Cyber Security GRC Engineer

RATP Dev
Cairo, القاهرة
منذ أسبوع

Cyber Security GRC Engineer

  • Fixed-term contract
  • Full-time
  • Less than 2 years of experience (Entry level)
  • Bachelor degree
  • IT Specialist

Mission

JOB PURPOSE:

The Cybersecurity GRC Engineer plays a critical dual role in safeguarding the organization’s digital assets while advancing its cybersecurity governance maturity. This position is responsible for detecting and responding to threats, managing vulnerabilities, and maintaining core security infrastructure. Simultaneously, the role ensures alignment with regulatory standards and cybersecurity frameworks by managing risk, enforcing compliance, and supporting audit readiness. By integrating operational defense with strategic risk oversight, the engineer contributes to a secure, resilient, and regulation-compliant environment that supports business continuity and digital trust.


Profile

RESPONSIBILITIES/DUTIES

Cybersecurity Operations

  • Perform root cause analysis and assist in remediation of security breaches.
  • Conduct vulnerability assessments and ensure timely patching and configuration updates.
  • Collaborate with IT teams to safeguard systems, networks, and cloud environments.

Governance, Risk & Compliance (GRC)

  • Develop and enforce security policies, procedures, and standards aligned with ISO 27001, NIST, and internal audit requirements.
  • Maintain the information security risk register and manage control assessments.
  • Support third-party risk assessments and internal/external audit readiness.
  • Perform risk and impact assessments for IT and business processes, proposing mitigation plans.
  • Monitor compliance with data protection laws, regulatory standards, and internal controls.
  • Develop cybersecurity awareness content and promote a risk-aware culture.

Security Monitoring, Metrics & Reporting

  • Build dashboards and metrics for key risk indicators (KRIs) and performance indicators (KPIs).
  • Provide reports on incident response, compliance gaps, and control effectiveness.
  • Ensure documentation of security incidents, investigations, and preventive actions.
  • Support change management processes by reviewing technical risks and security implications of system modifications.

Continuous Improvement & Research

  • Stay updated on cybersecurity trends, technologies, and threat intelligence.
  • Recommend tools and best practices to enhance detection, prevention, and recovery capabilities.
  • Participate in cybersecurity projects, system upgrades, and cross-departmental initiatives.
  • Drive maturity improvement by contributing to gap analyses, self-assessments, and capability building.

ESSENTIAL QUALIFICATIONS, KNOWLEDGE & EXPERIENCE

QUALIFICATIONS:

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or related field.
  • Relevant certifications such as:

o Technical Security: CompTIA Security+, CEH, eJPT, ECIR, or GIAC.

o GRC & Risk: CRISC, ISO 27001 Lead Implementer/Auditor.

  • Fluent in English and Arabic, French is a plus.

KNOWLEDGE:

  • Strong grasp of cybersecurity principles, risk assessment, incident response, and threat intelligence.
  • Familiarity with industry frameworks: ISO 27001, NIST CSF, CIS Controls.
  • Good understanding of IT infrastructure, access control, networking protocols (TCP/IP, DNS, HTTP), and Active Directory.
  • Working knowledge of scripting (e.g., PowerShell, Python, Bash) is a plus.

EXPERIENCE:

  • 1-3 years of experience in cybersecurity or GRC, preferably within a large or regulated organization.
  • Practical involvement in security operations, compliance audits, vulnerability assessments, and control implementations.
  • Experience handling internal and external assessments, including ISO audits and risk evaluations.
  • Exposure to Operational Technology (OT)/IACS environments is a strong advantage.
  • Experience with third-party risk management and security audits.
  • Experience using security technologies: SIEM, firewalls, IDS/IPS, EDR, vulnerability management platform.

DESIRED BEHAVIORS

  • Security-first mindset with a high sense of integrity, responsibility, and ethical conduct.
  • Critical thinker who applies analytical skills to diagnose risks and resolve security challenges effectively.
  • Detail-oriented, especially when evaluating incidents, documentation, and compliance requirements.
  • Communicates with impact, able to translate technical risks into understandable business terms across all levels.
  • Collaborative team player who fosters alignment between cybersecurity, IT, and business functions.
  • Proactive learner who stays current with evolving threat landscapes, compliance standards, and best practices.
  • Resilient and organized under pressure, capable of balancing multiple tasks while meeting deadlines.
  • Persuasive and assertive, driving security adoption across the organization without compromising stakeholder relationships.
  • Comfortable with ambiguity, and adaptable to evolving priorities in a dynamic cybersecurity landscape.

Location

Location
Address

Cairo, Cairo, Egypt

تقديم
توصيات وظائف أخرى:

Cyber Security Business Partner

Bupa
القاهرة
  • Developing and maintaining effective professional...
  • To ensure appropriate Technology frameworks required of...
منذ أسبوع

Cloud Security Engineer with English & French

Concentrix
مصر
  • Hands-on experience with Azure security and governance...
  • Familiarity with Microsoft Security Assessments, such as...
منذ يوم

Track Engineer Intern

RATP Dev
Cairo, القاهرة
The intern will gain hands-on experience in worksite coordination, compliance procedures, and technical support, contributing to...
منذ أسبوع

OCC Engineer - Internship

RATP Dev
Cairo, القاهرة
  • Monitoring and control of train movements.
  • Monitoring and control of power supply systems and...
منذ أسبوع

Senior Machine Learning Engineer

Evolvice
Cairo, القاهرة
  • good understanding of neural network architectures,...
  • Design and develop machine learning models and algorithms...
منذ أسبوعين

Information Security Senior Lead

Vodafone
القاهرة
  • Acts as the primary point of contact in designing/enforcing...
  • Designs and implements information security program that...
منذ أسبوع

Cyber Security Analyst - Octopus by RTG

robusta
Remote
  • Perform analysis of log files to collect more contextual...
  • Provide forensics analysis and investigation...
منذ أسبوع

AFC Engineer - Internship

RATP Dev
Cairo, القاهرة
This internship offers hands-on experience in the maintenance and operation of Automated Fare Collection (AFC) systems Through...
منذ أسبوع

Civil Engineer - Junior (Section 1)

SYSTRA
Cairo, القاهرة
  • Liaising with the technical office about the ordering and...
  • Liaising with procurement about the ordering and...
منذ 3 أيام

Schedule & KPI Engineer /Cost Engineer-Cairo, Egypt

Segula Technologies
Cairo, القاهرة
  • Develop and manage the master project schedule,...
  • Track and update the status of each equipment, including...
منذ 4 أسابيع