Cybersecurity GRC Consultant
פורסם לפני 16 ימים · 0 מועמדים
התפקיד במילים פשוטות
תפקיד של יועץ אבטחת מידע ו-GRC הכולל הובלת פעילויות ממשל, ניהול סיכונים ועמידה ברגולציות עבור לקוחות. העבודה היומיומית כוללת ביצוע הערכות סיכונים מקצה לקצה, כתיבת נהלי ומדיניות אבטחה, ביצוע סקרי פערים והכנת לקוחות לתקנים וביקורות כגון ISO 27001, SOC 2 ו-GDPR. בנוסף, התפקיד דורש עבודה שוטפת מול צוותים טכניים ולקוחות לתרגום דרישות לבקרות אבטחה מעשיות ותוכניות לתיקון ליקויים.
- 3+ years of hands-on experience in Cybersecurity / Information Security with focus on GRC, risk management, and compliance
- Hands-on experience conducting cybersecurity and information security risk assessments end to end
- Experience writing and implementing information security policies and procedures
- Practical experience working with security frameworks, standards, and regulations such as ISO 27001, SOC 2, GDPR, and NIST
- Experience conducting gap assessments, control assessments, and compliance readiness projects
- Experience working directly with auditors and certification bodies
- Relevant certifications such as CISSP, CISM, CISA, ISO 27001 Lead Implementer / Lead Auditor, or CCSP
- Experience with cloud security and modern SaaS environments
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים לבעלי ניסיון מעשי של 3 שנים ומעלה בתחומי אבטחת מידע ו-GRC, המנוסים בביצוע הערכות סיכונים, כתיבת נהלים ועבודה מול תקני אבטחה, ובעלי אנגלית שוטפת. התפקיד פחות מתאים למי שמחפש עיסוק טכני בלבד או חסר רקע ברגולציות, תקנים וכתיבת מסמכי מדיניות.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןCompany Description
Peer Security is a leader in cybersecurity innovation, specializing in web application, mobile, thick client, and infrastructure penetration testing.
Founded by experienced industry researchers, Peer Security is dedicated to helping organizations identify, understand, and reduce cybersecurity risks. We combine deep technical expertise with a practical, customer-focused approach to deliver high-quality security services tailored to each client’s environment and business needs.
Role Description
We are looking for a Cybersecurity GRC Consultant to join our team and lead Governance, Risk, and Compliance activities for our clients.
This is a hands-on role combining cybersecurity knowledge with practical experience in risk assessments, security policies and procedures, regulatory requirements, and security frameworks.
The ideal candidate can understand business, regulatory, and technical requirements and translate them into practical security controls, procedures, and remediation plans.
Responsibilities
• Conduct end-to-end cybersecurity and information security risk assessments, including risk identification, analysis, prioritization, and remediation planning.
• Develop, review, and maintain information security policies, procedures, standards, and guidelines.
• Write and maintain security procedures in areas such as Patch Management, Vulnerability Management, Access Control, Incident Response, Change Management, Backup, Business Continuity, and Disaster Recovery.
• Perform gap assessments against security frameworks, standards, and regulatory requirements.
• Lead and support compliance processes related to ISO 27001, SOC 2, GDPR, NIST, and other relevant security requirements.
• Translate regulatory, compliance, and security requirements into practical technical and organizational controls.
• Work closely with technical teams to understand existing environments, identify security gaps, and define appropriate remediation measures.
• Support clients in preparing for security audits, certifications, and customer security assessments.
• Develop risk treatment and remediation plans and follow up on their implementation.
• Review existing security processes and controls and recommend practical improvements.
• Communicate security risks, gaps, and recommendations clearly to both technical and non-technical stakeholders.
• Work directly with clients and support them throughout security and compliance projects.
Requirements
• 3+ years of hands-on experience in Cybersecurity / Information Security, with a strong focus on GRC, risk management, and compliance.
• Proven hands-on experience conducting cybersecurity and information security risk assessments end to end.
• Experience writing and implementing information security policies and procedures.
• Practical experience working with security frameworks, standards, and regulations such as ISO 27001, SOC 2, GDPR, and NIST.
• Experience conducting gap assessments, control assessments, and compliance readiness projects.
• Good technical understanding of IT environments, cloud infrastructure, applications, networks, and common security controls.
• Familiarity with vulnerability management and penetration testing concepts, including OWASP Top 10.
• Ability to translate identified risks and regulatory requirements into clear and practical remediation actions.
• Strong documentation and stakeholder management skills.
• Ability to communicate effectively with both technical and non-technical audiences.
• Ability to work independently and manage multiple projects and client engagements.
• Fluent English (spoken and written) – MUST.
Advantages
• Experience working in a cybersecurity consulting, penetration testing, or security services company.
• Experience working directly with auditors and certification bodies.
• Relevant certifications such as CISSP, CISM, CISA, ISO 27001 Lead Implementer / Lead Auditor, or CCSP.
• Experience with cloud security and modern SaaS environments.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- 3+ years of hands-on experience in Cybersecurity / Information Security with focus on GRC, risk management, and compliance, Hands-on experience conducting cybersecurity and information security risk assessments end to end, Experience writing and implementing information security policies and procedures, Practical experience working with security frameworks, standards, and regulations such as ISO 27001, SOC 2, GDPR, and NIST, Experience conducting gap assessments, control assessments, and compliance readiness projects