Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ" ИНН: 9704271170
описание
Are you happy to make yourself available for the required hybrid model of 3 days in office per week? At Bitpanda, we work Hybrid. 3 days onsite, 2 days from home, combining the best of in person collaboration and connection with at home flexibility.
Bitpanda operates a trade-everything investment platform that enables more than 7 million customers to invest in cryptocurrencies, crypto indices, stocks, precious metals, and commodities. The company operates across Europe and is headquartered in Austria.
задачи
Own one or more GRC domains, including ISO 27001/ISMS, control testing, third-party risk management, risk governance, or business continuity management; manage yearly plans, cadence, and measurable outcomes
Build scalable processes and playbooks to reduce audit friction and improve control consistency across teams and entities
Coordinate internal and external audits from readiness planning through remediation verification
Translate regulatory and customer requirements into control impacts, implementation guidance, and tracked delivery plans
Draft and quality-review audit responses, management action plans, risk acceptances, and control descriptions
Facilitate and challenge risk assessments for systems, products, and material changes; ensure consistent scoring and clear treatment decisions
Drive risk treatment plans with accountable owners and escalate unacceptable timelines or residual risks
Improve leadership risk reporting, including themes, systemic issues, KRIs/KPIs, and prioritization based on business criticality
Lead due diligence for critical vendors when within scope; define minimum security requirements, review evidence, and track remediation
Partner with Legal and Procurement to embed security requirements in contracts and ensure ongoing oversight of renewals, periodic reviews, and SLA/security obligations
Design and run a risk-based control testing plan covering design and operating effectiveness, with repeatability and traceability
Identify recurring control failures and drive cross-functional improvements, including clearer ownership, automation, improved tooling, and updated standards
Introduce automation and dashboards for evidence collection, control health reporting, and risk and audit tracking where useful
требования
Typically 4–7 years of experience in GRC, audit/assurance, security risk management, compliance, or information security
Strong working knowledge of ISO 27001 or comparable frameworks, with the ability to map requirements to controls, evidence, and operational processes
Experience leading audits or assessments, or significant parts of them, from planning through closure
Security fundamentals across IAM, SDLC governance, incident management, vulnerability management, logging/monitoring, and third-party risk concepts
Excellent written communication; able to produce policy/control documentation and audit-ready narratives with minimal supervision
условия
Flexible hybrid working model with onsite collaboration and remote work; an additional 25 days per year to work from a city or country of choice
Competitive total compensation package aligned with Bitpanda’s pay-for-impact policy, including participation in the stock option plan
Confidential coaching, counselling, and mental health resources through OpenUP
Three additional paid days off in 2027 after six months of employment
Unlimited access to Udemy’s online course library
Discounts, rewards, and perks from partners worldwide across lifestyle, wellness, tech, and travel
Up to eight additional weeks of gender-neutral new parent leave
Free onsite dining, freshly prepared lunches, and snacks for employees in Vienna, Bucharest, Barcelona, and Berlin
Tenure recognition and rewards, Bitpanda-branded merchandise, and company events
Benefits may be adjusted at Bitpanda’s discretion; benefits do not apply to internships, and exceptions to the hybrid policy apply to teams with shift schedules or roles requiring office presence
Hybrid schedule: three days onsite and two days from home per week