Security inspector Jobs - Cairo Egypt
2348 Jobs Found
<p><h4>Role profile</h4>
<p>Conduct regular cybersecurity assessments and audits for Vodafone Cash and other fintech products.<br>
Develop and implement cybersecurity policies, procedures, and controls specific to mobile money services.<br>
Monitor and report on cybersecurity metrics and KPIs for Vodafone Cash and other fintech products.<br>
Risk management for cash and fintech products.<br>
Identify, assess, and mitigate cybersecurity risks associated with Vodafone Cash and other fintech products.<br>
Develop and implement cybersecurity risk management frameworks and strategies.<br>
Conduct threat and vulnerability assessments for Vodafone Cash and other fintech products.<br>
Ensure the implementation of data protection measures, including data encryption, access controls, and data loss prevention.<br>
Assess the cybersecurity posture of third-party vendors and partners involved in Vodafone Cash and other fintech products.<br>
Follow up on cybersecurity risks associated with third-party relationships.<br>
Develop and deliver cybersecurity awareness training programs for employees involved in Vodafone Cash and other fintech products.</p>
<h4>Competencies and qualifications</h4>
<ul>
<li>Certifications in cybersecurity (e.g., CISSP, CISM, CISA, ISO27001).</li>
<li>Very good knowledge of PCI-DSS.</li>
<li>Experience in the fintech industry, with a focus on mobile money services, at least 2 years.</li>
<li>Knowledge of specific fintech products and services, including mobile wallets and payment systems.</li>
<li>Reporting and project management skills are a plus.</li>
<li>Good grasp of mobile network security and vulnerabilities.</li>
<li>Must have technical and professional qualifications:</li>
<ul>
<li>Bachelor’s degree in engineering or computer science.</li>
<li>Strong understanding of cybersecurity frameworks and standards (e.g., ISO 27001, PCI-DSS, NIST Cybersecurity Framework).</li>
<li>In-depth knowledge of cybersecurity threats, vulnerabilities, and countermeasures.</li>
<li>Proficiency in cybersecurity tools and technologies.</li>
<li>Strong analytical and problem-solving skills.</li>
<li>Attention to detail and accuracy.</li>
<li>Ability to communicate effectively with both technical and non-technical stakeholders.</li>
<li>Strong interpersonal and teamwork skills.</li>
</ul>
</ul>
<h4>Join us</h4>
<p>At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.</p>
<h4>Not a perfect fit?</h4>
<p>Worried that you don’t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you’re excited about this role but your experience doesn’t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.</p>
<h4>Who we are</h4>
<p>We are a leading international telco, serving millions of customers. At Vodafone, we believe that connectivity is a force for good. If we use it for the things that really matter, it can improve people's lives and the world around us. Through our technology we empower people, connecting everyone regardless of who they are or where they live and we protect the planet, whilst helping our customers do the same.</p>
<p>Belonging at Vodafone isn't a concept; it's lived, breathed, and cultivated through everything we do. You'll be part of a global and diverse community, with many different minds, abilities, backgrounds and cultures. We're committed to increase diversity, ensure equal representation, and make Vodafone a place everyone feels safe, valued and included.</p>
<h4>Accessibility</h4>
<p>If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, please refer to the company’s application adjustments guidance for support.</p>
<p>Together we can.</p></p><p></p>
<p><h4>Position summary</h4>
<p>Patrol all areas of the property; assist guests with room access. Monitor closed circuit televisions, perimeter alarm system, duress alarms, and fire life safety system. Lock property entrances when required. Conduct daily physical hazard inspections. Respond to accidents, contact EMS or administer first aid/CPR as required. Assist guests/employees during emergency situations. Notify appropriate individuals in the event of accidents, attacks, or other incidents. Defuse guest/employee disturbances. Call for outside assistance if necessary. Complete incident reports to document all security/loss prevention related incidents. Handle all interruptions and complaints. Resolve safety hazard situations. Escort any unwelcome persons from the property without interrupting the orderly flow of property operation. Report to scenes of vehicle accidents/thefts. Call for assistance using proper code responses. Complete a loss prevention shift summary/daily activity report. Maintain confidentiality of all security/loss prevention and property reports/documents; release information only to authorized individuals. Conduct investigations and gather evidence. Conduct interviews with relevant parties.</p>
<p>Follow</p><p></p>
<p><h4>Join us</h4>
<p>At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.</p>
<h4>Role purpose</h4>
<p>Evaluate customer business needs and create the overall technical vision for a specific solution to a business problem whether computer systems, networks, hardware, and/or software.</p>
<h4>Key accountabilities and decision ownership</h4>
<ul>
<li>Understanding business problems, analysing and documenting them and translating/transforming them into technology solutions</li>
<li>Lead architecture design discussions, reviews and recommendations to fulfil customer requirements and needs</li>
<li>Develop end-to-end security solutions for ensuring scalability and alignment with client requirements</li>
<li>Conduct detailed technical assessments of customer environments to identify gaps and opportunities</li>
<li>Design solutions leveraging a deep understanding of security methodologies and best practices</li>
<li>Collaborate with sales teams to understand client requirements, provide technical guidance, and contribute to proposal development</li>
<li>Prepare and deliver compelling technical presentations and demonstrations to clients, highlighting the value of proposed solutions</li>
<li>Respond to RFPs/RFQs/RFIs, ensuring technical accuracy and competitive positioning</li>
<li>Act as a technical advisor for clients, building trust and understanding their long-term infrastructure needs</li>
<li>Work closely with internal delivery teams to ensure proposed solutions are feasible and align with implementation capabilities</li>
<li>Stay updated on emerging technologies, industry trends, and competitive offerings in compute and networking</li>
<li>Provide thought leadership by sharing insights on best practices and innovative approaches to infrastructure challenges</li>
<li>Develop comprehensive technical documentation, including architecture diagrams, solution blueprints, and configuration specifications</li>
</ul>
<h4>Core competencies</h4>
<ul>
<li>8 years experience as pre-sales/solution architect working with information security solutions and services</li>
<li>Computer science or engineering bachelors graduate</li>
<li>Core competence in business development in the area of “cyber security solutions” for infrastructure (datacenter, end user, network, cloud and mobility) and managed security services</li>
<li>Strong communication, interpersonal and presentation skills</li>
<li>Persuasion and negotiation skills</li>
<li>Excellent command of Arabic and English</li>
