Apply Edge Start your job search

IT Risk, Security & Cloud Infrastructure Manager

Daam Outsourcing · Qesm El Maadi, Cairo, Egypt

Apply & track with Apply Edge
Job Purpose:This role serves as the process owner of all assurance activities related to the availability, integrity, and confidentiality of customer, business partner, employee, and business information in compliance with the organisation's information security policies. A key element of the role is working with management to determine acceptable levels of risk for the organisation. This position is responsible for establishing and maintaining a corporate-wide information security management program to ensure that information assets are adequately protected. The role will also be responsible for the implementation of different security solutions to ensure compliance with the different applicable security and risk standards in the Kingdom of Saudi Arabia and other geographies that we will operate in.Key Accountabilities:Develop, implement, and monitor a strategic, comprehensive enterprise information securityand IT risk management programFull abreast with the SAMA IT risk framework and ensure all implementation is in full compliance with the framework, regulations, and guidelinesWork directly with the business units to facilitate risk assessment and risk management processesDevelop and enhance an information security management frameworkUnderstand and interact with related disciplines through committees to ensure the consistentapplication of policies and standards across all technology projects, systems, and servicesProvide leadership to the enterprise's information security organizationAdvise the leadership team on the appropriate administration of information security standards,assisting them in developing plans within their business units to manage these risks effectivelyby understanding the fundamental aspects of their business objectives.Partner with business stakeholders across the company to raise awareness of riskmanagement concernsAssist with the overall business technology planning, providing current knowledge and futurevision of technology and systemsManage institution-wide information security governance processes, chair the InformationSecurity Advisory Committee and lead Information Security Liaisons in the establishment of aninformation security program and project priorities.Perform risk assessments that address security threats, changes to systems and/orapplications, process improvement initiatives, supplier assessments (including downstreamoutsourcers) and other requests from the business.Develop and implement a comprehensive cloud strategy, selecting between public, private, or hybrid cloud modelsOversee the allocation of compute, storage, and networking resources using Infrastructure asCode (IaC) to ensure consistency and prevent & configuration drift".Monitor cloud usage and spending to identify underutilized resources, right-sizing instances toensure the cloud investment remains cost-effective.Establish real-time monitoring and alerting systems to proactively detect and resolveperformance bottlenecks or system failures.Implement robust security protocols, including Identity and Access Management (IAM), dataencryption, and regular audits to maintain compliance with industry standardsEstablish annual and long-range security and compliance goals, define security strategies,metrics, reporting mechanisms and program services; and create maturity models and aroadmap for continual program improvements.Mature and operationalise various GRC capability areas such as enterprise security riskmanagement, compliance management, policy management, 3rd party risk management, andmetrics and reporting.Drive remediation activities from identification, remediation plan, and closure. Hold ownersaccountable for delivery of remediation solutions within the agreed upon/reasonable SLA.Manage BCP/DRP and Incident Response procedures, tests, and audits.Interface with internal and external auditors to articulate security controls when appropriate.Assess and communicate all security risks associated with purchases or practices performedby the company.Work with internal stakeholders across the business to identify, assess, report, track, andremediate risks and support the development of risk mitigation strategies.Make risk-based decisions and trade-offs impacting annual investment strategies and projectprioritisation.Maintain a strong understanding of risk management methodologies and frameworks.Understand business processes, regulations, and controls and develop meaningful tests toensure controls are operating effectively.Perform operational deep dives on compliance-related processes and systems.Identify, gather, track, and report key risk indicators.Work with partners to identify the root cause of issues.Identify potential risks and develop protocols that staff must follow to reduce or manage those risks.Implementing and overseeing the organisation’s cybersecurity programAligning cybersecurity and business objectivesMaintain PCI compliance of the organisation.Working closely with the cybersecurity teamMonitoring Incident Response ActivitiesManaging business continuity and disaster recoveryManaging the governance and setup of Cloud InfrastructurePromoting a culture of strong information securityManaging vendor relationshipsUtilising cybersecurity budgets effectivelyProviding awareness and trainingJob Requirements:Professional security management certification is mandatory (CISSP/CCSP/CISM/CISA)Degree in business administration or a technology-related (computer science or Computer Engineering) field required. 7+ years of experience in Information/Cybersecurity or IT Risk ManagementStrong knowledge of Cloud computing/Elastic computing across virtualised environmentsMinimum of 7 years of experience in a combination of risk management, information security and IT jobsKnowledge of common information security management frameworks, such as ISO/IEC 27001 and NIST.Excellent written and verbal communication skills and high level of personal integrityInnovative thinking and leadership with an ability to lead and motivate cross- functional, interdisciplinary teamsExperience with contract and vendor negotiations and management, including managed services.Specific experience in Agile (scaled) software development or other best-in-class development practices.