O SEU PRÓXIMO CAPÍTULO
GRC Expert – Governance, Risk and Compliance
Sobre a vaga
• Advise clients on achieving compliance with NIS2, DORA, ISO 27001, GDPR and industry-specific frameworks
• Conduct audits and maturity assessments, document gaps and develop remediation plans
• Draft and maintain policies, procedures, charters and other documentation
• Prepare for and support certification processes and external audits
• Conduct risk analyses using EBIOS Risk Manager and ISO 27005
• Develop and facilitate risk maps, treatment plans and monitoring indicators
• Support security governance through committees, dashboards and reporting to senior management
• Translate regulatory requirements into architectural requirements in collaboration with cloud and infrastructure architects
• Contribute to the design of landing zones and reference architectures with compliance built in
• Participate in business continuity plans and crisis management exercises
• Draft technical responses to requests for proposals and present and defend proposals
• Assess and qualify client needs relating to compliance and governance
• Develop and evolve GRC offerings and create accelerators
• Contribute to structuring the Cybersecurity practice, its positioning and the facilitation of the cyber community
• Lead regulatory monitoring for the practice
• Master's degree, engineering degree or equivalent
• At least 8 years of experience in cybersecurity, including 3 years focused on GRC
• Proficiency in ISO 27001/27002/27005, NIS2, DORA, GDPR and ANSSI guidelines
• Proficiency in the EBIOS Risk Manager methodology and knowledge of ISO 27005
• Experience conducting audits and maturity assessments
• Strong understanding of cloud, infrastructure, networking and IAM architectures
• Professional proficiency in English
• ISO 27001 Lead Auditor or Lead Implementer certifications are a plus
• EBIOS Risk Manager, CISM, CISSP or CRISC certifications are highly valued
• Dedicated training and certification budget
• Career development path toward becoming a Cybersecurity practice subject-matter expert
• Remote working available