GRC Consultant

Balwurk

Lisboa

Presencial

EUR 40 000 - 60 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

A leading consulting firm in Lisbon is seeking an experienced GRC professional to define, implement, and monitor Governance, Risk & Compliance frameworks. The role requires 2-5 years of relevant experience in Information Security, auditing, and risk management, with mandatory ISO 27001 Lead Auditor certification. Excellent command of English and Portuguese is essential. The candidate will work closely with technical and management teams to ensure compliance with industry standards and improve security practices.

Qualificações

  • 2 to 5 years of experience in GRC, Information Security, IT Risk or Compliance roles.
  • Experience in risk assessments, audits, compliance and defining security controls.
  • Good knowledge of frameworks and standards such as ISO 27001, ISO 22301, NIST CSF.

Responsabilidades

  • Define, implement and monitor Governance, Risk & Compliance frameworks.
  • Conduct Information Security Risk assessments.
  • Support technology risk management and third-party risk.

Conhecimentos

ISO 27001 certification projects
Supplier auditing
Business continuity
GRC tools
Information security awareness
Knowledge of DORA and NIS2
ISO 27001 Lead Implementer
CRISC
CISA
CISM

Formação académica

ISO 27001 Lead Auditor certification

Descrição da oferta de emprego

Define, implement and monitor Governance, Risk & Compliance frameworks in line with client requirements and industry best practice.

Conduct Information Security Risk assessments, identifying threats, vulnerabilities, impact and mitigation measures.

Support the definition, review and maintenance of security policies, standards, procedures and controls.

Conduct gap analyses against standards and frameworks such as ISO 27001, NIST CSF, NIS2 (DL125-2025), amongst others.

Monitor internal audits, ensuring the collection of evidence, handling of non-conformities and definition of action plans.

Support processes for technology risk management, third‑party risk, business continuity and security awareness.

Produce technical and executive reports containing conclusions, identified gaps, maturity levels and recommendations for improvement.

Collaborate with technical, business and management teams to ensure the implementation and monitoring of defined controls.

2 to 5 years’ practical experience in GRC, Information Security, IT Risk or Compliance roles.

Experience in risk assessments, audits, compliance and defining security controls.

Good knowledge of frameworks and standards such as ISO 27001, ISO 22301, NIST CSF, or equivalent.

Solid knowledge of applicable regulatory and statutory requirements, namely NIS2, GDPR and QNRCS.

Experience and ability to draft policies, procedures, executive reports and remediation plans independently.

Ability to interact with various stakeholders, from technical teams to management.

Mandatory certification: ISO 27001 Lead Auditor.

Good command of English (written and spoken).

Excellent command of Portuguese (written and spoken).

What skills do you need to have?
  • Experience in ISO 27001 certification projects.
  • Experience in supplier auditing and third‑party risk management.
  • Knowledge of business continuity and disaster recovery.
  • Experience with GRC tools and risk/compliance management platforms.
  • Experience in information security awareness, training and outreach.
  • Knowledge of DORA, NIS2 or other relevant regulatory frameworks.
  • One of the following certifications or equivalents will be an advantage: ISO 27001 Lead Implementer, CRISC, CISA, CISM.
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Governance, Risk and Compliance Consultant
Governance, Risk and Compliance Consultant

PwC Portugal • Matosinhos

Presencial
EUR 38 000 - 52 000
GRC & InfoSec Risk Consultant – ISO 27001 Lead Auditor
GRC & InfoSec Risk Consultant – ISO 27001 Lead Auditor

Balwurk • Lisboa

Presencial
EUR 40 000 - 60 000
Governance, Risk and Compliance Consultant
Governance, Risk and Compliance Consultant

PwC Portugal • Portugal

Presencial
EUR 42 000 - 62 000
GRC & Cybersecurity Consultant — DORA/NIS2 Focus
GRC & Cybersecurity Consultant — DORA/NIS2 Focus

PwC Portugal • Matosinhos

Presencial
EUR 38 000 - 52 000
IT Security Specialist GRC
IT Security Specialist GRC

Match Profiler • Porto

Híbrido
EUR 40 000 - 60 000
Personalized support from the team
Exclusive discounts with partners
Celebration of victories
+2
Strategic GRC & Cybersecurity Consultant
Strategic GRC & Cybersecurity Consultant

PwC Portugal • Portugal

Presencial
EUR 42 000 - 62 000
Compliance & ISO Specialist
Compliance & ISO Specialist

ManpowerGroup • Porto

Presencial
EUR 35 000 - 50 000
IT Risk Analyst Lisbon
IT Risk Analyst Lisbon

Consort • Lisboa

Híbrido
EUR 43 000 - 52 000
Health insurance
TR card
CSE
PROC25423 - RFQ for Cyber Governance Officer
PROC25423 - RFQ for Cyber Governance Officer

Smartconsulting • Lisboa

Híbrido
EUR 60 000 - 80 000
Senior IT Risk & GRC Analyst
Senior IT Risk & GRC Analyst

Decskill • Lisboa

Híbrido
EUR 60 000 - 90 000