Sign up to save this job, get alerts, and apply with an optimized CV.

Information Security Officer

Senior

Job description

Ideal Candidate

Competences and relevant experience:
  • Higher education in information security, computer science or related fields
  • Minimum 5 years of experience in cybersecurity/information risk management and 8-10 years of IT experience
  • Experience in incident response, risk management, and coordinating security programs
  • Solid knowledge about security technologies, cyber threats, and compliance
  • Multi-platform experience: Windows, Linux, Mac, Android, cloud (AWS/Azure), network
  • Knowledge in EDR, SIEM/SOAR, vulnerability management, hardening, policies, and compliance
  • Experience in security architecture, Identity & Access Management, Business Continuity/Disaster Recovery
  • Certifications that constitute an advantage: CISSP, CISM, CEH, CRISC, ISO 27001
  • Leadership skills, strategic thinking, and ability to work efficiently under pressure
  • Excellent communication and analysis skills
  • Integrity and respect for confidentiality.

Job Description

Job Purpose:
Information Security Officer – ISO develops, implements, and oversees the information security strategy and measures to protect the organization's assets. The role ensures the security of information assets, compliance with regulatory obligations, and continuous improvement of cyber resilience. Information Security Officer – ISO coordinates initiatives related to risk management, incident response, business continuity planning, reducing vulnerabilities, and employee awareness.

Responsibilities:

1. Developing the security program
  • Developing, implementing, and maintaining a comprehensive information security program aligned with industry frameworks (e.g., ISO 27001, NIST)
  • Defining and updating policies, standards, and procedures for security
  • Conducting periodic maturity evaluations and promoting continuous improvement
  • Maintaining regular monitoring and evaluation of implemented security measures for services and products developed by the company, throughout their entire lifecycle

2. Managing incident response
  • Governing and updating the Incident Response Plan (IRP)
  • Coordinating activities for managing incidents: detection, isolation, elimination, recovery, and post-incident analysis
  • Coordinating forensic investigations and documentation

3. Business continuity and crisis management
  • Developing and maintaining the Business Continuity Plan (BCP) and crisis management framework
  • Coordinating impact analyses and exercises for business continuity
  • Providing decision-making support and leadership in crisis situations to ensure operational resilience

4. Risk evaluation and management
  • Conducting periodic risk evaluations for security, focusing on systems, projects, and third-party vendors
  • Identifying threats, vulnerabilities, and potential impact on business operations
  • Developing measures to reduce risks and maintaining the risk register

5. Vulnerability management
  • Developing and coordinating vulnerability management programs for the organization
  • Coordinating periodic vulnerability scans, penetration testing, and configuration evaluations
  • Collaborating with IT and engineering teams to prioritize remediation based on risk
  • Maintaining regular monitoring of vulnerability closure and ensuring compliance with SLAs

6. Compliance and regulations
  • Ensuring compliance with applicable regulations regarding information security and data protection (e.g., NIS2, GDPR, eIDAS, industry standards)
  • Coordinating internal and external audits, evaluations, and certification processes
  • Maintaining documentation for compliance and providing support for reporting to authorities

7. Awareness and training in security
  • Developing and delivering awareness and training programs for information security
  • Organizing phishing simulations, workshops, and training sessions for high-risk roles
  • Promoting a security-oriented organizational culture

For this position, the company reserves the right to request professional references and/or letters of recommendation.

About the Company

Who we are

certSIGN is a Romanian company that develops products and services aimed at ensuring information security and protection.

The story begins in 2006, when we started with a small team of enthusiastic and ambitious people. Today, we are the most important provider of trust services at the national level and certified at the European level, pioneers on the Romanian market through the introduction of paperless technologies in business processes, software solution producers, cybersecurity solutions implementers, and archiving implemented with success in 20 countries.

Business areas

Servicii de încredere (semnătură electronică calificată, marcare temporală, certificate SSL) Securitate cibernetică Identitate digitală Arhivare fizică și electronică

Our team

certSIGN has a qualified team of experts with numerous certifications and solid technical competencies, proven in important projects for implementing complex security solutions for information protection, research and development, consulting, and auditing. The innovative spirit is our main quality, as most of the company's solutions are proprietary products developed internally.

We are leaders on the Romanian market for electronic signatures. We are pioneers of digital tachographs in Romania and a provider of digital tachograph solutions in 20 countries across Europe and Asia. We are the only provider of PKI and data encryption solutions in Romania. We are proud to be certSIGN!

Certifications

Prestator de Servicii de Încredere Calificat conform eIDAS, WebTrust, Trusted Introducer, ORNISS și NATO pentru produse destinate protecției informațiilor clasificate, ISO 9001, ISO 37001, ISO 18001, ISO 14001.

Sign up to apply

Create a free account to apply for this job and get access to:

  • AI-powered CV optimization for this specific job
  • Save jobs and create custom alerts
  • See your CV match score for each job

Company information

Company
CERTSIGN SA
Location
Bucuresti
Romania
Posted
5 months ago

Find similar jobs

Explore more opportunities like this one.

Interested in this position?

Create your free account and tailor your CV to match this job.