6 дней назад
GRC Specialist (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Specialist (Cybersecurity): Strengthening information security governance, risk management, and compliance practices for a global luxury fashion marketplace with an accent on security frameworks, policy management, risk assessments, and regulatory alignment. Focus on identifying control gaps, supporting audits, reducing unauthorized-access risks, and contributing to Data Privacy, AI Governance, and Data Governance initiatives.
Location: Hybrid work in Porto, Portugal
Company
operates a global luxury fashion marketplace connecting customers with brands, boutiques, and department stores across more than 190 countries and territories.
What you will do
- Support the development, implementation, and continuous improvement of the Information Security governance framework.
- Review, maintain, and audit security policies, procedures, controls, and related documentation.
- Perform Information Security risk assessments, security reviews, gap analyses, and mitigation planning.
- Monitor compliance with legal, regulatory, and industry requirements and support audits and assessments.
- Coordinate company-wide Information Security controls and collaborate with stakeholders to manage risks and compliance requirements.
- Contribute to security awareness initiatives and projects involving Data Privacy, AI Governance, and Data Governance.
Requirements
- Degree in Computer Science, Information Security, or a related field.
- More than four years of experience in Information Security, GRC, Risk, or Compliance.
- Background in software development or systems administration.
- Knowledge of network protocols, network design and operations, Information Security principles, and technologies.
- Experience with governance frameworks and standards including COBIT and ISO 27001, plus risk assessment methodologies such as OCTAVE and NIST SP 800-30.
- Strong written and verbal English communication skills; ability to work proactively with minimal supervision.
Nice to have
- Information Security certifications such as CRISC, CISA, CEH, or similar.
- Experience with Data Privacy Impact Assessments.
- Experience with AI and Data Governance projects.
Culture & Benefits
- Health insurance for the whole family.
- Flexible working environment with well-being support and tools.
- Extra days off, a sabbatical program, and community giving days.
- Training opportunities and free access to Udemy.
- Flexible benefits program.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
9 дней назад
Senior Information Security Engineer (GRC)
10 дней назад
Global Risk Manager (Cybersecurity, Data & AI)
9 дней назад
Staff Information Security Engineer
10 дней назад
Global Cybersecurity Director – Data Loss Prevention
12 дней назад
Customer Technical Advisor (Cybersecurity)
8 дней назад