Information Security Governance, Risk & Compliance Manager
МакГрегър България ЕООД · Manager
Умения
Сертификати
Описание
MacGregor – Let's shape the future together
As an Information Security Governance, Risk & Compliance Manager, you develop and maintain our information security Governance, Risk and Compliance programs.
When it comes to Governance and Change Management, you will develop and maintain information security policies, standards, and procedures based on compliance and cyber defense requirements. You will develop and maintain security awareness and compliance training as well as drive improvement initiatives across the Information Security landscape.
On the side of risk you will manage and shape how the organization identifies, documents, and responds to information security risk.
In terms of compliance you will build, maintain, and mature our information security and compliance procedures, leading internal and external audits, ensuring our controls are well-designed, well-documented, and operating effectively.
You will in the role also support other cyber and information security activities to ensure resilience and overall success for MacGregor.
More tasks and responsibilities
- Develop, implement, and maintain information security policies, standards, and procedures
- Conduct risk assessments to identify, evaluate, and prioritize risks; maintain the risk register
- Coordinate and support internal and external audits
- Track remediation of audit findings and control gaps through to closure
- Manage third-party/vendor risk assessments, including security questionnaires and reviews
- Monitor compliance and manage controls are aligned with relevant frameworks, laws and regulations, and contractual obligations
- Develop and deliver security awareness and compliance training
- Support incident response and business continuity/disaster recovery planning
- Prepare reports for leadership on risk posture, compliance status, and audit progress
- Stay current on emerging regulations, threats, and industry best practices
Reporting directly to the Director, Information Security (CISO) located in Finland. The position will be based in MacGregor’s office in Gdansk or Sofia.
What you’ll need to succeed
Good written and verbal communication skills, with the ability to translate varied requirements into understandable and implementable controls, risks and initiatives for both technical and non-technical audiences will be key for a successful candidate. Sound judgment in prioritizing and escalating risk issues in addition to the ability to manage multiple activities and deadlines independently will help you in your daily work. Strong analytical and organizational skills with attention to detail as well as collaborative mindset and comfort working cross-functionally are crucial for this role.
Ideally you have:
- Bachelor's degree in Information Security, Computer Science, Business, or a related field (or equivalent practical experience).
- Relevant certifications preferred, but not required, such as CISA, CRISC, CISSP, CISM, or ISO 27001 Lead Auditor/Implementer.
- 2–5 years of experience in information security, risk management, internal audit, or compliance.
- Working knowledge of common frameworks and regulations (e.g., NIST, ISO 27001, NIS2, GDPR).
- Ability to present information in clear, suficient and understandable manner
- Proficiency with Microsoft Office, particularly spreadsheets and presentations.
Why MacGregor?
Our people are behind every success. People create the technology and product lifecycle solutions that make us great, our people are the ones who innovate, and people drive our business forward. With us you will be part of an international collaborative working culture with challenges and opportunities to further develop yourself professionally.
Values guide our daily decisions
- Customer Success: Our customer's success is our success. We focus on partnership, transparency, and accountability to deliver lifetime value.
- Passion to Improve: Always moving forward. We foster a growth mindset, encourage curiosity, and the courage to challenge the status quo.
- Winning Together: No one makes the difference alone. We emphasise internal collaboration and mutual trust to ensure we win as "One MacGregor."
MacGregor is an equal opportunity employer. We recognise that diversity is key to our continued success, and strive to maintain a fair and equitable recruitment process for all applicants.
Additional Information
Kindly note that we will only review CVs and applications submitted in English through our recruitment portal. Unfortunately we do not consider CVs sent per email.
If you are ready to step into an exciting new role where you can make a significant impact and contribute to the success of MacGregor, apply today!
История на обявата
- 10 октомври 2026 г.Появи сеобхождане
Очаквано възнаграждение
Обявата не посочва заплата. Оценката по-долу е за GRC / Compliance / Risk на ниво Senior според бенчмарка на CSF.BG — не е предложение на работодателя.
Няма нито една обява за тази роля и ниво с публикувана заплата, с която да се сравни.
Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.