Job Description:
Collaborate closely with your Product Owner, Project Manager and other team members to successfully complete and implement project deliverables related to IT & cyber security governance, IT controls, privacy and GDPR
Facilitate technical workshops with stakeholders from Security, Legal, Compliance, Risk, technical and non-technical subject-matter experts across various business units
Elicit and evaluate requirements from a regulatory (privacy) and user angle and translate needs into user stories that are understood by the technical teams and other related stakeholders
Be responsible for revision of governing documentation, analysis of requirements, detection of nonconformities, and develop recommendations
Identify underlying business needs and risks that needs to be addressed, challenge and improve existing practices and lead business analysis in your area with example
Develop security roadmaps, document new roles and responsibilities, workflows and controls in Standard Operating Procedures and Business Procedures
Translate conceptual ideas into visual representations to drive effective roadmap, product, process development
Perform review of risk assessments framework, security governance and architecture, develop privacy and security awareness and training
Create and deliver key reporting to meet regulatory requirements and business needs
About you:
12 + years of experience as business analyst or consultant in cyber and information security / information security governance / data & analytics area, ideally from a medium or large corporation working with sensitive data
Solid understanding of security frameworks, e.g. NIST, ENISA RM/RA, and standards, e.g. ISO27k is required
Solid understanding of regulations, e.g. GDPR, PCI is required
Strong knowledge of IT governance, data security and information protection are required
Strong knowledge of IT controls, risk management processes, risk assessments, risk responses and risk management strategy
Experience with business/functional analysis, methodologies and techniques and their practical application
Experience with reviewing and creating documentation such as security policies and procedures as well as great communication and facilitation skills
Advanced English language skills