<li>Previous experience in solution integrations is a plus</li>
</ul>
<h4>Technical/professional skills</h4>
<ul>
<li>Expert in infrastructure (data center, network & end user computing) security, cloud security, managed security services & risk management</li>
<li>Advanced understanding of IT infrastructure and cloud development</li>
<li>Excellent technical skills for building security architecture aligned with the business's requirements</li>
<li>Good understanding of AI and M/L (machine learning)</li>
<li>Good understanding of coding, databases and software development</li>
</ul>
<h4>Who we are</h4>
<p>We are a leading international telco, serving millions of customers. At Vodafone, we believe that connectivity is a force for good. If we use it for the things that really matter, it can improve people's lives and the world around us. Through our technology we empower people, connecting everyone regardless of who they are or where they live and we protect the planet, whilst helping our customers do the same.</p>
<p>Belonging at Vodafone isn't a concept; it's lived, breathed, and cultivated through everything we do. You'll be part of a global and diverse community, with many different minds, abilities, backgrounds and cultures. We're committed to increase diversity, ensure equal representation, and make Vodafone a place everyone feels safe, valued and included.</p>
<p>If you require any reasonable adjustments or have an accessibility request as part of your recruitment journey, for example, extended time or breaks in between online assessments, please contact the recruitment team for guidance.</p>
<p>Together we can.</p></p><p></p>
<p><h4>Join us</h4>
<p>At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.</p>
<h4>Role purpose</h4>
<p>To run and manage cyber security systems and user access control facilities (logical & physical) to ensure that access is authorized according to Vodafone Egypt security policy.</p>
<h4>Job responsibilities</h4>
<p><strong>Key accountabilities and decision ownership</strong></p>
<ul>
<li>Maintain cyber security systems availability and ensure resolving issues escalated from first line within the agreed SLA.</li>
<li>Responsible for implementation of bulk user access profiles defined and approved by the production system and data owners.</li>
<li>Responsible for implementing major approved and assigned security request for changes.</li>
<li>Maintain knowledge transfer and documentation of systems on hand.</li>
<li>Handle incidents communications within the team and with other teams when necessary.</li>
<li>Escalate issues to vendors and ensure that issues are resolved within contract SLA.</li>
</ul>
<h4>Not a perfect fit?</h4>
<p>Worried that you don’t meet all the desired criteria exactly? At Vodafone we are passionate about empowering people and creating a workplace where everyone can thrive, whatever their personal or professional background. If you’re excited about this role but your experience doesn’t align exactly with every part of the job description, we encourage you to still apply as you may be the right candidate for this role or another opportunity.</p>
<h4>Job requirements</h4>
<p><strong>Core competencies, knowledge and experience</strong></p>
<ul>
<li>Interpersonal and communication skills.</li>
<li>Time management skills.</li>
<li>Innovative thinking.</li>
<li>Team player and customer focused.</li>
<li>Logical thinking and takes responsibility.</li>
</ul>
<p><strong>Must have technical/professional qualifications:</strong></p>
<ul>
<li>Bachelor’s degree in engineering or computer science.</li>
<li>Experience 4-5 years in technology, including 3 years as security engineer.</li>
<li>Experience in security systems/services KPIs maintenance.</li>
<li>Generic or vendor security certificate is preferred (CISSP, CIH, CCNP, F5).</li>
</ul>
<h4>Who we are</h4>
<p>We are a leading international telco, serving millions of customers. At Vodafone, we believe that connectivity is a force for good. If we use it for the things that really matter, it can improve people's lives and the world around us. Through our technology we empower people, connecting everyone regardless of who they are or where they live and we protect the planet, whilst helping our customers do the same.</p>
<p>Belonging at Vodafone isn't a concept; it's lived, breathed, and cultivated through everything we do. You'll be part of a global and diverse community, with many different minds, abilities, backgrounds and cultures. We're committed to increasing diversity, ensuring equal representation, and making Vodafone a place everyone feels safe, valued and included.</p>
<p>Together we can.</p></p><p></p>
Must-Have(Ideally should be between 4-6 Yrs) Daily assessment of vulnerabilities identified by infrastructure scan Prioritizing vulnerabilities discovered along with remediation timeline(s) Work with Security team to have harderning documents reviewed and applied on all systems. Comply with MBSS client standards and SLAs. Conduct DR Drills for identified systems and maintain runbooks and drill documents updated. Allign with BCP/BCM team on DR activities and all deliverables. Provides analysis of vulnerabilities to other team members to assist with overall vulnerability remediation efforts Perform analysis of security issues and/or vulnerabilities Maintain knowledge of security trends and threats Develop metrics and capabilities to ensure effective vulnerability management Executing the vulnerability lifecycle management strategy across the organization Configuring, scheduling and executing vulnerability scans, and delivering scan reports Establishing relationships with system owners and business process partners for the purposes of ensuring that identified vulnerabilities are remediated in accordance to established timelines Working with cross functional teams and internal users to enforce technical security standards by providing assistance in applying established standards to projects Provides analysis of vulnerabilities to other team members to assist with overall vulnerability remediation efforts Support the identification and impact classification for new vulnerabilities identified in the environment Brief VM leadership on vulnerability assessment results and potential risks Drive KPI/SLAs for the account related to Security metrics. Segregate Compliance and Vulnerability report and followup end to end driving closure and SLA attainment. Knowledge on Business Impact Assessment and regular updates to BCM and BCP team. Additional knowledge on Archer, Qualys scan tool will be an advantage.<br>Good-to-Have Should have hands on experience on Vulnerability scanning tools like Qualys & Archer. Working knowledge of multiple IT platforms (i.e. Windows, Linux/Unix, Database, Network etc.).<br>Job Type Details of The Role (For Candidate Briefing) Reporting ToSecurity & Vulnerability Admin Manager Size of the Team, if any Reporting to this Role This is an individual contributor role
