Senior Information Technology Auditor
Recruitify Global · Sofia, Sofia City, Bulgaria · Senior
Умения
Сертификати
Описание
Our client is a fast-growing company based in Bulgaria, delivering advanced offensive security, risk management, and compliance solutions to organizations operating in highly regulated environments. They support clients across FinTech, banking, and digital sectors by strengthening their security posture and ensuring compliance with international standards.
Role Overview:
We are seeking a Sr. IT Auditor / Security Compliance Analyst (GRC) ( 4+ years of experience) to join their cybersecurity practice. This role is focused on supporting the design, implementation, and monitoring of governance frameworks, risk management processes, and compliance programs. You will work closely with senior consultants, security engineers, and international clients, gaining hands-on exposure to real-world cybersecurity governance projects. This is an ideal entry point into cybersecurity consulting, with a clear path toward advanced GRC and advisory roles.
Key Responsibilities
Governance
•Support the development and maintenance of security policies, procedures, and standards
Assist in implementing cybersecurity governance frameworks
Document organizational security controls and processes
Participate in internal and client governance reviews
Risk Management
Assist in conducting risk assessments and maintaining risk registers
Identify, analyze, and document security risks
Track remediation plans and mitigation activities
Support risk workshops and stakeholder discussions
Compliance
Support compliance initiatives across frameworks such as: o ISO 27001 o NIST CSF o NIS2 o GDPR o PCI-DSS
Assist with gap assessments and control mapping • Prepare organizations for audits and regulatory assessments
Maintain compliance documentation and evidence
Reporting & Documentation
Prepare security assessment reports and risk summaries
Contribute to security governance and strategy documentation
Maintain documentation repositories and control libraries
Support executive and operational reporting
Advisory Support
Assist senior consultants in client advisory engagements
Support security awareness initiatives and governance training
Contribute to internal GRC methodologies, templates, and frameworks
Required Qualifications
Bachelor’s degree in: o Cybersecurity o Information Security o Information Technology o Computer Science o Risk Management o Or related field
OR equivalent practical experience in cybersecurity/compliance
Preferred Skills
Understanding of cybersecurity principles and controls
Basic knowledge of risk management methodologies
Familiarity with frameworks such as: o ISO 27001 o NIST o CIS Controls
Strong analytical and documentation skills
Ability to communicate technical concepts clearly
Attention to detail and structured thinking
Basic understanding of IT infrastructure and cloud environments
Nice to Have
Entry-level certifications: o ISO 27001 Foundation o CompTIA Security+ o ISACA ITF+ / CISA (in progress) o ISC2 Certified in Cybersecurity
Exposure to: o GRC platforms o Compliance tools o Risk registers o Security policy development
Personal Profile
Strong motivation to build a career in cybersecurity & GRC
Structured, analytical, and detail-oriented mindset
Strong organizational and prioritization skills
Team player with a consulting mindset
Professional communication and stakeholder management skills
What We Offer
Exposure to real-world international cybersecurity projects
Work with leading frameworks and regulations (NIS2, DORA, ISO)
Mentorship from senior cybersecurity & GRC experts
Clear career progression toward: o GRC Consultant o Risk Analyst o Compliance Specialist o vCISO track
All applications will be treated strictly confidentially.
Only short-listed candidates will be contacted.
РЕКРУТИФАЙ ЕООД притежава лиценз, регистриран към Министерството на Труда и
социалната политика за извършване на посредническа дейност с Удостоверение
№3521/18.05.2023 и Удостоверение №3522/18.05.2023
История на обявата
- 12 август 2026 г.Появи сеобхождане
- 7 септември 2026 г.Затворенаобхождане
- 16 септември 2026 г.Отворена отновообхождане
Очаквано възнаграждение
Обявата не посочва заплата. Оценката по-долу е за GRC / Compliance / Risk на ниво Senior според бенчмарка на CSF.BG — не е предложение на работодателя.
Няма нито една обява за тази роля и ниво с публикувана заплата, с която да се сравни.
Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.