Information Security Specialist
3 days ago
Bucharest, România
Nexent Bank N.V. Amsterdam Sucursala București
Full-time
Gratuit cu e-mail sau Google
Salvați acest job și păstrați-vă căutarea organizată
Creați un cont gratuit pentru a salva locuri de muncă, pentru a crea alerte și pentru a reveni la această listă din tabloul de bord.
Gratuit cu e-mail sau Google
Continuând, sunteți de acord cu Termenii & Politica de confidențialitate.
Cybersecurity is about more than protecting systems. It’s about building trust, managing risk and enabling business resilience.
We’re looking for an Information Security Specialist who combines technical expertise, critical thinking and a strong sense of ownership to help us strengthen our security framework.
From security governance and risk assessments to incident response, compliance and cybersecurity awareness, this role offers the opportunity to connect technology, risk and business impact.
What will you do?
Assess risks. Strengthen resilience.
• Assess cybersecurity threats, IT vulnerabilities and data protection risks, translating findings into actionable recommendations.
• Evaluate IT architecture and security controls, identifying opportunities to improve our security posture.
• Coordinate risk mitigation plans with IT teams, business units and third-party providers. Drive security governance and compliance.
• Contribute to the design and continuous improvement of IT security architecture, standards, policies and controls.
• Support compliance with relevant frameworks and regulations, including ISO 27001, NIST, COBIT, GDPR, SWIFT and DORA.
• Coordinate with IT and Risk Management teams to ensure risks are appropriately addressed, controls are effective and management has clear visibility of the risk landscape. Be ready when it matters.
• Coordinate information security incident response activities, working closely with IT teams, the Security Operations Center (SOC) and external security partners.
• Support threat intelligence activities, including the investigation of phishing threats and fraudulent websites.
• Follow up on incidents and remediation actions, helping strengthen our ability to prevent and respond to future threats. Make security everyone's business.
• Promote cybersecurity awareness across the organization through training, phishing simulations and practical guidance.
• Monitor awareness initiatives and communicate progress and results to management.
• Coordinate external penetration testing activities and ensure findings are tracked through to remediation. Keep third-party risks in focus.
• Contribute to the information security assessment of ICT third-party providers throughout onboarding, contracting and ongoing monitoring. What will help you succeed?
• A university degree, preferably at Master's level, in IT, Information Systems or a related field.
• A solid understanding of network infrastructure, architecture, protocols, operating systems, encryption techniques and security technologies.
• Knowledge of networking technologies and protocols, including Ethernet, TCP/IP and IP routing, as well as security architecture and mobile technologies.
• Familiarity with vulnerability assessment and penetration testing tools such as Nexpose, Metasploit and Burp Suite is an advantage.
• Good knowledge of information security standards, frameworks and regulatory requirements, particularly ISO 27001 and PCI DSS.
• Strong analytical and problem-solving skills, critical thinking and the ability to navigate complex situations.
• Advanced English communication skills, both written and spoken.
• The ability to manage competing priorities and remain effective under pressure. What matters just as much as technical expertise? We believe how we work matters as much as what we know. Integrity. Courage. Excellence. Individual Responsibility. Caring for Others. These are our values, and we look for people who bring them to life through their decisions, collaboration and everyday actions. If you enjoy navigating complex challenges, connecting technical and business perspectives, and turning security requirements into practical solutions, we’d love to hear from you
• Assess cybersecurity threats, IT vulnerabilities and data protection risks, translating findings into actionable recommendations.
• Evaluate IT architecture and security controls, identifying opportunities to improve our security posture.
• Coordinate risk mitigation plans with IT teams, business units and third-party providers. Drive security governance and compliance.
• Contribute to the design and continuous improvement of IT security architecture, standards, policies and controls.
• Support compliance with relevant frameworks and regulations, including ISO 27001, NIST, COBIT, GDPR, SWIFT and DORA.
• Coordinate with IT and Risk Management teams to ensure risks are appropriately addressed, controls are effective and management has clear visibility of the risk landscape. Be ready when it matters.
• Coordinate information security incident response activities, working closely with IT teams, the Security Operations Center (SOC) and external security partners.
• Support threat intelligence activities, including the investigation of phishing threats and fraudulent websites.
• Follow up on incidents and remediation actions, helping strengthen our ability to prevent and respond to future threats. Make security everyone's business.
• Promote cybersecurity awareness across the organization through training, phishing simulations and practical guidance.
• Monitor awareness initiatives and communicate progress and results to management.
• Coordinate external penetration testing activities and ensure findings are tracked through to remediation. Keep third-party risks in focus.
• Contribute to the information security assessment of ICT third-party providers throughout onboarding, contracting and ongoing monitoring. What will help you succeed?
• A university degree, preferably at Master's level, in IT, Information Systems or a related field.
• A solid understanding of network infrastructure, architecture, protocols, operating systems, encryption techniques and security technologies.
• Knowledge of networking technologies and protocols, including Ethernet, TCP/IP and IP routing, as well as security architecture and mobile technologies.
• Familiarity with vulnerability assessment and penetration testing tools such as Nexpose, Metasploit and Burp Suite is an advantage.
• Good knowledge of information security standards, frameworks and regulatory requirements, particularly ISO 27001 and PCI DSS.
• Strong analytical and problem-solving skills, critical thinking and the ability to navigate complex situations.
• Advanced English communication skills, both written and spoken.
• The ability to manage competing priorities and remain effective under pressure. What matters just as much as technical expertise? We believe how we work matters as much as what we know. Integrity. Courage. Excellence. Individual Responsibility. Caring for Others. These are our values, and we look for people who bring them to life through their decisions, collaboration and everyday actions. If you enjoy navigating complex challenges, connecting technical and business perspectives, and turning security requirements into practical solutions, we’d love to hear from you