Rejobs
Voltalia

IT Security Specialist GRC (m/w/d)

成为Voltalia在葡萄牙波尔图的IT安全专家GRC。监督信息安全的治理、风险和合规性。与团队合作实施安全策略并管理风险,享受可再生能源领域的动态工作环境。
Voltalia
Voltalia
葡萄牙波尔图   现场   全职  UTC+00:00   1001-5000   26 天前

Voltalia

公司概况

Voltalia

法国巴黎

2005年

商业模式

可再生能源

电力生产、可再生能源项目开发与运营

电力销售、项目开发与管理服务

地点与地理

Voltalia在多个国家运营,包括法国、巴西、葡萄牙、意大利和希腊。

公司文化

他们的使命是推动可再生能源的使用,以应对气候变化。

Voltalia提供一个多元化和包容性的工作环境,鼓励创新和团队合作。

公司重视员工的职业发展,提供培训和晋升机会。

活动与项目

Voltalia正在进行多个可再生能源项目,包括风能和太阳能发电厂的建设。

他们致力于开发新技术以提高可再生能源的效率。

Voltalia实施可持续发展战略,致力于减少环境影响。

职业机会

Voltalia通常招聘工程师、项目经理和可再生能源专家。

公司提供竞争力的薪资、健康保险和灵活的工作安排。

联系信息

Voltalia LinkedIn

Voltalia的职业机会


最后更新于 2025-03-26 | 报告问题

Job Description

At Voltalia we are passionate about renewable energies! We are an electricity producer from wind, solar, hydro, biomass and storage and also a service provider to 3rd party clients such as Development, EPC, O&M and Distribution. Today we are in 20 countries, split among 4 continents, and offering a global operating capacity to our clients. We are listed on the regulated Euronext market in Paris since July 2014.

Our IT Security and Infrastructure Team is looking for an IT Security Specialist GRC.

The IT Security Specialist GRC (Governance, Risk, and Compliance) is responsible for overseeing governance, risk, and compliance aspects of information and cyber security. It plays a key role in promoting security best practices across VOLTALIA and requires support from Executive Committee Members, business managers, and IT leaders. Led by the Information Security Officer (ISO), this function has the following responsibilities:

Information and Cyber Security Strategy & Policy

  • Assist the ISO in implementing the information and cyber security strategy and program.

Information and Cyber Security Risk Management

  • Support the development and implementation of a risk management methodology aligned with VOLTALIA’s objectives, overall risk strategy, and regulatory requirements.
  • Ensure alignment between information and cyber security risk management and VOLTALIA’s enterprise risk management framework.
  • Provide guidance and support on information and cyber security risk management activities.
  • Assess the effectiveness of security controls in IT and OT environments.
  • Monitor information and cyber security risks by evaluating control implementation, asset vulnerabilities, threat landscapes, and security incidents.
  • Report risk trends to Risk Owners and other relevant committees.

Security Standards & Architecture

  • Develop and maintain security documentation, including standards, processes, procedures, guidelines, contractual clauses, and control catalogs.
  • Design and maintain a unified IT and OT security architecture aligned with the overall security strategy.
  • Establish a security architecture repository, including principles, terminology, security services, control frameworks, and reference models.

Security by Design

  • Support first-line teams in identifying and addressing cyber security risks and requirements in new products, projects, processes, and services.

Security Awareness & Training

  • Develop and implement security education, training, and awareness programs to foster security-conscious behaviors across IT and OT environments.

Audit & Compliance Support

  • Provide evidence of risk oversight and control implementation for internal and external audits.
  • Communicate the status and progress of the security program to key stakeholders.

Monitoring & Continuous Improvement

  • Monitor compliance with security architecture and standards.
  • Collect and analyze key performance and effectiveness metrics to support decision-making and inform the ISO.

Requirements

The ideal candidate will have/ be:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related.
  • 3+ years of experience in Information Security GRC.
  • Strong knowledge of security frameworks (e.g., ISO 27001, ISO27005, NIST, IEC 62443).
  • Familiarity with regulatory requirements such as GDPR, NIS2, etc.
  • Experience with risk management tools, compliance platforms, and security monitoring solutions.
  • Experience conducting security audits and risk assessments.
  • Understanding of IT security principles, cloud security, and network security.
  • Certifications such as CRISC, CISA, ISO 27001 Lead Auditor/Implementer, ISO 27005 Risk Manager (preferred).
  • Fluent English.
  • Possible travel, mainly in Europe.

Key Skills

  • Challenges-driven, rigorous, strong commitment, and investment.
  • Excellent analytical and problem-solving skills with the ability to assess and prioritize security risks.
  • Willing to develop new skills and competencies.
  • Comfortable working with high autonomy and as a team player;
  • High level of integrity and ability to handle sensitive and confidential information.
  • Very well organized. Able to manage and prioritize time and multiple tasks efficiently, especially when operating under pressure or deadlines.
  • Strong communication and collaboration skills to work effectively with cross-functional teams and external stakeholders. Know how to adapt your communication.
  • Passionate about cybersecurity and staying up-to-date on the latest threats and trends.

关于这个角色

2025年3月22日

全职

公司

Voltalia

2025年3月25日

现场

voltalia.com

  •  葡萄牙波尔图

3+ years in Information Security GRC

UTC+00:00

立即申请

工作已过期?

请告知 Voltalia 您是在 Rejobs 上找到这份工作的。这将帮助我们成长,并让更多人投身于可再生能源工作!

如何连接

查看您的连接

在 LinkedIn 上查看您在 Voltalia 的联系人,在申请此职位时充分利用您的人际网络

与朋友分享

形势严峻,谈话的时机已过。现在是采取行动的时候。 帮助朋友加快向可持续未来的转变。

分享这份工作 - IT Security Specialist GRC (m/w/d) - 给你的朋友们,帮助他们找到一份值得自豪的职业。