UN
Hiring from
Ukraine
Work type
Remote
Posted
Sep 27, 2026
Is this job info correct?

CISO / Information Security Consultant (GRC) (ISO27001, SOC2)


Requirements:

  • 4+ years in IT security and compliance

  • Extensive, practice-based knowledge of security management frameworks, such as ISO 27k series, GDPR, SOC2 etc.;

  • Proven track record of IT security audits/projects implementation

  • Ability to develop information security policies, setup ISMS and guidelines, implement CIS20 and derive security requirements from them;

  • Understanding access modelling. Ability to develop access models and assess them. Understanding of segregation of duties

  • Experience in IAM & SSO solutions. Understanding of purpose and approaches of IAM. Knowledge of key tasks: identify, authenticate, and authorize

  • Good knowledge of risk management, its purpose, and approaches. Ability to evaluate risks and create a risks management plan

  • Understanding OWASP Top 10. Ability to describe vulnerabilities, ways of exploitations, and fix methods

  • Understanding and implemented of vulnerability & patch management. Knowledge in vulnerability scanners. Ability to validate scan results and provide recommendations

  • Ability to develop and conduct security trainings and workshops

  • Good level of professional English

  • Good communication skills, responsible, initiative, self-organized, eager to learn

  • Experience in Secure SDLC or AWS Security would be a plus


Responsibilities:

  • Conduct security audits and consulting projects, create an action plan & practical roadmap based on the audit results

  • Develop and enhance an information security management framework to ensure business sustainability

  • Build and maintain compliance guidelines. Create policies and standards for IT security and compliance

  • Conduct general IT security awareness training for the company staff

  • Evaluate and manage corporate risks related to IT security

  • Build and maintain application-specific threat models, explicitly apply security principles to design

  • Participate in the corporate certification and compliance activities

  • Design and implement security architecture and detailed cybersecurity designs together with IT and software development departments

  • Prepare and document standard operating procedures and protocols

  • Cooperation with Account Management, Sales & Marketing, Legal, Delivery and Clients for all security-related topics (audits, contractual compliance, reviews, risk assessments, etc.)

  • Keeping up to date with developments in IT security standards and threats


What we offer:


  • Training and career development programs 

  • Knowledge sharing sessions

  • Branded souvenirs

  • Internal training and workshop

  • Comfortable workplace & office equipment

  • Opportunities for self-realization and career growth

  • 18 days of paid vacations & 5 days of paid sick leaves

  • Quarterly Team building & corporate events (2 grand events per year)

  • Guaranteed regular compensation review

  • On-demand Knowledge Evaluation and promotion

  • English language courses

  • Medical insurance with pretty much good coverage for you to feel safe


Please send your CVs to ulyana.volynets@underdefense.com





Similar jobs

Apply for this job