Senior Cybersecurity GRC Consultant
476 - 508 EUR/ dzień.B2B
441 - 473 EUR/ dzień.UoP
SeniorFull-time·B2B·Umowa o pracę
#394839·Dodano 2 dni temu·2
Źródło: justjoin.itTech Stack / Keywords
GRCComplianceRisk ManagementCISAISO 27001
Firma i stanowisko
Ayesa Digital is a global company of over 11,000 professionals engaged in high-impact European Union projects focused on addressing major European challenges through science and innovation. These strategic projects emphasize international collaboration and socially oriented results.
Wymagania
- Master's degree (Level 7) or equivalent qualification in Cybersecurity, Information Security, Information Technology, Law, Risk Management, or a related discipline.
- Minimum 9 years of relevant professional experience within cybersecurity, information security, governance, risk, compliance, or privacy domains.
- Minimum 8 years of experience in a similar Cybersecurity GRC, Risk Management, Compliance, or Information Security Governance role.
- English proficiency at C1 level or higher.
- Must hold at least four of the following internationally recognized certifications (or accepted equivalents): CISA, CISM, CRISC, CISSP, CGRC, CSSLP, CCSP, CISSP-ISSMP, GSNA, GCCC, GIAC Certified ISO-27000 Specialist, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, ISO 27005 Risk Manager.
- Strong knowledge of cybersecurity laws, regulations, and legislative requirements.
- Deep understanding of cybersecurity standards, frameworks, methodologies, and best practices.
- Knowledge of cybersecurity governance, risk management, and compliance principles.
- Understanding of privacy impact assessment frameworks, methodologies, and regulatory obligations.
- Proven experience in cybersecurity GRC environments, with a strong focus on cybersecurity risk management.
- Demonstrated experience designing, implementing, or operationalising cyber risk management frameworks.
- Hands-on experience with ServiceNow GRC (IRM, Risk, Policy & Compliance modules).
- Experience maintaining and managing cybersecurity risk registers.
- Strong understanding of integrating risk management processes with vulnerability management, incident management, cloud risk, and third-party risk programmes.
- Experience contributing to cybersecurity maturity assessments and improvement initiatives.
Obowiązki
- Lead and support cybersecurity governance, risk, compliance, privacy, and data protection initiatives across the organization.
- Ensure compliance with cybersecurity, data protection, privacy, and regulatory requirements, providing expert guidance on applicable laws, regulations, and industry standards.
- Identify, assess, document, and monitor cybersecurity and compliance risks, maintaining an accurate and up-to-date cybersecurity risk register.
- Design, implement, maintain, and continuously improve cybersecurity risk management frameworks, processes, and controls.
- Conduct and oversee privacy impact assessments, compliance reviews, and risk assessments using recognized methodologies, standards, and frameworks.
- Develop, maintain, communicate, and promote cybersecurity, privacy, and data protection policies, procedures, and governance frameworks.
- Collaborate with business stakeholders, technology teams, and third parties to ensure cybersecurity and privacy requirements are effectively integrated into organizational processes.
- Manage and utilize ServiceNow GRC (IRM, Risk, Policy & Compliance modules) to support governance, risk, and compliance activities.
- Integrate cybersecurity risk management practices with vulnerability management, incident management, cloud risk management, and third-party risk management programmes.
- Support audits, compliance assessments, control testing activities, and remediation initiatives.
- Deliver awareness, training, and communication activities to promote a strong cybersecurity and data protection culture.
- Act as a key point of contact for cybersecurity governance, compliance, risk, and privacy-related matters.
- Contribute to cybersecurity maturity improvement programmes and the ongoing development of the organization's cybersecurity strategy.
Benefity
- Prestigious projects within European institutions.
- International, innovative, and multicultural environments.
- Continuous support from a team of experts in EU projects.
- Rate: 476,55€ - 508€ per day.
Inne informacje
In accordance with Organic Law 3/2007 of March 22, the company promotes equal opportunities and non-discrimination on grounds of sex, race, gender, functional diversity, religion, sexual orientation, gender identity, or any other personal or social condition, aiming for an inclusive environment.
Ayesa Digital
4 aktywne oferty