Angajatorii vă vor vedea în baza noastră de date și vor putea singuri să vă ofere locuri de muncă
  • Premium profile
    Nou
  • Căutare locuri de muncă
  • Favorite
  • Conversație
  • Notificările mele
  • Salarii
  • Abonări

Cybersecurity Compliance Manager

Ocupare deplină

Who we are looking for

  • At least 5 years of experience in information security, risk management, or regulatory compliance functions, ideally operating within a multi-country or regional environment as internal staff or an external consultant;
  • Security related certification such as CISSP, CISM or CRISC is a plus;
  • Strong working knowledge of NIS2 and its national transpositions and the ability to translate legal and regulatory text into operational requirements;
  • Working knowledge of ISO 27001, ISO 22301, NIST, Cyber Fundamentals is an advantage;
  • Experience and knowledge in Information Security Risk Management;
  • Experience conducting information security audits and risk assessments including managing external auditors and regulatory audit cycles is an advantage;
  • Practical experience with security incident response and statutory incident notification to regulatory authorities;
  • Knowledge of administrative, technical/logical and physical information security controls;
  • Very good communication and presentation skills and service quality oriented;
  • Proficiency in Microsoft Office;
  • English - advanced level, both written and spoken; additional regional language in one of the in scope countries (Polish, Romanian, Czech, Slovak, Slovenian, or Hungarian) is an advantage;
  • Comfortable with information technology, systems and data;
  • Analytical skills and thoroughness;
  • Sense of responsibility, independence and willingness to learn and implement new processes.

Your future role

We are looking for a Cybersecurity Manager to take ownership of NIS2 compliance across our in-scope entities in Central Europe (Poland, Romania, Czech Republic, Slovakia, Slovenia, Bulgaria and Hungary), working across regional and local stakeholders to embed regulatory requirements into day-to-day operational practice and ensure ongoing compliance with regulatory requirements.

This role sits within the regional CISO team, offering direct visibility into strategic security decision-making and the opportunity to meaningfully shape it. The individual in this position will have a tangible impact on regulatory standing and operational resilience across the region.

Scope of responsibilities:

1.   Develop an understanding of local requirements:

  • Maintain a continuous awareness of NIS2 laws and regulations across the various countries of Central Europe and cooperate with local legal experts and consultants to understand scope and impact across the company;
  • Maintain and continuously update the roster of local roles and responsibilities of various functions across the company that are required to either act or provide input for NIS2 related matters;
  • Maintain and continuously update the catalogue of business services, hardware and software assets, and third-party suppliers across all in-scope entities, ensuring accuracy and completeness as the operational landscape evolves;
  • Support gap assessment initiatives across in-scope entities, identifying deficiencies in controls, documentation, and processes related to NIS2 and applicable national regulatory requirements.

2.   Implement and NIS2 across the Central Europe region:

  • Develop and oversee structured remediation plans to address identified compliance gaps, coordinating remediation efforts across regional security functions and local stakeholders through to closure;
  • Draft, implement and maintain Standard Operating Procedures and Work Instructions to support the compliance framework and satisfy legal and regulatory obligations;
  • Ensure vendor contracts and internal documentation remain aligned with applicable legal and regulatory requirements;
  • Development and ongoing maintenance of security policies, procedures, and supporting documentation, applying version control, periodic review cycles, and management approval processes to ensure continued regulatory alignment;
  • Create and maintain a centralized control matrix related to NIS2 requirements as well as identify local, national level requirements, different from the Directive text and maintain local, country level controls, along with associated policies, procedures and work-instructions.

3.   Monitor business continuity requirements:

  • Monitor and support the development, documentation and implementation of a business continuity and disaster recovery framework in alignment with NIS2 requirements, working with the relevant functions to ensure timely delivery and appropriate governance oversight;
  • Monitor periodic testing of business continuity, disaster recovery, and backup procedures including tabletop exercises, technical failover tests, and restoration verification ensuring that accountable teams conduct testing as required, findings are documented and identified gaps are tracked through to remediation.

4.   Coordinate local level incident communication with regulatory bodies:

  • Serve as the primary point of contact for national authority inquiries, managing communications and coordinating the cyber incident response process across regional stakeholders and in-scope entities, gathering and disseminating relevant threat intelligence;
  • Manage the end-to-end process of cybersecurity incident notification to national authorities, ensuring all reporting obligations are fulfilled within prescribed regulatory timeframes.

5.   Coordinate NIS2 activities to meet regulatory audit and self-assessment requirements:

  • Ensure periodic/event-triggered risk assessments and compliance reviews, including findings documentation, remediation tracking, and escalation to the Risk Register where required;
  • Manage the full lifecycle of mandated periodic regulatory audits, encompassing auditor procurement, scheduling and adherence to prescribed regulatory timelines, including preparation of audit evidence, facilitation of audit sessions, while maintaining an up-to-date Risk Treatment Plan and actively following up on the resolution of audit findings with local entities and regional stakeholders.

