Information Security Compliance Specialist role
English is a Must
Position Overview
The Information Security Compliance Specialist is responsible for ensuring governance and compliance across Identity Access Management (IAM), Secure Software Development Lifecycle (SDLC), and Cloud Security Infrastructure (DevSecOps), in alignment with the Group Information Security Framework (GISF).
Key Responsibilities
Identity Access Management (IAM) Governance & Compliance
- Ensure the governance and compliance of the IAM Target Operating Model (TOM) in alignment with Group Information Security Framework
- Monitor and enforce IAM policies, standards, and procedures across the organization
- Ensure and monitor user access review processes and recertification processes to ensure least privilege and segregation of duties (SoD)
- Oversee IAM control effectiveness through regular assessments and reviews
- Collaborate with IAM operations teams to ensure proper implementation of role-based access control (RBAC) and privileged access management (PAM)
- Track and report IAM-related risks, exceptions, and remediation activities
- Ensure compliance with regulatory requirements related to identity and access (e.g., GDPR, DORA, NIS2)
Secure Software Development Lifecycle (SDLC) Governance
- Establish and maintain governance frameworks for secure SDLC practices across development teams
- Define and enforce security requirements at each phase of the software development lifecycle
- Ensure integration of security testing (SAST, DAST, SCA) into CI/CD pipelines
- Review and validate security architecture and threat modeling for new applications and services
- Monitor compliance with secure coding standards and guidelines
- Provide guidance and training to development teams on secure development practices
Cloud Security Infrastructure & DevSecOps Compliance
- Ensure compliance of cloud security infrastructure with Group Information Security Framework and industry best practices
- Govern the implementation of security controls in cloud environments (IaaS, PaaS, SaaS)
- Monitor and enforce DevSecOps practices including infrastructure-as-code (IaC) security scanning
- Oversee cloud security posture management (CSPM) and cloud workload protection
- Ensure proper configuration management and hardening of cloud resources
- Validate compliance with cloud security benchmarks (e.g., CIS Benchmarks, CSA CCM)
- Collaborate with cloud engineering teams to embed security into deployment pipelines
General Governance & Compliance
- Align all activities with the Group Information Security Framework (GISF) and relevant policies
- Prepare and present compliance reports, dashboards, and KPIs to management
- Support internal and external audits related to information security
- Manage and track security exceptions, risk acceptances, and remediation plans
- Contribute to the continuous improvement of information security governance processes
- Liaise with Group Information Security, Risk Management, and Compliance functions
Application Confirmation
You're applying for the role below: