BS Information Security Specialist (GRC Analyst)
SoftServe · Remote - Ukraine · Full-time · 2026-09-16
Job description
ABOUT COMPANY
SoftServe Business Systems was founded in 2003. We aim high; our mission is to lead the digital revolution in the FMCG industry. It means delivering the best products & services possible that empower businesses to grow and improve efficiency.
We are a product company, and this affects our day-to-day activities. Our team is highly involved in the client's needs, we value business expertise, and we take every step with extra carefulness. Among our clients are businesses like AB InBev, Unilever, JDE, PepsiCo, Henkel, and others.
SoftServe Business System's ideal candidate is someone who can implement and support the Information Security Management System throughout the company and ensure the company’s compliance with information security requirements (client’s or regulatory).
REQUIREMENTS
Experience
- 1-2 years of experience in information security
- Experience in creating and maintaining security documentation
- Experience in participating in internal and external audits
Specialized knowledge
- Knowledge of risk management techniques
- Strong knowledge of Information Security standard ISO 27001/27002
- Understanding of data protection regulation (GDPR)
Competencies
- Ability to work on multiple projects independently
- Ability to lead meetings, record meeting minutes and document decision outcomes
- Experience with process development, analysis, implementation, and continuous improvement methodologies
- Excellent analytic skills
- Detail-oriented with strong organizational and prioritization skills
- Upper-Intermediate English level (both speaking and writing)
Education and degree
- Information Security or Computer science
RESPONSIBILITIES
- Providing an annual Security Risk Assessment, documenting identified system vulnerabilities, mitigating controls, and residual risks
- Creating and maintaining IS policies and standards based on best practices and compliance requirements
- Collaborating with different departments to describe and document processes
- Identifying security requirements and providing consultancy on their implementation
- Facilitating internal, external, and third-party audits, organizing meetings, and preparing all necessary input information
- Analyzing client security requirements and defining potential areas of non-compliance
- Working with various teams to track system and application security weaknesses from identification through remediation or risk acceptance
- Ensuring compliance with personal data protection laws, including GDPR