If you're passionate about leading security consulting engagements, conducting risk assessments, developing information security policies, and ensuring compliance with international security standards and best practices, this role is for you! Join a leading organisation in cybersecurity!The GRC Consultant plays a key role in helping clients understand their security needs, mitigate risks, and align their governance, risk, and compliance strategies with business objectives.This position is full time and based in Athens.
key responsibilities
- Plan and execute security consulting projects, ensuring high-quality delivery of risk assessments and mitigation strategies.
- Develop and implement information security policies and frameworks based on industry best practices.
- Perform audits against international standards including ISO 27001, ISO 22301, PCI DSS, NIS2, and GDPR.
- Translate complex security risks and compliance gaps into actionable technical and executive-level reports for diverse stakeholders.
- Mentor junior team members and contribute to the development of internal GRC tools and best practices.
experience
Hands-on experience in a GRC or a cybersecurity consulting role.
qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, or a related field.
- Hands-on experience in a GRC or cybersecurity consulting role.
- Experience in regulatory frameworks such as ISO 27001, ISO 27701, NIST, GDPR, NIS2, or other.
- Solid understanding of security and network architectures, IT system security, and risk assessment methodologies.
- Strong analytical, organizational, and communication skills, with a strong client-oriented approach.
- Data Protection related certification like Certified DPO is considered an asset.
- Business continuity related certification (e.g. ISO / IEC 22301 Lead Auditor, MBCI) is considered an asset.
- Additional certifications in risk management (ISO 27005), cloud security (CCSP, CCSK), governance (CGEIT), or related areas are considered an asset.
- Project Management related training and certification (e.g., PMI-PMP, PRINCE2, Agile, Scrum) is considered an asset.