Business Sustainability Ratings
Senior IT Security GRC Specialist
Location
Greece
Posted
38 days ago
Salary
0
Seniority
Senior
Job Description
Senior IT Security GRC Specialist
EcoVadis
• Develop and implement GRC Strategy: Create, author, develop and implement a comprehensive GRC strategy, which includes policies, procedures, and security requirements that aligns with industry best practices and regulatory requirements. • Deploy, maintain and continuously develop a proprietary control framework that is consistent with the organization’s compliance requirements and needs. • Support in conducting risk and control assessments, and identify, evaluate, and prioritize potential threats and vulnerabilities. • Author and conceptualize original risk mitigation plans and corrective actions to address risks effectively. • Collaborate with Product teams to ensure "Compliance-by-Design," providing requirements and highlighting security risks during the discovery phase of new features and improvements. • Ensure Regulatory and Industry Standards Compliance: Stay abreast of relevant laws, regulations, security frameworks and industry standards (e.g. GDPR, ISO 27001, NIS2, SOC 2,...), and work towards ensuring the organization’s compliance with them. • Promote awareness of applicable laws and regulations towards employees and upper management. • Conduct regular audits and assessments to monitor compliance and identify areas of improvement. • Be an active participant in third party audits, including leading them to support IT Security needs. • Support Business Processes: Perform deep-dive analysis and author technical responses for security questionnaires, translating complex internal security controls into customized client-facing documentation. • Review and provide expert analysis of security clauses in contracts, drafting customized security requirements for clients and suppliers. • Participate in clients meetings to address cybersecurity concerns and requirements, Conduct and document security reviews of SaaS applications, producing original risk assessment reports and designing mitigation recommendations. • Building and maintaining a Security Trust Center or similar customer-facing resources. • Provide Strategic Guidance: Become one of the main points of contact for senior management on GRC matters, and create strategic advisory materials/models detailing the impact of GRC initiatives on business decisions. • Develop and maintain strong relationships with key stakeholders across the organization. • Ensure Functional Supervision Provide expert guidance and alignment for the GRC team; act as the technical mentor and "quality gatekeeper" for key deliverables, including security awareness program and third-party risk assessments. • Deliver IT Security Reporting: Develop, support and maintain key performance indicators (KPI) for the Security function. Gather, analyze and report on security metrics and compliance status. Prepare and design customized presentations and reports to senior management on the status of the IT Security program, including key risks, threats, and vulnerabilities. • Implement AI-Powered GRC Operations: Lead the practical adoption of Generative AI tools (LLMs, AI Agents) to automate evidence collection, draft security policies, and summarize regulatory changes, significantly increasing team efficiency.
Job Requirements
- Fluent written and spoken English.
- 5+ years of experience in GRC positions.
- Exceptional ability to build stakeholder relationships and translate technical risks into business impact.
- Ability to align and guide peers/junior staff through influence and technical authority, rather than formal people management.
- High degree of autonomy and the ability to drive complex GRC projects independently from inception to completion.
- Strong understanding of GRC frameworks, methodologies, and best practices.
- Knowledge of relevant laws, regulations, and industry standards, and open to explore other national-led frameworks that may be applicable to the organization.
- Hands-on experience creating, maintaining and improving compliance programs based on multiple standards or regulations (e.g. ISO 27001, SOC2, etc.)
- Practical experience using AI to streamline compliance workflows and an understanding of the risks associated with AI adoption.
- Strong analytical and problem-solving skills, with the ability to assess risks and develop effective control measures.
- Ability to conduct research about areas unknown to him/her, and use that knowledge to deliver security guidelines and propose improvements.
- Hands-on experience with Google Workspace is a plus.
Benefits
- Support with all the necessary office and IT equipment
- Flexible working hours
- Wellness allowance for mental and physical wellbeing
- Access to professional mental health support
- Referral bonus policy
- Learning and development
- Sustainability events and community involvement
- Peer recognition program
- Employee-led resource groups
- Optional (fully covered or co-financed) health care and life insurance
- Multisport card
- Multikafeteria
- Lunch card
- Hybrid work organization
- Remote work from abroad policy
- Internet and Electricity bill allowance
- Additional day for community service when volunteering
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Provide expert advice on data protection, manage inbound queries, support compliance activities, and draft information sharing arrangements to ensure effective information governance and risk management across the organization.
