Company Description Aarcalev Technology Solutions helps organizations across India, the Middle East, Africa, and Europe build secure, resilient, and compliant digital ecosystems through specialized Cybersecurity Advisory and Compliance services. The company is led by Ms. Sireesha Dandu, a Forbes Technology Council member and cybersecurity leader with over 18 years of global experience, supported by a leadership team with Big4 and enterprise backgrounds. Aarcalev delivers GRC and regulatory compliance advisory, cybersecurity consulting, and assessment and audit services covering standards such as ISO 27001, PCI DSS, GDPR, CERT-IN, DPDP, PDPL, SAMA, NCA ECC, NDPA, and CBN IT standards. With a focus on global expertise combined with local compliance knowledge, Aarcalev provides independent, transparent, and tailored solutions to organizations of all sizes. Its mission is to prepare, protect, and empower clients to thrive securely and confidently in the digital era.
Senior GRC / Information Security Compliance Expert
üìç Location: Cairo, Egypt
üè¢ Work Location: Cairo
⏱️ Experience: 5 Years+
üö® Joining: Immediate / Urgent Requirement
üîπ Key Requirements
We are looking for experienced GRC professionals with strong practical experience in Information Security Governance, Risk Management, Compliance, Auditing, and Regulatory Frameworks.
Candidates should have hands-on experience with several of the following:
International Frameworks & Standards
‚úÖISO/IEC 27001:2022
‚úÖNIST Cybersecurity Framework
‚úÖNIST SP 800-series
‚úÖSOC 2
‚úÖPCI-DSS
‚úÖRisk Management Frameworks
‚úÖInformation Security Governance & Compliance
‚úÖSecurity Risk Assessments
‚úÖInternal / External Audit Preparation
‚úÖPolicies, Procedures, Controls & SOA
‚úÖControl Mapping and Gap Assessments
‚úÖEgyptian Centra Bank of Egypt framework
‚úÖEgyptian data protection and privacy requirements
‚úÖEgyptian cybersecurity / information security regulatory requirements
‚úÖAbility to map international frameworks to Egyptian requirements
üîπ Responsibilities
‚úÖLead and execute GRC assessments and compliance projects
‚úÖPerform gap assessments and maturity assessments
‚úÖDevelop and review information security policies and procedures
‚úÖPerform risk assessments and risk treatment
‚úÖDevelop and maintain Statement of Applicability (SOA)
‚úÖMap controls across ISO 27001, NIST, SOC 2, PCI-DSS, NCA ECC, SAMA, PDPL, CST CRF and other frameworks
‚úÖSupport organizations during internal and external audits
‚úÖPrepare compliance evidence and audit documentation
‚úÖConduct control effectiveness assessments
‚úÖDevelop remediation plans and track compliance gaps
‚úÖWork with technical and business teams to implement security controls
‚úÖPrepare professional GRC, risk and compliance reports for management
üîπ Preferred Certifications
Relevant professional certifications are highly desirable, such as:
ISO/IEC 27001 Lead Auditor / Lead Implementer, CISA, CISM, CISSP, CRISC, CGEIT
- PCI Professional / PCI-related certifications