Senior Grc Security Engineer
4 days ago
Job Purpose:
As a Senior Security GRC Engineer at Instabug, you will be responsible for leading and optimizing the organization’s Security Governance, Risk, and Compliance (GRC) program. This role encompasses conducting risk assessments, developing and implementing risk mitigation strategies, and managing remediation plans. You will oversee threat modeling, internal audits, vulnerability assessments, and compliance initiatives related to SOC 2 Type II, ISO 27001, and PCI-DSS standards. Additionally, you will manage governance processes for change, asset, and configuration management to ensure robust security and compliance practices. Serving as a critical interface, you will respond to customer inquiries and third-party risk management (TPRM) audits, including addressing questionnaires and surveys. You will also design and deliver security awareness programs and conduct security training for internal stakeholders. The role extends to assessing the security posture of Instabug’s vendors and ensuring alignment with the company’s security standards.
Job Responsibilities:
- Risk Management:
- Conduct comprehensive risk assessments and develop actionable risk mitigation strategies.
- Monitor and follow up on remediation plans to address identified vulnerabilities and risks
- Perform threat modeling to identify potential security weaknesses and improve system design.
- Compliance and Governance:
- Lead and execute internal audits to ensure adherence to SOC 2 Type II, ISO 27001, and PCI-DSS compliance standards.
- Oversee governance processes for change, asset, and configuration management to align with security best practices.
- Administer and maintain the organization’s compliance with applicable regulatory and industry standards.
- Vulnerability Management:
- Conduct vulnerability assessments and oversee the vulnerability management lifecycle.
- Customer and Third-Party Engagement:
- Respond to third-party risk management (TPRM) surveys, questionnaires, and audits.
- Collaborate and engage with customers to address security inquiries and ensure satisfaction with Instabug’s security posture.
- Training and Awareness:
- Develop and deliver security awareness programs, training materials, and workshops for internal stakeholders.
- Vendor Management:
- Perform TPRM assessments for Instabug's vendors and third-party providers to evaluate and enhance their security posture.
- Evaluate and assess the security posture of vendors and third-party providers through TPRM assessments.
- Collaborate with cross-functional teams to promote a security-first culture across the organization.
Working with agile practices in an agile environment with a customer focused acumen
Job Requirements:
- A minimum of 5-8 years of professional experience in Security GRC, including hands-on experience in risk assessments, vulnerability management, and compliance initiatives.
- Relevant certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor/Implementer, or PCI-DSS QSA are highly preferred.
- Proficient in conducting risk assessments, threat modeling, and internal auditing.
- Strong understanding of SOC 2 Type II, ISO 27001, and PCI-DSS standards and audit processes.
- Experience in vulnerability assessment tools and techniques.
- Experience with and extensive knowledge of security standards such as NIST, ISO, and COBIT.
- Experience and knowledge of privacy program principles are a plus.
- Excellent communication and interpersonal skills for customer engagement and cross-team collaboration.
- Strong analytical and problem-solving abilities.Fluent in English, with strong written and verbal communication skills.
Bonus:
- Proven ability to develop and deliver engaging security awareness programs.
- Experience in TPRM processes, including vendor assessments.
- Working experience with the Atlassian tool suite (i.e., Jira Agile) or similar.
- Excellent experience in Agile Development methodology.
- Knowledge of cloud computing and cloud security principles is a plus.
-
Cyber Security Grc Engineer
3 days ago
Cairo, Egypt RATP Dev Full time**Cyber Security GRC Engineer**: - Fixed-term contract- Full-time- Less than 2 years of experience (Entry level)- Bachelor degree- IT Specialist **Mission**: **JOB PURPOSE**: The Cybersecurity GRC Engineer plays a critical dual role in safeguarding the organization’s digital assets while advancing its cybersecurity governance maturity. This position is...
-
Cyber Security
4 days ago
Cairo, Egypt Giza Systems EG Full time**Governance Development & Implementation**: - Develop, implement, and maintain the organization's cybersecurity governance framework, policies, standards, and procedures in alignment with business objectives and regulatory requirements. - Lead the development and maintenance of cybersecurity awareness and training programs for all employees. **Risk...
-
GRC Engineer
3 days ago
Cairo, Cairo, Egypt Paymob Full timeDeveloping and implementing an organization GRC program, which includes procedures and policies designed to protect enterprise communications, systems and assets from both internal and external threats. Alongside with Aligning with company's strategy to ensure meeting business objectives with security international standards. Compiling with standards and...
-
GRC Junior Analyst
5 days ago
Cairo, Cairo, Egypt Bankawy - بنكاوى Full timeFor A Leading Fintech Company (Owned by One of Egypt's Largest Local Banks)***Kindly apply only if you are willing to attend on-site interview in few days***GRC Junior AnalystPosition Summary:Job purpose:We are seeking a proactive and detail-oriented GRC Analyst to join our Information Security team. The ideal candidate will have at least 3 years of hands-on...
-
GRC Specialist
1 week ago
Cairo, Cairo, Egypt Premier Services and Recruitment Full timeKey Responsibilities:Assist in the development and maintenance of information security policies, procedures, and standards .Support risk assessment and risk treatment activities across business units.Help track and monitor compliance with frameworks such as ISO 27001 , NIST , GDPR , or other relevant regulations.Maintain documentation and...
-
Cybersecurity Grc Specialist
1 week ago
Cairo, Egypt Giza Systems EG Full time**Key Responsibilities**: - Support the development and implementation of cybersecurity policies, standards, and compliance frameworks (ISO 27001, NIST). - Conduct cybersecurity risk assessments and internal control reviews. - Monitor vendor performance and validate service levels (SLAs/KPIs). - Coordinate cybersecurity audits and support audit readiness. -...
-
Cybersecurity & Technology Grc
4 days ago
Cairo, Egypt Giza Systems EG Full time**Key Responsibilities**: - Support the development and implementation of cybersecurity policies, standards, and compliance frameworks (ISO 27001, NIST). - Conduct cybersecurity risk assessments and internal control reviews. - Monitor vendor performance and validate service levels (SLAs/KPIs). - Coordinate cybersecurity audits and support audit readiness. -...
-
SAP Grc
16 hours ago
Cairo, Egypt DXC Technology Full time**Job ID**: 51559507 **Location**: Cairo, Egypt **Category**: Finance **Employment Type**: Full time At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances....
-
Cyber Security Lead Engineer
1 week ago
Cairo, Cairo, Egypt Arpu Telecommunication Services Full timeObjective: (summary about the position)Seeking a highly experienced Security Lead Engineer to lead the design, implementation, and continuous improvement of cybersecurity measures across our hybrid environment. This role requires overseeing infrastructure, application, and cloud security; managing threat detection and response systems; guiding the security...
-
Senior Security Integration Engineer
5 days ago
Cairo, Cairo, Egypt Cyshield Full timeCompany DescriptionEstablished in 2016, CyShield is a leading digital services company specializing in Artificial Intelligence, Cyber Security, Data Science, IoT, and Software Engineering. CyShield collaborates with large organizations in the financial, media, healthcare, and governmental sectors. Our innovative solutions and services help clients navigate...