TL;DR
Information Security Risk Specialist: Applying knowledge of information security in an international IT company, interacting with a global team and partners, and participating in GRC and compliance projects with our Security team. Focus on risk management, communication with clients, and ensuring device compliance with security requirements.
Location: Remote
Компания
hirify.global is an international Support-as-a-Service company providing business process outsourcing services for other IT companies worldwide, specializing in technical and user support and user experience enhancement services.
Что делать
- Manage supplier risks by conducting security audits, gathering information from open sources (OSINT), and maintaining risk assessment registers.
- Communicate with clients by filling out and processing security questionnaires according to international standards (ISO 27001, SOC 2, NIST).
- Ensure device compliance with security requirements through monitoring, analysis, and communication with users.
- Create and update internal instructions, procedures, and knowledge base materials on information security.
- Participate in phishing simulations and assist in preparing security awareness materials for employees.
- Handle initial processing of security incidents, including evidence collection, basic investigation, and coordination of communication between parties.
Требования
- Understanding of information security principles (Confidentiality, Integrity, Availability).
- Understanding of requirements of information security standards and legislation in the field of security and personal data protection.
- Analytical thinking and ability to work with documentation, data, and security incidents.
- Developed soft skills: communication skills, attention to detail, self-organization, and ability to work with deadlines.
- English level B1–B2.
Культура и преимущества
- Providing services during business hours.
- Unique art spaces in Kyiv or the option to work remotely.
- Communication based on trust and no activity trackers.
- Harmony between project workload and personal time, as well as an internal medical policy.
- Creative community and people-oriented culture with mutual feedback.
- Attractive rewards for referring friends.
- Competitive compensation in USD.
- Paid onboarding and access to the corporate library.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →