What is your role?
You will be part of a journey where you will have two impacts: a client impact and an internal impact. For the internal impact, based on your skills and time, you will be joining our internal security community at CBTW, to share knowledge and best practices. For the client impact, tasks can vary depending on the client and the project, but as a GCR Expert, you will mainly:
1. Strategy and Governance:
-
Help define information security strategy and scope
-
Organize, frame, and manage security projects
-
Implement an Information Security Management System (ISMS)
-
Contribute to defining/revising policies and procedures (ISSP, SCS, incident response)
2. Risk Management:
-
Analyze and map risks (ISO 27005, EBIOS RM)
-
Identify, evaluate, and monitor operational, compliance, and security risks
-
Implement security performance indicators (KPIs)
3. Compliance and Regulation:
-
Ensure compliance with cybersecurity and data protection regulations (NIST, NIS2, DORA, GDPR)
-
Evaluate information security posture
-
Conduct internal audits
4. Incident Management:
-
Coordinate security incident response
-
Monitor remediation plans (following incidents, audits)
-
Implement corrective measures
5. Training and Awareness:
-
Provide training and raise employee awareness about GRC policies
-
Promote security standards and best practices