RESOURCES RIGHT Job Title: InfoSec Engineer Location: 6th of October, Egypt P OSITION O VERVIEW The Information Security Engineer is responsible for ensuring the security and integrity of an organization's information systems and data. They play a crucial role in designing, implementing, and maintaining effective security measures to protect against cybersecurity threats and vulnerabilities. The Information Security Engineer collaborates with crossfunctional teams to identify security risks, develop mitigation strategies, and ensure compliance with industry standards and regulations. Key Responsibilities: Develop and implement information security policies, procedures, and standards to safeguard the organization's information assets. Assess the organization's current security posture and identify vulnerabilities and risks through regular security audits and penetration testing. Design and deploy security solutions, including firewalls, intrusion detection systems, data loss prevention systems, and encryption technologies. Monitor and analyze security logs and alerts to detect and respond to security incidents and breaches in a timely manner. Conduct investigations of security incidents, document findings, and recommend corrective actions to prevent future incidents. Stay up-to-date with the latest cybersecurity threats, vulnerabilities, and industry best practices to proactively address emerging risks. Collaborate with IT teams to ensure security measures are integrated into the design and implementation of new systems and applications. Provide guidance and support to IT staff and end-users on security-related issues, policies, and best practices. Participate in disaster recovery planning and testing to ensure the availability and resilience of critical systems and data. Contribute to the development and delivery of security awareness training programs to educate employees on security risks and best practices. Requirements and Qualifications Bachelor's degree in computer science, information technology, or a related field. Relevant certifications such as CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) are highly desirable. Proven experience in information security roles, with a focus on designing and implementing security controls and technologies. Strong knowledge of cybersecurity principles, industry standards, and regulatory requirements (e.g., ISO 27001, NIST Cybersecurity Framework, GDPR). Experience with security tools and technologies, such as firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM (Security Information and Event Management) systems, and vulnerability assessment tools. Familiarity with network protocols, systems administration, and cloud computing platforms (e.g., ASS, Azure, Google Cloud). Proficient in conducting security audits, risk assessments, and penetration testing. Solid understanding of secure coding practices and web application security. Excellent analytical and problem-solving skills, with the ability to identify and mitigate security risks effectively. Strong communication and interpersonal skills to collaborate with cross-functional teams and effectively convey security concepts to technical and non-technical stakeholders. Ability to work independently, prioritize tasks, and manage multiple projects simultaneously.