Information Security & GRC Officer
We are a leading digital agency specializing in custom web development, enterprise e-commerce platforms, and high-performance digital products. We deliver end-to-end software solutions for major corporate clients, combining cutting-edge design with robust engineering. As we scale our enterprise operations, ensuring the highest standards of security, infrastructure governance, and compliance is our top priority.
We are seeking a dedicated Mid-level Information Security & GRC Officer to join our team on-site at our Athens offices.
Position Overview
In this role, you will be a key driver of our Information Security Management System (ISMS). You will be responsible for maintaining our ISO 27001 certification and aligning security policies with our complex hybrid environment ( Azure Cloud & On-Premises VMware Private Cloud ). Working directly alongside our Chief Information Security Officer (CISO) and our Data Protection Officer (DPO) , you will bridge the gap between compliance frameworks like NIS2 , secure development methodologies ( Secure SDLC ), and hands-on technical operations.
Key Responsibilities
- ISO 27001 & Compliance Ownership: Manage, update, and improve the company’s ISMS, including policies, procedures, asset registers, and the Statement of Applicability (SoA).
- Secure SDLC Governance: Collaborate with tech leads, developers, and DevOps engineers to govern and maintain security controls throughout our software development lifecycle ( Secure SDLC ), embedding security into our CI/CD pipelines.
- NIS2 Readiness & Compliance: Assist the CISO in assessing, adapting, and aligning the agency's security posture and reporting mechanisms to meet NIS2 directive obligations for both the company and our regulated clients.
- Hybrid Infrastructure Governance: Collaborate with the infrastructure teams to ensure compliance controls are strictly maintained across our Azure Cloud setups and On-Premises VMware private cloud datacenters.
- Collaboration with CISO & DPO: Work hand-in-hand with the CISO on overall security strategy and risk mitigation. Support the DPO in ensuring full GDPR compliance regarding client data handled within our development and hosting environments.
- Risk Assessments: Execute asset-based and application-level information security risk assessments, maintaining and updating the corporate risk register.
- Audit Management: Organize and execute internal audits, and act as the primary facilitator during annual external ISO 27001 certification audits.
- Client & Vendor Procurement Support: Respond to complex technical security questionnaires (DDQs) from prospective enterprise clients and vet the security posture of third-party vendors.
Requirements
- 3+ years of professional experience in Information Security, Governance, Risk & Compliance (GRC), IT Compliance, or IT Audit.
- Previous experience within a software development company, digital agency, or technology-driven environment will be considered a strong advantage.
- Proven hands-on experience in implementing, maintaining, and continuously improving ISO 27001 Information Security Management Systems (ISMS).
- Solid understanding of key regulatory and security frameworks, including GDPR, NIS2 , and Secure Software Development Lifecycle (SSDLC) principles, with familiarity with OWASP guidelines and best practices.
- Good understanding of security requirements and risk considerations across hybrid IT environments , including Microsoft Azure , VMware virtualization, and private cloud infrastructure.
- ISO 27001 Lead Implementer or Lead Auditor certification is strongly preferred.
- Additional relevant certifications such as CompTIA Security+, CISA, CRISC , or equivalent will be considered a significant advantage.
- Strong analytical, risk assessment, and problem-solving skills, with the ability to translate security and compliance requirements into practical business and technical controls.
- Excellent technical documentation and reporting skills , with the ability to produce clear, structured, and professional security and compliance documentation.
- Fluency in both Greek and English , with excellent written and verbal communication skills.
- Ability to work effectively with technical and non-technical stakeholders , including development, infrastructure, IT, management, and external auditors.
Benefits
- Private Health Insurance – covering you and your loved ones, because your family’s well-being matters to us.
- Unlimited Coffee – enjoy free coffee anytime at our cozy on-site cafeteria.
- 24/7 Mental Health Support – unlimited access to professional psychological support whenever you need it.
- Nutrition Support – guidance from a professional nutritionist to help you stay healthy and energized.
- In-House Training & Education – grow your skills with tailored learning opportunities.
- Paid Training – we invest in your professional development.
- Attendance at Conferences & Events – stay connected and up-to-date with industry trends.
- Competitive Compensation Package – because great work deserves great rewards.
- Excellent Career Prospects – we support your growth and long-term success.
At ATCOM, we are proud to be an Equal Opportunity Employer, fostering an inclusive work environment that values diversity. We believe in treating all individuals with respect and fairness, promoting collaboration and innovation for our collective success.
Sourced from a public career listing. Jobverse is an aggregator, not the employer.