Information Security Officer - Senior
ГРУПАМА ЗАСТРАХОВАНЕ ЕАД · Senior
Умения
Сертификати
Описание
Why Groupama?
For over 15 years, Groupama has been a driving force on the Bulgarian insurance market through our two highly successful entities: Groupama Zastrahovane EAD and Groupama Zhivotozastrahovane EAD. As a proud part of the international Groupama Group—a leading French insurance giant boasting 12 million members and 32,000 employees across Europe, Asia, and Africa—we blend global stability with local innovation.
In Bulgaria, we are the exclusive insurance partner of DSK Bank AD, delivering top-tier Credit Protection, Accident, Property, and Motor insurance solutions to millions of customers. We leverage advanced technologies and digital transformation to provide personalized, modern protection in an ever-changing world.
At Groupama, we believe our people are our greatest asset. We cultivate an environment that celebrates innovation, fosters team spirit, and rewards collective success.
We are looking for an Information Security Officer - Senior to join our team. In this pivotal position, you will ensure effective monitoring and implementation of information security processes, manage ICT risks (including vendor/third-party risks), and drive regulatory compliance with DORA (Regulation (EU) 2022/2554) across our financial services operations.
Key Responsibilities
- Information Security & Controls: Monitor, test, and continuously improve security processes, policies, and standards. Represent security requirements in internal and external audits.
- ICT Risk Management: Identify, classify, and mitigate ICT security risks. Maintain the risk register, create risk treatment plans, and report risk statuses to management.
- Vendor & Third-Party Risk Management: Perform pre-contractual and ongoing risk assessments for ICT vendors, review security clauses in contracts, and manage vendor concentration risks.
- DORA Compliance: Assist in developing the ICT risk framework, maintain the register of information for ICT agreements, support operational resilience testing, and manage ICT incident reporting according to regulatory requirements.
Requirements & Qualifications
- Education: Bachelor's or Master's degree in Cybersecurity, Computer Science, Business Informatics, or a related field.
- Experience: 3+ years of professional experience in information security management, with demonstrated experience in risk management and vendor/third-party risk management.
- Regulatory & Framework Knowledge:
- Deep understanding of information security standards (NIST CSF, ISO/IEC 27001/17/18, SOC 2, ISO 31000/27005).
- Solid knowledge of DORA requirements and related technical standards (RTS/ITS).
- Certifications: CISM, CISA, or NIST Practitioner certifications are considered strong advantages.
- Languages: Fluent spoken and written English.
- Key Skills: Analytical mindset, precision, excellent presentation and communication skills, ability to negotiate contract terms, and strong team coordination capabilities.
What We Offer in Return
- Rewards: Competitive salary and performance-based bonus system.
- Health & Wellness: Premium additional health insurance, food vouchers, and an extra paid day off to celebrate your birthday.
- Work-Life Balance: A flexible, modern hybrid work model and a progressive paid annual leave policy that increases with your tenure.
- Growth: Access to specialized leadership academies and international training programs.
- Environment: A vibrant, conveniently located office and a collaborative team culture that feels like family.
- Referral Program: An attractive internal referral bonus scheme.
If our offer is interesting for you and you feel that you meet the above requirements, please apply by sending your CV. Only short-listed candidates will be invited for an interview.
All applications will be treated with strict confidentiality under the provisions of the Law for Protection of Personal Data.
История на обявата
- 10 октомври 2026 г.Появи сеобхождане
Очаквано възнаграждение
Обявата не посочва заплата. Оценката по-долу е за Security Engineer (Cloud / Network) на ниво Senior според бенчмарка на CSF.BG — не е предложение на работодателя.
Само 2 обяви за тази роля и ниво публикуват заплата — твърде малко за средна стойност.
Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.