SolarWinds, PRTG, Zabbix) to identify, diagnose, and resolve complex network issues, performing thorough root cause analysis.</li><li>Design, implement, and maintain robust, secure, and scalable LAN, WAN, and WLAN infrastructures across all locations.</li><li>Develop and maintain comprehensive network documentation, including diagrams, configurations, and standard operating procedures.</li><li>Collaborate with IT teams and external vendors to understand requirements, propose solutions, and implement new network services and technologies.</li><li>Manage network addressing schemes (IPAM), implement and configure routing protocols (e.g., BGP, OSPF, EIGRP), and configure network devices for authentication and authorization services.</li><li>Ensure strict compliance with company’s IT security policies and industry best practices specifically related to network infrastructure.</li><li>Participate actively in network capacity planning, disaster recovery initiatives, and business continuity planning relevant to network infrastructure.</li><li>Provide specialized technical guidance and support to other IT teams and end-users on network-related issues, ensuring optimal network connectivity for all enterprise systems.</li></ul><p>Your Profile:</p><br><ul><li><span>Bachelor's degree in Computer Science, Information Technology, Electrical Engineering, or a closely related field.</span></li><li><span>A Master's degree is a Core networking certification such as CCNA, CCNP, or CompTIA Network+ is preferred.</span></li><li><span>Highly Desirable: Specialized certifications in cloud networking (e.g., Azure Network Engineer Associate, Google Cloud Certified – Network Engineer), advanced Cisco (CCIE), or specific firewall vendors (Palo Alto PCNSE, Fortinet NSE).</span></li><li><span>3-5 years of proven experience in a dedicated Network Engineer or Network Administrator role.</span></li><li><span>Excellent command of the English language, both written and spoken, to facilitate global collaboration.</span></li><li><span>Proficiency in Microsoft Office Suite for documentation and reporting.</span></li><li><span>Deep knowledge of network protocols including TCP/IP, routing protocols (BGP, OSPF, EIGRP), and switching technologies (VLANs, STP).</span></li><li><span>Extensive experience with network devices: Configuration, maintenance, and troubleshooting of routers, switches, firewalls, and load balancers.</span></li><li><span>Strong grasp of network security: VPN management (IPSec, SSL), ACLs, IDS/IPS), and NAC solutions.</span></li><li><span>Proficiency in network monitoring, diagnostic, and analysis tools.</span></li></ul><ul><li><span>Excellent analytical, diagnostic, and problem-solving skills with a methodical approach to troubleshooting.</span></li><li><span>Strong communication and collaboration skills, with the ability to articulate technical information clearly and effectively to diverse audiences (technical and non-technical stakeholders) and to create comprehensive documentation.</span></li><li><span>Ability to work effectively in cross-functional teams, fostering positive relationships with development teams, business users, and other IT colleagues.</span></li><li><span>A proactive individual who can anticipate potential issues, propose effective solutions, and take ownership of tasks to improve system reliability and performance.</span></li><li><span>Highly detailed-oriented in configuration, monitoring, and problem diagnosis to prevent errors and ensure high-quality service delivery.</span> <span></span></li></ul><span><b>Think outside the box with us! #shapeandcreate</b></span> </div>
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, 80,000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars. Could you be the full-time Project Cyber Security Manager in Egypt we re looking for? Your future role Take on a new challenge and apply your Cybersecurity Project Management expertise in a new cutting-edge field. You ll work alongside passionate, motivated, and dedicated teammates. You'll help shape the future of secure transportation systems by analyzing project and program security needs, determining security objectives, and addressing main cybersecurity risks. Day-to-day, you ll work closely with teams across the business (engineering, project management, and customer support), plan security activities within the development lifecycle, and ensure alignment with laws, regulations, and customer expectations. You ll specifically take care of delivering turnkey projects, ensuring they align with contractual requirements and exceed customer expectations. We ll look to you for: • Ensuring the Cost/Quality/Delay of project/program cybersecurity deliverables • Conducting cybersecurity risk analysis and defining cybersecurity architecture and requirements • Cascading requirements to suppliers and managing third-party risks • Defining and applying cybersecurity assurance levels • Developing cybersecurity operating procedures • Evaluating the project's achieved cybersecurity level • Providing support during technical design meetings for cybersecurity activities • Obtaining agreement from project/program/customer on implemented security measures • Managing vulnerabilities, cybersecurity issues, and action plans • Handling program/project cybersecurity communications • Managing relationships with external auditors during cybersecurity audits • Establishing lessons learned to improve future projects All about you We value passion and attitude over experience. That s why we don t expect you to have every single skill. Instead, we ve listed some that we think will help you succeed and grow in this role: • A university or engineering degree • Experience with direct responsibility for hands-on architecture, design, and development • Knowledge of cybersecurity, with deployment experience of security technologies • Cybersecurity certifications such as GICSP, CISSP, GSEC, or CISM • Experience in embedded or industrial systems (railway, aeronautics, etc.) • Familiarity with cybersecurity standards and regulations, such as ISO 2700X, 62443, NIST, and NIS • Proficiency in cybersecurity risk analysis methods, such as EBIOS • Strong QCD (Quality, Cost, Delivery) management skills Things you ll enjoy Join us on a life-long transformative journey the rail industry is here to stay, so you can grow and develop new skills and experiences throughout your career. You ll also: • Enjoy stability, challenges, and a long-term career free from boring daily routines • Work with new security standards for rail signalling • Collaborate with transverse teams and helpful colleagues • Contribute to innovative projects • Utilise our flexible and inclusive working environment • Steer your career in whatever direction you choose across functions and countries • Benefit from our investment in your development through award-winning learning • Progress towards senior leadership roles or technical expertise paths • Benefit from a fair and dynamic reward package that recognises your performance and potential, plus comprehensive and competitive social coverage (life, medical, pension) You don t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you ll be proud. If you re up for the challenge, we d love to hear from you! Important to note As a global business, we re an equal-opportunity employer that celebrates diversity across the 70+ countries we operate in. We re committed to creating an inclusive workplace for everyone. Job Segment: Project Manager, Manager, Technology, Management</p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><ul><li>A university or engineering degree</li><li>Experience with direct responsibility for hands-on architecture, design, and development</li><li>Knowledge of cybersecurity, with deployment experience of security technologies</li><li>Cybersecurity certifications such as GICSP, CISSP, GSEC, or CISM</li><li>Experience in embedded or industrial systems (railway, aeronautics, etc.)</li><li>Familiarity with cybersecurity standards and regulations, such as ISO 2700X, 62443, NIST, and NIS</li><li>Proficiency in cybersecurity risk analysis methods, such as EBIOS</li><li>Strong QCD (Quality, Cost, Delivery) management skills</li></ul><p></p></section>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>Information Security & Risk Manager1.<br> Job Details Position Title: Information Security & Risk Manager Department: Technology Services / IT Reports To: Information Security / CTO Employment Type: Permanent Location: Maadi, Degla – On-site Grade: As per organizational structure Direct Reports: As per approved organizational structure 2.<br> Job Purpose The Information Security & Risk Manager is responsible for leading the organization’s Information Security and Cyber Risk function.<br> The role will design, implement, and maintain the cybersecurity program, manage enterprise information security risks, ensure compliance with applicable Saudi regulatory and industry requirements, and promote a strong security-aware culture across the organization.<br> The role provides strategic and operational leadership across Information Security Governance, Risk & Compliance (GRC), Security Operations, Incident Response, Data Protection, and Security Awareness .<br> 3. Key Accountabilities & Deliverables The role will be accountable for the development, implementation, and continuous improvement of: Information Security Strategy and Cybersecurity Roadmap Information Security policies, standards, procedures, and guidelines Information Security Management System (ISMS) Enterprise IT and Cybersecurity Risk Register Information Security Risk Assessment Reports Risk Treatment and Remediation Plans Security Compliance Reports, including ISO 27001 and applicable regulatory requirements Cybersecurity Control Framework and Control Effectiveness Reports Vulnerability Assessment and Penetration Testing (VAPT) Reports Cybersecurity Incident Reports and Root Cause Analysis (RCA) Security Monitoring and Threat Dashboards Cybersecurity KPI and KRI Dashboards Identity and Access Management (IAM) Policies, Models, and Access Matrices Data Classification and Data Protection Framework Internal and External Audit Reports and Evidence Repository Audit Findings and Remediation Tracking Business Continuity and Disaster Recovery (BCP/DR) Security Alignment Security Awareness and Training Programs and Reports Regulatory Assessments, submissions, and compliance evidence 4.<br> Key ResponsibilitiesA.<br> Information Security Strategy & Governance Define, develop, and execute the organization’s Information Security Strategy and cybersecurity roadmap.<br> Own and continuously improve the Information Security Management System (ISMS).<br> Develop and maintain information security policies, standards, procedures, and guidelines.<br> Establish effective cybersecurity governance frameworks aligned with business objectives.<br> Provide regular reporting on cybersecurity posture, risk exposure, compliance, and security program performance to the CTO and executive leadership.