Leads zerohash’s European security, governance, risk, and compliance programs, focusing on DORA, ISO 27001, SOC 1/2, and technical risk mitigation across IT infrastructure.
You will develop, implement, and maintain zerohash’s security, governance, risk management, and compliance programs in Europe, with a focus on DORA compliance. You will manage technical security controls, assess and mitigate IT risks, oversee incidents, maintain policies, and report to senior management and the board.
Responsibilities
Manage the company’s compliance with DORA
Monitor laws, regulations, and industry standards related to IT security and compliance
Manage technical compliance programs and initiatives
Conduct compliance assessments and prepare audit documentation
Develop and maintain governance policies, procedures, standards, and frameworks
Manage ISO 27001, SOC 1, and SOC 2 governance frameworks
Coordinate governance committees and technical committees
Develop and implement IT security strategies and solutions
Manage and monitor firewalls, intrusion detection systems, and endpoint protection
Conduct security assessments, vulnerability scans, and penetration tests
Respond to security incidents and conduct forensic investigations and root cause analysis
Identify, assess, prioritize, and mitigate technical risks
Monitor risk mitigation activities and control effectiveness
Develop and enforce technical security policies and procedures
Oversee technical incident management and corrective actions
Deliver security, governance, risk, and compliance training
Collaborate with auditors, regulators, and technical teams
Present security, governance, risk, and compliance reports to senior management and the board
Requirements
Experience in a Risk Management or GRC leadership role
Experience with the Digital Operational Resilience Act
Technical IT security, governance, risk management, and compliance experience
Knowledge of IT governance frameworks, regulatory requirements, and best practices
Experience with SOC 1, SOC 2, and ISO 27001
Strong analytical and problem-solving skills
Ability to manage multiple technical projects and priorities
Experience with technical security and GRC tools and software
Excellent communication and interpersonal skills
Proficiency in risk assessment methodologies and tools