Randstad Enterprise logo

Senior Information Security Compliance Analyst

Randstad Enterprise
Posted 5 hours ago
HungaryRemoteEngineering & Development
Is this job info correct?

Randstad Enterprise Solutions — including Randstad Sourceright, Global Enterprise Strategic Accounts Team and Randstad RiseSmart — provides solutions and expertise that help enterprise clients position for growth, execute on strategy and improve business agility. Working across the broad spectrum of Randstad Enterprise Solutions, the collective experience of the teams encompasses all facets of the global talent spectrum, from the acquisition of talent to skilling and coaching to outplacement solutions. Enabled by innovative technologies, key offerings include HR and recruitment solutions, recruitment process outsourcing (RPO), managed services programs (MSP), statement of work (SOW), outplacement, skilling/coaching and total talent solutions.

Randstad Enterprise Information Security Office is responsible for the Information Security Management System (ISMS) of the Randstad Enterprise (RE) including Randstad Sourceright (RSR), Randstad RiseSmart (RRS) and Global Enterprise Strategic Accounts (GESA) organizations.

As RE is a global organization, our team aims at global coverage as well to provide continuous support in all regions from APAC to NAM/LATAM. At the moment we have security specialists in India, Hungary.


about the job

The Information Security Compliance Analyst is a critical, high-impact role within the Randstad Enterprise Information Security Team. This position is responsible for ensuring that all security strategies, compliance plans, and governance activities are seamlessly executed and implemented to meet strict corporate quality and regulatory standards. Operating in a vibrant, multinational landscape, the Analyst will serve as a key GRC collaborator. This role bridges the gap between cross-functional internal stakeholders—including the RE Global Digital Office, Enterprise Risk Management, and localized business groups—and external entities to protect our enterprise, clients, and talent data.


Location: Budapest, Hungary (Full-remote - once a month office attendance)

Language: English


what you will do

  • Execute Vendor Risk Assessments: Direct and perform technical security risk assessments for international hardware and software platforms, verifying supplier compliance against the Randstad Enterprise security baseline requirements.
  • Execute internal compliance assessments: Monitoring control execution compliance within the responsibilities of internal parties (business and IT operations, development, backoffice functions, etc.), identifying control gaps, and supporting and overseeing mitigation efforts.
  • Manage GRC Core Operations: Perform repeatable risk management activities, including risk identification, scoring, and tracking within the corporate risk register to support the continuous improvement of the Information Security Management System (ISMS) in compliance with ISO/IEC 27001:2022 standards.
  • Facilitate Client Assurance: Serve as a central point of contact for external client security assessments, delivering authoritative, precise evidence to demonstrate how our platform architectures meet rigorous IT security and data privacy mandates.
  • Synthesize Threat Intelligence Reports: Systematically aggregate threat intelligence metrics from internal detection tools, external vendor bulletins, and bug bounty disclosures to draft structured monthly landscape syntheses and annual threat governance reports for management review.
  • Support Secure Development Baselines: Partner with the Security Engineer and the application development teams to verify that security checkpoints, threat modeling results, and secure coding principles are natively embedded into the Software Development Life Cycle (SDLC).
  • Champion Security Awareness: Support the deployment and execution of enterprise-wide security culture programs, providing role-specific guidance and training on phishing recognition, credential sharing restrictions, mobile profile separation, and proactive incident reporting.


skills you will need

  • Education & Experience: Bachelor’s degree in Computer Science, Information Security, Cyber Security, Risk Management, or equivalent practical corporate experience.
  • Seniority & Track Record: 5+ years of general experience in information security, including in dedicated GRC roles with direct experience mapping controls to ISO 27001:2022 and SOC 2 frameworks.
  • Client-Facing & Audit Capabilities: Proven experience managing client security assurance requests, completing complex security questionnaires, and supporting external audits.
  • Technical & Cloud Knowledge: Broad understanding of cloud security concepts (AWS, Azure, GCP), data privacy mandates (GDPR, CCPA), and application security practices (SAST/DAST, OWASP guidelines, CSPM).
  • Tooling Proficiency: Practical experience with GRC automation platforms (e.g., SAI360, ServiceNow), security posture and scanning tools (e.g., Rapid7, Invicti, Lacework), and operations workflow management (ServiceNow SPM).
  • Core Competencies: Exceptional analytical problem-solving skills, fluent English communication abilities, strong cross-functional collaboration, and the persuasive ability to influence without direct authority.


what’s in it for you?

  • An empathetic culture and supportive leadership who priorities your well-being and personal development
  • Ability to grow in multiple areas in the company. We offer internal career opportunities, international mobility and a fully flexible working environment.
  • Being part of a culture of inclusion and belonging: we value the diversity that our people bring to our workplace and communities.


If you are passionate about bringing people and organisations together and want to be part of a global organisation with development opportunities, we would love to hear from you so please apply now!


Similar jobs