Skip to content

Open nowPosted 53 days ago

Information Security & Cybersecurity Risk Manager

Workable (global search)108,016 open roles

Where
Cairo, Cairo Governorate, Egypt
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInformation Security & Cybersecurity Risk ManagerWorkable (global search) · Cairo, Cairo Governorate, Egypt
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 53 days ago

Workable (global search) median: 7 days open

The posting

Information Security & Risk Manager

1. Job Details

Position Title: Information Security & Risk Manager Department: Technology Services / IT Reports To: Information Security / CTO Employment Type: Permanent Location: Maadi, Degla – On-site Grade: As per organizational structure Direct Reports: As per approved organizational structure

2. Job Purpose

The Information Security & Risk Manager is responsible for leading the organization’s Information Security and Cyber Risk function. The role will design, implement, and maintain the cybersecurity program, manage enterprise information security risks, ensure compliance with applicable Saudi regulatory and industry requirements, and promote a strong security-aware culture across the organization.

The role provides strategic and operational leadership across Information Security Governance, Risk & Compliance (GRC), Security Operations, Incident Response, Data Protection, and Security Awareness.

3. Key Accountabilities & Deliverables

The role will be accountable for the development, implementation, and continuous improvement of:

  • Information Security Strategy and Cybersecurity Roadmap
  • Information Security policies, standards, procedures, and guidelines
  • Information Security Management System (ISMS)
  • Enterprise IT and Cybersecurity Risk Register
  • Information Security Risk Assessment Reports
  • Risk Treatment and Remediation Plans
  • Security Compliance Reports, including ISO 27001 and applicable regulatory requirements
  • Cybersecurity Control Framework and Control Effectiveness Reports
  • Vulnerability Assessment and Penetration Testing (VAPT) Reports
  • Cybersecurity Incident Reports and Root Cause Analysis (RCA)
  • Security Monitoring and Threat Dashboards
  • Cybersecurity KPI and KRI Dashboards
  • Identity and Access Management (IAM) Policies, Models, and Access Matrices
  • Data Classification and Data Protection Framework
  • Internal and External Audit Reports and Evidence Repository
  • Audit Findings and Remediation Tracking
  • Business Continuity and Disaster Recovery (BCP/DR) Security Alignment
  • Security Awareness and Training Programs and Reports
  • Regulatory Assessments, submissions, and compliance evidence

4. Key Responsibilities

A. Information Security Strategy & Governance

  • Define, develop, and execute the organization’s Information Security Strategy and cybersecurity roadmap.
  • Own and continuously improve the Information Security Management System (ISMS).
  • Develop and maintain information security policies, standards, procedures, and guidelines.
  • Establish effective cybersecurity governance frameworks aligned with business objectives.
  • Provide regular reporting on cybersecurity posture, risk exposure, compliance, and security program performance to the CTO and executive leadership.
  • Establish and monitor security KPIs, KRIs, and performance metrics.
  • Ensure information security requirements are incorporated into technology initiatives, projects, and business processes.

B. Information Security Risk Management

  • Lead regular information security and cybersecurity risk assessments across the organization.
  • Own and maintain the enterprise IT and cybersecurity risk register.
  • Identify, assess, prioritize, and communicate information security risks.
  • Develop and manage risk treatment plans and ensure remediation activities are tracked through to closure.
  • Work closely with business units, IT, and other stakeholders to establish appropriate risk mitigation strategies.
  • Translate technical cybersecurity risks into business impact and communicate them effectively to senior management.
  • Monitor the organization’s overall cyber risk profile and provide recommendations for risk reduction.

C. Security Operations & SOC

  • Oversee Security Operations Centre (SOC) activities, including SOC Analysts and Security Engineers.
  • Ensure effective security monitoring, threat detection, investigation, and response capabilities.
  • Oversee SIEM operations and security monitoring platforms such as Microsoft Sentinel, Splunk, or equivalent technologies.
  • Establish and monitor security incident management processes.
  • Review security alerts, incidents, trends, and threat intelligence.
  • Ensure appropriate escalation and response mechanisms are in place for critical security events.
  • Monitor and improve the effectiveness of security controls and operational processes.

D. Cybersecurity Incident Response

  • Lead the organization’s cybersecurity incident response capability.
  • Ensure effective detection, containment, eradication, recovery, and post-incident activities.
  • Develop, maintain, and continuously improve the Cybersecurity Incident Response Plan (CIRP).
  • Conduct regular incident response exercises and simulations.
  • Lead investigations into significant security incidents and ensure Root Cause Analysis (RCA) is completed.
  • Track corrective and preventive actions resulting from security incidents.
  • Ensure lessons learned are incorporated into security controls and processes.

