Information Security Governance Analyst at SSC HR Solutions
Sheikh Zayed, Giza, Egypt -
Full Time


Start Date

Immediate

Expiry Date

16 Jun, 26

Salary

0.0

Posted On

18 Mar, 26

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Iso 27001, Risk Management, Compliance, Governance, ISMS, GRC, KPI/KRI Reporting, Risk Assessments, Audit Readiness, Security Awareness, GRC Platforms, Documentation, Data Collection, Process Improvement, Stakeholder Collaboration, Detail-Oriented

Industry

Human Resources Services

Description
Job Purpose: Support the implementation, monitoring, and continuous improvement of information security governance, risk management, and compliance program. This role contributes directly to maintaining ISO 27001:2022 certification, supporting surveillance and external audits, driving KPI/KRI reporting, and enabling the maturity and scalability of GRC processes. Job Responsibilities: ▪ Support the development, implementation, and enhancement of the Information Security Management System (ISMS) in line with ISO 27001:2022 . ▪ Assist in maintaining GRC policies, procedures, and standards aligned with regulatory and business requirements ▪ Gather and report on security-related KPIs and KRIs to monitor control effectiveness and program health ▪ Participate in risk assessments, maintain the risk register, and support mitigation tracking ▪ Contribute to internal and external audit readiness, including ISO surveillance visits ▪ Collaborate with internal stakeholders to promote security awareness and compliance culture ▪ Support the implementation and use of GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust) ▪ Engage with ongoing projects to support secure development practices, compliance checks, and risk registers ▪ Prepare documentation and participate in quarterly ISMS and GRC reporting cycles ▪ Operates under the direction of the GRC Manager with a focus on execution and coordination, not strategic program ownership Job Skills and Abilities: - Basic understanding of ISO 27001and risk frameworks - Awareness of data protection laws - Familiarity with risk management processes - Clear communication and cross-functional collaboration - Analytical and documentation skills - Process-focused, detail-oriented mindset - Ability to coordinate across departments on compliance topics - Ability to manage multiple assignments under supervision - Ability to collect and maintain reliable compliance data Qualifications: - Bachelor’s degree in computer science engineering - 2–6 years of experience in information security, risk management, or GRC roles - Exposure to ISO 27001. - Experience with GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust) is a plus - Certifications preferred: ISO/IEC 27001 Foundation or Implementer, CompTIA Security+, CISA, CRISC
Responsibilities
This role supports the implementation, monitoring, and continuous improvement of the information security governance, risk management, and compliance program, focusing on maintaining ISO 27001:2022 certification and driving GRC process maturity. Key tasks include supporting ISMS development, assisting with policy maintenance, gathering KPI/KRI data, participating in risk assessments, and preparing reporting documentation.
Loading...