Informacijos saugos specialistė (-as) (GRC sritis)
Core
Design, implement, and enhance the Group-level Information Security Governance, Risk, and Compliance (GRC) control system for the energy sector.
Role type
Senior GRC Information Security Specialist
Builds
GRC control systems, security policies, and compliance frameworks for the EPSO-G group
Domain
Energy sector, Cybersecurity, Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GRC framework design, regulatory interpretation (Cybersecurity Law, ISO 27001), risk assessment, audit coordination, policy creation, third-party risk management, incident response, analytical thinking, process structuring
Preferred skills
CISM, CRISC, ISO 27001 Lead Auditor certifications, experience in regulated sectors (energy, critical infrastructure), GRC tool usage
Technologies
ISO 27001, CIS Controls, GRC tools
Responsibilities
Create and maintain security policies and procedures, manage third-party security risks, develop security metrics and reports, consult on governance issues, coordinate audits and self-assessments, participate in security incident management
Seniority
Senior, hands-on IC