Information Security Manager - EMEA
Grow with us
About this opportunity:
At Ericsson, security is a fundamental enabler of our business, customer trust, and operational resilience. We are looking for an experienced and motivated Information Security Manager to join the EMEA Enterprise Security organization, reporting to the Head of Information Security, BCM & IT Security, EMEA. This is an exciting opportunity for a security professional who is passionate about risk management, governance, and building strong partnerships across a diverse multinational environment. You will play a key role in strengthening Ericsson's security posture across Market Area Europe, Middle East, and Africa (EMEA) by leading the Third-Party Security Risk Management (TPSRM) domain while contributing to the region's Information Security Management System (ISMS), Information Security Risk Management (ISRM), Statement of Applicability (SoA), security awareness, and regulatory compliance activities.
Location: This position is open to qualified candidates located anywhere within the EMEA region.
What you will do:
- Lead the Third-Party Security Risk Management program across EMEA, ensuring effective assessment, monitoring, and management of supplier-related security risks.
- Develop and execute TPSRM operational plans, roadmaps, KPIs, and management reporting.
- Support and oversee supplier risk treatment activities in collaboration with internal and external stakeholders.
- Monitor emerging supply chain threats, cybersecurity trends, and industry best practices to continuously enhance the TPSRM framework.
- Support the implementation, maintenance, and continual improvement of the Information Security Management System (ISMS) in alignment with ISO/IEC 27001:2022.
- Lead Information Security Risk Assessments (ISRAs) and support risk treatment planning and follow-up for assigned organizational units.
- Support the development and maintenance of Statements of Applicability (SoA), including control applicability reviews, gap assessments, and remediation planning.
- Act as a trusted security advisor to business leaders, providing risk-based guidance and enabling informed decision-making.
- Contribute to security awareness, competence development, and initiatives that promote a strong security culture across EMEA.
- Support internal and external audits, regulatory compliance activities, and continuous improvement initiatives.
- Provide subject matter expertise for security investigations, incident management, and post-incident reviews.
- Support compliance with cybersecurity regulations across the EMEA region.
The skills you bring:
- Minimum 5 years of experience in Information Security, Cybersecurity Risk Management, Third-Party Security Risk Management, Governance Risk & Compliance (GRC), or related domains.
- Experience working within large multinational organizations and complex matrix environments.
- Demonstrated experience performing security risk assessments, supplier assessments, risk treatment planning, and compliance activities.
- Strong understanding of Information Security Management Systems (ISMS), Information Security Risk Management (ISRM), and supplier risk management practices.
- Solid understanding of ISO/IEC 27001:2022, NIST Cybersecurity Framework (CSF), NIST SP 800-53, and cybersecurity regulatory requirements including NIS2, GDPR, and other EMEA relevant cybersecurity regulations.
- Experience supporting and maintaining an ISO/IEC 27001-certified environment is highly desirable.
- Experience engaging with senior stakeholders and influencing risk-based decisions.
- Good understanding of AI and Generative AI tools, including security, privacy, governance, and compliance implications. Practical experience leveraging GenAI to streamline processes, improve efficiency, and support informed decision-making is highly desirable.
- Bachelor's degree in Information Technology, Cybersecurity, Engineering, Computer Science, or a related field.
- Preferred certifications include CISSP, CISM, CRISC, ISO/IEC 27001 Lead Implementer/Auditor, CTPRP, or equivalent cybersecurity, risk management, governance, or compliance certifications.
- Fluent in English, both written and spoken.
Why Join Us?
- Shape the security posture of one of the world's leading technology companies.
- Work with diverse stakeholders across Europe, the Middle East, and Africa.
- Influence strategic decisions in supplier security, risk management, and information security governance.
- Be part of a collaborative team dedicated to protecting Ericsson's people, information, and customers.
Why join Ericsson?At Ericsson, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build solutions never seen before to some of the world’s toughest problems. You´ll be challenged, but you won’t be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
What happens once you apply?Click Here to find all you need to know about what our typical hiring process looks like.Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we champion it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity Employer. learn more.
Primary country and city: Egypt (EG) || Cairo
Req ID: 788422