<section><p class="heading jdMain">Job Description</p><p class="heading">Roles & Responsibilities</p><div class="paragraph"><p>About us: Where elite tech talent meets world-class opportunities! At Xenon7, we work with leading enterprises and innovative startups on exciting, cutting-edge projects that leverage the latest technologies across various domains of IT including Data, Web, Infrastructure, AI, and many others. Our expertise in IT solutions development and on-demand resources allows us to partner with clients on transformative initiatives, driving innovation and business growth. Whether it's empowering global organizations or collaborating with trailblazing startups, we are committed to delivering advanced, impactful solutions that meet today s most complex challenges.</p><p>About the Client: Join one of Egypt s premier financial institutions, renowned for its extensive suite of banking services, including Institutional Banking, Personal Banking, and Islamic Banking. With a global presence through over 50 branches and correspondents, we serve a diverse and dynamic clientele. As we embark on a groundbreaking digital transformation journey, we are committed to leveraging the latest technologies to establish a state-of-the-art data architecture that will redefine our performance and service delivery.</p><p>Key Responsibilities:</p><ul><li>Drive "Compliance and Security by Design": Proactively architect and embed compliance guardrails directly into the lifecycle of all Data and AI initiatives, anticipating evolving Central Bank of Egypt (CBE) cyber security regulations and the Egyptian Data Protection Law to eliminate compliance risks before models and data pipelines are deployed.</li><li>Execute Predictive Threat Modeling for AI: Lead advanced, preventative threat modeling and vulnerability assessments tailored specifically for machine learning models, LLMs, and big data repositories, neutralizing emerging AI-specific threats (such as data poisoning, adversarial attacks, and model inversion) during the early design phases.</li><li>Establish Continuous Automated Monitoring: Implement and manage automated, real-time vulnerability scanning and continuous compliance monitoring systems across the bank's data infrastructure, ensuring any drift from security standards is detected and remediated before it can be exploited.</li><li>Foster a Proactive Security Culture with AI Teams: Partner closely with data scientists, AI engineers, and data governance teams to champion secure coding and data handling practices, conducting proactive risk-readiness workshops to prevent human-error vulnerabilities in algorithmic workflows.</li><li>Develop Next-Gen Incident-Prevention Playbooks: Devise and stress-test predictive incident-response playbooks tailored for AI assets, leveraging global threat intelligence to simulate potential data breaches and algorithmic failures, ensuring the bank s defenses are (always) one step ahead of sophisticated cyber threats.</li></ul></div></section><section><p class="heading">Desired Candidate Profile</p><p class="paragraph"></p><ul><li>4 + years of progressive experience in cybersecurity compliance, risk management, or vulnerability assessment, with a mandatory and proven track record of working within a regulated banking or financial services institution.</li><li>Bachelor s degree from a recognized institution in Computer Science, Cybersecurity, Computer Engineering, or a strictly relevant technical field.</li><li>Possessing elite industry certifications such as CISSP, CISM, CRISC, or CISA is highly preferred.</li><li>Comprehensive understanding of the Central Bank of Egypt (CBE) cybersecurity frameworks and regulations, as well as the Egyptian Data Protection Law , paired with foundational knowledge of data science workflows, big data architecture, and emerging AI security frameworks (e.g., OWASP Top 10 for LLMs).</li><li>Demonstrated expertise in deploying automated vulnerability scanning tools and leading predictive threat modeling exercises specifically tailored to mitigate risks like data poisoning, adversarial attacks, and unauthorized data exposure within complex data pipelines.</li></ul><p></p></section>
Pharmaplast is looking for a Senior Quality Inspector to join its Quality team in Borg El Arab, Alexandria.<br><br>Requirements<br><br>Bachelor's degree in Science. Previous experience in the pharmaceutical industry is required. Good knowledge of GMP requirements and quality inspection practices. Strong attention to detail and documentation skills. <br><br>Key Responsibilities<br><br>Perform in-process and final product inspections. Ensure compliance with approved specifications, procedures, and GMP requirements. Record inspection results and report any non-conformities. Support investigations and corrective actions related to quality issues. Collaborate with Production and Quality teams to maintain product quality standards. <br><br>If you have the required experience and are interested in joining a dynamic manufacturing environment, we would be pleased to hear from you.<br><br>To apply, please send your CV to<br><br> hr.bea@pharmaplast-online.com <br><br>and include "Careers" in the body of your email.
Freelance Third-Party Quality Inspector (Assignment-Based)???? Location: Egypt (Nationwide) About CSG-EGCSG-EG is an independent third-party Inspection, Audit & Compliance company providing professional quality assurance services across Egypt. We are expanding our network of freelance inspectors to support inspection projects across multiple industries. We are looking for dedicated professionals who are committed to quality, integrity, and delivering reliable inspection services. Key Responsibilities Conduct Final Random Inspections (FRI) Conduct During Production Inspections (DUPRO) Conduct Pre-Production Inspections (PPI) Conduct Container Loading Supervision (CLS) Verify products against specifications and quality requirements Identify and document quality issues Prepare professional inspection reports with clear findings and photographs Submit reports within required timelines Minimum Requirements Applicants should:Be based anywhere in Egypt Be available to travel when required Own a laptop Own a modern digital camera or a high-quality smartphone camera Have good English reading and writing skills Be proficient in Microsoft Word, Excel, Outlook and Email Be able to prepare professional inspection reports Have strong attention to detail and professional ethics Previous experience with a Third-Party Inspection company is preferred but not mandatory. Candidates with factory quality control experience are also encouraged to apply. Preferred Industry Experience Priority will be given to candidates with experience in:Garments & Apparel Home Textiles Textile Manufacturing Carpets & Rugs Experience in the following industries is also an advantage:Consumer Products Glass Products Marble & Building Materials Electrical Appliances Fresh Produce Frozen Foods Herbs & Agricultural Products What We Offer Assignment-based freelance opportunities Professional training and continuous development Long-term cooperation opportunities Exposure to international inspection standards Professional and supportive working environment How to Apply Please send your CV to:???? careers@csg-eg.comEmail Subject:Freelance Third-Party Quality Inspector – [Your City]In your email, please include:Your current city and governorate Industries you have experience inspecting Whether you are currently working with an Inspection, Audit or Certification company (Please specify the company name) Your current inspection/freelance daily rate (if applicable) Your expected daily rate Your availability (Freelance / Full-Time / Both) Your notice period (if currently employed) Confirmation that you own:A laptop A modern digital camera or high-quality smartphone Only shortlisted candidates will be contacted.
