Chief Information Security Officer
Location
Giza, El Omraniya
Job Description
About Swypex
Swypex is a fast-scaling fintech platform handling thousands of transactions per minute. Security, compliance, and trust are at the core of our business. Weβre looking for a Chief Information Security Officer (CISO) to own and lead our security strategy, protect our infrastructure, and guide us through PCI-DSS and SOC 2 compliance with excellence.
Responsibilities
SIEM/SOC Ownership
β’ Monitor and analyze SIEM logs daily to detect threats, anomalies, and suspicious activities.
β’ Develop, refine, and implement new SIEM rules and alerting mechanisms.
β’ Provide actionable recommendations on security alerts and drive remediation to closure.
β’ Ensure SIEM deployment remains up to date, tuned, and aligned with best practices.
Compliance Leadership
β’ Lead annual PCI-DSS and SOC 2 compliance audits end-to-end.
β’ Prepare policies, procedures, evidence, and narratives for external auditors.
β’ Implement ongoing controls and processes to ensure continuous compliance readiness.
β’ Partner with third-party auditors and penetration testers; track findings to resolution.
Secure Engineering Practices
β’ Establish and evangelize secure coding standards (SAST/DAST, dependency scanning, secrets management).
β’ Proactively identify risks in application and data architecture; design mitigation strategies.
β’ Participate in architecture reviews to ensure security-by-design for new features/products.
Education & Collaboration
β’ Train and guide cross-functional teams on security risks, secure SDLC, and incident response.
β’ Serve as the primary security point of contact for external stakeholders (e.g., enterprise clients, security questionnaires).
Requirements
ο»Ώ
β’ Proven experience as a CISO, Security Director, or Senior Security Engineer in a regulated or fintech environment.
β’ Strong expertise with SIEM management (Wazuh, Splunk, ELK, or equivalent).
β’ Hands-on experience with PCI-DSS and SOC 2 audits and evidence collection.
β’ Knowledge of modern security best practices in Kubernetes, Postgres, and cloud-native environments.
β’ Strong communication skills to influence engineering, operations, and executive teams.
β’ Ability to collaborate effectively with auditors, pen testers, and enterprise customers.