Remote Jobs RockRemote Jobs Rock

Information Security Risk Officer

πŸ“… Feb 5, 2024
Information SecurityRisk ManagementRisk AssessmentIT Infrastructure

πŸ“œ Description

  • Plan and execute technical and targeted risk assessments in IT infrastructure and applications.
  • Assess internal controls and develop remediation strategies for identified deficiencies.
  • Perform risk analysis and maintain the risk register and Information Security Risk Management Program.
  • Prepare comprehensive reports summarizing actions taken to remediate identified risks.
  • Act as the escalation point for any information security related risks.

πŸ› οΈ Requirements

  • BSc/MSc in Information Security or any other relevant degree
  • At least 3 years of work experience in information security risk management and information security risk assessment
  • Technical knowledge of operations, physical, network, host and application security, as well as security architecture, virtualisation, and cloud infrastructures
  • Good understanding of security regulations and frameworks, such as ISO 27005, ISO 27001, NIST CSF and 800-53, DORA, GDPR, etc
  • Ability to work autonomously with minimum supervision and to integrate well within a team
  • Ability to articulate security risks and communicate effectively to various levels of management
  • Self-motivated, proactive, and efficient
  • Ability to work under pressure in a fast paced environment
  • Strong interpersonal, organisational, and project management skills
  • Excellent communication skills with the ability to explain technical concepts to a non-technical audience.

✨ Benefits

  • Attractive remuneration package
  • Private health insurance
  • Corporate pension fund
  • Intellectually stimulating work environment
  • Continuous personal development and international training opportunities
Full job description
The role:
Join our dynamic Information Security GRC team to play a crucial role in strengthening our business operations. As a key member, you'll enforce our Information Security Framework, conduct internal risk assessments, and collaborate your line manager to define assessment scopes. Your responsibilities will include: review internal systems, processes, and procedures, record risks, and prepare insightful reports. Additionally, you'll contribute to Information Security projects, ensuring state-of-the-art solutions in line with regulatory requirements and best practices. This is an opportunity to make a significant impact in a forward-thinking environment, safeguarding our business while driving innovation in Information Security. Join us for a fulfilling journey!
All applications will be treated with strict confidentiality!

The main responsibilities of the position include:

  • Plan and execute technical and targeted risk assessments in IT infrastructure, applications, technologies, and third parties
  • Assess internal controls, processes, and policies related to Information Technology and Security, identify deficiencies, and develop remediation strategies
  • Perform risk analysis on current risks and identify potential risks at operational, tactical, and strategic level
  • Perform risk evaluation on previously handled risks and compare mitigation approaches to potential risks
  • Maintain the risk register and the Information Security Risk Management Program
  • Identify information security risks and make recommendations that are appropriate, practical, and cost-effective
  • Manage and monitor the progress of remediation steps on risk assessment findings
  • Prepare comprehensive reports summarising the actions taken for to remediate identified risks
  • Provide regular reports and metrics on the security posture of the company
  • Act as the escalation point of the information security department for any information security related risks
  • Main requirements:

  • BSc/MSc in Information Security or any other relevant degree
  • At least 3 years of work experience in information security risk management and information security risk assessment
  • Technical knowledge of operations, physical, network, host and application security, as well as security architecture, virtualisation, and cloud infrastructures
  • Good understanding of security regulations and frameworks, such as ISO 27005, ISO 27001, NIST CSF and 800-53, DORA, GDPR, etc
  • Risk-related certifications, such as CRISC, CGRC, and CISSP, are a plus
  • Ability to work autonomously with minimum supervision and to integrate well within a team
  • Ability to articulate security risks and communicate effectively to various levels of management
  • Self-motivated, proactive, and efficient
  • Ability to work under pressure in a fast paced environment
  • Strong interpersonal, organisational, and project management skills
  • Excellent communication skills with the ability to explain technical concepts to a non-technical audience.
  • Excellent written and verbal skills in English
  • Benefit from:

  • Attractive remuneration package
  • Private health insurance
  • Corporate pension fund
  • Intellectually stimulating work environment
  • Continuous personal development and international training opportunities
  • The Hiring Experience: What Awaits You

  • Let’s Connect – Intro Chat with Talent Acquisition
  • Deep Dive – First Interview with Your Future Team
  • Final Connection – Final Interview
  • Cloudflare

    Rack Integration Operations Engineer

    πŸ•’ 2 days ago
    CloudflareπŸ‘₯ 10,000+ employees🏒 Computer And Network Security🀝 B2B

    As a Rack Integration Operations Engineer, you will ensure BOM accuracy, optimize materials planning, and modernize operations through AI-enabled automations while collaborating with hardware partners.

    Bill Of Materials (bom) ManagementHardware Vendor ManagementContract ManufacturingTechnical Specifications Evaluation
    Abnormalsecurity

    Software Engineer II - Insider Risk

    πŸ•’ 2 days ago
    AbnormalsecurityπŸ‘₯ 1001 - 5000 employees🏒 Computer & Network Security

    Build and enhance identity verification and fraud detection systems to protect organizations from insider threats and fraudulent employee identities.

    Software DevelopmentFraud DetectionIdentity VerificationData Analysis
    Replit

    Staff Software Engineer, Identity & Authorization

    πŸ•’ 2 days ago
    ReplitπŸ‘₯ 10,000+ employees🏒 Software Development🀝 B2B

    Design, build, and operate identity and authorization systems that secure critical interactions on Replit, enabling efficient and reliable user and agent identity management.

    Oauth 2.0OIDCJWTMtls
    Aecom2

    OLE Engineer

    πŸ•’ 2 days ago
    Aecom2πŸ‘₯ 10,000+ employees🏒 Architecture And Engineering🀝 B2B

    The OLE Engineer will engage in design activities for international railway projects, focusing on technical reports, structural design, and interdisciplinary collaboration.

    OLE DesignStructural DesignTechnical ReportingCAD Tools
    Cloudflare

    Software Engineer - Egress (Go/Rust)

    πŸ•’ 2 days ago
    CloudflareπŸ‘₯ 10,000+ employees🏒 Computer And Network Security🀝 B2B

    As a key technical contributor on the Egress team, you will enhance Cloudflare's network software infrastructure, ensuring robust connectivity for various products.

    GoRustLinux NetworkingClickhouse

    Trusted by Remote Workers