Role Objectives Production Quality Inspector is a professional member of Breadfast family who will be responsible for inspecting and testing products and overseeing operations for the company to ensure they meet production standards.<br> Roles & Responsibilities:Inspect quality standards for the products a company produces Follow up on all operational activities and specifications to ensure that operations meet production standards Inspect and test the materials and equipment produced by a company Reject all products and materials that fail to meet quality expectations. Measure product dimensions, examine functionality, and compare the final product to the specifications. Document inspection outcomes by completing detailed reports and performance records. Teach the production team about quality control concerns to improve product excellence. Monitor the production process and personal hygiene. Collect all important data needed for quality engineers.<br>REQUIRED EDUCATION, KNOWLEDGE, AND SKILLSWork Experience in quality control or similar field is preferred. Strong understanding of quality control standards and testing techniques. Excellent command of the written and spoken Excellent communication and handling skills
Position Summary:The Information Security Lead is responsible for leading, managing, and continuously improving One Health's Information Security Program. The role serves as the primary operational owner of all information security, cybersecurity, risk management, governance, compliance, security operations, security architecture, vulnerability management, and incident response activities. The Information Security Lead will ensure that security controls, policies, standards, and procedures are effectively implemented and maintained across the organization while supporting business objectives and compliance requirements. The role will coordinate with business units, IT teams, third-party providers, auditors, regulators, and AXA Group stakeholders to maintain an effective and mature security posture.<br>Key Responsibilities Information Security Governance & Management• Lead and manage the Information Security Program across the organization.• Develop, implement, maintain, and continuously improve the Information Security Strategy, Roadmap, Policies, Standards, Procedures, and Guidelines.• Define and execute annual information security objectives aligned with business goals and AXA Group requirements.• Establish and monitor Information Security KPIs, KRIs, compliance metrics, and security maturity indicators.• Prepare and present security reports, dashboards, and risk updates to senior management, executive leadership, and relevant governance committees.• Manage information security documentation and ensure continuous review and improvement of security processes.<br>Risk Management & Compliance• Own and manage the Information Security Risk Management Program in alignment with AXA’s IRM framework.• Conduct and oversee enterprise security risk assessments and maintain the Information Security Risk Register.• Identify security threats, vulnerabilities, and business impacts and ensure effective remediation plans are implemented.• Manage compliance with local regulations, legal requirements, AXA Group standards, ISO 27001 requirements, and other applicable security frameworks.• Coordinate internal and external audits and ensure timely closure of audit findings and security observations.• Manage security exceptions, risk acceptance processes, and compliance tracking activities.<br>Information Security Management System (ISMS)• Own, maintain, and continuously improve the Information Security Management System (ISMS).• Ensure all security controls remain effective and aligned with organizational risks and compliance requirements.• Coordinate management reviews, internal assessments, corrective actions, and continuous improvement initiatives.<br>Security Operations & Incident Response• Manage and oversee all security operations activities, including security monitoring, vulnerability management, threat management, and incident response.• Manage internal and external Security Operations Center (SOC) services and ensure effective detection, investigation, escalation, and response to security events.• Lead cybersecurity incident investigations and coordinate remediation activities with IT, business stakeholders, vendors, legal, and HR functions.• Ensure security incidents are properly documented, investigated, reported, and resolved.<br>Vulnerability Management & Security Testing• Own and manage vulnerability assessment and penetration testing programs.• Ensure regular vulnerability scans, penetration tests, security assessments, and remediation activities are conducted.• Track and report remediation status and ensure closure of identified security weaknesses.<br>Security Architecture & Secure Design• Review and approve security requirements, architectures, and designs for new systems, applications, cloud environments, and technology initiatives.• Ensure cybersecurity requirements are incorporated into projects, procurement processes, RFIs, RFQs, and RFPs.• Participate in project governance processes and provide security approvals before production deployment.• Promote secure-by-design and security-by-default principles across all technology initiatives. Application Security & Change Management• Ensure security requirements are embedded within Software Development Lifecycle (SDLC), Change Management, and Project Management processes.• Conduct security reviews and risk assessments for new applications, infrastructure, and business initiatives.• Ensure appropriate security testing is completed before Go-Live approval. Third-Party & Vendor Security Management• Conduct security reviews and risk assessments for vendors, suppliers, partners, and third parties.• Define and monitor security requirements for third-party relationships.• Manage security assessments and remediation activities related to external service providers. Security Awareness & Training• Develop and manage the Information Security Awareness Program.• Deliver security awareness initiatives and promote a strong security culture throughout the organization.• Conduct targeted awareness activities for technical and non-technical employees. Resource, Budget & Vendor Management• Manage security vendors, consultants, and external security service providers.• Support development and management of the Information Security budget and resource plans.• Identify resource requirements and recommend improvements to strengthen the organization's security capabilities.<br>Qualifications Education• Bachelor's Degree in Information Security, Computer Science, Information Technology, Engineering, or a related discipline. Professional Experience• Minimum 8–10 years of progressive experience in Information Security, Cybersecurity, Risk Management, Security Operations, Security Architecture, or related disciplines.• Minimum 3–5 years in a management role responsible for information security programs.• Proven experience managing Information Security Management Systems (ISMS), security governance, risk management, compliance programs, incident response, vulnerability management, and security operations.• Experience managing third-party security providers, auditors, consultants, and security vendors.• Experience within healthcare, insurance, financial services, or highly regulated environments is preferred. Technical Knowledge• Strong understanding of ISO 27001, NIST Cybersecurity Framework, CIS Controls, and information security best practices.• Strong knowledge of cloud security, network security, application security, vulnerability management, and security monitoring.• Experience with security risk assessment methodologies and cybersecurity governance frameworks.• Knowledge of regulatory and compliance requirements applicable to healthcare and insurance sectors. Preferred Certifications• CISSP• CISM• CRISC• ISO 27001 Lead Implementer and/or Lead Auditor• CCSP• Security+, CEH, or equivalent cybersecurity certifications<br>Leadership Competencies Motivates People – Gains commitment to achieve business objectives through effective communication, coaching, and leadership. Models our Values – Promotes accountability, integrity, ownership, and adherence to company values and standards. Strategic Thinking – Aligns security initiatives with business objectives and organizational priorities. Stakeholder Management – Builds strong relationships with business leaders, technology teams, auditors, regulators, and external partners. Decision Making – Makes sound risk-based decisions while balancing business and security requirements.
IT Security Manager Experience in healthcare industry. The IT Security Manager is responsible for the day‑to‑day operation and execution of the healthcare organization’s security function, covering cyber, physical, and operational security domains. The role ensures that security technologies are effectively operated, security scenarios are actively monitored and managed, and security incidents are detected, analyzed, and resolved in collaboration with IT and clinical teams. The Security Manager leads the security team’s daily activities and acts as the operational arm of the security pillar under the direction of the Security Director.. Security Operations Execution Execute the organization’s security strategy and policies as defined by the Security Director. Manage daily security operations across IT systems, clinical platforms, infrastructure, and facilities. Ensure continuous monitoring of security events, alerts, and risks. Maintain operational readiness for security incidents affecting patient care, data, or facilities. 2. Security Technologies & Equipment Management Manage, operate, and oversee security technologies and equipment, including:Cybersecurity Technologies Firewalls and network security appliances IDS / IPS systems Endpoint protection and EDR solutions SIEM and log monitoring platforms Email and web security solutions Identity and Access Management (IAM), including AD-based access controls Vulnerability assessment and patch management tools Physical & Facility Security Systems CCTV and video surveillance platforms Access control systems (card based, biometric, secure zones) Security systems protecting data centers and critical technical areas 3. Security Scenarios & Incident Response Define, document, and operationalize security scenarios, including:Cyberattacks and malware outbreaks Ransomware and phishing incidents Unauthorized access to HIS, PACS, ERP, or clinical systems Data leakage or privacy breaches Physical security incidents impacting IT or clinical assets Lead incident detection, containment, investigation, and recovery activities. Coordinate with the Security Director during high severity or organization wide incidents. 4. Team Leadership & Daily Management Lead and manage the security team’s day to day activities, including monitoring, analysis, and response. Assign tasks, shifts, and on call coverage to ensure continuous security operations. Review alerts, incidents, and investigations for quality and completeness. Coach and develop team members on security tools, procedures, and threat response techniques. 5. Collaboration with IT & Operations Work closely with:Applications teams to secure HIS, PACS, Oracle Fusion, and custom solutions Infrastructure teams to secure networks, servers, cloud platforms, and data centers Hospital and clinical operations to ensure security controls do not disrupt patient care Provide security input into system changes, implementations, and upgrades. 6. Risk, Compliance & Reporting Identify and report security risks, vulnerabilities, and incident trends to the Security Director. Support audits, assessments, and regulatory reviews by preparing security evidence and reports. Ensure security controls are operating effectively and consistently across the organization. Technical Strong hands‑on experience with cybersecurity and physical security systems. Understanding of healthcare IT environments, clinical systems, and sensitive data protection. Experience operating monitoring, alerting, and incident response processes. Leadership & Behavioral Proven ability to lead operational teams in a 24/7 or high‑availability environment. Strong incident management and decision‑making skills under pressure. Clear and disciplined communication with security leadership and IT peers.<br><br><br>education requirements<br>Bachelor’s degree in Information Security, Computer Science, or related field.7–10+ years of experience in IT or security operations, preferably in healthcare or regulated environments. Demonstrated experience managing security tools, incidents, and operational teams.
