SI

Information Security Auditor & GRC Specialist

Hiring from
Romania
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Company Description Safetech Innovations, founded in 2011 by a team of Information Security and IT experts, provides cyber security services and solutions tailored to the specific needs of each organization. The company focuses on helping clients protect critical assets, manage risk, and meet regulatory and compliance requirements. Safetech Innovations combines technical expertise with strategic advisory capabilities to design and implement effective security controls. Team members collaborate closely with customers across industries, working on complex and impactful security projects.

Role Description The Information Security Auditor & GRC Specialist is a full-time hybrid role with the possibility to work from home part of the time. This role is responsible for plans and performs risk-based cybersecurity, information security, IT audit, and governance, risk, and compliance assessments. The role evaluates governance and controls, prepares and maintains audit documentation, assessment records, reports, and other GRC deliverables, communicates business-relevant findings, and works with stakeholders to define, document, and monitor practical remediation actions. The role also involves contributing to security awareness initiatives and continuous improvement of the organization’s security posture.


Main Responsibilities


Audit Planning and Execution

  • Develop risk-based audit and assessment plans aligned with organizational objectives, risk exposure, and applicable requirements.
  • Plan and conduct cybersecurity, information security, IT, and GRC audits and assessments.
  • Collect and evaluate evidence to determine compliance, assess control design and operating effectiveness, and support defensible audit conclusions.


Governance, Risk, and Compliance

  • Assess information security governance, including roles, responsibilities, policies, procedures, and management oversight.
  • Evaluate risk management processes, including risk identification, assessment, treatment, acceptance, and monitoring.
  • Assess compliance with applicable laws, regulations, standards, contractual requirements, and internal policies, and perform related gap assessments.
  • Review risk assessments, risk registers, treatment plans, and risk acceptance decisions.


Control, Third-Party, and Resilience Assessments

  • Assess cybersecurity risks and controls across IT systems, applications, infrastructure, data, and third parties/
  • Evaluate third-party and supplier security risk management processes and controls.
  • Assess business continuity, disaster recovery, and cyber resilience arrangements from an information security perspective.
  • Maintain awareness of the evolving threat landscape and its relevance to the organization’s business and risk profile.


Reporting, Remediation, and Collaboration

  • Analyze audit results to identify control weaknesses and evaluate associated risks and business impacts.
  • Prepare clear audit reports and communicate findings, risks, and recommendations to management and relevant stakeholders.
  • Develop practical, risk-based recommendations; support remediation planning; and monitor actions through closure.
  • Collaborate with management, technical teams, internal staff, clients, auditors, and other external stakeholders to address security, compliance, and risk issues.


Required Qualifications

  • Relevant professional experience in IT audit, information security, cybersecurity, GRC, risk management, or compliance.
  • Experience conducting information security, cybersecurity, IT audit, or GRC assessments.
  • Strong knowledge of information security governance, risk management, compliance, and control-effectiveness assessment.
  • Experience applying information security standards and regulatory requirements, such as ISO/IEC 27001, ISO/IEC 27002, NIS2, PCI DSS, NIST CSF, or comparable frameworks.
  • Experience assessing policies, procedures, controls, compliance gaps, third-party risk, and supplier security.
  • Knowledge of business continuity, disaster recovery, and cyber resilience.
  • Foundational knowledge of IT, including networking, architecture, protocols, file systems, and operating systems.
  • Ability to translate technical security issues into business risks and compliance implications.
  • Professional working proficiency in English.


Preferred Qualifications

  • CISA certification.
  • Experience engaging with clients, auditors, external authorities, and senior management.


Core Skills and Competencies

  • Excellent written and verbal communication, including concise, evidence-based audit reporting.
  • Strong analytical and problem-solving skills, with close attention to detail.
  • Ability to explain security risks, compliance gaps, control weaknesses, and business impacts to both technical and nontechnical audiences.
  • Sound risk-based judgment and the ability to prioritize findings and remediation actions.
  • Ability to work independently, manage multiple assignments, and remain effective under pressure and changing priorities.
  • Collaborative approach and ability to contribute effectively within cross-functional teams.
  • Confidence engaging with client management and communicating sensitive issues, risks, and recommendations professionally.

Similar jobs

Apply on LinkedIn