Senior Security Compliance Officer
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
As part of strengthening its cybersecurity governance and complying with several regulatory and normative requirements, client is looking for a Security Compliance Consultant .
The consultant will work within the cybersecurity program to build, maintain, and develop the compliance framework to meet the requirements of several regulatory and normative frameworks, including:
- NIS2
- PCI DSS
- Cyber Resilience Act (CRA)
- Any other regulatory or normative requirements applicable to the organization
The mission is primarily focused on building the compliance framework , formalizing requirements, and defining controls. The consultant will not be responsible for the operational implementation of the controls, which will remain the responsibility of the relevant business and IT teams.
The consultant will be responsible for translating regulatory, normative and cybersecurity requirements into a coherent, measurable, auditable and sustainable compliance framework.
In this capacity, he will ensure the definition and maintenance of control frameworks, assessment methodologies, evidence requirements and associated reporting mechanisms.
Main responsibilities:
Construction and maintenance of control repositories
- Analyze the applicable regulatory and normative requirements.
- Translate these requirements into concrete and measurable controls.
- Build and maintain the control repositories associated with:
- NIS2
- PCI DSS
- CRA
- other applicable regulatory frameworks.
- Define for each control:
- the objective;
- the evaluation criteria;
- the evidentiary requirements;
- roles and responsibilities;
- monitoring indicators;
- the expected level of maturity.
Compliance Governance:
- Maintain traceability between:
- regulatory requirements;
- cybersecurity risks;
- controls;
- remediation plans;
- evidence.
- Define the governance mechanisms that allow for compliance monitoring.
- Participate in defining monitoring and escalation processes.