Summary of Duties:Responsible for managing and implementing the cybersecurity assurance programme. including vulnerability management, application security testing, penetration testing, and security compliance monitoring to protect enterprise systems and applications from security threats. Manage vulnerability management programme using Scanners for comprehensive vulnerability scanning, assessment, remediation tracking, and reporting ensuring effective vulnerability management across the enterprise. Manage and oversee FIM, DAM and firewall assurance operations, coordinating teams, tracking remediation, and ensuring timely closure of identified security gaps. Lead application security testing (SAST) , dynamic application security testing (DAST), software composition analysis (SCA), and secure coding practices ensuring secure application development. Oversee ATM security programme for ATMs including vulnerability assessment, penetration testing, security hardening, and compliance monitoring ensuring ATM security resilience. Coordinate security compliance monitoring including baseline compliance scanning for security baselines, configuration compliance, and regulatory compliance with automated scanning and compliance reporting. Lead IT Security assessment practice for multiple technologies including WAF, NGFW, IPS, ISE, Device Control, MFA, Web Proxy, Mail Proxy, EDR, Application Control, Sandbox, Routers, Switches, SD-WAN .. etc to Validate control effectiveness through configuration reviews, threat-based testing, rule analysis, logging verification, and use-case validation as per standards and industry best practice. Integrate security into Dev Sec Ops pipeline including automated security testing (SAST, DAST, SCA), security gates, and pipeline automation ensuring secure CI/CD. Develop security assurance reports and metrics, prepare evidence for audits, and ensure audit readiness.<br>Minimum Qualifications BSC in Communication Engineering or computer science CISSP (Certified Information Systems Security Professional) certificate is preferred. CEH (Certified Ethical Hacking) or OSCP preferred GIAC certifications (GWAPT, GPEN) preferred Master's degree in Information Security or related field preferred<br>Minimum Experience:8+ Years of IT & Information Security experience with demonstrated leadership in vulnerability management, application security, and security assurance programmes<br>Job Specific Skills Vulnerability Management experience with enterprise tools (Tenable, Nessus, Qualys) Application Security Testing (SAST, DAST, SCA) experience with Fortify and similar tools Penetration testing methodologies and frameworks (OWASP, PTES) Security compliance monitoring and baseline management Dev Sec Ops integration and CI/CD security Network security (Firewalls, IPS, WAF) management Security reporting and metrics development Audit evidence preparation and regulatory compliance (CBE, PCI, ISO 27001) Banking environment experience Risk Management Strategic planning and programme management Team leadership and mentoring Stakeholder management at executive level
Role Description This is a full-time, hybrid Chief Information Security Officer (CISO) role based in Cairo, Egypt, with flexibility for partial work from home. The CISO will define and lead CYBER سايبر’s information security strategy, policies, and frameworks, ensuring alignment with business objectives and regulatory requirements. Daily responsibilities include overseeing security operations, monitoring threats, managing incident response, and coordinating vulnerability assessments and penetration testing. The role involves partnering with executive leadership and department heads to assess risk, prioritize security initiatives, and support secure digital transformation. The CISO will guide security architecture for applications and infrastructure, manage security awareness programs, and lead the development and testing of business continuity and disaster recovery plans. The position includes managing security vendors and tools, preparing regular risk and compliance reports, and leading, mentoring, and growing the security team.<br>Qualifications<br> Strong expertise in Information Security Management and Information Security, with a track record of building and maintaining enterprise-wide security programs. Deep knowledge of Cybersecurity practices, including threat detection, incident response, security monitoring, and risk assessment. Hands-on experience with Application Security, including secure SDLC, code review practices, and collaboration with development teams to embed security by design. Proven experience in Business Continuity planning, disaster recovery, and resilience strategies to ensure minimal disruption to critical operations. Familiarity with relevant security standards and frameworks (e.g., ISO 27001, NIST, CIS Controls) and regulatory or industry compliance requirements. Demonstrated leadership experience managing cross-functional security initiatives and guiding technical and non-technical stakeholders. Excellent communication, presentation, and stakeholder management skills, with the ability to translate complex security topics into clear business language. Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field; advanced degree or recognized security certifications (e.g., CISSP, CISM, CISA, CCSP) are preferred. Experience in hybrid or cloud environments (e.g., AWS, Azure, GCP) and modern security technologies such as SIEM, EDR, IAM, and DLP is highly beneficial. Proven ability to operate in a fast-paced environment, make informed risk-based decisions, and uphold high ethical and professional standards.
