About You
- You're a go-getter with mad juggling skills (or multiple hats) who can thrive in a fast-paced, agile environment
- You enjoy doing purpose-led and meaningful work
- You have a strong thirst for knowledge and are driven to find solutions that don't exist yet
- You are comfortable with ambiguity and extremely resourceful (in your past life, you could've been a detective)
- You always find a way to get things done without sacrificing the quality of your work, integrity, and values
- No task is off limits for you
- You are humble and prioritize the success of the team over your own with an eagerness to help those around you
- You don't shy away from challenges and can bounce back from setbacks
- We strongly encourage individuals with disabilities to apply. We believe in equal opportunity and strive to create an inclusive workplace where everyone can thrive.
What you'll do and what success looks like in this role:
- Support the implementation of cybersecurity frameworks in line with international standards (e.g., NIST Cybersecurity Framework and ISO 27001).
- Develop, maintain, and update cybersecurity policies, standards, and procedures.
- Support internal and external audits by preparing relevant evidence and documentation.
- Identify, assess, and mitigate cybersecurity risks.
- Conduct hardening compliance reviews and provide mitigation or improvement recommendations when necessary.
- Collaborate with internal stakeholders to address cybersecurity policy and procedure requirements.
What Is Required and What We're Looking For
- Bachelor's Degree (S1) in Computer Science, Information Systems, or a related field.
- Minimum 5 years of experience in cybersecurity, IT infrastructure security, risk management, or IT compliance.
- Strong knowledge of security standards and frameworks, including ISO 27001, NIST, and CIS Controls.
- Familiar with security controls, risk registers, compliance monitoring, and assurance reporting.
- Solid understanding of IT infrastructure and application security, including network, server, cloud, and endpoint security.
- Strong risk identification, assessment, and mitigation skills.
- Relevant certifications such as CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or equivalent are preferred.
- Excellent communication skills with the ability to coordinate across functions and present reports to management.
- Strong problem-solving and analytical skills.
- Proven ability to lead and guide team members in achieving organizational objectives.