
Information Security GRC Specialist
5 days ago
Let's be #BrilliantTogether
Position Overview
In this role, you will support the information security agenda for ISS STOXX, playing a crucial part in securing the confidentiality, integrity, and availability of our information assets, systems, and services. As part of the Governance, Risk, and Compliance (GRC) team within the Information Security Office, you will work closely with technology functions to identify areas of greatest risk and support initiatives to maintain the information security and technology risk profile within appetite. You will also interact with internal business customers and internal and external audit functions responsible for managing compliance testing of control requirements.
Responsibilities
- Assist in ensuring compliance with regulatory requirements and industry standards such as ISO 27001, GDPR, and NIST.
- Support the design, implementation, and monitoring of policies, procedures, and controls for compliance and regulatory activities.
- Assist in creating reports, metrics, and dashboards to measure the effectiveness of security controls and communicate insights to stakeholders.
- Support the implementation and continuous improvement of the organization's Information Security Management System (ISMS).
- Collaborate with IT and business teams to integrate information security seamlessly into the system development lifecycle.
- Assist with monitoring, maintaining, and measuring compliance with industry standards, certifications, and internal controls.
- Support IT Vendor Security, Application Security, and Physical Security Assessment programs.
- Ensure accurate and timely reporting of security metrics and key risk indicators (KRIs).
- Perform vulnerability application scanning and coordinate penetration testing.
- Other duties as assigned to improve security posture within ISS STOXX.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Experience establishing and monitoring information security controls.
- Knowledge of security frameworks and standards such as ISO 27001, SOC, and SSAE is preferred.
- Experience writing supporting documentation and security policies.
Experience required
- Strong verbal and written communication skills with the ability to interact and coordinate effectively with clients and ISS STOXX personnel globally.
- Strong administrative skills, including task development and time/resource management to meet deadlines.
- Proficiency in general computer applications, including Microsoft Word, PowerPoint, and Outlook.
Advanced proficiency in Microsoft Excel, including:
Knowledge of complex formulas and functions such as VLOOKUP and logical functions.
- Experience creating and modifying PivotTables and PivotCharts for detailed data analysis and visualization.
- Excellent analytical, organizational, and interpersonal skills.
- Proven process-oriented mindset with attention to detail and compliance focus.
What You Can Expect from Us
At ISS STOXX, our people are our driving force. We are committed to building a culture that values diverse skills, perspectives, and experiences. We hire the best talent in our industry and empower them with the resources, support, and opportunities to grow—professionally and personally.
Together, we foster an environment that fuels creativity, drives innovation, and shapes our future success.
Let's empower, collaborate, and inspire.
Let's be #BrilliantTogether.
About ISS STOXX
ISS STOXX GmbH is a leading provider of research and technology solutions for the financial market. Established in 1985, we offer top-notch benchmark and custom indices globally, helping clients identify investment opportunities and manage portfolio risks. Our services cover corporate governance, sustainability, cyber risk, and fund intelligence. Majority-owned by Deutsche Börse Group, ISS STOXX has over 3,400 professionals in 33 locations worldwide, serving around 6,400 clients, including institutional investors and companies focused on ESG, cyber, and governance risk. Clients trust our expertise to make informed decisions for their stakeholders' benefit.
Visit our website:
View additional open roles:
Institutional Shareholder Services ("ISS") is committed to fostering, cultivating, and preserving a culture of diversity and inclusion. It is our policy to prohibit discrimination or harassment against any applicant or employee on the basis of race, color, ethnicity, creed, religion, sex, age, height, weight, citizenship status, national origin, social origin, sexual orientation, gender identity or gender expression, pregnancy status, marital status, familial status, mental or physical disability, veteran status, military service or status, genetic information, or any other characteristic protected by law (referred to as "protected status"). All activities including, but not limited to, recruiting and hiring, recruitment advertising, promotions, performance appraisals, training, job assignments, compensation, demotions, transfers, terminations (including layoffs), benefits, and other terms, conditions, and privileges of employment, are and will be administered on a non-discriminatory basis, consistent with all applicable federal, state, and local requirements.