Information Security & Risk Manager<br><br> Job Details<br><br>Position Title: Information Security & Risk Manager<br><br>Department: Technology Services / IT<br><br>Reports To: Information Security / CTO<br><br>Employment Type: Permanent<br><br>Location: Maadi, Degla - On-site<br><br>Grade: As per organizational structure<br><br>Direct Reports: As per approved organizational structure<br><br> Job Purpose<br><br>The Information Security & Risk Manager is responsible for leading the organization's Information Security and Cyber Risk function. The role will design, implement, and maintain the cybersecurity program, manage enterprise information security risks, ensure compliance with applicable Saudi regulatory and industry requirements, and promote a strong security-aware culture across the organization.<br><br>The role provides strategic and operational leadership across Information Security Governance, Risk & Compliance (GRC), Security Operations, Incident Response, Data Protection, and Security Awareness.<br><br> Key Accountabilities & Deliverables<br><br>The role will be accountable for the development, implementation, and continuous improvement of:<br><br>Information Security Strategy and Cybersecurity Roadmap Information Security policies, standards, procedures, and guidelines Information Security Management System (ISMS) Enterprise IT and Cybersecurity Risk Register Information Security Risk Assessment Reports Risk Treatment and Remediation Plans Security Compliance Reports, including ISO 27001 and applicable regulatory requirements Cybersecurity Control Framework and Control Effectiveness Reports Vulnerability Assessment and Penetration Testing (VAPT) Reports Cybersecurity Incident Reports and Root Cause Analysis (RCA) Security Monitoring and Threat Dashboards Cybersecurity KPI and KRI Dashboards Identity and Access Management (IAM) Policies, Models, and Access Matrices Data Classification and Data Protection Framework Internal and External Audit Reports and Evidence Repository Audit Findings and Remediation Tracking Business Continuity and Disaster Recovery (BCP/DR) Security Alignment Security Awareness and Training Programs and Reports Regulatory Assessments, submissions, and compliance evidence<br><br>B. Information Security Risk Management C. Security Operations & SOCD. Cybersecurity Incident Response E. Governance, Risk & Compliance F. Data Protection & Privacy G. Vulnerability & Security Testing H. Identity & Access Management I. Security Awareness & Culture J. Business Continuity & Disaster Recovery<br><br> Key Responsibilities Information Security Strategy & Governance Define, develop, and execute the organization's Information Security Strategy and cybersecurity roadmap Own and continuously improve the Information Security Management System (ISMS) Develop and maintain information security policies, standards, procedures, and guidelines Establish effective cybersecurity governance frameworks aligned with business objectives Provide regular reporting on cybersecurity posture, risk exposure, compliance, and security program performance to the CTO and executive leadership Establish and monitor security KPIs, KRIs, and performance metrics Ensure information security requirements are incorporated into technology initiatives, projects, and business processes Lead regular information security and cybersecurity risk assessments across the organization Own and maintain the enterprise IT and cybersecurity risk register Identify, assess, prioritize, and communicate information security risks Develop and manage risk treatment plans and ensure remediation activities are tracked through to closure Work closely with business units, IT, and other stakeholders to establish appropriate risk mitigation strategies Translate technical cybersecurity risks into business impact and communicate them effectively to senior management Monitor the organization's overall cyber risk profile and provide recommendations for risk reduction Oversee Security Operations Centre (SOC) activities, including SOC Analysts and Security Engineers Ensure effective security monitoring, threat detection, investigation, and response capabilities Oversee SIEM operations and security monitoring platforms such as Microsoft Sentinel, Splunk, or equivalent technologies Establish and monitor security incident management processes Review security alerts, incidents, trends, and threat intelligence Ensure appropriate escalation and response mechanisms are in place for critical security events Monitor and improve the effectiveness of security controls and operational processes Lead the organization's cybersecurity incident response capability Ensure effective detection, containment, eradication, recovery, and post-incident activities Develop, maintain, and continuously improve the Cybersecurity Incident Response Plan (CIRP) Conduct regular incident response exercises and simulations Lead investigations into significant security incidents and ensure Root Cause Analysis (RCA) is completed Track corrective and preventive actions resulting from security incidents Ensure lessons learned are incorporated into security controls and processes Lead Information Security Governance, Risk, and Compliance (GRC) activities Ensure compliance with applicable regulatory and industry requirements, including:National Cybersecurity Authority (NCA) requirements Saudi Personal Data Protection Law (PDPL) National Data Management Office (NDMO) requirements, where applicable ISO/IEC 27001Other applicable cybersecurity and data protection regulations Coordinate internal and external security audits and assessments Manage audit evidence collection and maintain an organized security evidence repository Track audit findings, remediation plans, and closure status Prepare management and regulatory compliance reports Support regulatory assessments, reviews, and submissions as required Establish and maintain data protection and information classification frameworks Ensure appropriate security controls are implemented for sensitive and personal data Work with relevant stakeholders to support compliance with PDPL and applicable data protection requirements Establish appropriate data access, handling, retention, and protection controls Support privacy and data protection risk assessments where required Oversee vulnerability management activities across IT environments Coordinate Vulnerability Assessments and Penetration Testing (VAPT) Review vulnerability and penetration testing reports Ensure security vulnerabilities are appropriately prioritized based on business risk Track remediation activities and validate closure of critical and high-risk vulnerabilities Ensure security testing is incorporated into relevant technology projects and systems Establish and maintain IAM policies, standards, and access control frameworks Ensure appropriate access governance and segregation of duties Review privileged access and high-risk accounts Support periodic user access reviews and access recertification Ensure access controls align with business requirements and security policies Develop and implement an organization-wide security awareness program Lead cybersecurity awareness campaigns and security training Implement phishing simulation and social engineering awareness programs Monitor employee security awareness performance and identify improvement areas Promote a strong cybersecurity culture across all business functions Ensure cybersecurity requirements are incorporated into Business Continuity and Disaster Recovery plans Participate in BCP/DR risk assessments and exercises Ensure critical systems have appropriate security, recovery, and resilience controls Support testing and continuous improvement of security-related recovery procedures Qualifications & Experience<br><br>Minimum Qualifications<br><br>Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Security, or a related discipline CISSP or CISM certification - Mandatory ISO/IEC 27001 Lead Implementer or Lead Auditor certification preferred NCA-related cybersecurity accreditation or certification is preferred<br><br>Minimum Experience<br><br>8-10 years of professional experience in Information Security / Cybersecurity At least 3 years of experience in a cybersecurity or