Information Security Specialist (GRC Analyst)
About the company
SoftServe Business Systems was founded in 2003. We aim high; our mission is to lead the digital revolution in the FMCG industry. It means delivering the best products & services possible that empower businesses to grow and improve efficiency.
We are a product company, and this affects our day-to-day activities. Our team is highly involved in the client’s needs, we value business expertise, and we take every step with extra carefulness. Among our clients are businesses like AB InBev, Unilever, JDE, PepsiCo, Henkel, and others.
SoftServe Business System’s ideal candidate is someone who can implement and support the Information Security Management System throughout the company and ensure the company’s compliance with information security requirements (client’s or regulatory).
Requirements
- 1-2 years of experience in information security
- Experience in creating and maintaining security documentation
- Experience in participating in internal and external audits
- Knowledge of risk management techniques
- Strong knowledge of Information Security standard ISO 27001/27002
- Understanding of data protection regulation (GDPR)
- Ability to work on multiple projects independently
- Ability to lead meetings, record meeting minutes and document decision outcomes
- Experience with process development, analysis, implementation, and continuous improvement methodologies
- Excellent analytic skills
- Detail-oriented with strong organizational and prioritization skills
- Upper-Intermediate English level (both speaking and writing)
- Information Security or Computer science
Responsibilities
- Provide an annual Security Risk Assessment, documenting identified system vulnerabilities, mitigating controls and residual risk(s)
- Responsible for the creation and maintenance of IS policies and standards based on knowledge of best practices and compliance requirements.
- Collaborate with different departments to describe processes
- Identify security requirements and provide consultancy for its implementation.
- Facilitate internal, external and third-party audits, organize meetings and prepare all necessary input information
- Analysis of client security requirements and define possible non-compliance
- Work with various teams to track system and application security weaknesses from identification to remediation/risk acceptance
- Responsible for compliance with personal data protection laws (GDPR)