# Senior Information Security Officer

**Company:** [ZainCash](null/companies/eQiV9Wf1838m3qnTLaYN3Y.md)
**Location:** Baghdad, Iraq
**Workplace:** on site
**Employment type:** Full-time
**Department:** IT

[Apply for this job](null/view/f6800d7c-8922-49f5-9e3b-bc0c6dff87cb)

## Description

**About Zaincash**

ZainCash Iraq is a leading mobile wallet in Iraq and recognized as Forbes top Fintech company of 2023 and 2024 as well as GSMA’s Best Mobile Innovation Supporting Humanitarian Situations. The company offers a range of consumer and business services including local and international money transfer, bill payments, companion payment cards, payroll, aid disbursement, and more. For more information, please visit www.zaincash.iq.

Responsibilities

-   **Security Monitoring:** Monitor systems, networks, and applications for security incidents. Actively monitor SIEM logs, EDR alerts, and investigate suspicious activities or potential threats.
-   **Incident Response:** Support incident response and recovery activities, from containment to full eradication. Prepare detailed incident reports and recommend corrective actions.
-   **Vulnerability & Risk Management:** Conduct risk assessments, track vulnerabilities, and oversee Vulnerability Assessment & Penetration Testing (VAPT) activities to ensure timely remediation.
-   **Governance & Compliance:** Maintain and update information security policies and procedures. Support the implementation of security KPIs and ongoing compliance monitoring.
-   **Access Control:** Assist in regular user access reviews and strictly enforce the principle of least privilege across all systems.
-   **Security Awareness:** Develop and execute security awareness initiatives to educate staff on emerging risks and best practices.

## Requirements

-   Education: Bachelor's degree in Computer Science, Cybersecurity, or IT
-   Qualifications: CISSP, CISM, CEH, or GCIH preferred.
-   Industry Experience: Enterprise IT Security, SOC, or GRC. Banking/fintech, telecom, or government a plus.
-   Years of Experience: 2-5 years in information security operations.
-   Technical Skills & Tools: SIEM (Splunk, QRadar, or Sentinel), EDR (CrowdStrike or SentinelOne), vulnerability scanning (Nessus or Qualys), ISO 27001 and NIST.
-   Language Proficiency: Fluent Arabic and English, written and spoken.
