Security Engineer
GRC Lead (Cybersecurity)
Bucharest
Apply on the employer's siteRole description
Job Description
We are looking for a GRC Lead to drive the cybersecurity governance, risk, and compliance program of a large enterprise. You will work closely with Legal, Privacy, Risk Management, and Government Affairs teams to address evolving regulatory requirements. This is a 12-month fully remote engagement. Fluent English is mandatory; French is a plus. Primary skills include GRC, GDPR, NIS2, ISO 27001, and the development of information security policies and procedures; secondary skills include NIST CSF and Privacy Management.
Core Responsibilities
- Lead the GRC Program: Drive the cybersecurity governance, risk, and compliance program across the enterprise.
- ISMS Ownership: Establish, implement, and continuously improve the Information Security Management System (ISMS) in line with ISO 27001/2.
- Policies and Frameworks: Develop, maintain, and improve policies, standards, procedures, and governance frameworks covering information security, privacy, data protection, and incident response.
- Enterprise Risk Management: Manage an enterprise-wide cybersecurity and risk program protecting the confidentiality, integrity, and availability of information assets; conduct risk assessments and support business units in identifying and mitigating security and compliance risks.
- Regulatory Expertise: Provide subject matter expertise on global cybersecurity and privacy regulations and frameworks, including GDPR, NIS2, ISO 27001/2, and NIST CSF.
- Audits and Assessments: Perform compliance assessments, audits, and gap analyses; oversee remediation initiatives; support internal and external audits, certification activities, and regulatory examinations.
- Threat and Control Evaluation: Evaluate security threats, vulnerabilities, and control effectiveness; communicate risks and recommendations to business and technical stakeholders; recommend security and privacy controls for new and existing technologies, applications, and infrastructure.
- Strategic Alignment and Reporting: Align cybersecurity, privacy, and compliance initiatives with organizational objectives; lead related governance and project management activities; deliver compliance reporting, governance metrics, and risk dashboards; monitor emerging threats, regulatory developments, and industry best practices; promote security and privacy-enhancing technologies.
Qualifications And Experience
- Proven experience leading GRC programs in complex enterprise environments.
- Deep expertise in GDPR, NIS2, ISO 27001/2, and information security policy development.
- Working knowledge of NIST CSF and Privacy Management.
- Strong stakeholder communication skills across business, legal, and technical audiences.
- Fluent English; French is a plus.
This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.