Cybersecurity Governance Manager
CREDIT GUARANTEE COMPANY S.A.E Egypt
Financial Services · 2-10 employees
About the role
The Cybersecurity Governance Manager will lead the development and implementation of the organization's Information Security Management System (ISMS) and governance framework. They are responsible for managing risk, ensuring regulatory compliance, and coordinating internal and external audits.
What they look for
Requirements
Candidates must hold a bachelor's degree in a relevant field and possess at least 7 years of industry experience, with a minimum of 3 years in Information Security or GRC. Professional certifications such as ISO 27001 Lead Implementer, CISSP, CISM, or CRISC are required.
Full description
Job Purpose
To lead the development, implementation, and continuous improvement of the
organization’s Information Security Management System (ISMS) and governance framework,
ensuring alignment with business objectives, regulatory requirements, and industry best practices. This
role provides strategic oversight, drives risk management and compliance initiatives, and establishes a
culture of accountability, security awareness, and operational excellence across the enterprise. The
Head of ISMS & Governance acts as the key authority on information security policies, standards,
controls, and audits, reporting directly to senior leadership and supporting informed decision-making at
the organizational level.
ACCOUNTIBILITIES
Develop and maintain the ISMS framework in line with ISO 27001 and best practices. Manage the ISMS lifecycle (scope, risk assessment, controls, monitoring, and improvement). Maintain ISMS documentation (policies, procedures, standards, SoA) and ensure compliance. Coordinate internal and external ISO 27001 audits and certification activities. Track audit findings, nonconformities, and corrective actions to closure. Maintain risk registers and ensure implementation of risk treatment plans.
Develop and maintain Information Security Policies, Standards, and Procedures. Ensure alignment with business and regulatory requirements. Manage document control and versioning. Support governance meetings and follow up on actions. Coordinate with IT, Risk, Compliance, Audit, Legal, and Business Units.
Identify and assess information security and technology risks. Maintain risk registers and monitor remediation plans. Ensure third-party risk assessments and controls are in place. Align cybersecurity risks with enterprise risk management.
Ensure compliance with relevant laws, regulations, and standards. Support ISO 27001, NIST CSF, GDPR, and similar frameworks. Manage audit evidence and compliance documentation. Ensure continuous compliance with certification requirements.
Act as main contact for security and compliance audits. Support audit preparation and provide required evidence. Track and close audit findings and remediation actions. Perform periodic control reviews.
Support security awareness programs. Ensure employees understand security policies and responsibilities. Conduct targeted training for high-risk teams.
Manage third-party risk assessments and monitoring. Ensure vendors comply with security requirements and contracts. Conduct due diligence for suppliers.
Develop KPIs and KRIs for security governance. Report ISMS status, risks, and compliance to management. Track audit issues, exceptions, and corrective actions.
Internal: Business Unit Directors, IT Operations, Risk Management, Internal Audit, Compliance & Legal External: ISO Certification Bodies, External Auditors, Regulators (e.g., CBE), Vendors, Consultants
Position Requirements
· Educational Requirements: Bachelor’s degree in information security, Computer Science, IT, Risk
Management, or equivalent.
· Special Certification or Training Required: ISO 27001 Lead Implementer or Lead Auditor,
CISSP, CISM, CRISC, Other security governance/GRC certifications
· Required Industry Experience: overall 7 years min. 3 yrs in Information Security, Governance,
GRC, or ISMS
· Experience with ISO 27001 implementation or maintenance is required
Similar roles
-
Senior Security Engineer - DevSecOps
carsales Sydney, New South Wales, Australia
-
Lead Cloud Security Engineer (DevSecOps)
Bilue Taguig, National Capital District, Philippines
-
Senior Security Engineer - Detection Engineering
LinkedIn United States · $129K–$212K/yr
-
Security Engineer
AlertMedia Austin, Texas, United States
-
F-35 Air Systems Information System Security Engineer | Active Secret clearance
General Dynamics Information Technology Eglin AFB, Florida, United States · $128K–$172K/yr
-
Full-Stack Engineers (Cybersecurity): Feedback On CI/CD Workflows
Terac United States · $218K/yr