Chief Information Security Officer
Giza,
Egypt
Location
Giza, El Omraniya
Job Description
About Swypex
Swypex is a fast-scaling fintech platform handling thousands of transactions per minute. Security, compliance, and trust are at the core of our business. We’re looking for a Chief Information Security Officer (CISO) to own and lead our security strategy, protect our infrastructure, and guide us through PCI-DSS and SOC 2 compliance with excellence.
Responsibilities
SIEM/SOC Ownership
• Monitor and analyze SIEM logs daily to detect threats, anomalies, and suspicious activities.
• Develop, refine, and implement new SIEM rules and alerting mechanisms.
• Provide actionable recommendations on security alerts and drive remediation to closure.
• Ensure SIEM deployment remains up to date, tuned, and aligned with best practices.
Compliance Leadership
• Lead annual PCI-DSS and SOC 2 compliance audits end-to-end.
• Prepare policies, procedures, evidence, and narratives for external auditors.
• Implement ongoing controls and processes to ensure continuous compliance readiness.
• Partner with third-party auditors and penetration testers; track findings to resolution.
Secure Engineering Practices
• Establish and evangelize secure coding standards (SAST/DAST, dependency scanning, secrets management).
• Proactively identify risks in application and data architecture; design mitigation strategies.
• Participate in architecture reviews to ensure security-by-design for new features/products.
Education & Collaboration
• Train and guide cross-functional teams on security risks, secure SDLC, and incident response.
• Serve as the primary security point of contact for external stakeholders (e.g., enterprise clients, security questionnaires).
Requirements
• Proven experience as a CISO, Security Director, or Senior Security Engineer in a regulated or fintech environment.
• Strong expertise with SIEM management (Wazuh, Splunk, ELK, or equivalent).
• Hands-on experience with PCI-DSS and SOC 2 audits and evidence collection.
• Knowledge of modern security best practices in Kubernetes, Postgres, and cloud-native environments.
• Strong communication skills to influence engineering, operations, and executive teams.
• Ability to collaborate effectively with auditors, pen testers, and enterprise customers.