Description
Job Summary:
Information security professional responsible for managing risks, ensuring regulatory compliance, and maintaining operational resilience and cybersecurity.
Key Highlights:
1. Manage cybersecurity and privacy risks and regulatory compliance.
2. Lead GAP analyses, action plans, and compliance audits.
3. Contribute to resilience, third-party management, and security culture.
**Responsibilities and Duties**
**Risk Management**
* Develop and maintain risk assessments and control frameworks aligned with ISO/IEC 27001, NIST CSF, ENS, and DORA.
* Track treatment plans: status, progress, and effectiveness of defined measures.
* Monitor non-conformities and corrective actions until closure, ensuring traceability and evidence.
* Support the operation and evolution of GRC tools (e.g., Archer, OneTrust, Formalize, or similar).
**Regulatory Compliance**
* **Define, implement, and maintain the regulatory compliance framework for cybersecurity and privacy, ensuring alignment with cybersecurity regulations**\*.
(\*) Familiarity with the following topics is valued: National cybersecurity regulations **ENS, GDPR, NIS2, LPIC, CNPREC**, European Directives **such as DORA, AI Act, eIDAS2, CRA**, best practices such as **ISO 27002, 27018, 27017, 42001**, sector-specific standards such as **PCI DSS, ISA 62443**, and certification schemes such as **Europrivacy or ISO 27001\.**
* **Conduct compliance GAP analyses**, identifying non-compliances, deviations, and regulatory risks, and proposing improvement measures aligned with the risk level and criticality of services and assets.
* **Define, develop, and monitor action and remediation plans**, coordinating technical teams, business units, and vendors until effective closure of actions.
* **Manage and coordinate internal compliance audits and support external audits and certification processes**, including management of findings, corrective actions, and verification of their closure.
* **Manage the collection, maintenance, and traceability of compliance evidence**, ensuring consistency with regulatory requirements, policies, procedures, and established controls.
* **Prepare reports and reporting for senior management, as well as compliance dashboards, defining and monitoring KPIs and KRIs** related to compliance status, regulatory risk, audits, and action plans.
**Business Continuity and Resilience**
* Collaborate in designing, maintaining, and updating Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP).
* Support execution of exercises and simulations, documenting results and lessons learned.
* Monitor the status of critical assets and their coverage within the operational resilience model.
* Contribute to digital operational resilience requirements derived from DORA.
**Third-Party and Supply Chain Management**
* Support the evaluation and onboarding process of vendors from a security and risk perspective.
* Monitor the third-party risk lifecycle: periodic assessments, questionnaires, finding management, and continuous monitoring.
* Collaborate in developing and updating the inventory of critical vendors.
* Support automation of assessment processes using tools.
**Dashboards and Reporting**
* Develop and maintain risk and compliance dashboards for senior management and the CISO.
* Consolidate key metrics and indicators (KRI/KPI) that reflect the security posture in a comprehensible and actionable manner.
* Support preparation of periodic reports for risk committees, internal audit, and regulators.
* Translate technical information into executive language to facilitate decision-making.
**Security Culture and Training**
* Collaborate in designing and executing security awareness campaigns targeted at various organizational roles.
* Support development of training content and management of cybersecurity training platforms.
* Track participation and effectiveness metrics of awareness programs.
Contribute to building a robust and cross-functional security culture.
**Knowledge and Experience**
* **Experience** in information security risk management and regulatory compliance frameworks.
* **Knowledge** of standards and regulations: ISO/IEC 27001, NIST CSF, ENS, DORA, NIS2, and GDPR.
* **Ability** to interpret regulatory requirements and translate them into practical, verifiable controls.
* Knowledge of business continuity and crisis management (e.g., ISO 22301 or similar; desirable).
* Experience or knowledge of third-party and supply chain risk management.
* Solid knowledge of **cybersecurity technologies and information systems**.
* Proficiency with **GRC tools** (e.g., Archer, OneTrust, Formalize, or similar). Desirable: PILAR tool and MAGERIT methodology.
* Ability to **identify and apply efficiencies through process automation and use of AI tools**, contributing to continuous improvement of GRC operations.
* **English B2\.** Reading of international regulations and fluent communication with global teams.