6.   Monitor, report and participate in the NIS2 governance process across Central Europe:

  • Participate in the decision-making process to ensure that adequate support is allocated across the various business processes across the organization to support both the implementation of NIS2 requirements and the ongoing compliance obligations;
  • Deliver regular reporting on key risk indicators, key performance indicators, and overall compliance status to senior leadership, providing clear and actionable insight into the organization’s regulatory posture;
  • Drive continuous improvement across the compliance and cybersecurity governance framework, proactively identifying opportunities to strengthen controls, streamline processes and enhance the overall regulatory posture.

What we offer

Great perspective for your career

  • exposure from day one to various industries & a high diversity of tasks, projects and clients of well-known brands, both local and international
  • the chance to work for the Most Desired Employer in Romania, in the Financial Services Industry, six years in a row (Catalyst)
  • well-prepared care process for newcomers / peer learning and coaching program

Continuous learning

  • on the job learning from some of the best experts in our country
  • free access to lifelong learning opportunities through trainings in Business Skills, Technical Knowledge, Professional Qualifications, Soft Skills, depending on your needs
  • thousands of online courses (on LinkedIn Learning, Udemy for Business, GetAbstract and others), on almost any topic you want to learn about
  • Support in obtaining certifications

Focus on your needs

  • competitive compensation
  • a budget to spend on benefits that suit you, on top of your salary! Choose from a long list, up-to-date with the current reality (private medical insurance, food vouchers, vacation tickets, private pension, high range of online store vouchers and many more)
  • monthly teleworking allowance to cover your expenses while working from home
  • 25 vacation days & 2 sick leave days /year
  • Bookster subscription & corner at the office social area
  • Employee assistance program: free legal, financial, psychological & health support
  • wellbeing monthly programs are available to you covering physical, mental and emotional areas: on-site massage, sports sessions, mindfulness and financial education workshops as well as other topics related to wellbeing
  • travel insurance for professional & personal trips

Flexible working experience

  • hybrid work & flexible working hours. Teams set their team days and client office days, plan office presence together and communicate it clearly
  • exam period at University? Adapt your work schedule to accommodate your finals, while also getting the job done!

A culture of friendliness and acceptance

  • open colleagues, an environment that encourages everyone to enjoy their job and express their opinions freely and leaders whose doors are always open
  • recurring well-being programs to support your quality of life; an environment that supports everyone’s mental and physical health

Community involvement

  • 2 volunteering days/year paid by the firm, to support a cause of your choosing
  • the opportunity to volunteer for projects supported by Deloitte in partnership with non-profit organizations, with focus on education

Selection process

*We thank all applicants in advance for submitting their resumes but please note that only those candidates selected for an interview will be contacted.

About Deloitte

We give you the means and the know-how, you bring the inspiration and the enthusiasm. Join Deloitte Romania and explore where and how far you can go, through the countless learning and professional development opportunities that our company offers and the continuous support of our friendly team!

In Romania, the services are provided by Deloitte Audit SRL, Deloitte Tax SRL, Deloitte Consultanta SRL, Deloitte Accounting SRL, Deloitte Fiscal Representative SRL, Deloitte Tehnologie SRL, Deloitte Support Services SRL, Deloitte Shared Services SRL as well as Reff & Asociații SPRL, the correspondent law firm of Deloitte in Romania, (jointly referred to as “Deloitte Romania) which are affiliates of Deloitte Central Europe Holdings Limited. Deloitte Romania is one of the leading professional services organizations in the country providing services in professional areas of audit, tax, legal, management consulting, financial advisory, risk management services, outsourcing solutions and technology consulting and other related services through over 3,400 national and specialized expatriate professionals. To learn more about how Deloitte makes an impact that matters, please visit and connect with us on Facebook , LinkedIn YouTube and Instagram .

#LI-BV1

Oferta de muncă a fost publicată la 19 ore în urmă

Peste 300 000 de români

deja și-au creat profil pe Jooble

Ai obosit să cauți? Începe să muncești!

Creează-ți un profil pe Jooble, iar noi îți vom găsi jobul potrivit ✨

Oferte de muncă similare care v-ar putea interesaÎn baza ofertei de muncă Cybersecurity Compliance Manager din Craiova
  •  ...Who we are looking for We are looking for a Cybersecurity Project Manager with a passion for cybersecurity, project delivery, and working with...  ...to detail and strong ownership mindset. ~ Ability to manage multiple priorities in a dynamic project environment. ~... 
    Sugestii
    Full time
    Lucru hibrid
    Craiova
    O lună în urmă