-
Information Security Analyst
1 week ago
Prague, Hlavní město Praha, Czech Republic Deutsche Börse Group Full time 55,000 - 85,000 per yearArea of work:The section PaaS Delivery is operating clearing and trading applications for the Deutsche Börse Group.Your responsibilities:Work within an IT department to develop information security concepts and coordinate the tracking of deliverables including IT audits with other areas of information security and product organization including compliance...
-
IT Security Specialist
3 days ago
Prague, Hlavní město Praha, Czech Republic Whirr Crew Full time 60,000 - 80,000 per yearWe are looking for an IT Governance Specialist to join our IT Security & Governance team. The ideal candidate has a proactive approach to compliance and risk topics, demonstrates strong analytical and communication skills, and thrives in a structured corporate environment. You'll work closely with both our local IT team and headquarters in Germany, ensuring...
-
Application Security Engineer
5 days ago
Prague, Hlavní město Praha, Czech Republic Nord Security Full time 80,000 - 180,000 per yearThe world's most advanced VPN, and a whole lot more. If you're a curious problem-solver who carves their own path, join the team behind Threat Protection Pro, the NordLynx protocol, and the fastest VPN on the planet—tools that put privacy, security, and control back in people's hands.Your impact? Helping millions take back control of their online...
-
OT Security Architect
1 day ago
Prague, Hlavní město Praha, Czech Republic Sandoz Full time 120,000 - 240,000 per yearOT Security ArchitectSandoz continues to go through an exciting and transformative period as a global leader and pioneering provider of sustainable Biosimilar and Generic medicines. As we continue down this new and ambitious path, unique opportunities will present themselves, both professionally and personally. Join us, the future is ours to shapeJob...
-
Copy of Security Specialist
1 week ago
Prague, Hlavní město Praha, Czech Republic Palo Alto Networks Full time 900,000 - 1,200,000 per yearCompany Description Our MissionAt Palo Alto Networks everything starts and ends with our mission:Being the cybersecurity partner of choice, protecting our digital way of life.Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and...
-
IT Security Specialist
5 days ago
Prague, Hlavní město Praha, Czech Republic SearchTeam Full time 115,000 - 138,000 per yearIntroductionThis is just brief information about the job opportunity. More details, such as company name, official job description are available upon request. If you are not interested in this job opportunity but you might know somebody who can be suitable for this role please let us know. We offer a referral bonus for the candidate who will be placed and...
-
IT & Data Security Expert
1 week ago
Prague, Hlavní město Praha, Czech Republic Galytix Limited Full time 60,000 - 120,000 per yearPrague, Czech RepublicBusiness overview:Galytix (GX) is delivering Agentic AI for financial services.Founded in 2015 by credit and insurance experts together with world-class AI engineers, GX' financial services specialised AI Agents empower credit and risk professionals with a trusted and personalised agent delivering a step change in productivity and...
-
Prague, Hlavní město Praha, Czech Republic Vodafone Full time 900,000 - 1,200,000 per yearManage Infrastructure Operations team (manage, motivate, control, increase performance). Manage operation & maintenance activities on assigned systems or infrastructure of assigned OpCos by developing and maintaining a schedule of routine operation and maintenance tasks. Operate, administer, maintain, solve incidents and problems according to an appropriate...
-
Senior Infrastructure and DBA Specialist
1 week ago
Prague, Hlavní město Praha, Czech Republic Barclays Full time 1,200,000 - 2,400,000 per yearJoin us as a Senior Infrastructure and DBA Specialist at Barclays, where you'll spearhead the evolution of our digital landscape, driving innovation and excellence. You'll harness technology to revolutionise our infrastructure and database operations, ensuring resilient, scalable, and secure platforms that support world-class financial services.To be...
-
Senior Security
2 weeks ago
Prague, Hlavní město Praha, Czech Republic Bloomreach Full time 900,000 - 1,200,000 per yearBecome a Senior Security & Compliance Analyst for Bloomreach You will be an essential member of our Governance, Risk, and Compliance team, by analyzing and resolving compliance issues, as well as supporting engineering and sales teams with different customer requirements. Our company provides the best digital experience for the top international e-commerce...