Sr. InfoSec Risk Analyst
Solvex Solutions · Sofia, Bulgaria · Senior
Умения
Сертификати
Описание
Job Title: Senior Information Security Risk Analyst
Job Location: Sofia, BG
(Hybrid working model - 3 days onsite, 2 day remote)
We're a recruitment agency hiring on behalf of our client for a full-time, permanent position. Our client is a leading European fintech company, delivering innovative financial solutions to clients worldwide.
Your role:
- Establish, review, and continuously improve information security policies, standards, and procedures in response to evolving cyber and technology risks.
- Identify and assess technology risks, ensuring appropriate IT controls and operational processes are in place to mitigate them.
- Develop and maintain a comprehensive risk assessment process, including an internal risk register to track all technology risks to completion.
- Prepare risk reports for management and monitor the progress of remediation activities.
- Lead and coordinate the third-party risk management process, including external security assessments and audits.
- Support the Data Governance program and maintain applicable information security policies and standards.
- Record and maintain IT processes, risks, and controls within the organisation's GRC platform.
- Develop, document, and maintain security incident reporting processes and procedures, including stakeholder communication.
What makes you stand out:
- Minimum 6/7 years of experience in information security risk, audit, or a closely related field.
- Proven experience preparing enterprise-level risk reporting, including risk appetite statements, Key Risk Indicators (KRIs), and Key Performance Indicators (KPIs).
- Familiarity with GRC platforms and experience documenting IT processes, risks, and controls within such systems.
- Experience developing and delivering information and technology risk training material.
- Experience independently reviewing and updating corporate security policies, standards, and procedures,
- Familiarity with COBIT, ISO 27001 and PCI DSS.
- Experience managing or leading regular audits of IT processes and technology implementations to assess compliance with regulatory requirements, contractual obligations, and internal policies.
- Strong written communication skills, with experience producing risk reports and incident documentation for senior stakeholders.
Additional Advantages
- Bachelor's degree in computer science, information systems, or a related field
- One or more of the following certifications: CISA, CISM, CRISC, or CISSP.
Why join?
💰Annual performance bonus
📄Full-time & permanent position
🏡Hybrid model (2 remote days/week)
🎁Customizable benefits package
🏥Health insurance
🏃Sports card & team activities
🖥️ Modern, well-equipped office setup
🍎Free fruits, snacks & stocked kitchen
✨Plus many additional perks
interested? Let's connect!
История на обявата
- 1 август 2026 г.Появи сеобхождане
- 13 август 2026 г.Затворенаобхождане
Очаквано възнаграждение
Обявата не посочва заплата. Оценката по-долу е за GRC / Compliance / Risk на ниво Senior според бенчмарка на CSF.BG — не е предложение на работодателя.
Няма нито една обява за тази роля и ниво с публикувана заплата, с която да се сравни.
Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.