- Strong understanding of Information Security and Cybersecurity principles.
- Knowledge of Governance, Risk, and Compliance (GRC) processes.
- Experience with cybersecurity frameworks and standards (ISO 27001, NIST, CIS Controls).
- Basic understanding of cloud security, infrastructure security, application security, and data protection concepts.
- Experience in preparing and advising business on different mitigation strategies that would best fit the situation • Experience managing risk registers, KRIs, KPIs, and remediation tracking.
- Strong reporting, dashboarding, and analytical skills.
Behavioral
Competencies • Solid stakeholder management and influencing skills.
- Flexibility and ability to adjust approach,
frameworks and controls to specific business cases and risks • Excellent communication and presentation capabilities.
- Analytical and problem-solving mindset.
- Ability to prioritize and manage multiple risks and initiatives.
- Collaboration and teamwork across global and multicultural environments.
- High attention to detail and governance discipline. Good to Have • Functional & Technical Skills • Experience with NIS2, GDPR, and other regulatory frameworks.
- Knowledge of Third-Party Risk Management (TPRM).
- Experience with cybersecurity risk management tools and GRC platforms (e.g., ServiceNow GRC, Archer).
- Understanding of Security Operations, Vulnerability Management, and Incident Response processes.
- Data analytics and reporting automation capabilities (Power BI, Tableau, Excel advanced analytics).