Назад
Company hidden
6 дней назад

GRC Specialist (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Portugal
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Specialist (Cybersecurity): Strengthening information security governance, risk management, and compliance practices for a global luxury fashion marketplace with an accent on security frameworks, policy management, risk assessments, and regulatory alignment. Focus on identifying control gaps, supporting audits, reducing unauthorized-access risks, and contributing to Data Privacy, AI Governance, and Data Governance initiatives.

Location: Hybrid work in Porto, Portugal

Company

hirify.global operates a global luxury fashion marketplace connecting customers with brands, boutiques, and department stores across more than 190 countries and territories.

What you will do

  • Support the development, implementation, and continuous improvement of the Information Security governance framework.
  • Review, maintain, and audit security policies, procedures, controls, and related documentation.
  • Perform Information Security risk assessments, security reviews, gap analyses, and mitigation planning.
  • Monitor compliance with legal, regulatory, and industry requirements and support audits and assessments.
  • Coordinate company-wide Information Security controls and collaborate with stakeholders to manage risks and compliance requirements.
  • Contribute to security awareness initiatives and projects involving Data Privacy, AI Governance, and Data Governance.

Requirements

  • Degree in Computer Science, Information Security, or a related field.
  • More than four years of experience in Information Security, GRC, Risk, or Compliance.
  • Background in software development or systems administration.
  • Knowledge of network protocols, network design and operations, Information Security principles, and technologies.
  • Experience with governance frameworks and standards including COBIT and ISO 27001, plus risk assessment methodologies such as OCTAVE and NIST SP 800-30.
  • Strong written and verbal English communication skills; ability to work proactively with minimal supervision.

Nice to have

  • Information Security certifications such as CRISC, CISA, CEH, or similar.
  • Experience with Data Privacy Impact Assessments.
  • Experience with AI and Data Governance projects.

Culture & Benefits

  • Health insurance for the whole family.
  • Flexible working environment with well-being support and tools.
  • Extra days off, a sabbatical program, and community giving days.
  • Training opportunities and free access to Udemy.
  • Flexible benefits program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →