ЗатворенаLinkedIn

Sr. InfoSec Risk Analyst

Solvex Solutions · Sofia, Bulgaria · Senior

1 август 2026 г.
Първо видяна
12 август 2026 г.
Последно видяна
13 август 2026 г.
Статус
11 дни
Беше отворена

Умения

risk assessmentrisk managementcomplianceISO 27001PCI DSSauditGRC

Сертификати

Изискват се

Описание

Job Title: Senior Information Security Risk Analyst

Job Location: Sofia, BG

(Hybrid working model - 3 days onsite, 2 day remote)

We're a recruitment agency hiring on behalf of our client for a full-time, permanent position. Our client is a leading European fintech company, delivering innovative financial solutions to clients worldwide.

Your role:

  • Establish, review, and continuously improve information security policies, standards, and procedures in response to evolving cyber and technology risks.
  • Identify and assess technology risks, ensuring appropriate IT controls and operational processes are in place to mitigate them.
  • Develop and maintain a comprehensive risk assessment process, including an internal risk register to track all technology risks to completion.
  • Prepare risk reports for management and monitor the progress of remediation activities.
  • Lead and coordinate the third-party risk management process, including external security assessments and audits.
  • Support the Data Governance program and maintain applicable information security policies and standards.
  • Record and maintain IT processes, risks, and controls within the organisation's GRC platform.
  • Develop, document, and maintain security incident reporting processes and procedures, including stakeholder communication.

What makes you stand out:

  • Minimum 6/7 years of experience in information security risk, audit, or a closely related field.
  • Proven experience preparing enterprise-level risk reporting, including risk appetite statements, Key Risk Indicators (KRIs), and Key Performance Indicators (KPIs).
  • Familiarity with GRC platforms and experience documenting IT processes, risks, and controls within such systems.
  • Experience developing and delivering information and technology risk training material.
  • Experience independently reviewing and updating corporate security policies, standards, and procedures,
  • Familiarity with COBIT, ISO 27001 and PCI DSS.
  • Experience managing or leading regular audits of IT processes and technology implementations to assess compliance with regulatory requirements, contractual obligations, and internal policies.
  • Strong written communication skills, with experience producing risk reports and incident documentation for senior stakeholders.

Additional Advantages

  • Bachelor's degree in computer science, information systems, or a related field
  • One or more of the following certifications: CISA, CISM, CRISC, or CISSP.

Why join?

💰Annual performance bonus

📄Full-time & permanent position

🏡Hybrid model (2 remote days/week)

🎁Customizable benefits package

🏥Health insurance

🏃Sports card & team activities

🖥️ Modern, well-equipped office setup

🍎Free fruits, snacks & stocked kitchen

✨Plus many additional perks

interested? Let's connect!

История на обявата

  • 1 август 2026 г.Появи сеобхождане
  • 13 август 2026 г.Затворенаобхождане

Очаквано възнаграждение

Обявата не посочва заплата. Оценката по-долу е за GRC / Compliance / Risk на ниво Senior според бенчмарка на CSF.BG — не е предложение на работодателя.

€2,200 – €4,200нето/месец · 5+ години опит
Средно търсене·Всички нива за ролята

Няма нито една обява за тази роля и ниво с публикувана заплата, с която да се сравни.

Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.