- Experience
- 3–5 yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Position Overview
Join our Cyber Security Services cluster within the Infrastructure Services Division as a GRC Security Specialist. This full-time, remote position begins in October 2026 and lasts for 12-18 months with potential for extension. The role operates in the Egypt, KSA, or UAE time zones, ideally requiring proficiency in English combined with Arabic or French.
Key Responsibilities
- Develop, update, and uphold comprehensive information security policies, standards, and guidelines aligned with organizational objectives and legal regulations.
- Enhance organizational security awareness by supporting the creation and delivery of employee training initiatives.
- Lead and support both internal and external security audits such as SOC 2, ISO 27001, PCI-DSS, HIPAA, and GDPR compliance evaluations.
- Carry out routine internal audits to detect compliance shortcomings and collaborate with technical teams to implement corrective measures.
- Assess security risks across internal systems, processes, and infrastructure components.
- Oversee third-party and vendor risk management by assessing the security qualifications of key suppliers and SaaS solutions.
- Maintain and manage the IT/Security Risk Register ensuring all identified risks are properly recorded, tracked, addressed, or formally accepted.
Qualifications and Requirements
- Possess 3 to 5 years of professional experience in information security, IT audit, or Governance, Risk, and Compliance (GRC)-focused positions.
- Demonstrate a solid knowledge of major security standards and regulatory frameworks including NIST Cybersecurity Framework, ISO/IEC 27001, SOC 2, CIS Controls, and GDPR.
- Preferred certifications include CISA, CRISC, CISM, or CompTIA Security+.
Preferred Additional Skills
- Technical experience in cybersecurity operations or previous engagement within Security Operations Centers (SOC).
- Familiarity with enterprise IT environments, TCP/IP networking, and associated technical and procedural security controls.
- Certifications such as CISM, CRISC, CGEIT, CISSP or equivalent are desirable.
- Current knowledge or training related to the NIS2 directive is advantageous.
Industry
Management ConsultingSkills
Languages
Servicenow