Title: Director, Industrial Security Location: Remote, CAN Job Description: Job Title: Director, Industrial Security Job Location: Remote, CAN Job Code: 35839 Job Schedule: Day Shift Compensation Range: Between $173,500 - $243,500 CDN annually We are seeking an experienced, self-starting and adaptable security specialist to oversee and coordinate security efforts across Canada, including convergence with information technology, human resources, communications, legal, facilities management and other functional and support organizations. Develop, mentor and guide security representatives to maintain a cost-effective program to meet and exceed all customer requirements to include, Canadian Government and Corporate policies and directives as applicable. This role will act as the Corporate Company Security Officer (CCSO) for the group and divisions, under Industrial Security Policy for all L3Harris business units in Canada. Senior L3Harris point of contact for Government Relations with PWGSC Industrial Security; classified/protected contracts, domestic/international About you: To be successful in this role and to best leverage the opportunities provided by L3Harris, some skills & experience ideal applicants will bring include; - Experience in a Senior Security position within a defense or government organization involving classified programs - Oversight and implementation of Industrial Security Regulations, Controlled Goods Program, ITAR, and regulatory frameworks - Strong crisis management, risk assessment, and stakeholder engagement skills - Information Security experience and membership of Government / Industry Associations is highly desirable. - Must also have experience in working with but not limited to: Foreign Government information, emergency management, policy development, counterintelligence and investigations, and risk analysis - Highly developed policy development and implementation capabilities - Successful history in similarly fast-paced and complex technical environments - Self-starting, inquisitive, highly driven individuals, with good business acumen and an eye for practical outcomes, are best suited to the performance profile of this role. - Availability to travel. Domestic and international travel may be required (10-15%). Qualifications: - Bachelor’s Degree with a minimum of 15 years of security related experience in Government or industry and five years of management experience involving classified programs. Graduate Degree with a minimum of 13 years of prior related experience. In lieu of a degree, minimum of 19 years of prior related experience. Government security specific qualifications within security, risk management and personnel security management are also highly desired. - Experience in Government and/or industrial security programs as a Chief Security Officer (CSO), Associate CSO, and COMSEC Custodian. - Comprehensive and practical understanding of the Industrial Security Regulations, Controlled Goods Program, ITAR and regulatory frameworks. - This position also requires access to and experience with the various Canadian intelligence agencies, and other provincial, state, and local security, investigative, and law enforcement. Preferred Additional Skills: - Familiarity with global defense prime contractors - Qualifications in Security, Risk, Cybersecurity, or Defense Studies - Experience integrating physical security strategies - The candidate must also possess strong communications skills, written, verbal and interpersonal. Eligibility Criteria: - Must be eligible for registration with the Controlled Goods Program; - Must be eligible to obtain and maintain a government of Canada Secret Level 2/NATO Secret security clearance; - Must be eligible to meet the requirements for U.S. International Traffic in Arms Regulations (ITAR). L3Harris is proud to be an equal opportunity employer and is committed to treating all of its employees and job applicants with respect and dignity and to maintaining a workplace free from discrimination. Anyone applying for a position will be considered without regard to the following: race, national or ethnic origin, colour, religion, age, nationality, ancestry, ethnicity, gender, sex, sexual orientation, gender identity or expression, marital status, family status, genetic characteristics, disability, citizenship status, or conviction for an offence for which a pardon has been granted or in respect of which a record suspension has been ordered, or any other characteristic that is protected by applicable human rights legislation. L3Harris maintains a drug-free workplace and conducts pre-employment drug and alcohol testing and background checks, in accordance with applicable law. Such results are only accessible and viewed by individuals at L3Harris who have direct responsibility in the hiring process. If you fail to report for a drug and alcohol test, refuse to undergo such test or test positive for the presence of drugs or alcohol, the hiring process may be concluded or your offer of employment may be rescinded, in L3Harris’ sole discretion.
