Risk and Compliance Specialist, Information Security

3 days ago


New Cairo, Cairo, Egypt noon Full time

Who are we?

noon is the largest e-commerce player in the Middle East and is quickly becoming the go-to platform for all online customer needs. We've built a full-fledged ecosystem of products and services in e-commerce, quick-commerce, food, fintech, grocery, and fashion—and we're just getting started.

We are a team of dynamic professionals who are aggressively ambitious, rapidly scaling, and uniquely positioned to capitalize on the rapid adoption of e-commerce in the Middle East.

We're on an unconventional mission, doing something that has never been done before. We are developing the future of online shopping, and we're looking for top talent to join us on our mission.

Job Description

At noon, we recognize risk, compliance, and governance's importance and value to the broader Information Security program success. Therefore, We are seeking a Risk and Compliance Specialist to focus on building a security assurance program that enables our companies to meet regional/global regulatory and compliance requirements.

We are excited to have someone join the team with broad compliance, risk, and technical experience. This role will acquire and nurture collaborations with Legal, Internal Audit, the broader Infosec department, and other Engineering functions to drive a data-centric security assurance strategy.

Department: Information Security

Role:

  • Own all aspects of the compliance requirements, including the management and implementation of the key controls of PCI-DSS, ISO 27001, SOC 2 across our group of companies.
  • Overseeing the design and implementation of the Vendor risk assessment program and liaising with outside vendors/suppliers regarding security and compliance measures.
  • Confirm vendor controls and advise remediation activities. Prioritize, log, report all events, progress, and challenges regularly to higher management.
  • Execute projects related to data privacy gap assessments/Audits.
  • Development of data privacy framework including TOM, policies, procedures, and templates
  • Development & implementation of data privacy processes (e.g., Consent Management, DSAR requests, Data Privacy incident management, etc.)
  • Perform Gap Analysis and Risk Assessment as per the defined scope.
  • Effectively write and communicate audit, assessment or compliance results, findings, and recommendations to stakeholders.
  • Leveraging engineering principles to address compliance challenges.
  • Provide Subject-Matter-Expert guidance on the org-wide risk management program and risk appetite.
  • Periodic review and revision of all company policies and procedures.

Required Skills :-

  • Bachelor's degree, or equivalent experience, in Computer Science, Engineering, Mathematics or a related field.
  • Experience in international standards and local regulatory requirements related to payment security, data privacy and protection.
  • Experience advising customers on architectures meeting industry standards such as PCI DSS, ISO 27001, GDPR, and NIST/DoD frameworks
  • Must have at least 2 years in managing regulatory and compliance framework requirements (e.g., PCI DSS, SOC2, ISO27001, ISO 27701, GDPR, NCA/NDMO data privacy framework)
  • Hands-on experience analyzing and applying compliance requirements to security practices
  • Ability to monitor and keep current with changes and trends in the regulatory landscape.
  • Experience in Data Protection Impact Assessments.
  • Performing security risk assessments.
  • Development of security policies and procedures.

Preferred Qualifications :-

  • PCI DSS Qualified Security Assessor (QSA) Certification is a plus
  • GDPR practice and certification
  • CISSP/ CISA/ CISM or equivalent preferred
  • A hands-on technical background is preferred.
  • Able and comfortable wearing multiple hats.
  • Establishes industry expertise through writing, speaking, shipping open-source projects, or online presence.

Who will excel?

'noon isn't for everyone. And that's okay.' This is one of our core operating principles.

We're looking for resourceful doers. Thinkers who are both creative and analytical. Problem solvers who are enthusiastic about delivering results. Our ideal candidate will be comfortable in a fast-paced, multi-tasked, high-energy and often ambiguous environment.

If the above values resonate with you, then noon might be the place for you.



  • Cairo, Cairo, Egypt On Hire Full time

    Company Overview:Join a fast-growing fintech company dedicated to revolutionizing financial services with cutting edge technology. As a company operating under the Financial Regulatory Authority (FRA), we prioritize security, risk management, and regulatory compliance to ensure our customers' trust and data protection. We are seeking a GRC Engineer to help...


  • Cairo, Cairo, Egypt Xceed Full time 90,000 - 120,000 per year

    Company DescriptionXceed is a leading multilingual Business Process Outsourcing Service provider in the EMEA region with a capacity of more than 10,000 web-enabled multi-channel stations. Managing various outsourcing agreements, Xceed caters to key government and commercial accounts in 10 different languages. Xceed operates from sites in Egypt, Morocco,...


  • Cairo, Cairo, Egypt Onefinance Full time

    Are you passionate aboutcyber defense / application securityand ready to make a real impact in a fast-paced, regulated environment?We're looking for anInformation Security Senior Officerto lead and continuously improve our information security framework, working cross-functionally with key departments to ensure data protection, regulatory compliance, and...


  • Cairo, Cairo, Egypt TP Full time

    The IT Security, Lead ensures the safeguarding and protection of business infrastructure and systems, and responsible for supporting the information security efforts, programs and projects. The Lead, plays a critical role in protecting data and services from security threats, implementing and maintaining all necessary security measures, and ensuring the...


  • Cairo, Cairo, Egypt NBK Egypt Full time 90,000 - 120,000 per year

    Key ResponsibilitiesSupport and monitor the execution of the bank's information security governance framework.Ensure the design and implementation of controls that align with applicable standards and regulatory requirements.Develop and maintain security policies, procedures, and standards.Assist in the periodic review and enhancement of the Information...


  • Cairo, Cairo, Egypt Nano Health Suite Full time $30,000 - $90,000 per year

    Hiring Now: Cyber Security Specialist (Junior / Mid-Level / Senior) –We are expanding our IT Security team and looking for talentedCyber Security Specialistsacross multiple seniority levels:Junior:3–5 yearsMid-Senior:5–8 yearsSenior:8+ yearsLocation:onsiteEmployment Type:Full-TimeDepartment:IT Department About the RoleWe are seeking highly skilled...


  • Cairo, Cairo, Egypt Cyberthos Full time 60,000 - 120,000 per year

    Looking to kickstart your career in Cyber Security?Apply for a unique, fully FREE internship opportunity at Cyberthos Gain real-world experience in one of the world's fastest-growing fields. Work alongside experts and hone your skills.You will have the opportunity to train in the following areas: Network Security Penetration Testing SOC Analyst GRC...

  • GRC Specialist

    7 days ago


    Cairo, Cairo, Egypt Premier Services and Recruitment Full time

    Key Responsibilities:Assist in the development and maintenance of information security policies, procedures, and standards .Support risk assessment and risk treatment activities across business units.Help track and monitor compliance with frameworks such as ISO 27001 , NIST , GDPR , or other relevant regulations.Maintain documentation and...


  • Cairo, Cairo, Egypt NEXperience Full time 15,000 - 30,000 per year

    Company DescriptionNEXperience is a CX innovation company specializing in enhancing customer engagement for global brands. By combining top-tier talent, advanced AI solutions, and deep industry expertise, NEXperience delivers scalable nearshore services in customer support, digital sales, and back-office operations. Our solutions cater to key industries like...

  • Technology Risk

    1 day ago


    Cairo, Cairo, Egypt Giza Systems Full time

    We are seeking a highly experienced and results-driven professional to lead our Cybersecurity Governance, Risk, and Compliance (GRC) function. The successful candidate will be responsible for establishing and maintaining a robust security posture across the organisation, ensuring alignment with regulatory requirements, business objectives, and industry best...