Rådgiver innen informasjonssikkerhet - GRC (ISO 27001 / Risikostyring)
Core
Consultant specializing in information security, risk management, and regulatory compliance for complex projects at the intersection of IT and OT in critical sectors.
Role type
Information Security GRC Consultant
Builds
Governance, risk, and compliance frameworks and assessments for clients in energy, defense, industry, transport, and health.
Domain
Cybersecurity, Risk Management, Regulatory Compliance
Deliverable
client delivery
Required skills
Information security, GRC, risk management, regulatory compliance, ISO 27001, ISO 27005, NIST SP 800-53, NMS principles, management system implementation, Norwegian language proficiency
Preferred skills
Vendor management, internal audit, regulated sectors experience, OT environments, process management, change management
Technologies
ISO 27001, ISO 27005, NIST SP 800-53, NMS
Responsibilities
Develop and improve management systems, conduct maturity assessments, risk analyses, and gap analyses, provide advice on regulatory compliance (Security Act, NIS2, DORA, GDPR), collaborate in cross-functional teams
Seniority
Mid-level to Senior