Amideast Site | Job Openings

Amideast is a leading American non-profit organization engaged in international education, training and development activities in the Middle East and North Africa. Founded in 1951, Amideast in its early years focused on promoting U.S. study to students in the MENA region and managing U.S. scholarships and exchanges such as the flagship Fulbright Foreign Student Program.

Cybersecurity and Data Protection Officer

Apply For This Job
Location:
Middle East North Africa Region
Address:
,
Job Type:
Full-Time
Posting Date:
09/17/2026

COMPANY DESCRIPTION:
An American non-profit organization established in 1951 and headquartered in Washington, D.C., with country offices and programs in the Middle East and North Africa region and beyond. Amideast provides transformational education, training, testing, and exchanges that enable individuals, companies, and international partners to better address 21st-century challenges at home and abroad. For more information, visit us at www.amideast.org. 


POSITION DESCRIPTION:
The Cybersecurity and Data Protection Officer is responsible for protecting the organization’s information systems, networks, data, and digital assets from cyber threats, unauthorized access, and security breaches. This role involves developing and implementing security policies, monitoring systems for vulnerabilities and suspicious activities, conducting security gap analysis, risk assessments, and ensuring compliance with regulatory and industry security standards.


In addition, the role is responsible for ensuring compliance with applicable laws, regulations, and industry standards related to cybersecurity and data privacy through advising on emerging risks, supporting audits and regulatory reviews, managing third-party security and privacy risks, and promoting a culture of security awareness and responsible data handling throughout the organization.

RESPONSIBILITIES:
Develop, implement, maintain, and oversee enforcement of policies, procedures, and associated plans for system security administration and user system access based on industry-standard best practices
Implement, maintain, and monitor security compliance such as ISO (International Organization for Standardization), NIST (National Institute of Standards and Technology), and SOC (System and Organization Controls) standards
Design and advise on the implementation of disaster recovery plan for operating systems, databases, networks, servers, and software applications
Design and implement incident response plans based on filed office laws and regulations
Design, implement, and monitor data protection policies and procedures
Assess need for any security reconfigurations and execute them if required
Conduct email phish-hunting and submit malicious senders for blocking through anti-phishing policy
Execute Amideast’s security awareness program and report on user compliance
Keep current with emerging security alerts and issues
Conduct research on emerging products, services, protocols, and standards in support of security enhancement and development efforts
Recommend, schedule, and perform security improvements, upgrades, and/or purchases
Participate in deploying, managing, and maintaining all security systems and their corresponding or associated software, including firewalls, intrusion detection systems, cryptography systems, and anti-virus software
Ensure databases are securely configured, monitored, and maintained through access controls, encryption, vulnerability management, and regular security assessments to safeguard the confidentiality, integrity, and availability of information
Design, perform, and/or oversee penetration testing of all systems to identify system vulnerabilities
Design, implement, and report on security systems and end user activity audits
Monitor server logs, firewall logs, intrusion detection logs, and network traffic for unusual or suspicious activity. Interpret activity and make recommendations for resolution
Recommend, schedule (where appropriate), and guide fixes, security patches, disaster recovery procedures, and any other measures required in the event of a security breach
Evaluate new security software and/or technologies
Develop, implement, and oversee data protection policies, standards, and controls to ensure the secure collection, processing, storage, sharing, and disposal of sensitive and personal information, while maintaining compliance with applicable privacy regulations and organizational governance requirements. 
Provide on-call security support to end-users when needed


QUALIFICATIONS AND SKILLS:

Required
College diploma or university degree in the field of computer science, preferably with a focus on Cybersecurity
Minimum 5 years’ relevant work experience in the field of cybersecurity
One or more of the following certifications:
o Certified Ethical Hacker (CEH)
o GIAC Security Essentials Certification
o GIAC Certified Enterprise Defender
o ISACA Certified Information Security Manager
o Microsoft Certified Systems Engineer: Security
o (ISC)2 SCCP
o (ISC)2 CISSP
o (ISC)2 ISSAP
Knowledge of regulatory requirements and industry standards, such as GDPR, HIPAA, NIST, and ISO 27001
Hands-on experience implementing at least one security standard compliance for an organization and leading the certification process
Knowledge of applicable practices and laws relating to data privacy and protection and working experience implementing at least one privacy standard
Knowledge of law enforcement practices and procedures in the US and the MENA region
Intuition and keen instincts to preempt attacks
Strong practical experience conducting penetration testing and vulnerability assessments
High level of analytical and problem-solving abilities
Ability to conduct research into security issues and products as required
Broad hands-on knowledge of firewalls, intrusion detection systems, endpoint protection, data encryption, and other industry-standard techniques and practices
Working technical knowledge of network, PC, and Microsoft and Linux operating systems
Working technical knowledge Microsoft Cloud Security Portal for Office365
Working technical knowledge of current systems software, protocols, and standards
Strong interpersonal and oral communication skills
Advanced written and verbal proficiency in English and Arabic
Highly self-motivated and directed
Strong organizational skills
Excellent attention to detail
Ability to effectively prioritize and execute tasks in a high-pressure environment
Able to work in a team-oriented, collaborative environment


Preferred
Advanced written and verbal proficiency in French

WORK ENVIRONMENT:
If the successful candidate is hired in Morocco (Casablanca or Rabat), Tunisia (Tunis), Jordan (Amman), or West Bank (Ramallah), the position will operate under a hybrid work arrangement working 4 days per week remotely and 1 day per week from an Amideast office. If the successful candidate is hired in Egypt (Cairo or Alexandria), the position will operate full time (5 days per week) from the local Amideast office. 
The final schedule will be determined based on operational needs, collaboration requirements, and organizational guidelines. The incumbent will utilize the following equipment: 
Computer (laptop or desktop)
Printer/Photocopier/Scanner/Fax
Telephone

This position requires a non-standard work schedule to overlap with U.S. Eastern Time. Typical hours involve a later start and extended evening availability to meet business needs.

Up to 5% business travel may be needed to support business initiatives as needed.

The physical demands and work environment that have been described are representative of those an employee encounters while performing the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. This position description is an overview of the major functions and requirements of this position. This document is not intended to be an exhaustive list encompassing every duty and requirement of the position; the Employee’s supervisor may assign other duties as related or as otherwise deemed appropriate and necessary within the general scope, without the need for additional compensation. 

 

Amideast is an equal opportunity employer and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

Positions that involve interaction with children will be required to read, acknowledge, and comply with and attend special training in accordance with the Child Protection and Safeguarding policy. All Amideast representatives must comply with the Code of Conduct and all applicable organizational policies.