<br> Establish and monitor security KPIs, KRIs, and performance metrics.<br> Ensure information security requirements are incorporated into technology initiatives, projects, and business processes.<br> B. Information Security Risk Management Lead regular information security and cybersecurity risk assessments across the organization.<br> Own and maintain the enterprise IT and cybersecurity risk register.<br> Identify, assess, prioritize, and communicate information security risks.<br> Develop and manage risk treatment plans and ensure remediation activities are tracked through to closure.<br> Work closely with business units, IT, and other stakeholders to establish appropriate risk mitigation strategies.<br> Translate technical cybersecurity risks into business impact and communicate them effectively to senior management.<br> Monitor the organization’s overall cyber risk profile and provide recommendations for risk reduction.<br> C. Security Operations & SOC Oversee Security Operations Centre (SOC) activities, including SOC Analysts and Security Engineers.<br> Ensure effective security monitoring, threat detection, investigation, and response capabilities.<br> Oversee SIEM operations and security monitoring platforms such as Microsoft Sentinel, Splunk, or equivalent technologies.<br> Establish and monitor security incident management processes.<br> Review security alerts, incidents, trends, and threat intelligence.<br> Ensure appropriate escalation and response mechanisms are in place for critical security events.<br> Monitor and improve the effectiveness of security controls and operational processes.<br> D. Cybersecurity Incident Response Lead the organization’s cybersecurity incident response capability.<br> Ensure effective detection, containment, eradication, recovery, and post-incident activities.<br> Develop, maintain, and continuously improve the Cybersecurity Incident Response Plan (CIRP).<br> Conduct regular incident response exercises and simulations.<br> Lead investigations into significant security incidents and ensure Root Cause Analysis (RCA) is completed.<br> Track corrective and preventive actions resulting from security incidents.<br> Ensure lessons learned are incorporated into security controls and processes.<br> E. Governance, Risk & Compliance Lead Information Security Governance, Risk, and Compliance (GRC) activities.<br> Ensure compliance with applicable regulatory and industry requirements, including: National Cybersecurity Authority (NCA) requirements Saudi Personal Data Protection Law (PDPL) National Data Management Office (NDMO) requirements, where applicable ISO/IEC 27001 Other applicable cybersecurity and data protection regulations Coordinate internal and external security audits and assessments.<br> Manage audit evidence collection and maintain an organized security evidence repository.<br> Track audit findings, remediation plans, and closure status.<br> Prepare management and regulatory compliance reports.<br> Support regulatory assessments, reviews, and submissions as required.<br> F. Data Protection & Privacy Establish and maintain data protection and information classification frameworks.<br> Ensure appropriate security controls are implemented for sensitive and personal data.<br> Work with relevant stakeholders to support compliance with PDPL and applicable data protection requirements.<br> Establish appropriate data access, handling, retention, and protection controls.<br> Support privacy and data protection risk assessments where required.<br> G. Vulnerability & Security Testing Oversee vulnerability management activities across IT environments.<br> Coordinate Vulnerability Assessments and Penetration Testing (VAPT).<br> Review vulnerability and penetration testing reports.<br> Ensure security vulnerabilities are appropriately prioritized based on business risk.<br> Track remediation activities and validate closure of critical and high-risk vulnerabilities.<br> Ensure security testing is incorporated into relevant technology projects and systems.<br> H. Identity & Access Management Establish and maintain IAM policies, standards, and access control frameworks.<br> Ensure appropriate access governance and segregation of duties.<br> Review privileged access and high-risk accounts.<br> Support periodic user access reviews and access recertification.<br> Ensure access controls align with business requirements and security policies.<br> I. Security Awareness & Culture Develop and implement an organization-wide security awareness program.<br> Lead cybersecurity awareness campaigns and security training.<br> Implement phishing simulation and social engineering awareness programs.<br> Monitor employee security awareness performance and identify improvement areas.<br> Promote a strong cybersecurity culture across all business functions.<br> J. Business Continuity & Disaster Recovery Ensure cybersecurity requirements are incorporated into Business Continuity and Disaster Recovery plans.<br> Participate in BCP/DR risk assessments and exercises.<br> Ensure critical systems have appropriate security, recovery, and resilience controls.<br> Support testing and continuous improvement of security-related recovery procedures.<br> 5. Qualifications & ExperienceMinimum Qualifications Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Security , or a related discipline.<br> CISSP or CISM certification – Mandatory.<br> ISO/IEC 27001 Lead Implementer or Lead Auditor certification preferred.<br> NCA-related cybersecurity accreditation or certification is preferred.<br> Minimum Experience 8–10 years of professional experience in Information Security / Cybersecurity.<br> At least 3 years of experience in a cybersecurity or information security management/leadership role.<br> Proven experience managing enterprise cybersecurity programs and security teams.<br> Proven experience in GRC, risk management, security operations, and incident response.<br> Proven experience working with regulatory compliance, audits, and cybersecurity frameworks.<br> 6. Technical & Professional Skills The successful candidate should demonstrate: Strong knowledge of cybersecurity frameworks, standards, and best practices.<br> Deep understanding of NCA, PDPL, NDMO, ISO 27001 , and applicable data protection requirements.<br> Strong expertise in Governance, Risk, and Compliance (GRC).<br> Experience with SOC operations and SIEM platforms such as Microsoft Sentinel, Splunk , or equivalent.<br> Strong understanding of vulnerability management and penetration testing.<br> Strong knowledge of Incident Response and Cybersecurity Incident Response Plans (CIRP).<br> Strong understanding of IAM and access governance.<br> Knowledge of data protection, data classification, and data governance.<br> Strong understanding of secure architecture and security controls.<br> Ability to develop and monitor cybersecurity KPIs and KRIs.<br> Strong audit and regulatory assessment experience.<br> Ability to assess and communicate cybersecurity risks in terms of business impact.<br> Strong strategic thinking and high-level decision-making capability.<br> Excellent leadership and people-management skills.<br> Ability to manage cross-functional teams and stakeholders under pressure.<br> Strong communication, presentation, and reporting skills.<br> Bilingual proficiency in Arabic and English.<br> 7. Leadership Competencies Strategic Thinking Cybersecurity Leadership Risk-Based Decision Making Stakeholder Management Executive Communication Team Leadership & Development Problem Solving Crisis and Incident Management Governance & Accountability Continuous Improvement Business Acumen Change Management Special Requirements Ability to work effectively in a fast-paced and dynamic environment.<br> Ability to manage cybersecurity incidents and critical security situations.<br> Willingness to participate in security incident response and escalation activities when required.<br> Strong confidentiality and professional integrity.<br> Ability to work collaboratively with executive leadership, IT, business functions, auditors, and regulatory stakeholders.<br></span> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><span><strong>Job Purpose:</strong></span></p><br><p><span>The role is to ensure strategic alignment of Information Security GRC initiatives with the bank’s risk management strategy, regulatory obligations, governance frameworks and the organization’s enterprise ESG commitments. The role drives Information Security GRC initiatives to strengthen the security posture while ensuring compliance and organizational alignment through:</span></p><br><p><span>• Risk tracking and compliance monitoring</span></p><br><p><span>• Policy exception management</span></p><br><p><span>• RCSA coordination</span></p><br><p><span>• Offshoring risk reporting</span></p><br><p><span>The position also leverages automation to streamline Information Security GRC processes, enhance risk visibility, and maintain accurate reporting across the Information Security Group (ISG).</span></p><br><p><span>The role ensures that information security governance, risk, compliance, and reporting practices demonstrably support ESG governance and social objectives, without duplicating or replacing the responsibilities of the corporate ESG function.</span></p><br><p><span>This role operationalizes ESG-relevant cybersecurity controls, metrics, disclosures, and assurance activities within ISG, ensuring readiness for regulatory, investor, and board-level ESG scrutiny. Also support AVP – ISG GRC in preparing executive, board, and regulatory ESG-related cybersecurity governance responses.</span></p><br><p><span><strong>Key Result Areas:</strong></span></p><br><p><span><span><strong>Governance, Risk, Compliance:</strong></span></span></p><br><ul><li><p><span><span>Ensure adherence to internal policies, regulatory requirements, and industry standards. </span></span></p><br></li><li><p><span><span>Identify, assess, and manage information security risks across business units. </span></span></p><br></li><li><p><span><span>Maintain compliance documentation and evidence for audits.</span></span></p><br></li></ul><p><span><span><strong>Policy Exception Management:</strong></span></span></p><br><ul><li><p><span><span>Develop and maintain a comprehensive process for managing policy exceptions, including documentation, expiration date and approval workflows.</span></span></p><br></li><li><p><span><span>Ensure all policy exceptions are properly documented, reviewed, and approved in accordance with organizational standards.</span></span></p><br></li><li><p><span><span>Perform risk assessments for proposed policy exceptions to evaluate their potential impact on compliance and security. </span></span></p><br></li><li><p><span><span>Work with stakeholders to communicate policy exception process, develop compensating controls for policy exceptions, and ensure timely closure.