Principal Security Engineer
AchieveA leading digital personal finance company helping everyday people move forward on the path to a better financial future
• Architect the next generation of Identity at Achieve • Transition the enterprise from static, role-based access to a Risk-Based Authorization model • Enhance the enterprise Identity strategy, roadmap, and architecture • Design and architect comprehensive Identity solutions, including identity lifecycle management, authentication, authorization, and Privileged Access Management (PAM) • Lead the implementation and integration of Identity solutions across various environments • Partner with the SOC to build ITDR capabilities that detect and automatically neutralize identity-based attacks
Security Business Partner Senior
PNCFounded over 150 years ago, PNC is a financial services corporation that works with retail, business, and corporate clients and has assets totaling more than $290 billion. As an em
Title: Security Business Partner Sr Location: Virginia, United States Job ID: R218954 remote Job Description: Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As a Security Business Partner Sr within PNC's Technology organization, you will be based in Washington, DC. Position Summary The Security Business Partner Sr serves as a strategic partner and the senior relationship manager between Enterprise Information Security and PNC Lines of Business. Key Responsibilities Business & Security Partnership - Senior leader responsible for the client relationship with all PNC Lines of Business to ensure successful outcomes on the integrated delivery of cybersecurity services including cybersecurity technology, security risk management, business demand management, and client feedback. - Participate in key executive initiatives and program meetings to provide ongoing input to improve PNC's security and risk posture while supporting product strategies and revenue generation / cost reduction. - Manages the team responsible for Line of Business security relationships and participates in Line of Business leader meetings providing relevant security input and topics for discussion. - Lead the coordination and scheduling of Security topics for executive updates and committee presentations. Initiative Support - Responsible ensuring security requirements and standards are identified and incorporated across the business and technology lifecycle, including RFP activities, technology due diligence, and security approvals. - Engage with Line of Business leaders to promote adoption, accountability, and sustainability of security requirements and controls for Line of Business initiatives. - Serve as escalation point within the team for ad hoc or high priority security situations within the Lines of Business, including coordination of communications and remediation planning. Risk Management & Governance - Provide guidance to the team for Line of Business risk assessments, security reviews, and governance activities for initiatives with material technology, data, or business impact. - Partner with Line of Business Risk organizations to improve Security posture through the reduction of Policy Exceptions, open vulnerabilities, and implementation of automated identity access controls. - Translate information security requirements and risk considerations into relevant guidance to support informed decision making by Line of Business stakeholders. Organizational Alignment - Senior leader within the Security organization that engages with peer Security leaders responsible for Identity Access Management, Data Protection, Application Security, Cloud Security, PNC subsidiaries and Policy and Governance. Required Qualifications - CISSP, CRISC, or CISA certification. - 5 years' experience in information security, risk, or audit. - Expertise with one or more enterprise security domains such as Identity Access Management, Data Protection, Cloud Security, and Risk Management. - Demonstrated ability to work effectively with business, technology, and risk stakeholders. This position may be eligible for remote work in select geographic locations, subject to approval by PNC. If approved, work must be conducted from a quiet, secure, and confidential home-based workspace. Occasional in-office participation may be required based on business needs. PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position. Job Description - Serves as a partner and relationship manager with line of business(es) and staff areas to ensure integrated delivery of cyber, fraud and physical security services and a centralized escalation point. Serves as strategic partner and brings the right security resources together to provide security solutions. Supports business and staff areas in elevating their security posture in a risk-balanced manner and building trust in the brand. Supports business objectives while effectively managing risk. - Leads relationship with a line of business(es), serving as the point of escalation to ensure successful outcomes and is responsible for the overall client experience with a technology organization, including, cyber, fraud and physical security risk, business demand management, technology expenditures, client feedback & relationship management. - Identifies opportunities to implement improvements and ensure the execution of solutions that are cost effective, meet business requirements and are consistent with technology capabilities, functionality and the proactive integration of security. - Collaborates with internal T&I and business groups on process improvement projects designed to support product strategies and revenue generation/cost reduction. - Participates in the gathering and analysis of complex client requirements, and the transformation of requirements into functional/non-functional requirements. PNC Employees take pride in our reputation and to continue building upon that we expect our employees to be: - Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions. - Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNC's Enterprise Risk Management Framework. Qualifications Successful candidates must demonstrate appropriate knowledge, skills, and abilities for a role. Listed below are skills, competencies, work experience, education, and required certifications/licensures needed to be successful in this position. Preferred Skills Access Control (AC), Building Architecture, Customer Solutions, Disaster Recovery Planning, Information Security, Network Security, Physical Security, Risk Assessments, Security Technologies Competencies Business Acumen, Effective Communications, Influencing, Problem Solving, Relationship Management, Strategic Thinking Work Experience Roles at this level typically require a university / college degree. Higher level education such as a Masters degree, PhD, or certifications is desirable. Industry relevant experience is typically 8+ years. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered. Education Certifications No Required Certification(s) Licenses No Required License(s) Pay Transparency Base Salary: $80,000.00 - $215,800.00 Salaries may vary based on geographic location, market data and on individual skills, experience, and education. This role is incentive eligible with the payment based upon company, business and/or individual performance. Benefits PNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives. In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service. To learn more about these and other programs, including benefits for full time and part-time employees, visit pncthrive.com. Disability Accommodations Statement At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions. Equal Employment Opportunity (EEO) PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law. This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage Licensing Act of 2008 (SAFE Act) and/or the Financial Industry Regulatory Authority (FINRA), which prohibit the hiring of individuals with certain criminal history. California Residents Refer to the California Consumer Privacy Act Privacy Notice to gain understanding of how PNC may use or disclose your personal information in our hiring practices.



