


IT Security Risk Specialist
Our client is one of the leading technology hubs in Bucharest, where tech pros across various disciplines (security, infrastructure, cloud or software development) are delivering and owning services and processes for the group's subsidiaries.
The employer is a worldwide leading services and payments organization, supporting employee benefits administration, fleet&mobility solutions and Corporate payment services across 40+ countries. The Group brings together a unique network of 50 million employee users, 1M corporate clients and 1.7 million partner merchants.
In order to protect and further develop the business, the company is implementing a worldwide Security strategy meant to strenghten its portfolio of products and applications and to drive a culture of increased security awareness of ownership.
The IT Security Risk Analyst is part of the Global Application and Network Security Team, mandated to define and run the global risk practice. You'll get involved in all major global and local digital transformation projects, such as new applications or enhancements, cloud migrations, etc.
Your main responsibilities will revolve around the following:
Effectively run the security risk practice in the company;
Improve the Risk methodology, in line with practice set forward by the IT Compliance team;
Enforce security by design principles, by integrating security as part of the process across all technology initiatives;
Promote the risk methodology across the business units and train the local security stakeholders;
Perform and drive risk analysis across critical projects;
Assess and prioritize risks; Suggest improvement measures;
Consolidate and integrate risk analysis results in a GRC tool to contribute building and IT Risk Cartography;
Report on key compliance and operational metrics.
This role is for you if:
You have a good understanding of technical matters, able to arbitrate and make pragmatic decisions around prioritizing risk and measures;
You've been already involved in risk analysis, conducting business interviews and applying risk methodology;
You have proven experience working with stakeholders to integrate security by design in various technology projects;
Ideally, you're familiar with security frameworks and methodologies such as ISO27005, ISO27001, NIST, PCI-DSS, OWASP;
You understand threat modelling approaches to identify weak points in systems and applications;
You have a good understanding of GDPR and legal frameworks applicable within the EU.
You demonstrate critical thinking, situational analysis and problem solving skills and mindset.
Fluent in English.
Why you should consider this role?
You'll work in a global center of expertise, get exposure to a diverse range of cultures, technologies and best practices;
Competitive salary | Meal vouchers | Holiday vouchers | Benefit budget | Medical subscription | Life insurance | Extra days off
Budget for learning and certifications.
If you feel you still need to fill some gaps for this position don't give up, let's talk first.
If interested: send your resume to recruitment@itworx.ro and we'll reach out to you shortly.
Else: you can refer an interested friend or acquaintance.