Information Security Risk Officer
XM · District de Limassol
Job description
About the role
Join the dynamic Information Security GRC team to strengthen business operations by enforcing the Information Security Framework, conducting internal risk assessments and collaborating with line management to define assessment scopes.
Key responsibilities
- Plan and execute technical and targeted risk assessments in IT infrastructure, applications, technologies, and third parties.
- Assess internal controls, processes, and policies related to IT and security, identify deficiencies, and develop remediation strategies.
- Perform risk analysis on current risks and identify potential risks at operational, tactical, and strategic levels.
- Evaluate previously handled risks and compare mitigation approaches to potential risks.
- Maintain the risk register and the Information Security Risk Management Program.
- Identify information security risks and make practical, cost‑effective recommendations.
- Manage and monitor remediation steps on risk assessment findings.
- Prepare comprehensive reports summarising actions taken to remediate identified risks.
- Provide regular reports and metrics on the company’s security posture.
- Act as the escalation point for any information security‑related risks.
Required profile
- BSc/MSc in Information Security or a related field.
- At least 3 years of experience in information security risk management and assessment.
- Technical knowledge of operations, physical, network, host and application security, as well as security architecture, virtualisation, and cloud infrastructures.
- Good understanding of security regulations and frameworks such as ISO 27005, ISO 27001, NIST CSF, NIST 800‑53, DORA, GDPR.
- Risk‑related certifications (e.g., CRISC, CGRC, CISSP) are a plus.
- Ability to work autonomously, integrate well within a team and communicate risks to all management levels.
- Self‑motivated, proactive, efficient and able to work under pressure in a fast‑paced environment.
- Strong interpersonal, organisational and project‑management skills.
- Excellent communication skills with the ability to explain technical concepts to non‑technical audiences.
- Excellent written and verbal English.
Required skills
- Operations security
- Physical security
- Network security
- Host security
- Application security
- Security architecture
- Virtualisation
- Cloud infrastructures
- ISO 27005
- ISO 27001
- NIST CSF
- NIST 800‑53
- DORA
- GDPR
What we offer
- Attractive remuneration package
- Private health insurance
- Corporate pension fund
- Intellectually stimulating work environment
- Continuous personal development and international training opportunities
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Cyprus.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 2 hours ago
Expires 1 month from now
2 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
XM
District de Limassol