Senior Cybersecurity & Compliance Specialist
About the Role
We are looking for a Senior Cybersecurity & Compliance Specialist to help strengthen and continuously improve our organization's cybersecurity posture.
This role combines hands-on cybersecurity, risk management, compliance, and stakeholder engagement. You will work closely with IT teams, business stakeholders, and external partners to ensure security controls are effective, compliant, and aligned with business needs.
You'll have a real impact on shaping security processes, assessing new technologies, managing cyber risk, and supporting regulatory compliance initiatives.
Key Responsibilities
- Develop and enhance the organization's IT security architecture.
- Manage security risks, maintain the IT risk register, and provide recommendations to leadership.
- Coordinate and support security incident response, including critical incidents and post-incident reporting.
- Lead vulnerability management activities, including risk assessment and remediation oversight.
- Develop, review, and implement security policies, procedures, and standards.
- Support access management processes, including oversight of Active Directory, privileged accounts, and MFA controls.
- Assess the security of new systems, applications, and technology changes.
- Prepare regular and ad hoc cybersecurity reports for management.
- Deliver security awareness training and educational initiatives.
- Collaborate with external partners, CSIRTs, regulators, and cybersecurity institutions.
- Support business continuity activities and the continuous improvement of the Information Security Management System (ISMS).
What We're Looking For
Must-have:
- Several years of experience in IT Security, Cybersecurity, or Security Compliance.
- Practical experience in security risk management and incident handling.
- Knowledge of vulnerability management processes.
- Familiarity with cybersecurity regulations, including UKSC, NIS2, and GDPR.
- Knowledge of security standards such as ISO/IEC 27001 and ISO 22301.
- Experience with access and identity management in Active Directory environments.
- Ability to create security documentation, policies, analyses, and management reports.
- Strong analytical thinking and risk assessment skills.
- Ability to independently drive initiatives from identification to implementation.
- Excellent communication and stakeholder management skills.
Nice to have:
- Experience with S46, CSIRT/NASK, and UKSC/NIS2 reporting obligations.
- Knowledge of NIST, CIS Controls, OWASP, and MITRE ATT&CK.
- Experience with security and compliance audits.
- Experience developing or improving an ISMS.
- Certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor, or Lead Implementer.
- Familiarity with SIEM, EDR/XDR, Vulnerability Management, and DLP solutions.
What We Offer
- The opportunity to shape cybersecurity strategy and security maturity across the organization.
- A high level of ownership, autonomy, and impact.
- Participation in cybersecurity, compliance, and IT transformation initiatives.
- Close collaboration with IT, business teams, and senior leadership.
- Professional development opportunities, including support for certifications and continuous learning.
- Exposure to real-world cybersecurity and risk management challenges.
- Competitive compensation, benefits, and flexible working arrangements.