profile-img

Gerges Anwar Rizk

Corporate Information Security & IT GRC Engineer at Efg Hermes

Zaytoun, Cairo, Egypt

Work Experience

  • Corporate Information Security & IT GRC EngineerFull Time

    Efg Hermes

    Apr 2024 - Present -1 yr, 3 months

    Egypt

    • Job Details:- design & document our governance documents (policies, processes, procedures, etc) based on the international standards and local regulations such as NIST, PCI-DSS, ISO27K, etc. - Assure that the approved cyber security policies, processes and base lines are well communicated and understood to all concerned teams. - assess and design mitigation plans for our information technology and security risks. - ensure compliance with information technology and security industry standards such as ISO27001, ISO22001, ISO22301, PCI-DSS, SWIFT, FRA Cyber Security Framework, etc. - Securing the sensitive data and critical assets according to the international security standards and best practices. - assess Information Security Awareness for both employees and customers - Conducting regular system audits to ensure that security controls are applied and effective - assess IT Business Continuity and Disaster Recover planning, testing and improvement.
  • Corporate Information Security EngineerFull Time

    Telecom Egypt (sprint Egypt)

    Jun 2023 - Apr 2024 -10 months

    Egypt , Cairo

    • Job Details:- Develop, Review and update cybersecurity policies based on the international standards and local regulations such as NIST, PCI-DSS, ISO27K, etc. - Define and update systems security baselines following the standards. - Assure that the approved cyber security policies, processes and base lines are well communicated and understood to all concerned teams. - Providing security consultation, assessing changes in security systems including IT and Telecom domains ensuring compliance with security controls. - Identify, assess security risks and update risk registry. - Securing the sensitive data and critical assets according to the international security standards and best practices. - Conducting regular system audits to ensure that security controls are applied and effective
  • Information Security EngineerFull Time

    Optima PS

    Nov 2022 - Jun 2023 -7 months

    Egypt , Cairo

    • Job Details:Active participant in 24x7 operations of the SOC. This includes proactively monitoring and providing near-real-time cyber security status and reports to enable timely decision-making for 24/7 operations. Monitoring SIEM resources for any component failure. Perform initial triage/investigation of alerts to identify false positives, policy violations, intrusion attempts and compromises. Escalating triaged alerts to Tier II Analysts for deeper analysis and review. Contribute in Incident report writing.
  • Penetration Testing TraineeInternship

    Information Technology Institute - ITI

    Jan 2021 - May 2021 -4 months

    • Education

      • Bachelor's Degree in Computer science and information technology

        Ahram Canadian University (ACU)

        Jan 2016 - Jan 2020 - 4 yr

      • High School - Thanaweya Amma

        El Salam EXP Language School

        Jan 2016 

      Activities

      • Social Media Specialist at Praise Family Team

        Volunteering

        Aug 2015 - Present -9 yrs, 11 months

      Achievements

      Graduation Project: Monitoring System (Grade A)

      Skills

      • ICDL
      • HTML
      • Python
      • Penetration Testing
      • WordPress
      • MCSA
      • CCNA
      • Cyber Security
      • Security
      • SIEM
      View More

      Languages

      • Arabic

        Fluent
      • English

        Advanced

      Training & Certifications

      • ISO/IEC 27001 Lead Implementer

        PECB·2024
      • ISO/IEC 27001 Lead Implementer

        PECB·2024
      • Integrated Audit & Assurance Professional

        OCEG·2024
      • Integrated Audit & Assurance Professional

        GRC Certify·2024
      • GRC Auditor

        OCEG·2024
      • GRC Auditor

        2024
      • Integrated Policy Management Professional (IPMP)

        OCEG·2024
      • Integrated Policy Management Professional (IPMP)

        GRC Certify·2024
      • GRC Professional

        OCEG·2023
      • GRC Professional

        GRC Certify·2023
      • Fundamentals of Network Security

        Palo Alto Networks·2023
      • Introduction to Cybersecurity

        Palo Alto Networks·2023
      • The Fundamentals of SOC (Security Operations Center)

        Palo Alto Networks·2023
      • Partner Accreditation: SALES REP

        Sandvine·2022
      • Cisco Certified Network Associate (CCNA)

        2021
      • EC-Council Certified Security Analyst

        EC-Council·2021
      • Certified Ethical Hacker (CEH) V11.0

        2021
      • Certified Network Defender (CND) V2.0

        2021
      • EC-Council Ethical hacking (CEH) V11.0

        ITI - Information Technology Institute·2021
      • EC-Council Security Analyst (ECSA)

        ITI - Information Technology Institute·2021
      • EC-Council Certified Network Defender V2.0

        ITI - Information Technology Institute·2021
      • Red Hat I

        ITI - Information Technology Institute·2021
      • Cisco Certified Network Associate (CCNA)

        ITI - Information Technology Institute·2021
      • MS Windows Administration

        ITI - Information Technology Institute·2021
      Share this Profile