</span></span></p><br></li><li><p><span><span>Regularly review and monitor granted exceptions to ensure compliance with the terms and conditions.</span></span></p><br></li><li><p><span><span>Conduct periodic audits to assess compliance with approved exceptions and identify deviations for remediation. </span></span></p><br></li></ul><p><span><span><strong>Risk Control Self Assessments </strong></span></span></p><br><ul><li><p><span><span>Coordinate and ensure regular risk control self-assessments across various business units to identify and evaluate potential risks.</span></span></p><br></li><li><p><span><span>Compile and analyze assessment results and prepare detailed reports with actionable insights and recommendations.</span></span></p><br></li><li><p><span><span>Perform follow-ups to verify the effectiveness of implemented controls and risk mitigation measures.</span></span></p><br></li></ul><p><span><span><strong>Offshoring Reporting</strong></span></span></p><br><ul><li><p><span><span>Maintain accurate and timely reporting of offshoring activities</span></span></p><br></li><li><p><span><span>Ensure alignment with regulatory reporting requirements, and supporting the organization’s compliance posture concerning offshore operations</span></span></p><br></li><li><p><span><span>Establish streamlined reporting mechanisms that meet both internal and external requirements.</span></span></p><br></li><li><p><span><span>Assess and manage the risks associated with offshoring arrangements. Ensure that appropriate controls and mitigations are in place to address any regulatory or compliance risks tied to offshore activities.</span></span></p><br></li></ul><p><span><span><strong>GRC Function Automation: </strong></span></span></p><br><ul><li><p><span><span>Be the owner of the bank’s GRC platform for ISG and oversee the management of the bank’s IS GRC solution. </span></span></p><br></li><li><p><span><span>Oversee the administration, configuration, and maintenance of the GRC platform to ensure optimal performance and availability</span></span></p><br></li><li><p><span><span>Enable centralized knowledgebase and GRC solution to automate Information Security activities and governance process with a centralized risk register, risk reports and dashboards related to overall risk posture for specific location and business unit. </span></span></p><br></li><li><p><span><span>Automate the GRC functions and reduce manual efforts to provide near real time insights into risks by performing quantitative and qualitative assessments. </span></span></p><br></li><li><p><span><span>Support local CISO’s / IS SPOCs in regulatory audit discussion and data required from ISG and enabling the local CISOs with Archer access to onboard the open issues for centralized tracking and governance.</span></span></p><br></li><li><p><span><span>Ensure that the solution is effectively used to support the organization’s information security governance, risk, and</span></span><span><span> compliance activities</span></span></p><br></li></ul><p><span><span><strong>ESG–ISG Alignment Framework</strong></span></span></p><br><ul><li><p><span><span>Establish and maintain a formal mapping between ISG control frameworks (ISO 27001, NIST, regulatory requirements) and enterprise ESG governance and social disclosure requirements.</span></span></p><br></li><li><p><span><span>Define ESG-relevant cybersecurity control objectives and assurance artifacts.</span></span></p><br></li></ul><p><span><span><strong>ESG-Relevant Metrics and Reporting</strong></span></span></p><br><ul><li><p><span><span>Design cybersecurity ESG indicators (e.g., cyber risk governance, data protection maturity, incident disclosure readiness).</span></span></p><br></li><li><p><span><span>Ensure ISG reporting feeds into enterprise ESG dashboards and external disclosures where required.</span></span></p><br></li><li><p><span><span>Prepare cybersecurity governance inputs for board-level ESG and risk reporting.</span></span></p><br></li><li><p><span><span>Support CISO and VP IS GRC in responding to executive and regulator ESG inquiries.</span></span></p><br></li></ul><p><span><span><strong>ESG Assurance and Audit Support</strong></span></span></p><br><ul><li><p><span><span>Integrate ISG evidence collection to support ESG audits, sustainability assurance, and regulatory examinations.</span></span></p><br></li><li><p><span><span>Coordinate ISO 27001, cyber risk, and data protection assurance activities that support ESG governance reporting.</span></span></p><br></li></ul><p><span><span><strong>Policy and Standard Integration</strong></span></span></p><br><ul><li><p><span><span>Ensure ISG policies, standards, and procedures reflect ESG governance commitments and public disclosures.</span></span></p><br></li><li><p><span><span>Maintain consistency between internal security governance documents and enterprise ESG policy statements.</span></span></p><br></li></ul><p><span><span><strong>Stakeholder Coordination</strong></span></span></p><br><ul><li><p><span><span>Act as ISG liaison to the corporate ESG function.</span></span></p><br></li><li><p><span><span>Escalate material ESG-related cyber governance risks to AVP – ISG GRC for executive-level decision and disclosure consideration.</span></span></p><br></li></ul><p><span><span><strong>Regulatory and Disclosure Readiness</strong></span></span></p><br><ul><li><p><span><span>Monitor emerging ESG regulations relating to cybersecurity, data protection, and digital resilience.</span></span></p><br></li><li><p><span><span>Translate regulatory requirements into actionable ISG controls and reporting obligations.</span></span></p><br></li></ul><p><span><span><strong>Key Principles:</strong></span></span></p><br><ul><li><p><span><span>No ownership of enterprise ESG strategy — Alignment and integration only.</span></span></p><br></li><li><p><span><span>Evidence-driven governance — All ESG claims relating to cybersecurity must be auditable.</span></span></p><br></li><li><p><span><span>Consistency — Public ESG disclosures must match internal security practices.</span></span></p><br></li><li><p><span><span>Regulatory defensibility — Readiness for regulator, investor, and external assurance scrutiny.</span></span></p><br></li><li><p><span><span>Non-duplication — Avoid parallel ESG structures Inside ISG</span><span>.</span></span></p><br></li></ul><p><span><span><strong>Operating Environment, Framework and Boundaries, Working Relationships:</strong></span></span></p><br><ul><li><p><span><span>Operating environment: All the locations where Mashreq Bank is operational</span></span></p><br></li><li><p><span><span>Information Security / Cyber Security Regulations and Industry best practices. </span></span></p><br></li><li><p><span><span>All business units including LOD 1-3 including LOD1 – Business, Tech GRC, Technology, LOD-2 Group Compliance, Fraud Prevention, Risk Management and LOD-3 Internal Audit.</span></span></p><br></li></ul><p><span><span><strong>Problem Solving:</strong></span></span></p><br><ul><li><p><span><span>Translate high-level ESG commitments into concrete ISG control and reporting requirements.</span></span></p><br></li><li><p><span><span>Resolve conflicts between enterprise ESG narratives and actual ISG control maturity.</span></span></p><br></li><li><p><span><span>Design pragmatic metrics where ESG frameworks are vague or non-prescriptive.</span></span></p><br></li><li><p><span><span>Identify and remediate ESG-related cybersecurity disclosure gaps before external reporting.</span></span></p><br></li><li><p><span><span>Anticipate regulatory changes affecting cyber-related ESG obligations.</span></span></p><br></li></ul><p><span><strong>Decision Making Authority & Responsibility:</strong></span></p><br><ul><li><p><span><span>Consult and validate recommendations to mitigate information security risks</span></span></p><br></li><li><p><span><span>Consult and provide recommendations to mitigate the risk to a level aligned with the risk appetite of the bank. </span></span></p><br></li><li><p><span><span>Assure compliance with regulatory expectations and avoid regulatory penalties.</span></span></p><br></li><li><p><span><span>Confirm adequacy of the controls against internal information security policy, standards and applicable regulatory requirements.</span></span></p><br></li></ul><p><span><span><strong>Authority:</strong></span></span></p><br><ul><li><p><span><span>Define ISG ESG integration frameworks and reporting structures.</span></span></p><br></li><li><p><span><span>Propose cybersecurity ESG metrics and control mappings for approval by AVP – ISG GRC.</span></span></p><br></li><li><p><span><span>Recommend updates to ISG policies driven by ESG obligations.</span></span></p><br></li></ul><p><span><span><strong>Responsibility:</strong></span></span></p><br><ul><li><p><span><span>Accuracy and defensibility of cybersecurity inputs to ESG disclosures.</span></span></p><br></li><li><p></p></li></ul> </div>
<p><h4>Job description</h4>
<p>Directs Security Operations Center (SOC) activities including monitoring, triage, and escalation to ensure continuous protection of fintech and corporate infrastructure.</p>
<p>Oversees end-to-end incident response phases (detection to recovery) to minimize the impact of cyber threats on payment systems.</p>
<p>Coordinates incident response workflows across internal teams and external stakeholders to ensure a unified and rapid organizational defense.</p>
<p>Architects incident response playbooks and operational procedures to standardize security actions and improve response consistency.</p>
<p>Develops advanced detection rule sets and security anomaly patterns to enhance the organization's proactive defense capabilities.</p>
<p>Establishes a comprehensive cyber threat intelligence capability to integrate indicators of compromise (IOCs) into active detection systems.</p>
<p>Executes proactive threat hunting across endpoints and cloud environments to identify and neutralize hidden security risks.</p>
<p>Governs enterprise-wide vulnerability management and remediation tracking to ensure critical payment platforms remain secure and patched.</p>
<p>Analyzes operational security metrics to provide senior leadership with actionable reporting on the organization's defensive posture.</p>
<p>Leads and mentors SOC analysts and threat responders to foster a high-performing team culture focused on operational excellence.</p>
<h4>Skills description</h4>
<p><strong>Interpersonal skills</strong></p>
<ul>
<li>Strong operational leadership and team management.</li>
<li>Ability to lead teams during high-pressure cyber incidents.</li>
<li>Excellent communication skills for technical and executive audiences.</li>
<li>Strong decision-making and crisis management capabilities.</li>
<li>Collaboration with engineering, fraud, and product teams.</li>
<li>Ability to mentor and develop cyber defense professionals.</li>
</ul>
<p><strong>Technical skills</strong></p>
<ul>
