Faster chat, better deals — Get the App

Security Consulting Practitioner

Indeed

Company

Job typeFull-time
Workplace typeOnsite
Experience level1 to 2 years
Education levelNo degree limit

Description

ENS / Cybersecurity GRC Consultant (Technical Profile) A professional specialized in Governance, Risk, and Compliance (GRC) and cybersecurity, with experience in ENS (National Security Scheme) compliance, implementation, and certification projects within Public Administration and public-sector entities. This profile combines both regulatory and technical expertise, acting as a liaison between security, infrastructure, architecture, and business units. Key Responsibilities Implementation of ENS compliance projects (Basic, Medium, and High categories), including gap analyses, remediation plans, and monitoring of corrective measures. Development and maintenance of risk analyses using the MAGERIT methodology and the PILAR tool. Definition and review of security policies, procedures, standards, and instructions aligned with ENS, ISO/IEC 27001, and cybersecurity best practices. Identification, design, and validation of technical and organizational security measures for infrastructures, systems, and services. Coordination of ENS compliance audits, management of findings, and definition of remediation plans. Preparation of security documentation, asset inventories, statements of applicability, and evidence of compliance. Ongoing tracking of risks, non-conformities, and action plans, ensuring full traceability until closure. Preparation of executive reports and dashboards for security managers and senior leadership. Liaison with technical teams, vendors, service owners, and public-sector bodies. Knowledge and Experience Proven experience in ENS compliance and certification projects within Public Administrations or entities subject to ENS. Solid knowledge of MAGERIT, risk analysis and management, and practical use of PILAR. **Knowledge of security regulations and standards:** ENS, ISO/IEC 27001, ISO/IEC 27002, NIST CSF, and GDPR. Ability to translate regulatory requirements into implementable technical controls and security measures. Technical knowledge of system architecture, networks, cloud infrastructure, identity management, endpoint protection, and security monitoring. Experience collaborating with infrastructure, operations, development, and architecture teams. Strong technical writing skills and experience preparing compliance documentation. English proficiency at B1 level or higher. Required Experience 2–6 years of experience in cybersecurity, risk management, or regulatory compliance. Participation in at least 2\-3 ENS compliance or audit projects. Prior experience working with public-sector bodies, local authorities, regional administrations, or service providers to the Public Administration. **Desirable:** Certifications such as CISA, ISO 27001 Lead Implementer/Auditor, ENS, CCSK, Security\+, as well as experience with NIS2, DORA, or business continuity management. .

Source: indeed
Some content was automatically translated

Posted by

David Muñoz

Indeed · HR

Location

David Muñoz

Indeed · HR

Similar jobs

Security Consulting Practitioner job by Indeed in 2026 | ok.com