Governance, Risk and Compliance (GRC) Analyst
Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · Compliance & Regulatory
In short
Emerson is seeking a Governance, Risk and Compliance (GRC) Analyst in Cluj-Napoca, Romania, to strengthen cybersecurity and compliance programs, particularly focusing on NIS2. This hybrid role involves partnering with stakeholders to assess, implement, and monitor information security activities, identify compliance gaps, and support remediation efforts within frameworks like ISO 27001 and TISAX.
Responsibilities
- Support NIS2 assessments by evaluating information security controls, processes, and practices.
- Document security controls, coordinate evidence collection, and maintain compliance with NIS2 requirements.
- Identify compliance gaps and collaborate with stakeholders to develop and track remediation plans.
- Partner with teams to implement and sustain security measures aligned with regulatory and business requirements.
- Monitor progress toward compliance objectives and ensure effective remediation.
- Prepare and present compliance status updates, risks, and program initiatives to leadership.
- Support internal and external audits related to NIS2 and other cybersecurity frameworks.
- Deliver training sessions, awareness activities, and guidance on NIS2 requirements and best practices.
- Stay informed on regulatory changes and emerging requirements.
- Coordinate audit preparation activities, including scheduling, stakeholder engagement, and evidence collection.
- Review audit findings, track corrective actions, and report on remediation progress.
- Contribute to control assurance and compliance initiatives.
- Support information security framework assessments, management system implementations, and gap remediation efforts.
Requirements
- Experience in information security, governance, compliance, risk management, or a related field.
- Knowledge of cybersecurity principles, controls, standards, and regulatory requirements.
- Experience supporting or participating in assessments, audits, or compliance initiatives involving frameworks such as NIS2, ISO 27001, ISO 27002, TISAX, or similar standards.
- Ability to identify control gaps, evaluate risks, and support the development of practical remediation plans.
- Strong communication and collaboration skills with the ability to work effectively across diverse teams and stakeholder groups.
- Ability to organize, coordinate, and manage multiple priorities while maintaining attention to detail.
- Experience coordinating evidence collection, compliance documentation, or audit activities.
- Demonstrated ability to interpret requirements and translate them into actionable business and security practices.
- Fluency in English.
- Ability to travel up to 20% as business needs require.
- A degree in Information Technology, Information Systems, Computer Science, Cybersecurity, or a related field, or equivalent combination of education, training, and relevant experience.
Desired Qualifications
- Experience supporting internal or external audit programs.
- Familiarity with cybersecurity governance, risk management, and compliance programs in multinational organizations.
- Experience working with multiple information security frameworks and regulatory requirements.
- Knowledge of control assurance methodologies and continuous improvement practices.
- Proficiency in one or more additional European languages.
- Relevant industry certifications related to cybersecurity, information security, auditing, governance, risk management, or compliance.
Benefits
- Opportunities for career development and growth.
- Investment in employee success through mentorship, training, or leadership opportunities.
- An inclusive culture that fosters diverse perspectives.
- Support for thriving in a collaborative environment.
#GRC#cybersecurity#compliance#risk management#NIS2#ISO 27001#TISAX