<li>Deep understanding of SOC operations and security monitoring processes.</li>
<li>Experience operating SIEM, EDR, NDR, SOAR, and threat intelligence platforms.</li>
<li>Strong knowledge of incident response methodologies and digital forensics.</li>
<li>Experience with threat intelligence frameworks such as MITRE ATT&CK.</li>
<li>Experience with vulnerability management tools and patch prioritization.</li>
<li>Understanding of cloud security monitoring across AWS, Azure, or GCP.</li>
<li>Knowledge of malware analysis and threat actor tactics, techniques, and procedures.</li>
<li>Familiarity with security logging, detection engineering, and threat hunting techniques.</li>
</ul>
<p><strong>Professional experience</strong></p>
<ul>
<li>10+ years cybersecurity or security operations.</li>
<li>Minimum 5 years managing SOC or security operations teams.</li>
<li>Experience managing incident response programs and cyber crisis events.</li>
<li>Experience implementing threat intelligence and threat hunting capabilities.</li>
<li>Experience operating vulnerability management programs at enterprise scale.</li>
<li>Experience working in fintech, banking, payments, or other regulated environments is highly desirable.</li>
</ul>
<p><strong>Management experience</strong></p>
<ul>
<li>5+ years.</li>
</ul>
<p><strong>Educational background</strong></p>
<ul>
<li>Bachelor’s degree in Cyber Security, Computer Science, Information Technology or related field.</li>
<li>Relevant certifications may include:</li>
<ul>
<li>CISSP – Certified Information Systems Security Professional</li>
<li>GIAC Certified Incident Handler (GCIH)</li>
<li>GIAC Certified Forensic Analyst (GCFA)</li>
<li>Certified Ethical Hacker (CEH)</li>
<li>Certified SOC Analyst (CSA)</li>
</ul>
</ul></p><p></p>
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>Responsible for configuring, maintaining, and supporting CSOC platforms, tools and logging infrastructure ensuring all systems fully operational and secure. Manage the development, customization and tuning of security content, including use cases, rules, and playbooks, to effectively detect and respond to cyber threats, ensuring detection logic and automation workflows align with CSOC priorities and cyber threat intelligence. Designing and build CSOC technologies such as SIEM, SOAR, EDR, and other platforms. Design and develop security content for, SIEM, SOAR and EDR Configure and maintain SIEM, SOAR, EDR, and other CSOC platforms. Build and manage logging infrastructure to ensure full telemetry coverage. Manage log source onboarding, parsing, normalization, data ingestion pipelines, and enrichment activities. Develop, test, and fine-tune detection rules, correlation logic, and alert conditions. Map and report detection coverage against frameworks (e.g., MITRE ATT&CK). Propose new detection ideas based on threat research and attack simulations. Build SOAR playbooks and automation scripts for alert enrichment and incident response. Translate threat intelligence, red team findings, and vulnerability data into use cases. Perform false-positive analysis and rule optimization to improve fidelity. Maintain a content repository with versioning, documentation, and lifecycle status. Work with threat monitoring and DFIR teams to validate use case effectiveness. Maintain system documentation, configuration baselines, and maintenance records. Monitor health and availability of all logging pipelines and tools. Conduct root-cause analysis of tool outages or data loss.</p></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><ul><li>Bachelor's degree in Computer Engineering, Computer Science, Information Technology, or a related field.</li><li>3-6 years of experience in Cybersecurity Operations (CSOC), Detection Engineering, or Detection Content Development.</li><li>Strong understanding of SOC architecture, security technologies, and log management, including ingestion, parsing, enrichment, correlation, and storage best practices.</li><li>Hands-on experience with the design and implementation of SIEM/SOAR platforms, such as Splunk, ELK, LogRhythm, Microsoft Sentinel, Palo Alto XSIAM, or similar.</li><li>Solid knowledge of network infrastructure, Linux/Windows administration, and system monitoring, with expertise in security telemetry (firewall, EDR, proxy, and other log sources).</li><li>Proficiency in query and scripting languages (e.g., KQL, SPL, Sigma) for automation, detection tuning, and source validation.</li><li>Familiarity with SOAR automation and orchestration tools (e.g., Cortex XSOAR, Sentinel Logic Apps, or Phantom) and experience designing scalable, reusable detection content.</li><li>In-depth understanding of threat detection concepts, attacker behaviors, and MITRE ATT&CK mapping, including content gap analysis and threat model alignment.</li><li>Strong analytical and troubleshooting skills with the ability to ensure high availability and reliability of security tooling.</li><li>Knowledge of AI/ML concepts and their application in cybersecurity for detection and automation use cases.</li><li>Good communication and coordination skills, with the ability to collaborate effectively across teams such as Threat Monitoring, CTI, and DFIR.</li><li>Strong documentation and version control discipline (e.g., Git, Confluence) and attention to detection accuracy and operational impact.</li><li>Understanding of data integrity, retention policies, and relevant regulatory/compliance standards.</li><li>Relevant certifications in SIEM/SOAR/EDR platforms (e.g., Splunk, ELK, LogRhythm, Microsoft Sentinel, Palo Alto XSIAM, or equivalent) are preferred.</li></ul><p></p></section>
<p>Join Audio Technology and play a key role in driving technical sales success by designing, sizing, and presenting enterprise active networking solutions. As a Presales Active Network Engineer, you'll bridge the gap between customer requirements, leading technology vendors, and our commercial sales team to deliver innovative, scalable, and cost-effective networking solutions.</p><p><strong>Key Responsibilities</strong>:</p><p>- Analyze client RFPs, RFIs, and technical requirements to design enterprise networking solutions across LAN, WAN, SD-WAN, WLAN, and Data Center Networks.</p><p>- Develop end-to-end network architectures, including high-level topologies, routing and switching strategies, IP addressing schemes, and redundancy models.</p><p>- Select and specify the appropriate active network hardware and software, including core/distribution/access switches, edge routers, next-generation firewalls (NGFW), wireless controllers, and access points.</p><p>- Prepare accurate and detailed Bills of Quantities (BOQs), Bills of Materials (BOMs), and Scope of Work (SOW) documents.</p><p>- Collaborate with leading technology vendors such as Cisco, Aruba, Fortinet, and others for solution validation, deal registration, and special pricing approvals.</p><p>- Develop comprehensive technical proposals, compliance matrices, and detailed RFP responses.</p><p><strong>Requirements</strong></p><p>- Bachelor's degree in Computer Engineering, Electronics, Telecommunications, or a related field.</p><p>- 5–7 years of experience in enterprise network design or network engineering.</p><p>- Cisco Certification: CCNP Enterprise (Routing & Switching/Wireless) or CCNP Security/Data Center.</p><p>- Aruba/HPE Certification: ACMP or ACSP.</p><p>- Strong expertise in routing protocols (OSPF, BGP, EIGRP), switching technologies (VLANs, STP, VXLAN), SD-WAN, and Wi-Fi 6/6E.</p><p>- Solid knowledge of enterprise security solutions, including NGFWs, IPsec VPNs, SSL inspection, and firewall policy management.</p><p>- Proficiency with network design and diagramming tools such as Microsoft Visio, AutoCAD, or EdrawMax.</p><p></p>
<p><h4>Join us</h4>
<p>At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.</p>
<h4>Role purpose</h4>
<h4>About the role</h4>
<p>We are looking for a Cyber Security Assurance Senior Specialist to join our team and play a key role in ensuring the security of Vodafone’s digital environment. This role is responsible for conducting penetration testing, vulnerability analysis, and security assurance activities across web applications, mobile platforms, networks, and cloud environments.</p>
<p>As a Cyber Security Assurance Senior Specialist, you will work closely with technical teams and business stakeholders to identify, assess, and mitigate security risks while ensuring compliance with Vodafone’s cyber security policies and standards.</p>
<h4>Job responsibilities</h4>
<li>Conduct penetration testing on web applications, networks, mobile applications, and cloud environments to identify vulnerabilities and security weaknesses.</li>
<li>Perform vulnerability analysis and provide remediation recommendations to enhance security posture.</li>
<li>Ensure secure acceptance of new nodes and technologies by validating compliance with Vodafone’s security policies and industry standards.</li>
<li>Perform regular security assurance activities on existing systems and applications to maintain continuous compliance and protection against emerging threats.</li>
<li>Participate in risk assessments for new projects, providing a security assurance perspective to ensure risks are identified and mitigated early in the development cycle.</li>
<li>Collaborate with Vodafone technical teams and business units to address and remediate penetration testing findings effectively.</li>
<li>Stay up to date with emerging security threats, vulnerabilities, and industry best practices, applying them to improve security assurance processes.</li>
<h4>Not a perfect fit?</h4>
<p>Worried that you don’t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you’re excited about this role but your experience doesn’t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.</p>
<h4>Core competencies, knowledge, and experience</h4>
<h4>Key activities</h4>
<li>Follow internal delivery processes to deliver cyber security programs requirements in alignment with global/local policies.</li>
<li>Ensure delivery of projects on time and within allocated budget.</li>
<li>Ensure that all streams are running on the right track and fulfilling their main objectives.</li>
<li>Issue reports for running streams to Cyber Security and Technology Management.</li>
<li>Manage building proper interface with different vendors.</li>
<li>Ensure projects and activities delivery with vendors on time and within allocated budget.</li>
<li>Strong knowledge of security frameworks such as MITRE ATT&CK, NIST, and CIS.</li>
<li>Familiarity with hardening configurations for different environments (servers, databases, applications, etc.).</li>
<li>Experience in risk assessment and providing security recommendations in line with business requirements.</li>
<li>Ability to work collaboratively with cross-functional teams to address and mitigate security vulnerabilities.</li>
<li>Strong analytical and problem-solving skills, with the ability to communicate complex security issues to technical and non-technical stakeholders.</li>
<li>Relevant certifications are a plus (OSCP, eWPTX, eCPPT, or similar).</li>
<h4>Who we are</h4>
<p>We are a leading international telco, serving millions of customers. At Vodafone, we believe that connectivity is a force for good. If we use it for the things that really matter, it can improve people's lives and the world around us. Through our technology we empower people, connecting everyone regardless of who they are or where they live and we protect the planet, whilst helping our customers do the same.</p>
<p>Belonging at Vodafone isn't a concept; it's lived, breathed, and cultivated through everything we do. You'll be part of a global and diverse community, with many different minds, abilities, backgrounds and cultures. We're committed to increase diversity, ensure equal representation, and make Vodafone a place everyone feels safe, valued and included.</p>
<p>If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, please contact the recruitment team for guidance.</p>
<p>Together we can.</p></p><p></p>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><strong>JOB DETAILS:</strong></p><br><p>Position Title: Security Engineer</p><br><p>Reports to: Information Security and Risk Manager</p><br><p>Business Line/ Department: Information Security</p><br><p><strong>3. JOB PURPOSE: </strong></p><br><p> The Job Holder is Responsible to. Designs, implements, and maintains cybersecurity controls and technologies across the IT environment, ensuring technical security measures are robust, current, and aligned with NCA and internal security policies.</p><br><p><strong>4. Job Deliverables - Accountability</strong></p><br><p><strong>Description</strong></p><br><p> Deliverables</p><br><p> Security architecture designs & system diagrams (network, IAM, security controls) .</p><br><p> Risk assessment & vulnerability reports (risk register, threat analysis).</p><br><p> Security monitoring dashboards & SIEM reports (threat detection, events, alerts) .</p><br><p> Incident response artifacts (logs, RCA reports, response playbooks).</p><br><p> Security configuration & hardening outputs (policies, access controls, system configs) .</p><br><p> Compliance & audit documentation (control evidence, regulatory alignment.</p><br><p><strong>Description</strong></p><br><p><strong>Security Control Implementation</strong></p><br><p>• Design and implement cybersecurity controls: firewalls, EDR, DLP, PAM, email security, and WAF.</p><br><p>• Harden infrastructure, endpoints, and applications in line with security baselines.</p><br><p>• Manage vulnerability scanning and coordinate remediation with IT teams.</p><br><p><strong>Identity & Access Management</strong></p><br><p>• Administer Identity and Access Management (IAM) controls including Privileged Access Management (PAM).</p><br><p>• Manage MFA, Conditional Access, and Zero Trust access policies.</p><br><p>• Conduct access reviews and enforce least privilege principles.</p><br> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
Information Security & Risk Manager1. Job Details<p><strong>Position Title:</strong> Information Security & Risk Manager<br><strong>Department:</strong> Technology Services / IT<br><strong>Reports To:</strong> Information Security / CTO<br><strong>Employment Type:</strong> Permanent<br><strong>Location:</strong> Maadi, Degla – On-site<br><strong>Grade:</strong> As per organizational structure<br><strong>Direct Reports:</strong> As per approved organizational structure</p><br>2. Job Purpose<p>The Information Security & Risk Manager is responsible for leading the organization’s Information Security and Cyber Risk function. The role will design, implement, and maintain the cybersecurity program, manage enterprise information security risks, ensure compliance with applicable Saudi regulatory and industry requirements, and promote a strong security-aware culture across the organization.</p><br><p>The role provides strategic and operational leadership across <strong>Information Security Governance, Risk & Compliance (GRC), Security Operations, Incident Response, Data Protection, and Security Awareness</strong>.</p><br>3. Key Accountabilities & Deliverables<p>The role will be accountable for the development, implementation, and continuous improvement of:</p><br><ul><li>Information Security Strategy and Cybersecurity Roadmap</li><li>Information Security policies, standards, procedures, and guidelines</li><li>Information Security Management System (ISMS)</li><li>Enterprise IT and Cybersecurity Risk Register</li><li>Information Security Risk Assessment Reports</li><li>Risk Treatment and Remediation Plans</li><li>Security Compliance Reports, including ISO 27001 and applicable regulatory requirements</li><li>Cybersecurity Control Framework and Control Effectiveness Reports</li><li>Vulnerability Assessment and Penetration Testing (VAPT) Reports</li><li>Cybersecurity Incident Reports and Root Cause Analysis (RCA)</li><li>Security Monitoring and Threat Dashboards</li><li>Cybersecurity KPI and KRI Dashboards</li><li>Identity and Access Management (IAM) Policies, Models, and Access Matrices</li><li>Data Classification and Data Protection Framework</li><li>Internal and External Audit Reports and Evidence Repository</li><li>Audit Findings and Remediation Tracking</li><li>Business Continuity and Disaster Recovery (BCP/DR) Security Alignment</li><li>Security Awareness and Training Programs and Reports</li><li>Regulatory Assessments, submissions, and compliance evidence</li></ul>4. Key ResponsibilitiesA. Information Security Strategy & Governance<ul><li>Define, develop, and execute the organization’s Information Security Strategy and cybersecurity roadmap.</li><li>Own and continuously improve the Information Security Management System (ISMS).</li><li>Develop and maintain information security policies, standards, procedures, and guidelines.</li><li>Establish effective cybersecurity governance frameworks aligned with business objectives.</li><li>Provide regular reporting on cybersecurity posture, risk exposure, compliance, and security program performance to the CTO and executive leadership.</li><li>Establish and monitor security KPIs, KRIs, and performance metrics.</li><li>Ensure information security requirements are incorporated into technology initiatives, projects, and business processes.</li></ul>B. Information Security Risk Management<ul><li>Lead regular information security and cybersecurity risk assessments across the organization.</li><li>Own and maintain the enterprise IT and cybersecurity risk register.</li><li>Identify, assess, prioritize, and communicate information security risks.</li><li>Develop and manage risk treatment plans and ensure remediation activities are tracked through to closure.</li><li>Work closely with business units, IT, and other stakeholders to establish appropriate risk mitigation strategies.</li><li>Translate technical cybersecurity risks into business impact and communicate them effectively to senior management.</li><li>Monitor the organization’s overall cyber risk profile and provide recommendations for risk reduction.</li></ul>C. Security Operations & SOC<ul><li>Oversee Security Operations Centre (SOC) activities, including SOC Analysts and Security Engineers.</li><li>Ensure effective security monitoring, threat detection, investigation, and response capabilities.</li><li>Oversee SIEM operations and security monitoring platforms such as Microsoft Sentinel, Splunk, or equivalent technologies.</li><li>Establish and monitor security incident management processes.</li><li>Review security alerts, incidents, trends, and threat intelligence.</li><li>Ensure appropriate escalation and response mechanisms are in place for critical security events.</li><li>Monitor and improve the effectiveness of security controls and operational processes.</li></ul>D. Cybersecurity Incident Response<ul><li>Lead the organization’s cybersecurity incident response capability.</li><li>Ensure effective detection, containment, eradication, recovery, and post-incident activities.</li><li>Develop, maintain, and continuously improve the Cybersecurity Incident Response Plan (CIRP).</li><li>Conduct regular incident response exercises and simulations.</li><li>Lead investigations into significant security incidents and ensure Root Cause Analysis (RCA) is completed.</li><li>Track corrective and preventive actions resulting from security incidents.</li><li>Ensure lessons learned are incorporated into security controls and processes.</li></ul>E. Governance, Risk & Compliance<ul><li>Lead Information Security Governance, Risk, and Compliance (GRC) activities.</li><li>Ensure compliance with applicable regulatory and industry requirements, including:<ul><li>National Cybersecurity Authority (NCA) requirements</li><li>Saudi Personal Data Protection Law (PDPL)</li><li>National Data Management Office (NDMO) requirements, where applicable</li><li>ISO/IEC 27001</li><li>Other applicable cybersecurity and data protection regulations</li></ul></li><li>Coordinate internal and external security audits and assessments.</li><li>Manage audit evidence collection and maintain an organized security evidence repository.</li><li>Track audit findings, remediation plans, and closure status.</li><li>Prepare management and regulatory compliance reports.</li><li>Support regulatory assessments, reviews, and submissions as required.</li></ul>F. Data Protection & Privacy<ul><li>Establish and maintain data protection and information classification frameworks.</li><li>Ensure appropriate security controls are implemented for sensitive and personal data.</li><li>Work with relevant stakeholders to support compliance with PDPL and applicable data protection requirements.</li><li>Establish appropriate data access, handling, retention, and protection controls.</li><li>Support privacy and data protection risk assessments where required.</li></ul>G. Vulnerability & Security Testing<ul><li>Oversee vulnerability management activities across IT environments.</li><li>Coordinate Vulnerability Assessments and Penetration Testing (VAPT).</li><li>Review vulnerability and penetration testing reports.</li><li>Ensure security vulnerabilities are appropriately prioritized based on business risk.</li><li>Track remediation activities and validate closure of critical and high-risk vulnerabilities.</li><li>Ensure security testing is incorporated into relevant technology projects and systems.</li></ul>H. Identity & Access Management<ul><li>Establish and maintain IAM policies, standards, and access control frameworks.</li><li>Ensure appropriate access governance and segregation of duties.</li><li>Review privileged access and high-risk accounts.</li><li>Support periodic user access reviews and access recertification.</li><li>Ensure access controls align with business requirements and security policies.</li></ul>I. Security Awareness & Culture<ul><li>Develop and implement an organization-wide security awareness program.</li><li>Lead cybersecurity awareness campaigns and security training.