Punë
Cyber Security Compliance Consultant
Service Factory Solutions
cyber-security-compliance-consultant-9zwoah
Përshkrimi
We are seeking a skilled Cyber Security Compliance Consultant to join our dynamic team. You’ll work on high-impact cybersecurity and compliance projects, helping our clients strengthen their security governance, manage risk, and meet evolving regulatory requirements.
The ideal candidate has solid experience in Security Compliance/GRC, with previous exposure to the European regulatory environment and hands-on experience with GDPR and/or NIS2.
**What You’ll Do**
• Support clients in achieving and maintaining compliance with cybersecurity regulations and standards, including NIS2, ISO/IEC 27001, TISAX, and GDPR.
• Conduct Security Assessments, GAP Analyses, Risk Assessments, and Business Impact Analyses (BIA), identifying remediation actions and improvement opportunities.
• Design, implement, and maintain Information Security Management Systems (ISMS) aligned with international standards and best practices.
• Analyze business processes, operational dependencies, and critical systems to define business continuity requirements and parameters such as RTO, RPO, and MTPD.
• Support consulting engagements related to audit readiness, certification processes, and regulatory compliance programs.
• Provide strategic guidance on cybersecurity governance, risk management, and organizational security posture, including vCISO activities.
• Develop cybersecurity policies, procedures, standards, and governance documentation.
• Deliver training and awareness sessions on cybersecurity, compliance, and security best practices.
• Monitor regulatory developments and advise clients on new requirements and their operational impact.
• Collaborate with technical and business stakeholders, experienced consultants, and international teams.
**What We’re Looking For**
• 3–5 years of relevant experience in Cyber Security Compliance, GRC, cybersecurity consulting, governance, or information security management.
• Previous professional experience within the European regulatory and compliance environment.
• Strong knowledge and practical experience with GDPR and/or NIS2.
• Good knowledge of ISO/IEC 27001 and familiarity with TISAX.
• Proven experience with security audits, risk assessments, GAP analyses, and compliance programs.
• Experience in designing or implementing security governance frameworks, ISMS, and compliance processes.
• Knowledge of Business Continuity and Disaster Recovery principles and related methodologies, such as ISO 22301 and ISO/TS 22317.
• Strong analytical, organizational, documentation, and stakeholder management skills.
• Ability to work independently and manage different projects and priorities.
• Client-oriented and detail-focused approach.
• Availability to travel when required.
• Italian and English proficiency at B2 level or higher.
**Nice to Have**
• Degree in Computer Science, Engineering, Cybersecurity, Law, or a related field.
• Certifications such as ISO/IEC 27001 Lead Auditor, ISO/IEC 27001 Lead Implementer, CISA, CISM, or CISSP.
• Previous experience as a vCISO, Compliance Manager, or Information Security Manager.
• Knowledge of ISO 31000, ISO/IEC 27005, NIST Cybersecurity Framework, or ISO 22301.
• Experience in regulated industries such as financial services, automotive, energy, manufacturing, or healthcare.
• Experience with GRC platforms and certification/accreditation bodies.
• Technical understanding of Cloud Security, SIEM/SOC environments, Vulnerability Management, Network Security, and IAM.
**How to Apply**
Interested candidates are invited to submit their CV to: careers@servicefactory.al
*\*Please note that only shortlisted candidates will be contacted for an interview.*
Burimi: https://www.linkedin.com/jobs/view/4468596562/
Kërkesat
Niveli: mid level
Kjo shpallje vjen nga një burim i jashtëm. Aplikimi kryhet në faqen e punëdhënësit.
Apliko në burim