IT Security Specialist (Governance, Risk & Compliance)

Voltalia

Porto

Presencial

USD 35 034 - 70 069

Tempo integral

14 dias+
Gerador de candidaturas

Não envies um currículo genérico — gera um currículo e uma carta de apresentação adaptados a esta função específica.

Ultrapassa os filtros ATS

Resumo da oferta

Uma empresa inovadora no setor de energias renováveis está à procura de um Especialista em Segurança da Informação GRC. Nesta função, você será responsável por supervisionar aspectos de governança, risco e conformidade em segurança da informação e cibernética. Você ajudará a implementar estratégias de segurança e a desenvolver metodologias de gestão de riscos, garantindo a conformidade com os padrões de segurança e regulatórios. Se você é apaixonado por cibersegurança e deseja fazer parte de uma equipe dinâmica, esta é a oportunidade perfeita para você. Venha contribuir para um futuro sustentável e seguro!

Qualificações

  • 3+ anos de experiência em GRC de Segurança da Informação.
  • Conhecimento forte em frameworks de segurança como ISO 27001 e NIST.

Responsabilidades

  • Assistir na implementação da estratégia de segurança cibernética.
  • Desenvolver e manter documentação de segurança e arquitetura.

Conhecimentos

Análise e resolução de problemas
Gestão de riscos
Comunicação e colaboração
Autonomia
Organização

Formação académica

Licenciatura em Cibersegurança
Licenciatura em Tecnologia da Informação
Licenciatura em Ciência da Computação

Ferramentas

Ferramentas de gestão de riscos
Plataformas de conformidade
Soluções de monitoramento de segurança

Descrição da oferta de emprego

At Voltalia we are passionate about renewable energies! We are an electricity producer from wind, solar, hydro, biomass and storage and also a service provider to 3rd party clients such as Development, EPC, O&M and Distribution. Today we are in 20 countries, split among 4 continents, and offering a global operating capacity to our clients. We are listed on the regulated Euronext market in Paris since July 2014.

Our IT Security and Infrastructure Team is looking for an IT Security Specialist GRC.

The IT Security Specialist GRC (Governance, Risk, and Compliance) is responsible for overseeing governance, risk, and compliance aspects of information and cyber security. It plays a key role in promoting security best practices across VOLTALIA and requires support from Executive Committee Members, business managers, and IT leaders. Led by the Information Security Officer (ISO), this function has the following responsibilities:

Information and Cyber Security Strategy & Policy

  • Assist the ISO in implementing the information and cyber security strategy and program.

Information and Cyber Security Risk Management

  • Support the development and implementation of a risk management methodology aligned with VOLTALIA’s objectives, overall risk strategy, and regulatory requirements.
  • Ensure alignment between information and cyber security risk management and VOLTALIA’s enterprise risk management framework.
  • Provide guidance and support on information and cyber security risk management activities.
  • Assess the effectiveness of security controls in IT and OT environments.
  • Monitor information and cyber security risks by evaluating control implementation, asset vulnerabilities, threat landscapes, and security incidents.
  • Report risk trends to Risk Owners and other relevant committees.

Security Standards & Architecture

  • Develop and maintain security documentation, including standards, processes, procedures, guidelines, contractual clauses, and control catalogs.
  • Design and maintain a unified IT and OT security architecture aligned with the overall security strategy.
  • Establish a security architecture repository, including principles, terminology, security services, control frameworks, and reference models.

Security by Design

  • Support first-line teams in identifying and addressing cyber security risks and requirements in new products, projects, processes, and services.

Security Awareness & Training

  • Develop and implement security education, training, and awareness programs to foster security-conscious behaviors across IT and OT environments.

Audit & Compliance Support

  • Provide evidence of risk oversight and control implementation for internal and external audits.
  • Communicate the status and progress of the security program to key stakeholders.
  • Monitor compliance with security architecture and standards.
  • Collect and analyze key performance and effectiveness metrics to support decision-making and inform the ISO.

REQUIREMENTS

The ideal candidate will have/ be:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
  • 3+ years of experience in Information Security GRC.
  • Strong knowledge of security frameworks (e.g., ISO 27001, ISO27005, NIST, IEC 62443).
  • Familiarity with regulatory requirements such as GDPR, NIS2, etc.
  • Experience with risk management tools, compliance platforms, and security monitoring solutions.
  • Experience conducting security audits and risk assessments.
  • Understanding of IT security principles, cloud security, and network security.
  • Certifications such as CRISC, CISA, ISO 27001 Lead Auditor/Implementer, ISO 27005 Risk Manager (preferred).
  • Possible travel, mainly in Europe.

KEY SKILLS

  • Challenges-driven, rigorous, strong commitment, and investment.
  • Excellent analytical and problem-solving skills with the ability to assess and prioritize security risks.
  • Willing to develop new skills and competencies.
  • Comfortable working with high autonomy and as a team player.
  • High level of integrity and ability to handle sensitive and confidential information.
  • Very well organized. Able to manage and prioritize time and multiple tasks efficiently, especially when operating under pressure or deadlines.
  • Strong communication and collaboration skills to work effectively with cross-functional teams and external stakeholders. Know how to adapt your communication.
  • Passionate about cybersecurity and staying up-to-date on the latest threats and trends.

BUSINESS LINE
HR & Corporate Functions

CONTRACT TYPE
Not defined yet

CONTRACT DURATION

LOCATION
Portugal, Porto

STARTING DATE
Mar 25

Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

SCADA Engineer Senior Associate M/F
SCADA Engineer Senior Associate M/F

Voltalia • Porto

Híbrido
EUR 45 000 - 65 000
SCADA Engineer Associate M/F
SCADA Engineer Associate M/F

Voltalia • Porto

Presencial
EUR 42 000 - 55 000
Cybersecurity specialist
Cybersecurity specialist

Greenvolt Group • Lisboa

Híbrido
EUR 52 000 - 68 000
Health insurance
Flexible benefits
Pension plan
+4
Electrical Engineer - Porto
Electrical Engineer - Porto

Voltalia • Porto

Presencial
EUR 40 000 - 55 000
Contract Manager (O&M) M/F
Contract Manager (O&M) M/F

Voltalia • Porto

Presencial
EUR 60 000 - 90 000
QA/QC Regional Coordinator
QA/QC Regional Coordinator

Voltalia • Porto

Híbrido
EUR 42 000 - 65 000
Power Systems Engineer M/F
Power Systems Engineer M/F

Voltalia • Porto

Presencial
EUR 35 000 - 50 000
High-Voltage Engineer
High-Voltage Engineer

Renvolt Energy • Porto

Presencial
EUR 55 000 - 85 000
Electrical Engineering Coordinator - French Speaker M/F
Electrical Engineering Coordinator - French Speaker M/F

Voltalia • Porto

Presencial
EUR 40 000 - 60 000
Iot Technology Security Specialist
Iot Technology Security Specialist

Vodafone • Almada

Híbrido
EUR 60 000 - 90 000
Hybrid work model
Access to learning platforms
Internal mobility