Senior Security GRC Expert (all genders) in Berlin

Senior Security GRC Expert (all genders) in Berlin

Berlin Vollzeit Vor Ort
Z

As a Senior Security GRC Expert in the Information Security - Security Risk & Governance Team, you will be at the forefront of safeguarding trust for our customers, stakeholders, and employees. By expertly identifying, assessing, and managing security risks, you will directly influence the security posture of our internal applications and third-party relationships, becoming the go-to expert and a key architect of our evolving Security Risk Management process.

In this pivotal role, you will help maintain and advance our security posture by taking ownership of our risk management processes. As a key stakeholder, you will translate complex business requirements into clear, actionable security operational solutions, implementing and ensuring our security framework remains robust and effective as we continue to grow.

WHAT WE’D LOVE YOU TO DO (AND LOVE DOING)

Manage Security Compliance: Implement, maintain, and continuously improve the information security compliance framework. Experience with Secure Controls Framework (SCF) is a plus.

Ensure Regulatory Adherence: Monitor, enforce, and advise on compliance with DORA, GDPR, PCI-DSS, SOC2, NIS2, CRA, and other relevant regulations.

Develop Security Governance: Contribute to the creation, review, and upkeep of information security policies, procedures, and controls.

Drive Risk Management: Design, implement, and maintain the information security risk management framework for projects, systems, and processes.

Measure Risk Management Effectiveness : Develop KPIs to track the effectiveness of risk management efforts.

Report to Leadership : Prepare and present regular reports on security risks, compliance, and improvements.

You have 6+ years of experience working in Security Governance, Risk and Compliance functions.

You demonstrate strong communication skills and good interpersonal skills.You can communicate security risk-related concepts to technical and nontechnical audiences.

You have experience in interpreting and implementing security and privacy regulations and frameworks (e.g., NIST CSF, GDPR, ISO 2700x, SOC 2, PCI DSS, NIS2, CRA) into actionable security operational requirements.

You have a familiarity with the Secure Control Framework (SCF).

You have exceptional attention to detail, strong program/project management skills, analytical proficiency, and experience in operationalizing and developing scalable security processes in complex environments.

You have security certifications (e.g. CISSP, CRISC, CISM, ISO 27001 Lead Auditor/Implementer) as a plus.

OUR OFFER

Zalando provides a range of benefits, here’s an overview of what you can expect. Ask your Talent Acquisition Partner to learn more about what we offer.

27 days of holiday a year to start for full-time employees (+1 day for every calendar year up to 30 days)

40% off fashion and beauty products sold and shipped by Zalando, 30% off Lounge by Zalando, discounts from external partners

Family support, including counselling and dedicated services for parents and carers

Company pension scheme

Employee shares programme

Health and wellbeing options, including Wellhub

Mental health support and coaching

Development through our training platform and biannual peer-to-peer review

2 paid volunteering days a year

Relocation assistance (subject to prior agreement)

INCLUSIVE BY DESIGN

If you think you have what it takes, we encourage you to apply even if you don't meet every single requirement. You may just be the right candidate for this or other roles!

At Zalando, our vision is to be the leading European technology platform for fashion and lifestyle – one that thrives on diversity and is truly inclusive by design. We believe that diverse teams fuel innovation and creativity, and we actively seek out talent from all backgrounds.

We actively seek to reduce bias in our hiring and employment processes, focusing on your qualifications, skills, and contributions. To support this, we kindly ask that you refrain from including personal details such as your photo, age, or marital status in your CV, ensuring a fair and equitable evaluation based solely on your abilities and potential.

We are committed to providing an exceptional and accessible candidate experience for everyone. If you require any accommodations to support you throughout the hiring process, please let us know – we are here to assist you.

#J-18808-Ljbffr

Senior Security GRC Expert (all genders) in Berlin Arbeitgeber: Zalando GmbH

Zalando ist ein hervorragender Arbeitgeber, der eine inklusive und vielfältige Arbeitskultur fördert. Als Software Engineer (m/w/d) haben Sie die Möglichkeit, an innovativen Projekten zu arbeiten und Ihre Fähigkeiten in einem dynamischen Umfeld weiterzuentwickeln. Mit attraktiven Benefits wie 27 Urlaubstagen, einem Mitarbeiteraktienprogramm und Unterstützung für die persönliche Entwicklung bietet Zalando nicht nur ein erfüllendes Arbeitsumfeld, sondern auch zahlreiche Möglichkeiten zur beruflichen Entfaltung.

Z

Kontaktdaten:

Zalando GmbH Recruiting-Team