InfoSec Compliance & Assurance Lead - Banking
Xenon7
Employer Active
Posted 16 hrs ago
Send me Jobs like this
Nationality
Any Nationality
Gender
Not Mentioned
Vacancy
1 Vacancy
Job Description
Roles & Responsibilities
This role exists to accelerate the information security compliance posture across IT and Digital Transformation. The specialist acts as the InfoSec function's technical compliance arm tracking, evidencing, and reporting on remediation progress against CBE Cybersecurity Framework requirements, PCI DSS obligations, and internal control commitments. The role also leads and executes assurance exercises, either directly or by scoping and managing third-party security assessment engagements.
Key Responsibilities:A. IT & Digital Transformation Compliance Follow-Up
Maintain a live compliance tracker across all active CBE Cybersecurity Framework control domains (IAM,
PAM, GRC, Container Security, and others).
Conduct regular technical walk-throughs with IT and Digital Transformation teams to validate
implementation status and close evidence gaps.
Escalate risks and blockers to the Head of GRC and CISO with clear risk-quantified language suitable for
Risk Committee reporting.
Map remediation actions to OKR key results and track delivery against agreed timelines.
Prepare compliance status reports in a format suitable for senior management and regulatory audiences.
B. PCI DSS Engagement Lead
Own the end-to-end PCI DSS engagement cycle scoping, gap assessment, remediation tracking, QSA
coordination, and Report on Compliance (RoC) or Self-Assessment Questionnaire (SAQ) readiness.
Coordinate across IT, Operations, and Digital to ensure cardholder data environment (CDE) controls are
implemented, evidenced, and maintained.
Manage the relationship with the appointed Qualified Security Assessor (QSA) and act as the internal
point of contact throughout the assessment cycle.
Drive closure of PCI DSS findings and build a compensating controls register where technical controls are
not yet feasible.
Maintain PCI DSS documentation library including network diagrams, data flow diagrams, asset inventory,
and policies relevant to the CDE.
C. InfoSec Assurance Exercises
Plan and execute assurance activities including control testing, configuration reviews, access reviews,
and policy compliance spot checks.
Scope, procure, and manage third-party security assessment vendors where specialized assessment
capability is required (e.g., penetration testing, red team exercises, cloud security reviews).
Produce clear assurance reports with risk-rated findings, business impact statements, and prioritized
remediation recommendations.
Track finding remediation to closure and validate effectiveness of corrective actions.
Coordinate with the InfoSec Control Validation Manager to align assurance outputs with
broader control validation programme.
Desired Candidate Profile
Minimum 7 years of information security experience, with at least 3 years in a banking or financial
institution.
Hands-on PCI DSS experience must have participated in or led at least one full RoC or SAQ-D
assessment cycle.
Deep knowledge of CBE Cybersecurity Framework requirements and Egyptian regulatory context.
Experience conducting technical compliance gap assessments across IT infrastructure, network, and
application layers.
Strong written and verbal communication skills in both Arabic and English.
Preferred Certifications
CISA Certified Information Systems Auditor
PCIP or PCI ISA PCI Internal Security Assessor
ISO 27001 Lead Auditor
CISM Certified Information Security Manager
Preferred Experience
Prior experience in an Egyptian bank or financial institution operating under CBE oversight.
Familiarity with GRC tooling (RSA Archer, ServiceNow GRC, or equivalent).
Experience working with external auditors, QSAs, and regulators.
- Attractive, market-leading salary package
- Clear career advancement path with professional development opportunities
Company Industry
- Internet
- E-commerce
- Dotcom
Department / Functional Area
- IT Software
Keywords
- InfoSec Compliance & Assurance Lead - Banking
Disclaimer: Naukrigulf.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@naukrigulf.com
Similar Jobs
InfoSec Awareness & Engagement Lead - Banking
Xenon7
- 3 - 6 Years
- Cairo - Egypt
OT Cybersecurity Lead | Real Estate | AFET
Al Futtaim Private Company (LLC)
- 5 - 10 Years
- Dubai - United Arab Emirates (UAE)
Risk & Compliance Analyst Risk Register Management
Client of Salt
- 3 - 7 Years
- Abu Dhabi - United Arab Emirates
Cyber Security Assurance Tech Lead
Vodafone
- 1 - 5 Years
- Giza - Egypt
Cyber Security Governance & Compliance Lead
Silver Edge Arabia
- 3 - 8 Years
- Riyadh - Saudi Arabia