Information Security & GRC Specialist
Core
Own the day-to-day coordination and continuous improvement of the Information Security Management System (ISMS) to ensure compliance, audit readiness, and resilience for global transit and payment solutions.
Role type
Information Security & GRC Specialist (ISO 27001/PCI DSS focus)
Builds
Security compliance posture, audit evidence, and remediation actions for a global technology business serving 200+ cities.
Domain
Public transport and payments technology
Deliverable
dashboards & analysis
Required skills
ISO 27001 ISMS management, audit coordination, evidence management, remediation tracking, security policy maintenance, stakeholder relationship building, regulatory compliance support
Preferred skills
PCI DSS experience, ISO 27017/27018/22301 knowledge, regulated technology environment experience
Technologies
ISO 27001, ISO 27017, ISO 27018, ISO 22301, PCI DSS
Responsibilities
Coordinate ISO 27001 certification, surveillance, and internal audits; manage evidence and close findings; maintain security policies and compliance documentation; track and report on compliance status and risks; support PCI DSS and wider security assurance activities; help develop approaches for ISO 27017, ISO 27018, and ISO 22301.
Seniority
Mid-level, hands-on IC