
Information Security Framework Senior Specialist (VP) (f/m/x)
- București
- Permanent
- Full-time
- Take ownership of the control estate governance and work on one or several Cyber Security domain e.g. Cryptography, Data Security, Identity and Access Management, Network Security, Security Monitoring, Endpoint Security, Cyber Risk in collaboration with the designated subject matter experts, in order to define the most effective and efficient Control estate.
- Conduct and participate to assessments of information security controls, frameworks, processes, gap analysis against industry’s best practices, standards and regulations.
- Contribute to the continuous development and maintenance of the team’s knowledge base and standard content offering to support an efficient and consistent response process and other projects maturing and evolving our service offering and processes.
- Work with representatives of governance and control stakeholders to ensure controls are fit-for-purpose, agreed upon and ratified; actively taking part in control / framework design, development, maintenance and governance
- Act as an advisor to stakeholders on execution of Control framework and its lifecycle e.g. policy and control maintenance, as well as contribute to the continuous improvement including both control estate and team process and methodologies.
- Significant and multi-year work experience in the Information Technology / Information Security area or in IT Audit, Information Security Governance, Risk and Control related topics and/or frameworks, preferably in the financial industry; ideally combined with experience in project management.
- Ability to watch, track and clearly communicate progress, escalate issues when appropriate. Strong analytical and problem-solving skills.
- Professional appearance and strong verbal and written communication and presentation skills (technical and non-technical), with the ability to communicate on all hierarchy levels. Cross-functional collaboration, stakeholder engagement, influencing skills and familiarity with continuous improvement process. Positive attitude and proactive behavior. Fluent in English is required.
- Highly appreciated will be professional / industry recognized certifications such as: Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), ITIL, COBIT, Certified in Risk and Information Systems Control (CRISC)), or similar.
- Knowledge of IS threat analysis and frameworks (e.g., MITRE ATT&CK Framework) as well as cyber security standards (e.g., NIST, OWASP, ISO27001) and knowledge of the regulatory environment in the financial sector (e.g., KAIT, BAIT, ESMA cloud guidelines).
- Empowering managers who value your ideas and decisions. Show your positive attitude, determination, and open-mindedness.
- A professional, passionate, and fun workplace with flexible Work from Home options.
- A modern office with fun and relaxing areas to boost creativity.
- Continuous learning culture with coaching and support from team experts.
- Private healthcare and life insurance with premium benefits for you and discounts for your loved ones.
- Kids@TheOffice - support for unexpected events requiring you to care for your kids during work hours.
- Enjoy retailer discounts, cultural and CSR activities, employee sport clubs, workshops, and more.
- Competitive income, performance-based promotions, and a sense of purpose.
- 24 days holiday, loyalty days, and bank holidays (including weekdays for weekend bank holidays).