Enable job alerts via email!

Senior Security Engineer and GRC Specialist

emagine - Portugal

Mississauga

On-site

CAD 90,000 - 130,000

Full time

4 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company is seeking a hands-on Senior Security Engineer and GRC Specialist to integrate deep technical expertise in security with risk management and regulatory compliance. This hybrid role involves implementing security controls, managing compliance frameworks, and enhancing daily security operations. Ideal candidates will have 8-12 years of experience and a solid understanding of various security regulations. Join a dynamic environment where you can significantly contribute to organizational security and compliance efforts.

Qualifications

  • 8–12 years of cybersecurity experience with GRC and hands-on engineering background.
  • Strong understanding of frameworks and regulations like NIS2, GDPR, ISO 27001.
  • Relevant certifications such as CRISC, CISA, ISO/IEC 27001 Lead Auditor are a plus.

Responsibilities

  • Implement security controls and support security operations.
  • Conduct risk assessments and develop strategies to mitigate risks.
  • Develop, document, and enforce security policies and procedures.

Skills

Risk Management
Regulatory Compliance
Security Engineering
Incident Response
Cloud Security
Problem-Solving

Education

Bachelor’s degree in Information Security, Computer Science, or related field

Tools

SIEM
EDR
vulnerability scanners
Microsoft Azure security services
AWS security services

Job description

Senior Security Engineer and GRC Specialist
Senior Security Engineer and GRC Specialist

Direct message the job poster from emagine - Portugal

Senior Security Engineer and GRC Specialist

Summary

We are seeking a hands-on Security Engineer and GRC Specialist who blends deep technical expertise with risk management and regulatory compliance. This hybrid role involves implementing security controls, actively supporting security operations, and implementing regulatory readiness across the organization. The ideal candidate can define a risk and compliance framework while also being deeply engaged in day-to-day engineering tasks, incident response, and continuous security improvement.

Key ResponsibilitiesSecurity Engineering

- Apply secure configuration baselines and hardening across operating systems, databases, and cloud environments.

- Automate security processes where possible to improve efficiency and reduce manual overhead.

- Support performing security and vulnerability assessments.

- Support IT teams in implementing patches.

- Support threat hunting, root cause analysis, and post-incident improvement efforts.

Risk, Compliance & Governance

- Identify and assess security risks associated with IT systems and develop strategies to mitigate these risks.

- Develop, document, and enforce security policies, standards, and procedures.

- Conduct risk assessments and implement risk mitigation measures, and monitor their effectiveness.

- Ensure compliance with frameworks and regulations such as NIS2, GDPR, ISO 27001, NIST, IEC 62443, and Chinese data and cybersecurity regulations.

- Perform vendor and third-party risk assessments.

- Support the implementation of business continuity, disaster recovery, and incident response plans.

- Act as a trusted advisor to internal teams on security best practices and secure solution design.

- Translate complex security topics into actionable guidance for both technical and business stakeholders.

Qualifications

- Bachelor’s degree in Information Security, Computer Science, or a related technical field.

- 8–12 years of cybersecurity experience, with both GRC and hands-on engineering background.

- Strong understanding of frameworks and regulations such as NIS2, GDPR, ISO 27001, NIST, and Chinese data and cybersecurity regulations.

- Strong working knowledge of regulatory compliance requirements in NIS2.

- Familiarity with GRC tools, data protection, and risk assessment methodologies.

- Working knowledge of Microsoft Azure, AWS, or OCI security services.

- Experience with tools such as SIEM, EDR, vulnerability scanners, and cloud-native controls will be an advantage.

- Knowledge of IAM concepts including SSO, MFA, PAM, and access reviews.

- Relevant certifications are a plus: CRISC, CISA, ISO/IEC 27001 Lead Auditor or similar.

- Technical Depth: Strong hands-on capability in engineering and cloud security.

- Strategic Vision: Ability to balance long-term design with immediate needs.

- Problem-Solving: Practical, results-driven approach to complex challenges.

- Communication: Clear, concise, and persuasive communicator across all levels.

- Adaptability: Stays ahead of threats, tech changes, and regulatory shifts.

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Information Technology
  • Industries
    Software Development

Referrals increase your chances of interviewing at emagine - Portugal by 2x

Sign in to set job alerts for “Security Engineer” roles.

Copenhagen, Capital Region of Denmark, Denmark 3 weeks ago

Python Backend Senior Software Engineer - Remote 4 days a week (Europe)

Copenhagen, Capital Region of Denmark, Denmark $70,000.00-$80,000.00 3 weeks ago

Kyndryl Graduate Program – IT Strategy Consultant - Cloud / Security / Digital Workplace / Applications / Data / Network / Mainframe (m/f/x)

Brøndby Municipality, Capital Region of Denmark, Denmark 2 months ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.