
Gerges Anwar Rizk
Corporate Information Security & IT GRC Engineer at Efg Hermes
Zaytoun, Cairo, EgyptWork Experience
Corporate Information Security & IT GRC EngineerFull Time
- Job Details:- design & document our governance documents (policies, processes, procedures, etc) based on the international standards and local regulations such as NIST, PCI-DSS, ISO27K, etc. - Assure that the approved cyber security policies, processes and base lines are well communicated and understood to all concerned teams. - assess and design mitigation plans for our information technology and security risks. - ensure compliance with information technology and security industry standards such as ISO27001, ISO22001, ISO22301, PCI-DSS, SWIFT, FRA Cyber Security Framework, etc. - Securing the sensitive data and critical assets according to the international security standards and best practices. - assess Information Security Awareness for both employees and customers - Conducting regular system audits to ensure that security controls are applied and effective - assess IT Business Continuity and Disaster Recover planning, testing and improvement.
Corporate Information Security EngineerFull Time
- Job Details:- Develop, Review and update cybersecurity policies based on the international standards and local regulations such as NIST, PCI-DSS, ISO27K, etc. - Define and update systems security baselines following the standards. - Assure that the approved cyber security policies, processes and base lines are well communicated and understood to all concerned teams. - Providing security consultation, assessing changes in security systems including IT and Telecom domains ensuring compliance with security controls. - Identify, assess security risks and update risk registry. - Securing the sensitive data and critical assets according to the international security standards and best practices. - Conducting regular system audits to ensure that security controls are applied and effective
Information Security EngineerFull Time
Optima PS
Nov 2022 - Jun 2023 -7 months
Egypt , Cairo
- Job Details:Active participant in 24x7 operations of the SOC. This includes proactively monitoring and providing near-real-time cyber security status and reports to enable timely decision-making for 24/7 operations. Monitoring SIEM resources for any component failure. Perform initial triage/investigation of alerts to identify false positives, policy violations, intrusion attempts and compromises. Escalating triaged alerts to Tier II Analysts for deeper analysis and review. Contribute in Incident report writing.
Penetration Testing TraineeInternship
Information Technology Institute - ITI
Jan 2021 - May 2021 -4 months
Education
Bachelor's Degree in Computer science and information technology
Ahram Canadian University (ACU)Jan 2016 - Jan 2020 - 4 yr
High School - Thanaweya Amma
El Salam EXP Language SchoolJan 2016
Activities
Social Media Specialist at Praise Family Team
Volunteering
Aug 2015 - Present -9 yrs, 11 months
Achievements
Graduation Project: Monitoring System (Grade A)
Languages
Arabic
FluentEnglish
Advanced
Training & Certifications
ISO/IEC 27001 Lead Implementer
PECB·2024ISO/IEC 27001 Lead Implementer
PECB·2024Integrated Audit & Assurance Professional
OCEG·2024Integrated Audit & Assurance Professional
GRC Certify·2024GRC Auditor
OCEG·2024GRC Auditor
2024Integrated Policy Management Professional (IPMP)
OCEG·2024Integrated Policy Management Professional (IPMP)
GRC Certify·2024GRC Professional
OCEG·2023GRC Professional
GRC Certify·2023Fundamentals of Network Security
Palo Alto Networks·2023Introduction to Cybersecurity
Palo Alto Networks·2023The Fundamentals of SOC (Security Operations Center)
Palo Alto Networks·2023Partner Accreditation: SALES REP
Sandvine·2022Cisco Certified Network Associate (CCNA)
2021EC-Council Certified Security Analyst
EC-Council·2021Certified Ethical Hacker (CEH) V11.0
2021Certified Network Defender (CND) V2.0
2021EC-Council Ethical hacking (CEH) V11.0
ITI - Information Technology Institute·2021EC-Council Security Analyst (ECSA)
ITI - Information Technology Institute·2021EC-Council Certified Network Defender V2.0
ITI - Information Technology Institute·2021Red Hat I
ITI - Information Technology Institute·2021Cisco Certified Network Associate (CCNA)
ITI - Information Technology Institute·2021MS Windows Administration
ITI - Information Technology Institute·2021