</li><li>Implement phishing simulation and social engineering awareness programs.</li><li>Monitor employee security awareness performance and identify improvement areas.</li><li>Promote a strong cybersecurity culture across all business functions.</li></ul>J. Business Continuity & Disaster Recovery<ul><li>Ensure cybersecurity requirements are incorporated into Business Continuity and Disaster Recovery plans.</li><li>Participate in BCP/DR risk assessments and exercises.</li><li>Ensure critical systems have appropriate security, recovery, and resilience controls.</li><li>Support testing and continuous improvement of security-related recovery procedures.</li></ul>5. Qualifications & ExperienceMinimum Qualifications<ul><li>Bachelor’s degree in <strong>Information Technology, Computer Science, Cybersecurity, Information Security</strong>, or a related discipline.</li><li><strong>CISSP or CISM certification – Mandatory.</strong></li><li>ISO/IEC 27001 Lead Implementer or Lead Auditor certification preferred.</li><li>NCA-related cybersecurity accreditation or certification is preferred.</li></ul>Minimum Experience<ul><li><strong>8–10 years of professional experience in Information Security / Cybersecurity.</strong></li><li>At least <strong>3 years of experience in a cybersecurity or information security management/leadership role.</strong></li><li>Proven experience managing enterprise cybersecurity programs and security teams.</li><li>Proven experience in GRC, risk management, security operations, and incident response.</li><li>Proven experience working with regulatory compliance, audits, and cybersecurity frameworks.</li></ul>6. Technical & Professional Skills<p>The successful candidate should demonstrate:</p><br><ul><li>Strong knowledge of cybersecurity frameworks, standards, and best practices.</li><li>Deep understanding of <strong>NCA, PDPL, NDMO, ISO 27001</strong>, and applicable data protection requirements.</li><li>Strong expertise in Governance, Risk, and Compliance (GRC).</li><li>Experience with SOC operations and SIEM platforms such as <strong>Microsoft Sentinel, Splunk</strong>, or equivalent.</li><li>Strong understanding of vulnerability management and penetration testing.</li><li>Strong knowledge of Incident Response and Cybersecurity Incident Response Plans (CIRP).</li><li>Strong understanding of IAM and access governance.</li><li>Knowledge of data protection, data classification, and data governance.</li><li>Strong understanding of secure architecture and security controls.</li><li>Ability to develop and monitor cybersecurity KPIs and KRIs.</li><li>Strong audit and regulatory assessment experience.</li><li>Ability to assess and communicate cybersecurity risks in terms of business impact.</li><li>Strong strategic thinking and high-level decision-making capability.</li><li>Excellent leadership and people-management skills.</li><li>Ability to manage cross-functional teams and stakeholders under pressure.</li><li>Strong communication, presentation, and reporting skills.</li><li><strong>Bilingual proficiency in Arabic and English.</strong></li></ul>7. Leadership Competencies<ul><li>Strategic Thinking</li><li>Cybersecurity Leadership</li><li>Risk-Based Decision Making</li><li>Stakeholder Management</li><li>Executive Communication</li><li>Team Leadership & Development</li><li>Problem Solving</li><li>Crisis and Incident Management</li><li>Governance & Accountability</li><li>Continuous Improvement</li><li>Business Acumen</li><li>Change Management</li></ul>Special Requirements<ul><li>Ability to work effectively in a fast-paced and dynamic environment.</li><li>Ability to manage cybersecurity incidents and critical security situations.</li><li>Willingness to participate in security incident response and escalation activities when required.</li><li>Strong confidentiality and professional integrity.</li><li>Ability to work collaboratively with executive leadership, IT, business functions, auditors, and regulatory stakeholders.</li></ul> </div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>About us: Where elite tech talent meets world-class opportunities!<br> At Xenon7, we work with leading enterprises and innovative startups on exciting, cutting-edge projects that leverage the latest technologies across various domains of IT including Data, Web, Infrastructure, AI, and many others.<br> Our expertise in IT solutions development and on-demand resources allows us to partner with clients on transformative initiatives, driving innovation and business growth.<br> Whether it's empowering global organizations or collaborating with trailblazing startups, we are committed to delivering advanced, impactful solutions that meet today’s most complex challenges.<br> About the Client: Join one of Egypt’s premier financial institutions, renowned for its extensive suite of banking services, including Institutional Banking, Personal Banking, and Islamic Banking.<br> With a global presence through over 50 branches and correspondents, we serve a diverse and dynamic clientele.<br> As we embark on a groundbreaking digital transformation journey, we are committed to leveraging the latest technologies to establish a state-of-the-art data architecture that will redefine our performance and service delivery.<br> Key Responsibilities: Drive "Compliance and Security by Design": Proactively architect and embed compliance guardrails directly into the lifecycle of all Data and AI initiatives, anticipating evolving Central Bank of Egypt (CBE) cyber security regulations and the Egyptian Data Protection Law to eliminate compliance risks before models and data pipelines are deployed.<br> Execute Predictive Threat Modeling for AI: Lead advanced, preventative threat modeling and vulnerability assessments tailored specifically for machine learning models, LLMs, and big data repositories, neutralizing emerging AI-specific threats (such as data poisoning, adversarial attacks, and model inversion) during the early design phases.<br> Establish Continuous Automated Monitoring: Implement and manage automated, real-time vulnerability scanning and continuous compliance monitoring systems across the bank's data infrastructure, ensuring any drift from security standards is detected and remediated before it can be exploited.<br> Foster a Proactive Security Culture with AI Teams: Partner closely with data scientists, AI engineers, and data governance teams to champion secure coding and data handling practices, conducting proactive risk-readiness workshops to prevent human-error vulnerabilities in algorithmic workflows.<br> Develop Next-Gen Incident-Prevention Playbooks: Devise and stress-test predictive incident-response playbooks tailored for AI assets, leveraging global threat intelligence to simulate potential data breaches and algorithmic failures, ensuring the bank’s defenses are常に (always) one step ahead of sophisticated cyber threats.<br> Attractive, market-leading salary package Clear career advancement path with professional development opportunities Professional Experience: 4 + years of progressive experience in cybersecurity compliance, risk management, or vulnerability assessment, with a mandatory and proven track record of working within a regulated banking or financial services institution.<br> Educational Background & Certifications: Bachelor’s degree from a recognized institution in Computer Science, Cybersecurity, Computer Engineering, or a strictly relevant technical field.<br> Possessing elite industry certifications such as CISSP, CISM, CRISC, or CISA is highly preferred.<br> Regulatory & AI Domain Expertise: Comprehensive understanding of the Central Bank of Egypt (CBE) cybersecurity frameworks and regulations, as well as the Egyptian Data Protection Law , paired with foundational knowledge of data science workflows, big data architecture, and emerging AI security frameworks (e.<br>g., OWASP Top 10 for LLMs).<br> Technical Compliance & Threat Modeling Skills: Demonstrated expertise in deploying automated vulnerability scanning tools and leading predictive threat modeling exercises specifically tailored to mitigate risks like data poisoning, adversarial attacks, and unauthorized data exposure within complex data pipelines.<br></span> </div>
Established in 2008, Geidea epitomises customer focused empowerment and commercial success through continuous innovation Geidea makes best in class digital payment solutions available for all by attracting and leveraging the best creative & entrepreneurial talent in the market Our solutions give any business the chance to get ahead and reach for more no matter their size or maturity. Our technology mirrors our people - Smart, Innovative & Forward Thinkiking To maintain competitive advantage as we grow, we are currently looking for a new "Cybersecurity Defense Expert"<br>Job purpose:The purpose of this role is to lead the defense against cyber threats through proactive SOC Monitoring, DFIR, Threat Intelligence, and Vulnerability Management, ensuring the integrity, confidentiality, and availability of information systems in all regions.<br>Key accountabilities and decision ownership:Lead and enhance SOC operations, focusing on real-time threat detection, incident response, and continuous monitoring. Coordinate digital forensics and incident response efforts to mitigate threats efficiently and reduce recovery time. Develop and implement a threat intelligence program to identify and counteract evolving cyber threat Manage the Vulnerability Management Program, including regular assessments, risk prioritization, and remediation strategies. Support the cybersecurity vision and strategy in alignment with defense operations and organizational goals. Oversee information security audits, whether by performed by organization or third-party personnel. Lead integration of standard and non-standard logs in SIEM. Create reports, dashboards, metrics for SOC operations and presentation to Senior Management. Lead team & vendor management overall use of resources and initiation of corrective action where required for Security Operations Center. Develop and maintain enterprise Threat & Vulnerability Management framework and necessary program operational capabilities that include identify, risk assess, and monitor of vulnerability and associated remediation. Maintain control effectiveness and continuously identify gaps in detection controls across the environment, including Geidea’s cloud environments. Serve as the process owner of all ongoing activities related to the confidentiality, integrity and availability of information and resources of customers, business partners, employees, and business information, in compliance with the organization's Cyber and Information security policies. Evaluate team performance and build on people capabilities.<br>Must have technical / professional qualifications:2-3 years of experience Bachelor’s degree in computer science, Information Technology, Telecommunications, Electronics & Electrical or any related field. Certifications:GCIHGCFAExperience in cybersecurity architecture design. Experience in NESA IAR, SAMA CSF, PCI-DSS, NCA is a must.<br>Our values guide how we think and act - They describe what we care about the most. Customer first - It’s embedded in our design thinking and customer service approach. Open - Openness allows us to constantly improve and evolve. Real - No jargon and no excuses! Bold - Constantly challenging ourselves and our way of thinking. Resilient – If we fail, we bounce back stronger than before. Collaborative - We know that we can achieve a lot more as a team. We are changing lives by constantly striving for a better solution. Click apply below and become part of the Geidea story
