Information Security GRC Lead
Connect to your career at Deloitte
Deloitte, established globally in 1845, is the world’s largest and leading professional services firm, providing audit & assurance, tax & legal, and consulting and related services to public and private clients spanning multiple industries. Presented in more than 150 countries, Deloitte is distinct in its ability to help clients solve their most complex problems, from strategy to implementation.
Deloitte Innovation Hub (DIH) is a strategic initiative to support our ambition to become the leading business transformation partner of choice for our clients and to expand and scale our delivery footprint across EMEA. With access to a scaled, diverse, highly skilled, motivated, and engaged workforce, DIH is delivering complex technical solutions for clients’ most complex business problems, across portfolios that include ‘Strategy & Transactions’, ‘Customer’, ‘Engineering, AI & Data’, ‘Enterprise, Technology & Performance’ and ‘Cyber’. DIH is aiming to become the destination for top talents in Egypt for a long, exciting career.
We invest in outstanding people of diverse talents and backgrounds and empower them to achieve more than they could elsewhere. Our work combines advice with action and integrity. We believe that when our clients and society are stronger, so are we. Our organization has grown in scale and diversity, providing services across the region, with our shared culture remaining the same. We aim to help clients realize their ambitions, make a positive difference in society, and maximize the success of our people. This drive fuels the commitment and humanity that run deep through our every action.
Connect to your opportunity
As an internal information security GRC lead, you will run the compliance and risk framework for DIH applications, software, and internal IT ecosystem. Hands-on experience evaluating AI/ML infrastructure or algorithmic risk is required.
Your primary responsibilities will include:
Internal governance enforcement: maintaining and updating the DIH internal Information Security Management System (ISMS) to ensure the adherence of the Deloitte standards and regulations.
Work directly with internal application development squads to validate that new internal tools and platforms are built securely, mapping controls to ISO 27001 baselines before deployment.
Drive internal continuous compliance monitoring, collecting log evidence, tracking patch deployments, and managing user access reviews.
Oversee the DIH internal risk register, identifying vulnerabilities within our IT ecosystem and work with the technical teams to remediate them.
Evaluate and approve third-party software, SaaS tools, and technical vendors before they are cleared for use by internal DIH employees.
Promote a strong security and data privacy culture helping teams to understand their role and responsibility in protecting Deloitte brand and business.
Use strong communication skills in promoting standards, reusage, simplification, and cost-effective technology solutions.
Connect to your skills and professional experience
Essentials
Bachelor’s degree in computer science, cyber security, management information systems, or a related technical discipline.
7+ relevant years of experience.
Experience in GRC, IT security operations, or internal IT auditing in an IT or technology enterprise line of business.
Practical, hands-on experience implementing ISO/IEC 27001 controls and managing evidence collection for internal and external audits.
A solid understanding of identity management (IAM/SSO), cloud platform basics (AWS/Azure), and secure software lifecycles (CI/CD pipelines).
Strong communication skills, with the ability to influence internal technical leads and developers without direct authority.
Develop and enforce security guardrails for internal generative AI usage, large language model (LLM) integrations, and automated decision systems.
Ensure all deployments align with internal risk tolerances and emerging regulations (e.g., EU AI Act, NIST AI RMF).
Conduct targeted risk assessments on internal AI applications to mitigate unique vulnerabilities, including data leakage, prompt injection risks, shadow AI usage, and unauthorized data ingestion into public models.
Preferred certification: CISA, CISM, CRISC, ISO 27001 Internal Auditor and AI-specific credentials like the Artificial Intelligence Governance Professional (AIGP).
English language fluency.
Desirables
Knowledge in scripting & query capabilities (Python / SQL).
Familiarity with scanning tools like Terraform or Ansible scripts.
Understanding of Postman or API security concepts.
Prior exposure to adversarial testing on large language models.
Connect to your business – technology & transformation
Distinctive thinking, deep expertise, and collaborative working. That’s what connects us. That’s what makes us Deloitte. If you want to help solve some of the biggest challenges around, join us. Together, we’ll make an impact that matters.
Personal independence
Regulation and controls are standard practice in our industry and Deloitte is no exception. These controls provide important legal protection for both you and the firm. We are subject to several audit regulations, one of which requires that certain colleagues abide by specific personal independence constraints. This can mean that you and your "immediate family members" are not permitted to hold certain financial interests (shares, funds, bonds etc.) with audit clients of the firm. The recruitment team will provide further details as you progress through the recruitment process.
Connect with your colleagues
“What attracted me to Deloitte were the endless opportunities and the collective experience of other like-minded individuals. Deloitte’s clients include many of the world’s largest organizations; I wanted to be part of a team that made a difference that I could be proud of.” – Dan, Technology & Transformation
“Everyone always says ‘it’s the people,’ and that’s true. Working for a brand you feel proud of feels pretty good too. And you don’t have any stress about fitting into a particular stereotype, because there are so many different types of people in Deloitte Digital.” – Gillian, Technology & Transformation
Our commitment to you
Making an impact is more than just what we do: it’s why we’re here. So, we work hard to create an environment where you can experience a purpose you believe in, the freedom to be you, and the capacity to go further than ever before.
We want you. The true you. Your own strengths, perspective, and personality. So, we’re nurturing a culture where everyone belongs, feels supported and heard, and is empowered to make a valuable, personal contribution.
You can be sure we’ll take your wellbeing seriously, too. Because it’s only when you’re comfortable and at your best that you can make the kind of impact you, and we, live for.
Your expertise is our capability, so we’ll make sure it never stops growing. Whether it’s from the complex work you do, or the people you collaborate with, you’ll learn every day. Through world-class development, you’ll gain invaluable technical and personal skills. Whatever your level, you’ll learn how to lead.
Connect to your next step
A career at Deloitte is an opportunity to develop in any direction you choose. Join us and you’ll experience a purpose you can believe in and an impact you can see. You’ll be free to bring your true self to work every day. And you’ll never stop growing, whatever your level.