Risk and Compliance Expert
Telelink Business ServicesAre you looking for an exciting new opportunity? Do you desire a workplace where you can thrive – not just as an employee but as a whole person? Do you want to truly get the "Work in good company“ feeling?
That’s the way we
Treat each other.
Operate and do our job.
Strive to impact our community positively.
We are TBS Group (Telelink Business Services) - a leading managed services provider and systems integrator. From the heart of the Balkans, we deliver solutions globally, with a commercial footprint spanning 11 countries. With a team of 500+ people, we serve clients and deliver projects across 4 continents and 45 countries.
TBS Group maintains an integrated management system spanning eight ISO certifications and must meet a wide range of legal and regulatory requirements across the different markets in which it operates. This is the real scope of the compliance function — not an abstraction about being a “business partner,” but day-to-day work carrying real responsibility.
Currently, we are looking for a motivated professional to join us as a
Risk and Compliance Expert
who takes ownership of key compliance processes and turns them into something that works for the people in the organization, rather than an obstacle to business decisions. The core focus of the role is to ensure the development, maintenance, and continual improvement of the organization's risk and compliance management systems and processes, ensuring compliance with applicable regulatory requirements, international standards, and internal policies.
The Role
Strategic management of the integrated system
- Developing and maintaining the integrated management system, covering 8 ISO standards: ISO 9001, ISO 14001, ISO 45001, ISO/IEC 20000-1, ISO/IEC 27001, ISO/IEC 27701, ISO 22301, and ISO 37001;
- Implementing and maintaining additional frameworks beyond the core ISO integrated system — TISAX (automotive-sector information security), CSRD (EU sustainability reporting), and EcoVadis (ESG rating);
- End-to-end management of business processes — from identification and design to implementation and monitoring;
- Preparing and maintaining business process documentation that is practically applicable;
- Developing, reviewing, and updating policies, procedures, and internal regulatory documents.
Regulatory compliance
- Monitoring regulatory changes (Cybersecurity Act/NIS2, GDPR, applicable sector-specific legislation) and assessing their impact on the organization;
- Conducting compliance checks and gap analyses against applicable requirements;
- Supporting communication with regulatory and supervisory bodies.
Risk management
- Identifying, assessing, and documenting risks (risk register);
- Developing and implementing risk treatment measures;
- Periodic reporting on the organization's risk profile.
Audit activity
- Point of contact for certification and supervisory bodies;
- Planning and conducting internal audits;
- Documenting nonconformities and tracking corrective actions;
- Planning and conducting certification and surveillance audits;
Supporting teams during external audits (second- or third-party).
People and communication
- Developing and delivering training on compliance, risk, and internal control;
- Conducting onboarding and periodic staff training;
- Communicating new/changed processes through internal channels;
- Partnering with process owners across the organization.
The Profile We're Looking For
- University degree in Business Administration, Engineering, IT, or a related field;
- Minimum 2–4 years of relevant experience in compliance, risk management, quality, or internal audit;
- Practical experience implementing and/or maintaining at least one management system from the company's portfolio (ISO 9001, 27001, 22301, 20000-1, etc.);
- Working knowledge of GDPR and personal data protection;
- Fluent English — written and spoken;
- Excellent communication skills — the ability to translate complex requirements in a way that colleagues across all functions can understand;
- Ability to manage processes independently, end to end, without needing step by step instructions;
- Skills in researching and interpreting regulatory requirements;
- Strong analytical and problem-solving skills;
- Confident working knowledge of MS Office (Word, Excel, PowerPoint) for preparing documentation, analyses, and presentations to management;
- Knowledge of ITIL is considered an advantage;
- Experience with ESG reporting and/or rating frameworks (e.g., CSRD, EcoVadis) is considered an advantage.
You'll Fit in If:
- You can balance operational and strategic tasks at the same time, without losing focus;
- You take initiative — you come with solutions, not just questions, and you see things through with attention to detail;
- You meet deadlines — quality, timely work is the standard here, not the exception;
- You're ready, during the first few months, to invest time in getting to know the company's strategy and processes in depth;
- You work with a focus on results and efficiency, including when using AI tools — and you can confidently explain and stand behind your own contribution;
What We Offer
- Work on current GRC topics — from cybersecurity (NIS2/Cybersecurity Act) and data protection to risk management in a multi-ISO environment covering eight standards at once;
- Funded training and certifications (e.g., Lead Auditor courses) in the standards and topics relevant to the role;
- A genuine path for professional growth within the team — progression toward a Senior/Lead role as experience is gained;
- Flexibility and a hybrid work model;
- Team-building events and social activities outside of work.
Would you like to join?
- The Role gives a unique opportunity to be someone recognizable and valuable, to engage and inspire others.
- The People you work with will make all the difference in your job satisfaction and your ability to grow and learn.
- The Work you do will be more than just a paycheck or a task list, but a meaningful pursuit that aligns with your personal values and more importantly, fulfills your sense of accomplishment in the long run.
- The Company’s Impact on many communities will make you feel proud to be associated with our brand and our work as we improve the environment we live in daily.
If you're ready to take your career to the next level, apply now! We`re looking forward to reviewing your application.
Please be informed that TBS acts as a data controller with regard to the information provided by you in connection with your application. We inform you that applicants’ personal data, provided on a voluntary basis, will be processed by TBS solely for the purposes of employment selection and recruitment. For more information on how TBS handles your personal data – including rights you may have under applicable law – please review the TBS Privacy Policy on our website.
Your consent may be revoked at any time, but please note that in this case, TBS will not be able to continue reviewing your application.