GRC Security Expert (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
GRC Security Expert (Cybersecurity): Establishing and implementing organizational information security processes to ensure regulatory and contractual compliance with an accent on ISMS audit management and risk assessment. Focus on managing ISO/IEC 27001 and PCI DSS compliance, coordinating external audits, and developing security awareness programs.
Location: Must be based in Sofia, Bulgaria
Company
Leading technology company in the gaming industry providing B2B software and platform services.
What you will do
- Define and implement info-sec processes to meet regulatory, legislative, and contractual obligations.
- Manage internal and external ISMS audits and monitor the effectiveness of controls and corrective actions.
- Conduct gap analysis, compliance readiness, and monitoring for ISO/IEC 27001, PCI DSS, and other security audits.
- Identify and monitor information security risks and recommend mitigation measures.
- Develop and facilitate a comprehensive organizational information security awareness training program.
- Manage third-party security requirements, including due diligence and contract clauses.
Requirements
- 3+ years of proven experience in the security governance, risk, and compliance domain.
- Experience leading PCI DSS, ISO 27001:2022, and SOC/ISAE402 certification and surveillance audits.
- Bachelor’s Degree in Information Security, Cybersecurity, Risk Management, or equivalent work experience.
- Professional certification such as CISSP, CISM, or ISO 27001 Lead Implementer/Auditor.
- English: Very good written and spoken proficiency required.
- Location: Must be based in Sofia, Bulgaria.
Nice to have
- Prior experience working within a SaaS or Online Gambling organization.
- Technical experience in IT infrastructure, networks, databases, or software development.
Culture & Benefits
- Global scope and inclusive working environment.
- Constant learning and development opportunities.
- Support for an active lifestyle and mental well-being.
- Fun and engaging company events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →