Sign up to save this job, get alerts, and apply with an optimized CV.
Cybersecurity, GRC & Compliance Consultant
Senior
Job description
Candidate Ideal
Role Overview
This role is responsible for leading governance, risk, and compliance programs, managing cybersecurity and information systems audit initiatives, and developing end-to-end compliance frameworks aligned with EU and international standards. You will collaborate closely with technical teams, legal stakeholders, and executive leadership to enhance security resilience and drive strategic cybersecurity governance.
Required Certifications:
Expected Impact in the First 12 Months
Cybersecurity Governance & Risk Management
GRC & Compliance
Privacy & Data Protection
What we can offer:
With entrepreneurial thinking and business oriented, we are a multidisciplinary team willing to analyse, build and participate in brainstorming in order to identify optimal solutions for business development.
Curious to know more about us? Click on Apply and let's have a meeting.
This role is responsible for leading governance, risk, and compliance programs, managing cybersecurity and information systems audit initiatives, and developing end-to-end compliance frameworks aligned with EU and international standards. You will collaborate closely with technical teams, legal stakeholders, and executive leadership to enhance security resilience and drive strategic cybersecurity governance.
Required Certifications:
- CIPP/E Certified Information Privacy Professional/Europe
- CIPT – Certified Information Privacy Technologist (IAPP)
- CISA – Certified Information Systems Auditor (ISACA)
- AIGP – AI Governance Professional (IAPP)
- Strong background in cybersecurity, information systems auditing, governance, and regulatory compliance.
- Deep understanding of EU frameworks (GDPR, NIS2, DORA) and global standards (ISO 27001, SOC 2, PCI-DSS, HIPAA).
- Exceptional communication, advisory, and cross-functional leadership skills.
- Ability to translate complex technical and legal concepts into clear, actionable guidance for business leaders.
- English speaker;
- Ambition and desire to assert oneself through performance;
- Willingness to learn continuously
- Positive attitude and orientation towards the client (to have charisma)
- Ability to synthesize, observe, organize, and manage time efficiently
- Ability to have flexibility of the schedule, with orientation of the client’s needed
- Practice profession with passion
- Loyalty about the company and culture of company
- Family center of his/her principal value
Expected Impact in the First 12 Months
- Increase the GRC maturity level of supported organisations.
- Achieve successful ISO, SOC 2, NIS2, and DORA audit outcomes.
- Implement a structured enterprise IT & cyber risk management framework.
- Improve security posture and reduce regulatory or operational incidents.
Cybersecurity Governance & Risk Management
- Conduct comprehensive information systems audits, identify critical vulnerabilities, and develop remediation and risk-mitigation plans.
- Evaluate security controls across network security, identity and access management, intrusion detection, and zero-trust architecture.
- Lead cybersecurity maturity assessments for critical infrastructure and enterprise environments.
GRC & Compliance
- Manage full-cycle compliance projects for NIS2, ISO 27001, SOC 2, and DORA, from gap analysis to audit readiness and successful certification.
- Develop governance and operational-resilience frameworks for clients in the financial sector, healthcare, e-commerce, and technology.
- Drive IT governance processes and create policies, procedures, and enterprise-level risk methodologies.
Privacy & Data Protection
- Perform DPIAs, LIAs, ROPA, and design privacy policies to ensure robust GDPR compliance and effective regulatory engagement.
- Build and deliver tailored training programs on data privacy and cybersecurity awareness.
- Analyse regulatory implications on client operations and deliver strategic recommendations to senior leadership.
- Advise stakeholders on aligning business processes with technical and regulatory cybersecurity requirements.
- Contribute to national cybersecurity initiatives, including expert input for the transposition of the NIS2 Directive.
What we can offer:
- A pleasant and dynamic work environment where you can't get bored;
- The chance to learn and develop continuously - by participating in programs, courses, etc. in accordance with the established career plan;
- Private health insurance;
- Participation at conferences and business events paid by the company;
- Continuous training and preparation
- Flexible schedule: from home and from the office
- Open minded management vision
With entrepreneurial thinking and business oriented, we are a multidisciplinary team willing to analyse, build and participate in brainstorming in order to identify optimal solutions for business development.
Curious to know more about us? Click on Apply and let's have a meeting.
Required skills
Sign up to apply
Create a free account to apply for this job and get access to:
- AI-powered CV optimization for this specific job
- Save jobs and create custom alerts
- See your CV match score for each job
Company information
- Company
- DECALEX DIGITAL S.R.L.
- Location
-
Bucuresti
Romania - Posted
- 9 months ago
Interested in this position?
Create your free account and tailor your CV to match this job.