GRC/Information Security Consultant
Strovolos,
Cyprus
As an Information Security Consultant, you will guide our clients through the complexities of governance, risks and compliance (GRC).
Your role will involve assessing and managing risks, recommending risk-mitigating actions, developing security strategies, and ensuring clients' IT environments align with industry best practices and regulatory requirements.
Key Responsibilities
- Plan and execute assessments in the areas of IT Governance (ISO 27001, NIST), Regulatory Compliance (EBA, EIOPA, GDPR, DSA, etc), Risk Assessments and IT Audits.
- Evaluate Information Security controls (e.g. identify and assess IT risks and controls)
- Provide consultation on information security controls and compliance measures.
- Develop customized security policies and frameworks for clients, based on standards such as ISO 27001.
- Assist clients in managing and mitigating risks associated with their IT operations.
- Catalogue, test and monitor controls.
- Create and perform gap analysis as well as provide strategy to implement and mitigate identified risks.
- Define business architecture and functional design.
- Manage projects, develop project plans, and monitor performance.
- Monitor deliverables and ensure timely completion of projects.
- Conduct meetings and presentations to share ideas and findings.
- Conduct functional walk-throughs with various stakeholders.
- Analyze system impacts to other systems and procedures.
- Participate in training personnel on enhancements, and new systems or procedures.
- Creating executive reporting and strategy documents.
- Stay abreast of the latest developments in IT security, regulations, and best practices.
Must Have
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or related field.
- At least 2 years of experience in information security consulting, risk management, or a related field.
- Professional certifications such as CISA, CISSP, will be considered as an advantage.
- Excellent verbal and written communication skills at both business and deep technical levels.
- Self-directed and motivated.
- Exceptional analytical and problem-solving skills.
Nice to have
- Experience with SIEM and Log Analysis Tools
- Business Continuity & Disaster Recovery (BC/DR) Planning
- Familiarity with DevSecOps / Secure SDLC Practices
- Multilingual Communication Skills (e.g., Greek/English)
What's great in the job?
- Great team of smart people, in a friendly and open culture
- No dumb managers, no stupid tools to use, no rigid working hours
- No waste of time in enterprise processes, real responsibilities and autonomy
- Expand your knowledge of various business industries
- Real responsibilities and challenges in a fast evolving company
About Us
How To Apply
Interested candidates should submit their resume to careers@qsecure.global Join us and help shape the future of cybersecurity in Cyprus and beyond. You can make a real contribution to the success of the company. Several activities are often organized all over the year, such as team building events, and much more.