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><strong>Publication date :</strong> Jul 03, 2026, 12:00AM</p><br><br><p>Contract duration : </p><br><br>Orange Business is here!<br>About us<p>Join us at Orange Business!<br>We are a network and digital integrator that understands the entire value chain of the digital world, freeing our customers to focus on the strategic initiatives that shape their business.<br>Every day, you will collaborate with a team dedicated to providing consistent, sustainable global solutions, no matter where our customers operate. With over 30,000 employees across Asia, the Americas, Africa, and Europe, we offer a dynamic environment to develop and perfect your skills in a field filled with exciting challenges and opportunities.</p><br><br>About the role<p><span>The main job roles are:</span></p><br><br><p><span>- Assess the Security aspects relating to endpoint security including Anti-Virus, Anti-Malware, File Integrity Monitoring, Vulnerability Management, Host Intrusion Detection and Prevention Services and translate that to an appropriate level of security controls.</span></p><br><br><p><span>- Manage Security devices (Firewalls, IPS, reverse/forward proxies) policies</span></p><br><br><p><span>- Resolve end to end issues on Microsoft Defender for Endpoint agents.</span></p><br><br><p><span>- Assist in incident response activities such as malware analysis, remote system analysis, and remediation efforts.</span></p><br><br><p><span>- Operation of various scanning tools in use, and assessment and analysis of the data collected from scan tools.</span></p><br><br><p><span>- Operation or CISCO ISE Network Access Control solution</span></p><br><br><p><span>- Tracking and reporting on discovered vulnerabilities and remediation efforts.</span></p><br><br><p><span>- Help to the resolution of internal network related security incidents.</span></p><br><br><p><span>- Create documentations, reports, and Run books for ongoing deployment activities.</span></p><br><br><p><span>- Manage security change requests on our perimeter.</span></p><br><br><p><span>- Manage IT projects driven by Security concerns.</span></p><br><br><p><span>- Support the securing of our web services exposed on the Internet.</span></p><br><br><p><span>- Promote Security best-practices.</span></p><br><br><p><span>- Coordinate with deployment team, IT stakeholders during new rollouts, upgrades, functionality testing.</span></p><br><br><p><span>- Contribute to internal and external audits as needed.</span></p><br><br><p><span>- Additional responsibilities may be managed depending on the applicant’s skills</span></p><br><br><br><br>About you<p><span><strong>About you</strong></span></p><br><br><br><p><span>- 5+ years of experience working within a Security Operations Center (SOC) environment, including but not limited to incident response, vulnerability scanning, threat hunting, network monitoring/log management, and compliance management</span></p><br><br><p><span>- Experience on enterprise EPP/EDR (preferably Microsoft Defender for Endpoint / Harfanglab) operations including deployment, troubleshoot, threat analysis and endpoint automations and scripting in a large environment.</span></p><br><br><p><span>- Experience on implementing NAC (802.1x) solution, operations including deployment, troubleshoot and support of the solution.</span></p><br><br><p><span>- One or more Cloud Service Provide Professional certifications (e.g. Microsoft Azure Fundamentals, Microsoft Security, Compliance and Identity Fundamentals, AWS Cloud Practitioner, AWS Solutions Architect Associate, Google Cloud Digital Leader, Google Cloud Engineer) is a plus.</span></p><br><br><p><span>- Experience with networking concepts/protocols and knowledge in traffic sniff and analysis.</span></p><br><br><p><span>- Experience with scripting languages (Python, or PowerShell).</span></p><br><br><p><span>- Practice of network and security support / operations.</span></p><br><br><p><span>- Good communication skills and ability to lead by example in a high-functioning team.</span></p><br><br><p><span>- Excellent analytical and problem-solving skills.</span></p><br><br><p><span>- Industry relevant security certifications (e.g. Security+, CCSK, CSSP, GSEC) is a plus</span></p><br><br><p><span>- Fluent in spoken written English. French is a plus.</span></p><br><br><p>You bring a can-do attitude, tackle challenges head-on and challenge the status quo with new and innovative ideas.</p><br><br>What we offer<p><strong>• Global Opportunities:</strong> Work in multi-national teams with opportunity to collaborate with colleagues and customers from all over the world.<br><strong>• Flexible Work Environment:</strong> Flexible working hours and possibility to combine work from office and home (hybrid ways of working).<br><strong>• Professional Development:</strong> training programs and upskilling/re-skilling opportunities.<br><strong>• Career Growth:</strong> Internal growth and mobility opportunities within Orange.<br><strong>• Caring and Daring Culture:</strong> Health and well-being programs and benefits, diversity & inclusion initiatives, CSR and employee connect events.<br><strong>• Reward Programs:</strong> Employee Referral Program, Change Maker Awards.</p><br><br>Only your skills matterRegardless of your age, gender identity, race, ethnic origin, religion/belief, sexual orientation, marital status, neurotype, disability, veteran status or appearance, we encourage diversity within our teams because it is a strength for the collective and a vector of innovation. Orange Group is a disabled-friendly company and equal opportunity employer: don't hesitate to tell us about your specific needs.<p> At Orange, only your skills matter.
</p><br><br>
<p> Regardless of your age, gender, background, origin, religion, sexual orientation, disability, neurodiversity, or appearance, we actively encourage diversity within our teams, as it is a collective strength and a driver of innovation.Orange is a disability-inclusive employer: please feel free to let us know about any specific needs you may have.
</p><br><br><br> </div>
<p>Deloitte innovation hub (DIH) is a strategic initiative to support our ambition to become the leading business transformation partner of choice for our clients and to expand and scale our delivery footprint across EMEA. With access to a scaled, diverse, highly skilled, motivated, and engaged workforce, DIH is delivering complex technical solutions for clients most complex business problems, across Portfolios that include Strategy & Transactions , Customer , Engineering, AI & Data, Enterprise, Technology & Performance and Cyber . DIH is aiming to become the destination for top talents in Egypt for a long, exciting career. We invest in outstanding people of diverse talents and backgrounds and empower them to achieve more than they could elsewhere. Our work combines advice with action and integrity. We believe that when our clients and society are stronger, so are we. Our organization has grown in scale and diversity, providing services across the region, with our shared culture remaining the same. We aim to help clients realize their ambitions, make a positive difference in society, and maximize the success of our people. This drive fuels the commitment and humanity that run deep through our every action. Connect to your opportunity. We are seeking Identity and Access Management (IAM) engineers. The candidate should have the ability to design and implement identity and access solutions, conduct testing of the solution, and maintain and operate the technology. This role will involve working closely with cross-functional teams to ensure seamless deployment and integration of identity solutions, as well as contributing to the ongoing operation and maintenance of IAM technologies across our clients. As part of this role, you will be expected to:</p><p>Implement IAM solutions: Install solution components in on-premise environments where relevant, or configuration of cloud components (and scripting / coding of plug-ins / extensions for cloud solutions). Work with IT infrastructure teams (e.g, Networks, Endpoints) to ensure pre-requisites and dependencies have been met and are in place. Integrate IAM solutions with existing enterprise applications/systems such as directories, cloud applications, HR systems and third party identity providers. Execute unit, integration, functional and non-functional testing for IAM solutions. As part of this, troubleshoot and resolve issues (e.g, authentication failures, access policy conflicts, user provisioning errors etc.) by working with vendors. Deliver services post-implementation, from hyper-care support, resolving additional issues in production through advanced troubleshooting and debugging to ensure smooth operation. Conduct knowledge transfer to client IAM teams through technical training sessions on operating and maintaining the solution, empowering clients to effectively manage and support the IAM environment.</p><p>Connect to your skills and professional experience. To succeed in this role, you will need the following:</p><p>The following skills are also relevant:</p><p><br></p><p><strong>Desired Candidate Profile</strong></p><p>0 to 3 years of hands-on experience in the Cyber security, preferably the identity domain. Bachelor s degree in information technology, Cybersecurity, computer science or a related field. Familiarity with IAM and PAM tools (e.g, SailPoint, Saviynt, ForgeRock, CyberArk, Beyond Trust, Okta, Active Directory, Azure AD, Angular, Springboot, and PingFederate etc). Understanding of the software development life cycle processes.</p><p>The following skills are also relevant: Understanding of OAUTH, JSON, REST, SOAP, and Network Protocols (e.g., SSL, SSH, FTP, SMTP, HTTP and HTTPS etc). Experience in identity and access configuration of container-based architectures and implementations (e.g., Kubernetes, Docker, etc.). Technical skills including scripting - Python/JAVA/ASP/C#/PowerShell, Coding frameworks.</p>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span><b>Who we are</b>
