обновлено 8 дней назад
Senior Information Security Engineer (GRC)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Information Security Engineer (GRC): Designing and automating risk management programs for a cloud contact center platform with an accent on risk identification, assessment, and control scaling. Focus on maintaining the security risk register, driving remediation plans with engineering teams, and delivering executive risk reporting.
Location: Porto, Portugal — hybrid, with 3 days per week required in the Porto office
Company
Cloud contact center software provider delivering cloud-based customer experience solutions worldwide.
What you will do
- Identify, document, assess, and track security risks across production infrastructure, cloud services, corporate systems, and acquired platforms.
- Maintain the security risk register in Jira, including categorization, ownership, and lifecycle tracking.
- Work with service owners, engineering leads, operations, compliance, and vulnerability management teams to define and execute remediation or mitigation plans.
- Facilitate risk acceptance activities and coordinate stakeholder approvals.
- Develop dashboards, metrics, and executive reporting that communicate the security risk posture.
- Improve risk management policies, procedures, playbooks, frameworks, and methodologies.
Requirements
- 3+ years of information security experience, including at least 2 years in security risk management or GRC.
- Experience maintaining security risk registers and driving risk treatment decisions with cross-functional stakeholders.
- Strong understanding of qualitative and quantitative risk assessment methodologies.
- Familiarity with NIST CSF, NIST 800-53, ISO 27001, PCI, or SOC 2 frameworks.
- Ability to communicate security risks to technical and non-technical audiences.
- Experience with Jira or similar tools and direct collaboration with service owners, engineers, and leadership.
Nice to have
- Experience assessing risks in GCP, AWS, or Azure environments.
- Background in vulnerability management, compliance audits, or regulatory assessments.
- Experience building security metrics, KPI dashboards, or executive reports.
- Experience in SaaS or contact center and communications platform environments.
- Experience with agentic coding tools such as Cursor, Claude Code, or Copilot; working knowledge of Python.
- Professional certification such as CISSP, CISM, CISA, or CRISC.
Culture & Benefits
- Team-first, inclusive, and diversity-focused work environment.
- Shares and bonus scheme.
- 10% flex benefit and meal allowance.
- Medical and life insurance.
- 25 days of annual leave plus public holidays.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Senior Security Engineer (Cloud Security)
110 000 - 130 000€
14 дней назад
GRC Engineer (Cybersecurity)
52 000 - 72 000€
11 дней назад
Customer Technical Advisor (Cybersecurity)
11 дней назад
Cloud Security Engineer (AWS)
120 000 - 135 000$
10 дней назад
Global Risk Manager (Cybersecurity, Data & AI)
10 дней назад