
GRC Expert – Governance, Risk and Compliance
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in Greece.
• Provide guidance to clients on meeting compliance requirements for NIS2, DORA, ISO 27001, GDPR, and other industry-specific frameworks.
• Perform audits and maturity assessments, identify gaps, and create remediation strategies.
• Draft and update policies, procedures, charters, and other essential documentation.
• Prepare for and assist with certification processes and external audits.
• Execute risk analyses utilizing EBIOS Risk Manager and ISO 27005 methodologies.
• Create and manage risk maps, treatment plans, and monitoring indicators.
• Enhance security governance through the establishment of committees, dashboards, and reporting mechanisms for senior management.
• Convert regulatory mandates into architectural requirements in collaboration with cloud and infrastructure architects.
• Aid in designing landing zones and reference architectures that integrate compliance considerations.
• Engage in business continuity planning and crisis management drills.
• Prepare technical responses to requests for proposals and present and advocate for proposals.
• Evaluate and understand client requirements related to compliance and governance.
• Innovate and advance GRC offerings while developing accelerators.
• Assist in structuring the Cybersecurity practice, defining its positioning, and facilitating the cyber community.
• Oversee regulatory monitoring for the practice.
• Master's degree, engineering degree, or equivalent qualification.
• A minimum of 8 years of experience in cybersecurity, with at least 3 years dedicated to GRC.
• Expertise in ISO 27001/27002/27005, NIS2, DORA, GDPR, and ANSSI guidelines.
• Familiarity with the EBIOS Risk Manager methodology and knowledge of ISO 27005.
• Proven experience in conducting audits and maturity assessments.
• Strong comprehension of cloud, infrastructure, networking, and IAM architectures.
• Professional proficiency in English.
• ISO 27001 Lead Auditor or Lead Implementer certifications are advantageous.
• EBIOS Risk Manager, CISM, CISSP, or CRISC certifications are highly regarded.
• Allocated budget for training and certification.
• Opportunities for career advancement towards becoming a subject-matter expert in the Cybersecurity practice.
• Option for remote work.
biBerk Business Insurance
Doppel
PingWind Inc. (SDVOSB)
The Standard
Get handpicked remote jobs straight to your inbox weekly.