information security management/leadership role Proven experience managing enterprise cybersecurity programs and security teams Proven experience in GRC, risk management, security operations, and incident response Proven experience working with regulatory compliance, audits, and cybersecurity frameworks Technical & Professional Skills<br><br>The successful candidate should demonstrate:<br><br>Strong knowledge of cybersecurity frameworks, standards, and best practices Deep understanding of NCA, PDPL, NDMO, ISO 27001, and applicable data protection requirements Strong expertise in Governance, Risk, and Compliance (GRC) Experience with SOC operations and SIEM platforms such as Microsoft Sentinel, Splunk, or equivalent Strong understanding of vulnerability management and penetration testing Strong knowledge of Incident Response and Cybersecurity Incident Response Plans (CIRP) Strong understanding of IAM and access governance Knowledge of data protection, data classification, and data governance Strong understanding of secure architecture and security controls Ability to develop and monitor cybersecurity KPIs and KRIsStrong audit and regulatory assessment experience Ability to assess and communicate cybersecurity risks in terms of business impact Strong strategic thinking and high-level decision-making capability Excellent leadership and people-management skills Ability to manage cross-functional teams and stakeholders under pressure Strong communication, presentation, and reporting skills Bilingual proficiency in Arabic and English Leadership Competencies Strategic Thinking Cybersecurity Leadership Risk-Based Decision Making Stakeholder Management Executive Communication Team Leadership & Development Problem Solving Crisis and Incident Management Governance & Accountability Continuous Improvement Business Acumen Change Management<br><br>Special Requirements<br><br>Ability to work effectively in a fast-paced and dynamic environment Ability to manage cybersecurity incidents and critical security situations Willingness to participate in security incident response and escalation activities when required Strong confidentiality and professional integrity Ability to work collaboratively with executive leadership, IT, business functions, auditors, and regulatory stakeholders
Security Test Engineer<br>About the Role We are looking for a Security Test Engineer to validate the security, reliability, and correctness of authorization and policy enforcement systems used in AI agent platforms. This role combines security testing, automated test development, API security validation, and policy verification to ensure secure, compliant, and resilient platform services. As part of the Core Architecture Team, you will work closely with software engineers, architects, and security specialists to design and execute security-focused test strategies, build automated test suites with Python, and validate authorization mechanisms that protect enterprise-scale cloud platforms. This is an exciting opportunity to contribute to next-generation AI platforms while advancing modern application security and quality engineering practices.<br>Project Overview Our customer is a multinational corporation with more than a century of history and operations in over 180 countries. As part of its digital transformation journey, the company is investing heavily in Reduced-Risk Products (RRPs), targeting more than one billion consumers worldwide. The enterprise platform supports more than 700 applications across Digital Commerce, Digital Marketing, IoT, and Enterprise Services. Intellias partners with the customer to engineer a comprehensive software ecosystem for innovative IoT products and digital platforms. As a member of the Core Architecture Team, you will help build and secure an enterprise engineering platform that accelerates software delivery by providing reusable services, security controls, governance, and engineering best practices across multiple development teams.<br>Key Responsibilities Design and execute functional and security testing strategies for policy-driven authorization systems. Develop and maintain automated security and policy validation test suites using Python and pytest. Validate permit/deny decisions, policy precedence, parameter-level access controls, and authorization logic. Verify policy behavior during transitions between LOG_ONLY and ENFORCE modes. Perform API security testing aligned with the OWASP API Top 10. Conduct penetration testing, threat modeling, and security assessments for platform services and AI agent workflows. Design and execute test scenarios covering prompt injection, agent identity spoofing, policy bypass attempts, and other Agentic AI attack vectors. Validate audit logging, traceability, and security event generation for authorization decisions. Verify Agent-to-Agent (A2A) policy enforcement across distributed workflows. Collaborate with software engineering and security teams to identify vulnerabilities and strengthen the platform's security posture. Maintain security test documentation, test reports, and compliance evidence.<br>Required Qualifications Education Bachelor's degree in computer science, Software Engineering, Information Security, or a related technical field. Technical Skills Security testing, including penetration testing and threat modeling. Python test automation using pytest. Functional and security test design. API security testing based on the OWASP API Top 10. Agentic AI threat modeling, including:Prompt injection Policy bypass Agent identity spoofing Authorization and policy enforcement testing. Agent-to-Agent (A2A) policy enforcement validation. Audit log validation and security event verification. Policy validation, including:Permit/Deny correctness Policy precedence Parameter-level conditions LOG_ONLY to ENFORCE mode validation Experience4+ years of experience in Quality Assurance, Security Testing, or Application Security. Experience implementing automated security test suites. Hands-on experience with API security testing and vulnerability validation. Experience designing functional and security test strategies. Strong understanding of secure software development practices.<br>Nice to Have AWS security testing experience. Experience with Cedar policy testing tools. Regulatory compliance testing (GDPR, SOC 2). Experience testing cloud-native applications and distributed systems. Familiarity with AI security, authorization frameworks, and policy engines.<br>Why Join Us? Work on enterprise-scale platforms supporting more than 700 applications used across a global organization. Help secure next-generation AI agent platforms and modern authorization systems. Collaborate with experienced architects, software engineers, and security specialists on innovative cloud-native solutions. Contribute to the development of security standards and best practices that impact engineering teams worldwide. Expand your expertise in AI security, policy validation, cloud-native application security, and automated testing while working on cutting-edge technologies.
We're Hiring | Security Manager (Malls)???? Location: New Cairo, Egypt We are looking for an experienced Security Manager to join our team and oversee security operations for a leading shopping mall. Key Responsibilities:Manage all daily security operations within the mall. Lead, train, and supervise security supervisors and officers. Develop and implement security policies, procedures, and emergency response plans. Coordinate with mall management, tenants, and external authorities. Conduct risk assessments and incident investigations. Ensure compliance with health, safety, and security regulations. Prepare security reports and performance analyses. Requirements:Bachelor's degree is preferred.5+ years of experience in security management. Previous experience in shopping malls, commercial properties, or mixed-use developments is a must. Strong leadership, communication, and problem-solving skills. Excellent knowledge of security operations and emergency procedures. Good command of English is an advantage.???? Interested candidates are invited to apply through Linked In Easy Apply or send their CV to:mohamed.abdallah@alrabat.netPlease mention "Security Manager" in the email subject.
