Cybersecurity Governance, Risk and Compliance

Vitol

London, England, United Kingdom Full-time 5 days ago
Workplace
On-site
Location
London, England, United Kingdom
Who can apply
Based in the United Kingdom: you usually need the right to work there

Check your CV against this job

Free · No signup · A 0–100 ATS match score and the keywords you're missing.

Check my CV free

$14.99/month, cancel anytime. Already have an account? Log in

About the role

Job Description

The Governance and Risk Officer help ensure that the organization maintains a robust security posture, complies with relevant policies and standards, and fosters a culture of security among employees.

Key Responsibilities:

1.    Governance and Compliance:

* Ensure compliance with relevant laws, regulations, and standards when required. * Develop, enforce, review, and monitor compliance and update security policies, standards, and procedures.

2.    Risk Management:

* Assist in Identifying and assessing risks across the organization. * Conduct risk assessments, identify potential security risks, and implement mitigation strategies. * Monitor and report on risk exposure and mitigation efforts.

3.    Information Asset Inventories and Control Management

* Maintain information asset inventories including categorization, critical assets, risks, and security controls in place. * Ownership of the cybersecurity Control Catalog and ensure controls are applied.

4.    Security Auditing:

* Perform security audits, internally and respond to external audit demands. * Perform 3rd Party audits and maintain an inventory of vetted suppliers and tools.

5.  Portfolio Companies

* The focus for this position will be Vitol affiliates. * This position will ensure that Vitol affiliates remain compliant with Vitol Cybersecurity policies and standards. * This position requires traveling to Vitol affiliates locations.

Qualifications

* 3+ years of professional experience in cybersecurity, with focus on auditing, governance, risk management. * Strong understanding of regulatory requirements and industry standards (eg. NIS2) * Knowledge of best practices in modern security architectures and incident responses * Relevant security certifications such as CRISC, CISA. * Familiarity with security control frameworks: CIS Controls, NIST Special Publication 800-53 * Familiarity with cybersecurity frameworks: NIST CSF, ISO27001

Personal Characteristics

* Highly responsive, energetic and enthusiastic * Analytical thinking and problem-solving skills. * Ability to work independently and as part of a team. * Strong ethical standards and integrity. * Capable of prioritising tasks and meeting critical deadlines * Excellent judgment, attention to details * Excellent communication and interpersonal skills * Expect duty to expand beyond normal business hours. * User/business focus

Get matched & apply with FindAJobAI

Upload your resume once. We score every job against your profile, tailor your resume and cover letter, and autofill the application.