Senior Information Security Analyst - Compliance & GRC

Posted 3 Days Ago
Be an Early Applicant
Dhajeej-South Farwaniya, Farwaniya, KWT
In-Office
Senior level
Logistics • Transportation
The Role
Lead GRC and compliance efforts, maintain ISMS and BCSM frameworks, manage audit readiness, perform security assessments of cloud/on-prem systems, prioritize remediation from vulnerability and penetration testing, enforce IAM controls, and drive organization-wide security and resilience practices.
Summary Generated by Built In

Role Summary:

We are seeking a highly experienced and results-driven Senior Information Security Analyst to serve as our entral Governance, Risk, and Compliance (GRC) resource. This is a pivotal role responsible for the overall design, maintenance, and enhancement of the organization's security and resilience frameworks. The core purpose of this position is to ensure continuous compliance with all relevant international and local standards, with a specific focus on leading our audit readiness and certification efforts.

Your Responsibilities:

 Compliance and GRC Management

  •  Establish, maintain, and enhance the organization's Information Security Management System (ISMS) and Business Continuity & Supply Chain Management (BCSM) frameworks
  • Ensure the organization's compliance with all relevant local, regional, and international regulations and standards, ISO 27001, ISO 22301)
  • Act as the primary auditee and point of contact for all internal and external information security audits
  • Proactively identify, assess, and manage information security and business continuity risks to protect the organization's information assets
  • Drive a culture of security and resilience across the organization

 Security Controls & Technical Oversight

  •  Conduct security assessments and audits of various IT platforms, including cloud infrastructure , on-premise servers (Windows, Linux), databases, and network devices.
  • Utilize or interpret reports from vulnerability scanners and penetration testing tools to identify and prioritize security weaknesses
  • Evaluate and enforce robust Identity and Access Management (IAM) controls, including role-based access control (RBAC) and multi-factor authentication (MFA)
  • Review and ensure the security of cloud deployments (IaaS, PaaS, SaaS), including security groups, IAM policies, and logging
  • Apply strong knowledge of secure configuration baselines and hardening standards (CIS Benchmarks) for operating systems, web servers, and network equipment

Requirements

Your Qualifications:

  • Education: Candidate must possess at least a Bachelor of Science or Bachelor of Computer Application
  • Experience: A minimum of 5 - 10 years of experience in a similar environment
  • Domain: Experience in Government Sector or Private Sector with Enterprise data Center Security Compliance
  • Certifications: Essential certifications include ISO 27001, ISO 22301, CISSP, and CISA
  • Language: Must be fluent in English, with Arabic as an added advantage.

Your Competencies:

Technical:

  • Security Frameworks & Standards: Profound knowledge of ISO 27001, NIST, and CIS
  • Security Controls: A solid understanding of network security (Firewalls, IDS/IPS), Endpoint Security (EDR), IAM principles, and Cryptography
  • Tools: Practical experience with Vulnerability and Risk Assessment Tools and familiarity with SIEM platforms
  • Software Proficiency: Experience with GRC Platforms and documentation tools (Microsoft Office Suite, SharePoint, Jira, Confluence)

 Behavioral:

  • Teamwork and Collaboration
  • Quality and Results focused
  • Learning Agility
  • Business Acumen
  • Decision Making
  • Digital Savvy
  • Agility and Adaptability
  • Negotiation and influence
  • Planning and Organizing

Skills Required

  • Bachelor of Science or Bachelor of Computer Application
  • 5-10 years of relevant information security/GRC experience
  • Experience with Government or Enterprise Data Center Security Compliance
  • ISO 27001 certification
  • ISO 22301 certification
  • CISSP certification
  • CISA certification
  • Proven knowledge of ISO 27001, NIST, and CIS security frameworks
  • Hands-on experience with firewalls, IDS/IPS, and network security controls
  • Experience with endpoint security (EDR) solutions
  • Practical experience with IAM, RBAC, and MFA implementations
  • Experience reviewing cloud security (IaaS, PaaS, SaaS) including IAM policies and security groups
  • Experience assessing Windows and Linux servers, databases, and network devices
  • Familiarity with vulnerability scanners, penetration testing tools, and interpreting their reports
  • Experience with vulnerability and risk assessment tools and prioritization
  • Familiarity with SIEM platforms
  • Experience with GRC platforms and documentation tools
  • Proficiency with Microsoft Office Suite, SharePoint, Jira, and Confluence
  • Knowledge of secure configuration baselines and CIS Benchmarks
  • Knowledge of cryptography principles
  • Ability to lead audit readiness and act as primary auditee contact
  • Fluent in English
  • Arabic language skills
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Sulaibiya
8,943 Employees

What We Do

Agility is a global leader in supply chain services, infrastructure, and innovation with 45,000+ employees across six continents. A multi-business operator and investor, Agility specializes in growing and scaling operating businesses. Agility’s companies include the world’s largest aviation services company (Menzies Aviation); a global fuel logistics business (TriStar); the market leader in logistics parks across the Middle East, South Asia, and Africa (Agility Logistics Parks); and a commercial real-estate company developing a mega-mall in the UAE (UPAC). Other Agility companies offer customs digitization services, remote-site infrastructure services, defense and government services, and ecommerce-enablement and digital logistics. Agility invests in supply chain innovation, sustainability, and resilience, and has minority holdings in a growing portfolio of listed and non-listed companies.

Similar Jobs

Capco Logo Capco

Data Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

Capco Logo Capco

Information Technology Project Manager

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

Capco Logo Capco

Data Engineer

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

Capco Logo Capco

Information Technology Business Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

Similar Companies Hiring

Blissway Thumbnail
Computer Vision • Fintech • Hardware • Internet of Things • Machine Learning • Software • Transportation
Denver, CO
24 Employees
Toro TMS Thumbnail
Cloud • Enterprise Web • Sales • Software • Transportation
Chicago, IL
80 Employees
Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account