The Security Director is responsible for developing, leading, and governing the organization's security strategy across all operational assets, projects, facilities, and communities. The role ensures the protection of people, properties, business operations, and corporate assets through the implementation of effective security frameworks, risk management practices, emergency preparedness programs, and security technologies. The Security Director provides strategic leadership for security operations, contractor management, crisis response, and business continuity initiatives while ensuring compliance with regulatory requirements and industry best practices. Key Responsibilities:Develop and implement the organization's security strategy, policies, standards, and governance framework across all operational and development assets. Provide strategic leadership and oversight of all security operations, ensuring the effective protection of people, facilities, communities, and company assets. Establish security risk management frameworks and oversee periodic risk assessments, threat analyses, and vulnerability evaluations across the portfolio. Lead the development and implementation of crisis management, business continuity, and emergency response strategies. Oversee the performance and governance of outsourced security service providers, ensuring contractual compliance, service excellence, and cost-effectiveness. Direct the implementation and optimization of physical security systems, including CCTV, access control, perimeter protection, command centers, and other security technologies. Collaborate with Facility Management, Property Management, HSE, Legal, and Operations teams to ensure integrated security and operational resilience. Develop security standards and operational procedures for new developments, asset handovers, and project mobilization activities. Ensure compliance with applicable laws, regulations, security standards, and corporate governance requirements. Lead investigations related to major security incidents, fraud, asset protection concerns, and business disruptions. Prepare and present security performance reports, risk assessments, strategic initiatives, and improvement plans to executive management. Lead, mentor, and develop the security management team, promoting a culture of professionalism, accountability, and continuous improvement. Develop, manage, and control the annual security budget, ensuring the cost-effective allocation of resources, alignment with operational requirements, and adherence to approved financial plans. Perform any other duties or responsibilities assigned by the direct manager. Education: Police Academy graduate or former Police/Military officer is highly preferred, particularly within large-scale real estate, mixed-use, hospitality, or facility management environments. Professional certifications such as CPP (Certified Protection Professional), PSP (Physical Security Professional), ISO 18788, ISO 22301, or equivalent are a Plus. - Previous Experience: Minimum 5 years in a leadership role managing security operations across large-scale real estate portfolios, mixed-use developments, communities, or multi-site operations
Valleysoft | Center of Excellence, based in Riyadh, is a premier IT services provider partnering with global technology leaders like SAP to deliver innovative solutions worldwide. We are currently seeking a dedicated SAP Security Specialist (Band 6B) to join our dynamic team.<br><br>As a SAP Security Specialist, you will be responsible for assisting in implementing and maintaining SAP security frameworks that safeguard our clients' systems and data. You will work closely with senior consultants to ensure proper user access management, role design, and compliance with security policies.<br><br>Responsibilities<br><br>Assist in configuring and maintaining SAP security roles and authorizations Support user administration activities including provisioning and deprovisioning Help monitor SAP systems for security compliance and support remediation efforts Collaborate with SAP teams to implement security policies and procedures Participate in security audits and support documentation efforts Coordinate with other IT teams to address security incidents and vulnerabilities Stay updated on SAP security best practices and tools<br><br>Requirements<br><br>Bachelor's degree in Computer Science, Information Technology, or related field3-5 years of experience in SAP security or related roles Knowledge of SAP security concepts including user management, role design, and authorization objects Familiarity with SAP GRC and other security tools is a plus Good analytical and problem-solving skills Strong communication and teamwork abilities Ability to follow established security protocols and standards Saudi Arabian nationality is required<br><br>Benefits<br><br>Private Health Insurance Training & Development
We are hiring "Senior Network Security Engineer" Location Cairo (On-site | Full-time). Responsibilities We are looking for a Senior Network Security Engineer responsible for maintaining and improving the organization’s network security infrastructure. The role focuses on implementing secure network designs, managing security platforms and ensuring reliable and secure connectivity across internal systems, external partners, and remote access solutions. The candidate will work closely with infrastructure, cloud, and SOC teams to ensure that network security controls are properly implemented and aligned with the organization’s security standards. Job Description· Design, implement, and maintain network security solutions including firewalls, VPN gateways, Email gateway and network segmentation.· Manage and maintain firewall policies, NAT rules, and access control policies in line with security standards and operational requirements.· Implement and maintain secure connectivity including site-to-site VPNs and remote access VPNs for internal users and external partners.· Work with infrastructure and application teams to ensure new systems are deployed following the organization’s network security standards.· Perform security hardening for network devices including firewalls, routers, and switches.· Review and optimize firewall policies periodically to ensure proper access control and minimize security risks.· Support the SOC team during security investigations by providing network-level analysis, traffic verification, and infrastructure insights when needed.· Troubleshoot complex network and security-related issues affecting connectivity or service availability.· Participate in security projects such as network segmentation, data center security improvements, or cloud connectivity implementations.· Maintain proper documentation for network security architecture, firewall policies, VPN configurations, and operational procedures.· Ensure network security infrastructure is operating reliably and that upgrades, patches, and firmware updates are applied as required.· Manage and maintain email security gateway solutions to protect against spam, phishing, and malware threats.· Support the deployment and management of endpoint protection and EDR solutions in coordination with the SOC team. Requirements· Strong understanding of enterprise networking concepts including TCP/IP, routing, VLANs, NAT, and network segmentation.· Hands-on experience with Next Generation Firewalls (such as Fortinet, Palo Alto, Cisco, or similar technologies).· Experience implementing and troubleshooting IPSec VPN , SSL VPN and email gateway solutions.· Familiarity with IDS/IPS, WAF, and network security best practices. Experience analyzing network traffic and troubleshooting connectivity issues across multiple network layers.· Basic knowledge of cloud networking security (AWS, Azure, or similar environments) is a plus.· Proven 5+ years of hands-on experience in network security or network engineering roles. Experience working in enterprise environments with complex network infrastructures. Bachelor’s degree in Computer Science, Information Technology, or related field is preferred. Relevant certifications such as CCNP Security, Fortinet NSE, PCNSE, or similar are considered an advantage.
Lead the design and development of cloud security strategies for cloud service providers (e.g., AWS, Microsoft Azure, Oracle, Google Cloud Platform). Define the architecture, security frameworks, and guidelines for cloud security, covering areas like data encryption, identity and access management, and threat prevention. Work with stakeholders to ensure cloud security aligns with business requirements and regulatory compliance (e.g. GDPR, HIPAA, SOC 2, PCI DSS, etc.). Conduct regular risk assessments and threat modelling for cloud environments to identify vulnerabilities and areas of concern. Develop strategies to mitigate potential cloud-specific risks, such as data breaches, misconfigurations, and unauthorized access. Implement threat detection and response mechanisms to monitor cloud environments for suspicious activity and security incidents. Define and enforce security policies and best practices for cloud services, ensuring they are following both internal and external security requirements. Develop and implement a robust identity and access management (IAM) strategy for cloud resources, utilizing tools such as AWS IAM, Azure Active Directory, and Google Cloud IAM. Establish and maintain security standards for cloud architecture, configuration management, and service integrations. Design and implement security controls for cloud environments to ensure the confidentiality, integrity, and availability of data and applications. Implement security mechanisms such as encryption (in transit and at rest), firewalls, CASB, vulnerability scanning, and network segmentation to secure cloud platforms. Lead the effort to ensure cloud services and architectures comply with relevant regulatory frameworks, standards, and internal security policies. Collaborate with GRC team to assess the impact of regulatory requirements on cloud platforms and ensure proper implementation of controls. Oversee continuous monitoring and auditing of cloud infrastructure to ensure compliance and detect potential risks or gaps in security posture. Work closely with different teams, and other IT departments to integrate security into the entire cloud infrastructure lifecycle, from design to deployment. Provide thought leadership and mentorship on cloud security best practices to internal teams and stakeholders. Educate teams on secure cloud design and operational risk management. Lead the cloud security incident response process, identifying, investigating, and mitigating cloud-based security breaches or attacks. Collaborate with other security and IT teams to develop and implement incident response and disaster recovery plans specifically for cloud environments. Conduct post-incident reviews and root cause analysis to improve cloud security measures and response processes. Evaluate and implement cloud-native security tools, such as CASB, cloud security posture management (CSPM), cloud workload protection platforms (CWPP), and cloud identity and access management tools. Integrate automated security monitoring, reporting, and incident detection tools to reduce manual overhead and improve cloud security monitoring.