h3Job Description /h3pVitol is an energy and commodities company with revenues of $331 billion in 2024; its primary business is the trading and distribution of energy products globally – it trades over seven million barrels per day of crude oil and products and, at any time, has 250 ships transporting its cargoes. /ppVitol’s clients include national oil companies, multinationals, leading industrial companies and utilities. Founded in Rotterdam in 1966, today Vitol serves clients from some 40 offices worldwide and is invested in energy assets globally including 24mM3 of storage, 850kbpd of refining capacity, and 10,000 service stations. To date, we have committed over $2.5 billion of capital to renewable projects and are identifying and developing low‑carbon opportunities around the world. /ph3Key Responsibilities: /h3h31. Governance and Compliance: /h3ulliEnsure compliance with relevant laws, regulations, and standards when required. /liliDevelop, enforce, review, and monitor compliance and update security policies, standards, and procedures. /liliAssist in Identifying and assessing risks across the organization. /liliConduct risk assessments, identify potential security risks, and implement mitigation strategies. /liliMonitor and report on risk exposure and mitigation efforts. /li /ulh33. Information Asset Inventories and Control Management /h3ulliMaintain information asset inventories including categorization, critical assets, risks, and security controls in place. /liliOwnership of the cybersecurity Control Catalog and ensure controls are applied. /li /ulh34. Security Auditing: /h3ulliPerform security audits, internally and respond to external audit demands. /liliPerform 3rd Party audits and maintain an inventory of vetted suppliers and tools. /liliThe focus for this position will be Vitol affiliates. /liliThis position will ensure that Vitol affiliates remain compliant with Vitol Cybersecurity policies and standards. /liliThis position requires traveling to Vitol affiliates locations.br/ /li /ulh3Qualifications /h3ulli3+ years of professional experience in cybersecurity, with focus on auditing, governance, risk management. /liliStrong understanding of regulatory requirements and industry standards (eg. NIS2) /liliKnowledge of best practices in modern security architectures and incident responses /liliRelevant security certifications such as CRISC, CISA. /liliFamiliarity with security control frameworks: CIS Controls, NIST Special Publication 800-53 /liliFamiliarity with cybersecurity frameworks: NIST CSF, ISO27001 /li /ulh3Personal Characteristics /h3ulliHighly responsive, energetic and enthusiastic /liliAnalytical thinking and problem-solving skills. /liliAbility to work independently and as part of a team. /liliStrong ethical standards and integrity. /liliCapable of prioritising tasks and meeting critical deadlines /liliExcellent judgment, attention to details /liliExcellent communication and interpersonal skills /liliExpect duty to expand beyond normal business hours. /liliUser/business focus /li /ul #J-18808-Ljbffr
Governance, Risk & Compliance Officer in Genève Arbeitgeber: SmartRecruiters Inc
SmartRecruiters ist ein hervorragender Arbeitgeber, der eine inklusive und kollaborative Arbeitskultur fördert, in der jeder Mitarbeiter die Möglichkeit hat, zu wachsen und sich weiterzuentwickeln. Mit wettbewerbsfähigen Gehältern, großzügigen Aktienoptionen und einem remote-freundlichen Umfeld bieten wir unseren Mitarbeitern nicht nur bedeutende Wachstumschancen, sondern auch die Möglichkeit, an innovativen Lösungen zu arbeiten, die echte Auswirkungen auf die Talentakquise haben. Unsere Auszeichnungen für Vielfalt, Work-Life-Balance und Unternehmenskultur unterstreichen unser Engagement für das Wohlbefinden und die Zufriedenheit unserer Mitarbeiter.