ADACOM

GRC Consultant

ADACOM  •  Nicosia, CY (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

We are looking for a motivated and knowledgeable GRC Consultant to join our team in Nicosia, Cyprus, and support our customers in strengthening their Governance, Risk, and Compliance frameworks.

The ideal candidate will contribute to the delivery of consulting projects related to information security governance, risk management, regulatory compliance, business continuity, and information security management systems. The role involves assessing customer environments, identifying gaps, developing policies and procedures, and supporting organizations in achieving and maintaining compliance with regulatory requirements and international standards.

Responsibilities

  • Participate in GRC consulting projects related to Information Security Management, Risk Management, Business Continuity, Information Classification, Security Awareness, and Regulatory Compliance
  • Conduct gap assessments against applicable standards and regulatory frameworks, including ISO/IEC 27001, ISO 22301, PCI DSS, GDPR, NIS2, and other relevant requirements
  • Support the implementation and continuous improvement of Information Security Management Systems (ISMS) and other management systems
  • Perform information security and business risk assessments, identify risks and control gaps, and provide practical recommendations for remediation
  • Develop and review policies, procedures, standards, risk registers, controls, and other GRC-related documentation
  • Conduct interviews and workshops with customer stakeholders to understand business processes, security requirements, and compliance needs
  • Prepare high-quality project deliverables, including assessment reports, gap analyses, risk assessments, compliance documentation, and management presentations
  • Support customers in preparing for internal and external audits and certification activities
  • Monitor developments in cybersecurity regulations, standards, and industry best practices and support their integration into customer projects
  • Contribute to the development and standardization of internal GRC methodologies, templates, tools, and consulting practices
  • Collaborate with technical cybersecurity teams to ensure that governance and compliance requirements are appropriately translated into technical and organizational controls
  • Participate in pre-sales activities, including customer meetings, requirements gathering, project scoping, effort estimation, and preparation of proposals and Statements of Work (SOWs)
  • Follow up on project actions and identified issues, collaborating with internal teams and customer stakeholders to support their successful resolution

Requirements

  • University degree in IT, Cybersecurity, Computer Science, Risk Management, or a related field, with 2+ years of relevant experience in GRC, information security, cybersecurity consulting, risk management, or compliance
  • Experience with standards and frameworks such as ISO/IEC 27001, ISO 22301, PCI DSS, GDPR, NIS2, or similar, combined with a good understanding of risk management, security controls, and cybersecurity best practices
  • Strong analytical, problem-solving, communication, presentation, and technical writing skills, with the ability to work effectively with both technical and business stakeholders
  • Strong organizational skills, adaptability, and the ability to manage multiple tasks and projects within deadlines.
  • Advanced proficiency in English
  • Relevant postgraduate studies or certifications such as CISA, CISM, CISSP, CRISC, ISO 27001 Lead Auditor, or Lead Implementer will be considered an advantage

Benefits

  • Private Health Insurance
  • Private Pension Plan
  • Training & Development
  • Performance Bonus
  • Laptop
  • Phone - Mobile Plan
ADACOM

About ADACOM

ADACOM enables security online for Financial Institutions, Telecom Operators, Governments and Large Organizations, in more than 30 countries in EMEA. ADACOM provides consulting and customised solutions from established vendors and innovative startups, leveraging international know-how and best practices to deliver tangible results for internal or external threats, and practically every security challenge.

Operations are organised in all the major Cyber practices:

Infrastructure Security

Data Governance

Governance, Risk, Compliance & Assurance

Security Analytics

PKI & Strong Authentication

ADACOM interdisciplinary teams comprise of security advisors, architects, engineers and project managers, with broad academic qualifications and professional certifications. With a track record of several international large scale projects, and investments in assets, physical presence, education and training, ADACOM leads the developments in the cyber security arena. ADACOM is ISO 9001:2008 and ISO 27001:2013 certified for the quality and security of the provided services and solutions.

Industry
IT & Software
Company Size
51-200 employees
Headquarters
Athens, GR
Year Founded
1997
Social Media