GRC Cyber Consultant
- Hiring from
- Ukraine
- Work type
- Remote
- Posted
- Sep 27, 2026
CISO / Information Security Consultant (GRC) (ISO27001, SOC2)
Requirements:
4+ years in IT security and compliance
Extensive, practice-based knowledge of security management frameworks, such as ISO 27k series, GDPR, SOC2 etc.;
Proven track record of IT security audits/projects implementation
Ability to develop information security policies, setup ISMS and guidelines, implement CIS20 and derive security requirements from them;
Understanding access modelling. Ability to develop access models and assess them. Understanding of segregation of duties
Experience in IAM & SSO solutions. Understanding of purpose and approaches of IAM. Knowledge of key tasks: identify, authenticate, and authorize
Good knowledge of risk management, its purpose, and approaches. Ability to evaluate risks and create a risks management plan
Understanding OWASP Top 10. Ability to describe vulnerabilities, ways of exploitations, and fix methods
Understanding and implemented of vulnerability & patch management. Knowledge in vulnerability scanners. Ability to validate scan results and provide recommendations
Ability to develop and conduct security trainings and workshops
Good level of professional English
Good communication skills, responsible, initiative, self-organized, eager to learn
Experience in Secure SDLC or AWS Security would be a plus
Responsibilities:
Conduct security audits and consulting projects, create an action plan & practical roadmap based on the audit results
Develop and enhance an information security management framework to ensure business sustainability
Build and maintain compliance guidelines. Create policies and standards for IT security and compliance
Conduct general IT security awareness training for the company staff
Evaluate and manage corporate risks related to IT security
Build and maintain application-specific threat models, explicitly apply security principles to design
Participate in the corporate certification and compliance activities
Design and implement security architecture and detailed cybersecurity designs together with IT and software development departments
Prepare and document standard operating procedures and protocols
Cooperation with Account Management, Sales & Marketing, Legal, Delivery and Clients for all security-related topics (audits, contractual compliance, reviews, risk assessments, etc.)
Keeping up to date with developments in IT security standards and threats
What we offer:
Training and career development programs
Knowledge sharing sessions
Branded souvenirs
Internal training and workshop
Comfortable workplace & office equipment
Opportunities for self-realization and career growth
18 days of paid vacations & 5 days of paid sick leaves
Quarterly Team building & corporate events (2 grand events per year)
Guaranteed regular compensation review
On-demand Knowledge Evaluation and promotion
English language courses
Medical insurance with pretty much good coverage for you to feel safe
Please send your CVs to ulyana.volynets@underdefense.com