Descrição
Role purpose:
- The Security and Compliance SME Works closely with the Global Office IT Security & Compliance Manager to ensure that Global Office IT meets security and compliance requirements.
Key accountabilities and decision ownership:
Security Governance and Compliance:
- Identify, assess, and manage Global Office IT’s ability to meet all security and compliance requirements.
- Prepare road map for improvement (enhanced security posture, operational processes/procedures, etc..) based on gaps identified.
- Engage with Global Office IT domains to drive initiatives to close the gaps.
- Enforce Security Controls as per applicable standards & Regulations (ISO, GDPR, etc.)
- Internal Audit of ISO 27001 controls
Publish compliance reports Other:
Willing to work according to the German calendar in terms of the weekends and the public holidays according to the shift schedule
- Represent Security and Compliance function topics in Office IT-related team meetings - Core competencies, knowledge, and experience: IT Auditor (Internal/External)
- ISO 27001 (Lead implementer/ Lead Auditor) certified or experience in implementing ISO 27001 framework
- Experience with SOX testing and IT General Controls (ITGC) framework
- Preferably Certified Information Systems Auditor (CISA) and/or Certified Information Systems Security Professional (CISSP) professional
- IT Risk assessment, risk management experience
- Working experience in Data Privacy and Data Security frameworks and controls (encryption, GDPR, PKI, etc..) preferable.
- Working experience in Cyber Security (Anti-virus, Patching, Vulnerability Management, etc..) is preferable
Must have technical/professional qualifications:
- Education:_
- BSC in Computer Engineering or Computer Science
- Work Experience:_
- 6+ years of experience in IT/Information Security
- ISO27001 knowledge is a must
- English fluency is a must
movewithus #_VOIS
