Quality & Reliability S.A. (QnR)

Cybersecurity GRC Consultant (Mid/Senior)

Quality & Reliability S.A. (QnR) Athens, Attica, Greece

Software Development · 51-200 employees

5 h ago
Remote security Senior (5-10 yrs) Full-time Greece
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The consultant will conduct gap assessments, maturity reviews, and control evaluations to help organizations translate business risks into effective governance and policies. They will also coordinate compliance initiatives for frameworks like NIS2, DORA, and ISO/IEC 27001 while advising leadership on cybersecurity strategy.

What they look for

Cybersecurity Governance Risk Management Compliance ISO/IEC 27001 NIS2 DORA NIST CSF CIS Controls Gap Assessments Maturity Reviews Policy Development Audit Readiness Stakeholder Reporting Information Security Management Control Evaluation Risk Treatment

Requirements

Candidates must have professional experience in cybersecurity governance, risk, and compliance, along with detailed knowledge of ISO/IEC 27001 and related frameworks. A professional certification such as CISM, CISA, CRISC, or CGRC is required for both mid-level and senior roles.

Full description

Are you a Cybersecurity GRC Consultant? Think bigger about your next move!Build your future with QnR Group. JOIN THE NEXT EUROPEAN TECHNOLOGY POWERHOUSE 🚀

Cybersecurity GRC Consultant | SysteCom, member of QnR Group

Role overview

We are looking for a Cybersecurity GRC Consultant to help organisations translate cybersecurity obligations and business risks into workable governance, policies, controls and improvement roadmaps.

About QnR GroupQnR Group is a technology group with 35 years of experience, 8 companies, 4 delivery centers and 210+ professionals across Greece, Belgium, Cyprus and Poland. Listed on the Athens Stock Exchange since 2000, we deliver mission-critical digital transformation projects for the public and private sector. The Group’s capabilities covers software engineering, enterprise and generative AI, cybersecurity, cloud infrastructure, SAP and ServiceNow solutions, core banking and maritime intelligence.

About SysteComSysteCom, a member of QnR Group, specializes in cybersecurity, digital resilience and IT infrastructure. The company delivers solutions and services that help organizations protect their systems and data, strengthen operational continuity and modernize their technology environments. Bringing together security and infrastructure expertise, SysteCom supports businesses across sectors in building secure, reliable and resilient digital operations.

What you'll work on:

  • Conduct gap assessments, maturity reviews and control evaluations
  • Develop policies, standards, risk-treatment plans and governance reports
  • Support NIS2, DORA, ISO/IEC 27001 and related compliance initiatives
  • Coordinate evidence, audits, remediation actions and stakeholder reporting
  • At senior levels, advise leadership on cybersecurity strategy and governance

What you bring:

  • Experience in cybersecurity governance, risk, compliance, audit, information-security management or advisory work
  • Detailed knowledge of ISO/IEC 27001 and familiarity with NIST CSF, CIS Controls or comparable frameworks
  • Practical experience conducting gap assessments, maturity reviews, control evaluations or audit-readiness activities
  • Ability to interpret NIS2, DORA and other applicable obligations and convert requirements into proportionate controls and evidence
  • Strong policy, procedure, report and roadmap drafting skills
  • Ability to facilitate workshops, interview stakeholders and communicate findings to technical and executive audiences
  • Understanding of ISMS operation, risk treatment, statements of applicability, corrective actions and control ownership
  • For senior candidates, experience defining governance models, advising leadership and leading multi-workstream compliance programmes

Required certifications:

Mid-level and Senior: at least one professional certification, such as CISM, CISA, CRISC, ISC2 CGRC, ISO/IEC 27001 Lead Implementer or Lead Auditor, or equivalent

Nice to have:

  • CISM, CISA, CRISC, CGRC, ISO/IEC 27001 Lead Implementer/Auditor or equivalent
  • Experience in regulated or public-sector environments
  • Third-party-risk assignments may additionally require a recognised vendor-risk, audit or privacy certification

Similar roles