top of page
courage is a decision.png
blank.png

IT Security Risk Specialist


Our client is one of the leading technology hubs in Bucharest, where tech pros across various disciplines (security, infrastructure, cloud or software development) are delivering and owning services and processes for the group's subsidiaries.


The employer is a worldwide leading services and payments organization, supporting employee benefits administration, fleet&mobility solutions and Corporate payment services across 40+ countries. The Group brings together a unique network of 50 million employee users, 1M corporate clients and 1.7 million partner merchants.


In order to protect and further develop the business, the company is implementing a worldwide Security strategy meant to strenghten its portfolio of products and applications and to drive a culture of increased security awareness of ownership.


The IT Security Risk Analyst  is part of the Global Application and Network Security Team, mandated to define and run the global risk practice. You'll get involved in all major global and local digital transformation projects, such as new applications or enhancements, cloud migrations, etc. 

  



Your main responsibilities will revolve around the following:



  • Effectively run the security risk practice in the company;


  • Improve the Risk methodology, in line with practice set forward by the IT Compliance team;


  • Enforce security by design principles, by integrating security as part of the process across all technology initiatives;


  • Promote the risk methodology across the business units and train the local security stakeholders;


  • Perform and drive risk analysis across critical projects;


  • Assess and prioritize risks; Suggest improvement measures;


  • Consolidate and integrate risk analysis results in a GRC tool to contribute building and IT Risk Cartography;


  • Report on key compliance and operational metrics.



This role is for you if:


  • You have a good understanding of technical matters, able to arbitrate and make pragmatic decisions around prioritizing risk and measures;


  • You've been already involved in risk analysis, conducting business interviews and applying risk methodology;  


  • You have proven experience working with stakeholders to integrate security by design in various technology projects;


  • Ideally, you're familiar with security frameworks and methodologies such as ISO27005, ISO27001, NIST, PCI-DSS, OWASP;


  • You understand threat modelling approaches to identify weak points in systems and applications;


  • You have a good understanding of GDPR and legal frameworks applicable within the EU. 


  • You demonstrate critical thinking, situational analysis and problem solving skills and mindset.


  • Fluent in English.



Why you should consider this role?


  • You'll work in a global center of expertise, get exposure to a diverse range of cultures, technologies and best practices;


  • Competitive salary | Meal vouchers | Holiday vouchers | Benefit budget | Medical subscription | Life insurance | Extra days off


  • Budget for learning and certifications.


If you feel you still need to fill some gaps for this position don't give up, let's talk first.


If interested: send your resume to recruitment@itworx.ro and we'll reach out to you shortly.


Else: you can refer an interested friend or acquaintance.

Hybrid Bucharest

How can we help? Send us a note.

Email: recruitment@itworx.ro  

Phone: 00 40 725351268

 

  • LinkedIn Social Icon
  • Facebook

Continutul acestui website este publicat exclusiv de Itworx International SRL. Preluarea integrală sau parțială a oricarui text, reformularea minoră ori republicarea acestuia pe alte site-uri/platforme fără acord scris este interzisă.

The content of this website is published exclusively by Itworx International SRL. The full or partial copying of any text, minor rewording, or republication of this content on other websites/platforms without written permission is prohibited.

bottom of page