IT Governance, Risk & Compliance Manager
emerchantpay · Sofia
Описание на позицията
About the role
emerchantpay is seeking an IT Governance, Risk, and Compliance Manager to own the integrated control framework across its global payment platform. You will ensure that information security, risk, and regulatory requirements are embedded in daily operations and strategic growth.
Key responsibilities
- Define and maintain the information security strategy, standards, and roadmap aligned with regulations and best practices.
- Steer security architecture for a cloud‑native environment, creating secure‑by‑design patterns for microservices, APIs, and shared services.
- Establish a secure software development lifecycle and embed automated security controls into CI/CD pipelines.
- Define and enforce cloud security guardrails, including identity, network segmentation, encryption, secrets management, and configuration baselines.
- Build and operate security monitoring, logging, and threat detection across cloud, infrastructure, and application layers.
- Lead the full security incident response lifecycle and act as incident commander for security events.
- Own vulnerability and threat management, including scanning, risk‑based prioritisation, remediation tracking, and reporting.
- Plan and coordinate penetration testing and drive remediation of findings.
- Govern identity and access management, privileged access, and least‑privilege principles.
- Define data protection controls such as encryption, key management, data classification, and loss prevention for sensitive and cardholder data.
- Secure corporate IT, endpoints, networks, and collaboration platforms.
Required profile
- Proven experience in information security governance, risk management, and compliance within a complex, cloud‑native environment.
- Deep knowledge of ISO 27001, PCI DSS, SOC, and relevant regulatory frameworks (e.g., RBI licensing, NIS 2, EU AI Act).
- Strong track record of building and operating security monitoring, incident response, and vulnerability management programs.
- Ability to work cross‑functionally with Engineering, Legal, Finance, and senior leadership.
Required skills
- Cloud security (AWS, Azure, or GCP)
- Identity and Access Management (IAM)
- Vulnerability management and penetration testing
- Secure Software Development Lifecycle (Secure SDLC)
- CI/CD pipeline security
- Encryption, key management, and data loss prevention
- Threat detection, logging, and monitoring
- Network segmentation and secrets management
- Microservices and API security
Questions fréquentes
Защо докладвате тази оферта?
Кандидатствайте за 30 секунди
Въведете имейл, за да кандидатствате. Автоматично ще се създаде акаунт.
Продължавайки, приемате нашите условия за ползване.
Вече имате акаунт? Вход
Публикувано преди 12 часа
Изтича след 1 месец
5 прегледи · 0 interested
Увеличете шансовете си
Качете вашето CV: ние ще ви предложим обяви, съвпадащи с вашия профил.
Анализиране на твоето CV...
emerchantpay
Sofia