Governance, Risk and Compliance (GRC) Analyst
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · Regelefterlevnad
I korthet
Emerson seeks a Governance, Risk and Compliance (GRC) Analyst in Cluj-Napoca, Romania, to enhance cybersecurity and compliance programs, focusing on NIS2 directives. This hybrid role involves assessing controls, identifying gaps, and collaborating with stakeholders to implement security measures and support audits. The ideal candidate has experience in information security, risk management, and compliance frameworks like ISO 27001 and TISAX.
Ansvarsområden
- Support NIS2 assessments by evaluating information security controls, processes, and practices.
- Document security controls, coordinate evidence collection, and maintain compliance with NIS2 requirements.
- Identify compliance gaps and collaborate with stakeholders to develop and track remediation plans.
- Implement and sustain security measures aligned with regulatory and business requirements.
- Monitor progress toward compliance objectives and ensure timely remediation.
- Prepare and present compliance status updates, risks, and program initiatives to leadership.
- Support internal and external audits related to NIS2 and other cybersecurity frameworks.
- Deliver training and awareness activities on NIS2 requirements and information security best practices.
- Stay informed on regulatory changes and emerging requirements.
- Coordinate audit preparation activities, including scheduling, stakeholder engagement, and evidence collection.
- Review audit findings, track corrective actions, and report on remediation progress.
- Contribute to control assurance and compliance initiatives to enhance the organization’s cybersecurity posture.
- Support information security framework assessments, management system implementations, and continuous improvement initiatives.
Krav
- Experience in information security, governance, compliance, risk management, or a related field.
- Knowledge of cybersecurity principles, controls, standards, and regulatory requirements.
- Experience supporting or participating in assessments, audits, or compliance initiatives involving frameworks such as NIS2, ISO 27001, TISAX, or similar standards.
- Ability to identify control gaps, evaluate risks, and support the development of practical remediation plans.
- Strong communication and collaboration skills with the ability to work effectively across diverse teams and stakeholder groups.
- Ability to organize, coordinate, and manage multiple priorities while maintaining attention to detail.
- Experience coordinating evidence collection, compliance documentation, or audit activities.
- Demonstrated ability to interpret requirements and translate them into actionable business and security practices.
- Fluency in English.
- Ability to travel up to 20% as business needs require.
- A degree in Information Technology, Information Systems, Computer Science, Cybersecurity, or a related field, or equivalent combination of education, training, and relevant experience.
Önskade kvalifikationer
- Experience supporting internal or external audit programs.
- Familiarity with cybersecurity governance, risk management, and compliance programs in multinational organizations.
- Experience working with multiple information security frameworks and regulatory requirements.
- Knowledge of control assurance methodologies and continuous improvement practices.
- Proficiency in one or more additional European languages.
- Relevant industry certifications related to cybersecurity, information security, auditing, governance, risk management, or compliance.
Förmåner
- Opportunity to grow your career and help strengthen Emerson’s cybersecurity and compliance programs.
- Support and maintenance of compliance with the European Union Network and Information Security Directive (NIS2).
- Partnering with stakeholders across the organization to assess, implement, coordinate, and monitor information security activities.
- Key role in identifying compliance gaps, supporting remediation efforts, and enhancing cybersecurity governance.
- Contribution to broader security initiatives, including ISO 27001, TISAX, and other information security frameworks.
- Valued, respected, and empowered to grow.
- Environment that encourages innovation, collaboration, and diverse perspectives.
- Ongoing career development and growing an inclusive culture.
- Support for thriving through mentorship, training, or leadership opportunities.
- Investment in your success to make a lasting impact.
- Opportunity to contribute, develop, and succeed.
- Equitable opportunities, celebrating diversity, and embracing challenges.
#governance#risk#compliance#cybersecurity#information security#NIS2#ISO 27001#TISAX