E. Governance, Risk & Compliance

  • Lead Information Security Governance, Risk, and Compliance (GRC) activities.
  • Ensure compliance with applicable regulatory and industry requirements, including:
  • National Cybersecurity Authority (NCA) requirements
  • Saudi Personal Data Protection Law (PDPL)
  • National Data Management Office (NDMO) requirements, where applicable
  • ISO/IEC 27001
  • Other applicable cybersecurity and data protection regulations
  • Coordinate internal and external security audits and assessments.
  • Manage audit evidence collection and maintain an organized security evidence repository.
  • Track audit findings, remediation plans, and closure status.
  • Prepare management and regulatory compliance reports.
  • Support regulatory assessments, reviews, and submissions as required.

F. Data Protection & Privacy

  • Establish and maintain data protection and information classification frameworks.
  • Ensure appropriate security controls are implemented for sensitive and personal data.
  • Work with relevant stakeholders to support compliance with PDPL and applicable data protection requirements.
  • Establish appropriate data access, handling, retention, and protection controls.
  • Support privacy and data protection risk assessments where required.

G. Vulnerability & Security Testing

  • Oversee vulnerability management activities across IT environments.
  • Coordinate Vulnerability Assessments and Penetration Testing (VAPT).
  • Review vulnerability and penetration testing reports.
  • Ensure security vulnerabilities are appropriately prioritized based on business risk.
  • Track remediation activities and validate closure of critical and high-risk vulnerabilities.
  • Ensure security testing is incorporated into relevant technology projects and systems.

H. Identity & Access Management

  • Establish and maintain IAM policies, standards, and access control frameworks.
  • Ensure appropriate access governance and segregation of duties.
  • Review privileged access and high-risk accounts.
  • Support periodic user access reviews and access recertification.
  • Ensure access controls align with business requirements and security policies.

I. Security Awareness & Culture

  • Develop and implement an organization-wide security awareness program.
  • Lead cybersecurity awareness campaigns and security training.
  • Implement phishing simulation and social engineering awareness programs.
  • Monitor employee security awareness performance and identify improvement areas.
  • Promote a strong cybersecurity culture across all business functions.

J. Business Continuity & Disaster Recovery

  • Ensure cybersecurity requirements are incorporated into Business Continuity and Disaster Recovery plans.
  • Participate in BCP/DR risk assessments and exercises.
  • Ensure critical systems have appropriate security, recovery, and resilience controls.
  • Support testing and continuous improvement of security-related recovery procedures.

5. Qualifications & Experience

Minimum Qualifications

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Security, or a related discipline.
  • CISSP or CISM certification – Mandatory.
  • ISO/IEC 27001 Lead Implementer or Lead Auditor certification preferred.
  • NCA-related cybersecurity accreditation or certification is preferred.

Minimum Experience

  • 8–10 years of professional experience in Information Security / Cybersecurity.
  • At least 3 years of experience in a cybersecurity or information security management/leadership role.
  • Proven experience managing enterprise cybersecurity programs and security teams.
  • Proven experience in GRC, risk management, security operations, and incident response.
  • Proven experience working with regulatory compliance, audits, and cybersecurity frameworks.

6. Technical & Professional Skills

The successful candidate should demonstrate:

  • Strong knowledge of cybersecurity frameworks, standards, and best practices.
  • Deep understanding of NCA, PDPL, NDMO, ISO 27001, and applicable data protection requirements.
  • Strong expertise in Governance, Risk, and Compliance (GRC).
  • Experience with SOC operations and SIEM platforms such as Microsoft Sentinel, Splunk, or equivalent.
  • Strong understanding of vulnerability management and penetration testing.
  • Strong knowledge of Incident Response and Cybersecurity Incident Response Plans (CIRP).
  • Strong understanding of IAM and access governance.
  • Knowledge of data protection, data classification, and data governance.
  • Strong understanding of secure architecture and security controls.
  • Ability to develop and monitor cybersecurity KPIs and KRIs.
  • Strong audit and regulatory assessment experience.
  • Ability to assess and communicate cybersecurity risks in terms of business impact.
  • Strong strategic thinking and high-level decision-making capability.
  • Excellent leadership and people-management skills.
  • Ability to manage cross-functional teams and stakeholders under pressure.
  • Strong communication, presentation, and reporting skills.
  • Bilingual proficiency in Arabic and English.

7. Leadership Competencies

  • Strategic Thinking
  • Cybersecurity Leadership
  • Risk-Based Decision Making
  • Stakeholder Management
  • Executive Communication
  • Team Leadership & Development
  • Problem Solving
  • Crisis and Incident Management
  • Governance & Accountability
  • Continuous Improvement
  • Business Acumen
  • Change Management

Special Requirements

  • Ability to work effectively in a fast-paced and dynamic environment.
  • Ability to manage cybersecurity incidents and critical security situations.
  • Willingness to participate in security incident response and escalation activities when required.
  • Strong confidentiality and professional integrity.
  • Ability to work collaboratively with executive leadership, IT, business functions, auditors, and regulatory stakeholders.

Requirements

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.