Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ" ИНН: 9704271170
описание
Do you currently possess an EU passport or a valid work permit that authorises you to work in the specified hiring location? • Are you happy to make yourself available for the required hybrid model of 3 days in office per week?
Bitpanda operates a trade-everything investment platform that enables more than 7 million customers to invest in cryptocurrencies, crypto indices, stocks, precious metals, and commodities. Headquartered in Austria, it operates across Europe.
задачи
Define a multi-year GRC roadmap aligned with business strategy, risk appetite, and regulatory expectations
Evolve the control framework by rationalizing controls, reducing duplication, and ensuring proportionality based on criticality, data sensitivity, and business impact
Establish governance principles, including minimum control baselines, exception governance, and evidence-by-design
Advise leadership on material risk decisions, including risk acceptance, remediation prioritization, control investments, and scope decisions
Produce executive-grade risk narratives, board and committee materials, and regulator and customer responses with defensible rationale
Facilitate senior stakeholder alignment when priorities conflict
Own the strategy and approach for major audits and assurance activities, including ISO 27001, SOC 2, regulatory examinations, and key client due diligence
Lead responses to complex audit and regulatory issues, including root-cause analysis, corrective action programs, and sustained effectiveness verification
Serve as an SME in one or more areas: ISMS/ISO 27001 at scale, DORA and operational resilience governance, third-party risk for critical ICT providers, or security control assurance
Set standards and reusable artifacts, including control narratives, evidence templates, testing methodologies, and playbooks
Mentor specialists and associates through coaching and review
Partner with Security Engineering, IT, and Compliance to embed controls into workflows, using policy-to-automation where possible
требования
Typically 7–10+ years of experience in information security GRC, audit/assurance, security risk, compliance, software engineering, and/or financial services risk roles
Demonstrated ownership of complex, multi-stakeholder GRC programs and successful navigation of audits and regulatory scrutiny
Deep working knowledge of ISO 27001 and DORA, and strong familiarity with SOC 2, NIST CSF, BaIT, and COBIT, including control testing and evidence
Strong technology risk understanding across cloud, IAM, SDLC governance, incident management, vulnerability management, logging/monitoring, and crypto/fintech operational processes as relevant
Ability to influence across the organization and resolve conflicts with a risk-based, outcome-oriented approach
условия
Competitive total compensation package aligned with Bitpanda’s pay-for-impact policy, including participation in its stock option plan
Confidential coaching, counselling, and mental health resources through OpenUP
Three additional paid days off in 2027 after six months with the company
Unlimited access to Udemy’s online course library
Discounts, rewards, and perks from partners worldwide across lifestyle, wellness, tech, and travel
Up to eight additional weeks of gender-neutral new parent leave
Free onsite dining, freshly prepared lunches, and snacks for employees in Vienna, Bucharest, Barcelona, and Berlin
Tenure recognition and rewards, Bitpanda-branded merchandise, and company events
25 Additional days per year to work from a city or country of choice
Hybrid model: three days onsite and two days from home; exceptions apply to shift-schedule teams and roles requiring office presence