Duke ngarkuar...

Cyber Security Compliance Consultant

Service Factory Solutions

/job-details/10273

Tirana
full_time
Publikuar 2 dite me pare
We are seeking a skilled Cyber Security Compliance Consultant to join our dynamic team. You’ll work on high-impact cybersecurity and compliance projects, helping our clients strengthen their security governance, manage risk, and meet evolving regulatory requirements.

The ideal candidate has solid experience in Security Compliance/GRC, with previous exposure to the European regulatory environment and hands-on experience with GDPR and/or NIS2.

**What You’ll Do**

• Support clients in achieving and maintaining compliance with cybersecurity regulations and standards, including NIS2, ISO/IEC 27001, TISAX, and GDPR.

• Conduct Security Assessments, GAP Analyses, Risk Assessments, and Business Impact Analyses (BIA), identifying remediation actions and improvement opportunities.

• Design, implement, and maintain Information Security Management Systems (ISMS) aligned with international standards and best practices.

• Analyze business processes, operational dependencies, and critical systems to define business continuity requirements and parameters such as RTO, RPO, and MTPD.

• Support consulting engagements related to audit readiness, certification processes, and regulatory compliance programs.

• Provide strategic guidance on cybersecurity governance, risk management, and organizational security posture, including vCISO activities.

• Develop cybersecurity policies, procedures, standards, and governance documentation.

• Deliver training and awareness sessions on cybersecurity, compliance, and security best practices.

• Monitor regulatory developments and advise clients on new requirements and their operational impact.

• Collaborate with technical and business stakeholders, experienced consultants, and international teams.

**What We’re Looking For**

• 3–5 years of relevant experience in Cyber Security Compliance, GRC, cybersecurity consulting, governance, or information security management.

• Previous professional experience within the European regulatory and compliance environment.

• Strong knowledge and practical experience with GDPR and/or NIS2.

• Good knowledge of ISO/IEC 27001 and familiarity with TISAX.

• Proven experience with security audits, risk assessments, GAP analyses, and compliance programs.

• Experience in designing or implementing security governance frameworks, ISMS, and compliance processes.

• Knowledge of Business Continuity and Disaster Recovery principles and related methodologies, such as ISO 22301 and ISO/TS 22317.

• Strong analytical, organizational, documentation, and stakeholder management skills.

• Ability to work independently and manage different projects and priorities.

• Client-oriented and detail-focused approach.

• Availability to travel when required.

• Italian and English proficiency at B2 level or higher.

**Nice to Have**

• Degree in Computer Science, Engineering, Cybersecurity, Law, or a related field.

• Certifications such as ISO/IEC 27001 Lead Auditor, ISO/IEC 27001 Lead Implementer, CISA, CISM, or CISSP.

• Previous experience as a vCISO, Compliance Manager, or Information Security Manager.

• Knowledge of ISO 31000, ISO/IEC 27005, NIST Cybersecurity Framework, or ISO 22301.

• Experience in regulated industries such as financial services, automotive, energy, manufacturing, or healthcare.

• Experience with GRC platforms and certification/accreditation bodies.

• Technical understanding of Cloud Security, SIEM/SOC environments, Vulnerability Management, Network Security, and IAM.

**How to Apply**

Interested candidates are invited to submit their CV to: careers@servicefactory.al

*\*Please note that only shortlisted candidates will be contacted for an interview.*