Leadership & StrategyOwn and drive the IT and Security roadmap, aligning it with Trufla's business objectivesLead, mentor, and grow the IT & Security team across Cairo and Canada officesAct as the primary point of escalation for all IT and security-related mattersReport on IT and security program health, KPIs, and risk posture to senior leadershipManage vendor relationships, contracts, and procurement for IT and security toolingSOC 2 ComplianceLead the end-to-end implementation of SOC 2 (Type I and Type II) compliance across the organizationConduct gap assessments against SOC 2 Trust Service Criteria (Security, Availability, Confidentiality, Processing Integrity, and Privacy)Develop, document, and enforce the policies, procedures, and controls required to meet SOC 2 requirementsCoordinate with external auditors and manage the audit process through to successful certificationMaintain and continuously improve SOC 2 compliance posture post-certification, ensuring controls remain effective and audit-ready year over yearTrain and align internal stakeholders on their responsibilities within the SOC 2 control frameworkSecurityDemonstrate a thorough understanding of business processes, risk management, IT controls, and related standardsIdentify and evaluate business and technology risks; design and implement appropriate controls, technologies, and processes to mitigate themConduct and oversee capability assessments, developing pragmatic remediation strategies and good practice recommendationsLead the review of security-related events, assessing risk and validity, and producing clear executive reportingConduct research to maintain and expand knowledge of the latest security technologies, standards, and the evolving threat and vulnerability landscapeWork with security vendors to evaluate solution offerings and advise on appropriate technologiesConduct and oversee penetration testing activitiesDevelop and deliver security awareness training programs across the organizationIT Support & OperationsOversee the analysis, diagnosis, and resolution of complex workstation and infrastructure problems for end users in Cairo and remotely for other officesEnsure the installation, configuration, testing, maintenance, monitoring, and troubleshooting of end-user workstations, hardware, software, and telephony equipmentManage and improve incident ticketing processes, ensuring timely response and resolutionOversee move, add, and change (MAC) requests as submitted by line managersMaintain and uphold procedures for logging, reporting, and statistically monitoring workstation operationsLiaise with third-party support vendors and software/hardware providers as neededParticipate in an on-call rotation for after-hours and weekend critical supportJob QualificationsCollege diploma or university degree in Computer Science, Information Security, or a related field, or equivalent professional certification7+ years of experience in a Network, IT, or Security role3+ years of experience leading an IT or Security teamDemonstrated hands-on experience implementing or managing SOC 2 compliance (Type I and/or Type II)Strong knowledge of security frameworks and standards (SOC 2, ISO 27001, NIST, CIS Controls)Sound technical knowledge of PC hardware, networking, mobile devices, and related technologiesWorking knowledge of current operating systems, protocols, and infrastructure standardsExperience conducting penetration testingAble to read and understand technical manuals, procedural documentation, and OEM guidesExperience working in a team-oriented, collaborative environment across multiple time zones