ЗатворенаLinkedIn

IT Security & Compliance Specialist

WOGI · Bulgaria · Lead

12 август 2026 г.
Първо видяна
19 август 2026 г.
Последно видяна
20 август 2026 г.
Статус
7 дни
Беше отворена

Умения

business continuitysecurity awarenessincident responsedisaster recoveryrisk managementcloud securityzero trustcomplianceISO 27001SOC 2GDPRIAMMFAGRCOkta

Сертификати

Изискват се

Описание

🛡️ About the Role

We are looking for a proactive and detail-oriented IT Security & Compliance Specialist to strengthen our digital fortress 🏰 and lead our compliance initiatives!

In this role, you will bridge the gap between technical security controls and business enablement. Your mission? To ensure our infrastructure is locked down, our processes comply with global standards, and our prospective enterprise clients sleep like babies knowing their data is in safe hands. 🤝🔒

🔑 Key Responsibilities

🤝 Enterprise Client Enablement & Audits

Lead vendor security reviews by taking charge of Security Questionnaires and RFIs for prospective and current clients.

Be the primary point of contact for external auditors, enterprise clients, and third-party security assessors.

Review security & privacy clauses in client contracts and Data Processing Agreements (DPAs).

📋 Compliance & Standards Management

Drive our compliance engine: maintain and expand frameworks including ISO/IEC 27001, SOC 2 (Type I & II), and GDPR. 📜

Run internal security audits, risk assessments, and vulnerability reviews across all systems and teams.

Build & refine core security policies (Incident Response, Access Control, Business Continuity, Disaster Recovery, etc.).

🔐 Security Operations & Risk Mitigation

Implement internal security tools, access management protocols (Zero Trust, IAM, MFA), and endpoint protections. 💻

Monitor threats, manage security incidents, and conduct root-cause analyses whenever an event pops up.

Manage vendor risk (Vendor Risk Management) to ensure our suppliers meet our strict security standards.

Empower the team: design and execute engaging security awareness and anti-phishing training programs for all employees. 🎣🚫

🎯 Requirements & Qualifications

  • Experience: 3+ years of hands-on experience in information security, IT compliance, or GRC roles (preferably in a B2B SaaS or IT environment). 💼
  • Compliance Knowledge: Strong working knowledge of frameworks such as ISO 27001, SOC 2, GDPR, and risk management practices. 📚
  • Technical Aptitude: Solid understanding of cloud security, network basics, IAM, and endpoint security.
  • Communication Superpowers: Excellent verbal and written English. You can explain complex security concepts to non-technical stakeholders with ease. 🗣️🇬🇧
  • Analytical Mindset: Sharp attention to detail, strong problem-solving abilities, and a structured approach to documentation. 🧠

⭐ Nice-to-Haves (Bonus Points!)

🔥 Relevant certifications such as CISA, CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or Security+.

🛠️ Experience with automated compliance and GRC platforms (e.g., Vanta, Drata, Secureframe).

🌐 Hands-on experience with modern access control solutions (e.g., Cloudflare Zero Trust, Okta, Google Workspace Admin).

История на обявата

  • 12 август 2026 г.Появи сеобхождане
  • 14 август 2026 г.Затворенаобхождане
  • 19 август 2026 г.Отворена отновообхождане
  • 20 август 2026 г.Затворенаобхождане

Очаквано възнаграждение

Обявата не посочва заплата. Оценката по-долу е за GRC / Compliance / Risk на ниво Senior според бенчмарка на CSF.BG — не е предложение на работодателя.

€2,200 – €4,200нето/месец · 5+ години опит
Средно търсене·Всички нива за ролята

Няма нито една обява за тази роля и ниво с публикувана заплата, с която да се сравни.

Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.