Grc Consultant

il y a 6 jours


Luxembourg Econocom Temps plein

Econocom designs, finances and oversees companies' digital transformation.

The Econocom Group share is part of the BelMid index.

**Responsibilities**:
Developing and participating in implementation of client initiatives focused on the reduction of technology risk, governance and compliance with policies and external regulatory compliance

Evaluating business and IT risks with risks analysis standards (EBIOS, ISO 27005)

Developing IT security standards, procedures, and controls to manage risks.

Improve client's security positioning through process improvement, policy, automation, and the continuous evolution of capabilities

Evaluating information security threats and their impact on clients IT environment

Supporting and assisting internal team members and customers with the analysis of requirements and design of information security posture, as well as Legal, Regulatory and Scheme security requirements

Supporting in delivery of work streams for clients in compliance standards such as ISO/IEC 27001, EU GDPR and incident management disciplines

Performing and investigating internal and external information security risk and exceptions assessments

Assessing incidents, vulnerability management, scans, patching status, secure baselines, penetration test result, phishing, and social engineering tests and attacks

Documenting and reporting control failures and gaps to stakeholders

Providing remediation guidance and preparing management reports to track remediation activities

Staying current on best practices and technological advancements and acts as a technical resource for security assessment and regulatory compliance

Performing other related duties as assigned from time to time based on the business requirements

**Profile**:
3-5 years of proven work experience in compliance audit, analysis and risk management, in the consulting business or with an end customer

Understandings of ISO/IEC 27001, NIS/NIS-2, ITIL, ITSM COBIT, EBIOS standards and EU GDPR directive

Experience of risk management principles and associated methodologies

Excellent communication skills, strong analytical and writing skills in both French and English

Ideally have a CISSP, CISA or CISM qualification

Strong interpersonal and influencing skills with the ability to influence and drive change in a collaborative way both internally and externally

**We Offer**:
A competitive & challenging function in an innovative services company with room for initiatives.

An attractive salary package, company car, group insurance and extended hospitalization plan.

At Econocom you will operate in a professional environment where entrepreneurship is encouraged.

**Contact**:
Sébastien Missenard

Directeur PSF

T : +352 39 55 50 234

M : +352 621 146055


  • Grc Consultant

    il y a 2 semaines


    Luxembourg Spring Professional | LHH Recruitment Solutions Temps plein

    **Client Description**: One of our big clients, a European agile company, is looking for a GRC Consultant to join them as soon as possible (permanent contract). The Professional Spirit that drives us forward - Spring Professional | LHH Recruitment Solutions offers extensive HR solutions through one unique brand. We are specialised in the employment of...

  • SAP Security Consultant

    il y a 3 semaines


    Luxembourg Empiric Solutions Temps plein

    **SAP Security Consultant - Luxembourg** Empiric has received exclusive instructions from one of the leading Global IT Organisations for a SAP Security Consultant with experience in SAP GRC ARA, EAM, ARM, BRM. The SAP Security Consultant will be expected to have participated in at least 1 end-to-end SAP Security OR GRC implementation project, as well as...


  • Luxembourg Lux-Advisory Temps plein

    **Objective** Our client requires a full-time Operational Risk Senior Consultant to help with the management of institutional-wide operational risk management programme. The Consultant will maintain the operational risk management framework within the Risk Management Department and will provide a second line of defence oversight of the management of key...