<br></span><p>VOIS (Vodafone Intelligent Solutions) is a strategic arm of Vodafone Group Plc, creating value for customers by delivering intelligent solutions through Talent, Technology & Transformation. <br>As the largest shared services organisation in the global telco industry with 30,000 FTE, our portfolio of next-generation solutions and services are designed in partnership with customers across Vodafone Group, local markets, and partner markets to simplify and drive growth. With our strategic partner Accenture, we work alongside our Vodafone customers, other Telco and tech companies to drive transformation, meet the challenges of our industry and ensure we stay relevant and resilient. This partnership is a unique, industry-first model which brings together the best of in-house and 3rd party capability. <br>We work with customers across 28 countries from 10 VOIS locations: Albania, Egypt, Hungary, India, Romania, Spain, Turkey, UK, Germany, Ireland, and with a network of teams in Czech Republic, Italy, Greece, and Portugal. <br>#VOIS #BeUnrivalled #CreateTheFuture</p><br><br><br><b>About this Role</b>
<br>We are seeking an experienced infrastructure security professional to lead security governance, risk management, operational excellence, and service reliability across enterprise infrastructure services. This role is responsible for ensuring compliance with cyber security standards, improving security posture, managing security incidents, supporting critical infrastructure platforms, and leading technical teams to deliver secure, resilient, and customer-focused services. The position operates in a global environment and plays a key role in protecting business continuity, safeguarding information assets, and driving continuous service improvement.<br><br><br><b>What you’ll do</b>
<br><ul>
<li>Lead infrastructure security activities, ensuring compliance with cyber security and risk management standards across enterprise services.</li>
<li>Drive security posture management through proactive monitoring, risk remediation, vulnerability management, operating system patching, and security assessments.</li>
<li>Manage threat detection, investigation, incident response, recovery planning, and implementation of improved security controls.</li>
<li>Oversee technical operations, service availability, platform health, and operational excellence for critical infrastructure services.</li>
<li>Lead, coach, and develop technical operations teams, supporting capability building, knowledge sharing, and continuous improvement.</li>
<li>Manage stakeholder relationships, customer escalations, service reviews, and service improvement initiatives to enhance user experience and productivity.</li>
<li>Ensure compliance with service management processes, governance standards, service level agreements, and change management requirements.</li>
<li>Support project delivery by providing technical expertise, managing operational readiness, and ensuring successful implementation of new services and technologies.</li>
<li>Contribute to operational planning, budget management, service investment forecasting, and business continuity activities.</li>
</ul><br><br><b>Who you are</b>
<br><ul>
<li>Bachelor’s degree in Engineering, Computer Science, or a related technical discipline. </li>
<li>Extensive experience in IT support, infrastructure security, and technology operations, including significant experience leading technical teams. </li>
<li>Strong knowledge of enterprise infrastructure technologies including Microsoft Azure, Microsoft 365, virtualisation platforms, Windows Server</li>
<li>technologies, Active Directory, DNS, DHCP, storage solutions, and cloud-based services.</li>
<li>Experience with vulnerability management, configuration management, automated deployment, and information security controls.</li>
<li>Proven ability to manage operational services, troubleshoot complex technical issues, and deliver continuous service improvements.</li>
<li>Strong leadership, stakeholder engagement, strategic thinking, communication, and people development skills. </li>
<li>Comfortable working within an on-call support model and collaborating across international teams and cultures when required.</li>
</ul><br><br><b>Not a perfect fit?</b>
<br><p>Concerned you may not meet every requirement? Vodafone is committed to creating an inclusive workplace where everyone can thrive. If you are excited about this role but your experience does not align exactly with every aspect of the job description, you are encouraged to apply. You may be the right candidate for this or another opportunity, and the recruitment team will support you in exploring where your skills fit best.</p><br><br><br><b>What's in it for you</b>
<br><ul>
<li>Opportunity to lead security and infrastructure services that support large-scale global business operations.</li>
<li>Exposure to enterprise cloud technologies, cyber security programmes, and critical service management environments.</li>
<li>Experience influencing service strategy, operational excellence, and business continuity initiatives.</li>
<li>Leadership opportunities focused on coaching teams, stakeholder management, and organisational impact.</li>
<li>Participation in global projects that drive innovation, security maturity, and service transformation.</li>
</ul><br><br><b>What skills you will learn</b>
<br><ul>
<li>Advanced cyber security governance and enterprise risk management.</li>
<li>Large-scale infrastructure operations and service reliability management.</li>
<li>Strategic stakeholder engagement and customer-centric service delivery.</li>
<li>Security incident management, crisis response, and business continuity practices.</li>
<li>IT service management, operational governance, and continuous improvement methodologies.</li>
<li>Leadership and team development within complex global environments.</li>
</ul><br><br><b>VOIS Equal Opportunity Employer Commitment</b>
<br><p>Vodafone recognises and celebrates the value of diversity in building a workforce that reflects the customers and communities it serves. No form of discrimination is tolerated. This includes, but is not limited to, discrimination based on race, colour, age, veteran status, gender identity, gender expression, sexual orientation, pregnancy, maternity or parental status, ethnicity, disability, religion or belief, political affiliation, trade union membership, nationality, citizenship, indigenous status, medical condition, HIV status, neurodiversity, social origin, cultural background, marital or civil partnership status, or socio-economic background. </p><br><br><br><b>Join Us</b>
<br><p>At Vodafone, we’re working hard to build a better future. A more connected, inclusive and sustainable world. As a dynamic global community, it's our human spirit, together with technology, that empowers us to achieve this. <br>We challenge and innovate in order to connect people, businesses, and communities across the world. Delighting our customers and earning their loyalty drive us, and we experiment, learn fast and get it done, together. <br>With us, you can truly be yourself and belong, share inspiration, embrace new opportunities, thrive, and make a real difference.</p><br><br><br><b>Alert </b>
<br><p>Apply for Vodafone jobs only through the official Vodafone Careers website to avoid job scams and fraud. <br>#JDEnhancedByTARA</p><br><br><br><b>Follow us on social media</b>
<br>
<ul>
<li>LinkedIn: VOIS LinkedIn</li>
<li>Facebook: VOIS Facebook</li>
<li>Instagram: VOIS Instagram</li>
<li>You can also chat with our employees to learn more about our projects: Employee Network</li>
</ul>
<br><br><br><br>
</div>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
About this Position This position is part of the Global Business Solution (GBS+), IT Department. <p><strong>Shift:</strong> Rotational Shift <br><strong>Working Hours: </strong>10:00 AM – 6:00 PM or 6:00 PM – 2:00 AM<br><strong>Schedule:</strong> Based on need & will be shared ahead</p><br> What you´ll do <ul> <li>Monitor, analyze and prioritize security events.</li> <li>Investigate, contextualize and remediate security incidents based on playbooks and individual analysis leveraging data from different source and tools.</li> <li>Provide consultancy to internal and external parties in order to reduce the impact of security incidents.</li> <li>Coordinate and support the containment and eradication of security incidents within Henkel’s environment.</li> <li>Propose, analyze, and introduce new technologies or products to increase the information security level in Henkel (based on defined risks).</li> <li>Keeps up to date with the latest security and technology developments.</li> <li>Research/evaluates emerging cyber security threats and ways to manage them.</li> <li>Review past incidents and identify attack trends.</li> <li>Hunt for cyber-related threats from various threat intelligence sources.</li> <li>Identify and monitor the Tactics, Techniques, and Procedures (TTPs) employed by cyber threat actors.</li> <li>Be a leading source of knowledge in information security and intelligence matters.</li> </ul>
<br><br>
What makes you a good fit <ul> <li>Bachelor's degree in Networks Engineering, Computer Science, Business informatics, or any relevant study </li> <li>2-4 years of relevant work experience.</li> <li>Fluent English speaker.</li> <li>Excellent communication, analytical and report-writing abilities.</li> <li>Knowledge of IT forensic & incident response, threat intelligence, risk management, endpoint security, network administration, cryptography, weak point analysis, related tools and techniques are preferable.</li> <li>Knowledge and understanding of threat intelligence cycles, collection management, and TI application towards operational goals is preferable.</li> <li>Ability and willingness to conduct in-depth analysis of the tools and tradecraft used by actors of all types is preferable.</li> <li>Experience with TI platforms such as MISP & OpenCTI is a plus,</li> <li>Relevant certifications (e.g. CISM, CISA, CISSP, CSX, PMP, ITIL) are preferable.</li> <li>Master's degree in a respective field is plus.</li> </ul> Some perks of joining Henkel <ul> <li>Flexible work scheme with flexible hours, hybrid work model, and work from anywhere policy for up to 30 days per year</li> <li>Diverse national and international growth opportunities</li> <li>Global wellbeing standards with health and preventive care programs</li> <li>Gender-neutral parental leave for a minimum of 8 weeks</li> <li>Employee Share Plan with voluntary investment and Henkel matching shares</li> <li>Comprehensive Health Insurance for employee + dependents</li> <li>Employee Assistance Programme provides a wide range of mental health and wellbeing benefits</li> </ul> <p>At Henkel, we come from a broad range of backgrounds, perspectives, and life experiences. We believe the uniqueness of all our employees is the power in us. Become part of the team and bring your uniqueness to us! We look for a diverse team of individuals who possess different backgrounds, experiences, personalities and mindsets.</p><br>
<br> </div>