Information Security GRC Analyst
hace 2 días
Pozuelo de Alarcón
ph3IT Security Governance, Risk, and Assurance /h3 pWe believe that we make a difference every day. To do that, we need committed and engaged employees. Our people are accountable for delivering world‑class service and they are passionate about making the world a safer and more secure place. Our teams operate with integrity and respect for one another fueled by an entrepreneurial spirit. /p h3What We Look For /h3 pAn effective communicator, you are a confident team player with a genuine passion for making things happen in a dynamic organization. If you’re ready to take on a wide range of responsibilities and are committed to seeking out new ways to make a difference, this role is for you. /p h3The Role /h3 pReporting to the Cyber IT Risk Team Lead, your role will be focused on identifying, assessing, and mitigating risks related to cybersecurity, IT systems, and business processes. Your role will also support the implementation of our organization’s strategies around Cyber IT controls by maintaining and developing new ways of doing things and creating cross‑functional business relationships within Technology and other business units. /p pThe position is expected to work with internal stakeholders and take a supportive role in analysing key risks, establishing regular dialogue between risk and control owners to identify areas for improvement and develop strategies to enhance security of IT and business processes. /p h3Main Responsibilities /h3 ul liFocus on building and maintaining the Audit function within Information Security. /li liManage and mature the Information Security IT risk control framework to enable effective operation and monitoring of controls. /li liDocument and report control failures and gaps to stakeholders. Provide remediation guidance and occasionally drive projects to ensure deployment of mitigation actions. /li liDevelop security policies, standards, and procedures to drive standardization and centralization of control activities. /li liPerform risk assessment activities across the organization, identify potential risks within IT and business processes, and recommend risk mitigation strategies and controls. /li liEnsure risks and remediation plans are regularly addressed and implemented by risk and control owners. /li liSupport activities to maintain compliance with relevant regulations and standards (e.g., ISO27001, NIST, GDPR). /li liAudit and document processes and prepare reports summarizing findings and insights for management and stakeholders. /li /ul h3Required Qualifications /h3 ul liBachelor’s degree within a relevant field and at least 4 years of direct experience within Information Security IT risk and compliance. /li liExperience working in GRC departments and direct experience working in: ul liDefining, creating, and executing an Information Security IT risk control framework, internally and for third‑party partners, including documenting security procedures, policies, and standards. /li liPerforming information security IT assessments and conducting compliance and maturity assessments using international standards and best practices. /li liEnsuring that all risks, vulnerabilities, and non‑conformities are actively managed, monitored, documented, and mitigated. /li liDefining and tracking KPIs/KRIs and generating reporting adapted for different levels and stakeholders. /li liPerforming information security IT controls audits and executing remediation plans internally and for third‑party partners. /li /ul /li /ul h3Work Experience in a Professional Environment Preferred, Including /h3 ul liDemonstrated planning and problem‑solving skills and ability to analyze complex technical issues. /li liThorough understanding of market structures, including relevant regulatory compliance requirements (SOC 2, NIST, GDPR, COBIT, ITIL, etc.). /li liAbility to build professional relationships and collaborate effectively with peers and stakeholders. /li liExperience organizing and carrying out risk assessments and compliance projects. /li liFluent written and verbal communication skills in English. /li liTravel availability. /li /ul h3Preferred Qualifications /h3 ul liRelevant security certifications: CISSP, CRISC, CISM, CISA, Security+, ISO 27001. /li liProficient with MS Office, project management, and at least one GRC tool (recommended). /li liFamiliarity with auditing, monitoring, controlling, and process assessment. /li /ul h3The Company /h3 pWe are the leading provider of professionally monitored alarms for residential households and small businesses in Europe. We protect more than 3.4 million families and small businesses. Our service includes 24/7 monitoring, expert verification and response, customer care, service and maintenance services, and professional technical support. We protect against intrusion, fire, attack, theft, life‑threatening emergencies and other hazards. Verisure employees are dedicated and committed, providing what we believe is the best customer service in the industry. /p pWe operate in 17 countries across Europe and Latin America. Our business is driven by organic growth, based on our differentiated business model. We attract high quality customers, and we work hard to ensure that our customers are happy. This contributes to an industry‑leading level of attrition and a long customer lifetime. /p pOur ~29,000 teammates form the foundation of our company. Our business model combines technology and human expertise to protect people. More than 80% of our colleagues interact with customers every day, providing insight that inspires our innovation. We leverage these insights with significant investment in product and service innovation. The close customer contact fuels pride and drives engagement. /p pWe have been protecting what matters most since 1988. We have expanded beyond our roots in the Nordics and Spain, serving most of Europe and establishing a strong presence in Latin America. In 2019, we formed a strategic partnership with Arlo, a world leader in connected cameras. Verisure acquired all rights to Arlo’s European business, allowing us to offer connected camera services in Europe as a complement to our professionally monitored security service, and to access new go‑to‑market opportunities in retail and e‑commerce. /p h3Apply today! /h3 pVerisure Innovation is an equal‑opportunity employer and welcomes applicants from diverse backgrounds. We are an international company with offices and colleagues in multiple countries. Please note that we do not accept applications via email. /p pIf you have questions regarding this position, please reach out to our Group Talent Acquisition Lead, /p /p #J-18808-Ljbffr