Governance, Risk and Compliance (GRC) Expert
- Full-time, permanent
- Hybrid
- Sofia, Bulgaria
- Mid-level to Senior-level
Experience: 2 to 4 years
About SoCyber
SoCyber is a Bulgarian cybersecurity company on a mission to solve complex cybersecurity problems and help organizations across all industries and sizes fortify their cybersecurity defenses. We provide a wide range of security, compliance and vulnerability management solutions.
Our passionate team of experts is working on projects covering the full spectrum of digital and physical infrastructure. SoCyber is partnered with leading organizations worldwide, offering you the chance to learn from seasoned professionals and make a real difference in the fight against cyber threats.
About the role
SoCyber is looking for an experienced Governance, Risk and Compliance (GRC) Expert to join our tight-knit team of security specialists. This hands-on role involves supporting the ongoing development, implementation, and maintenance of the organization's and our clients' security governance frameworks, risk management processes, and regulatory compliance initiatives.
The GRC Expert independently executes and coordinates security governance frameworks, risk management procedures, and compliance initiatives. Sitting between operational support and high-level advisory, you will lead mid-complexity risk assessments, manage audit preparations, draft core security documentation, and serve as a primary client contact during GRC engagements, working with minimal supervision while collaborating with senior management on complex initiatives.
Responsibilities
Information security governance
- Draft, review, and maintain organizational security policies, procedures, and standards in alignment with industry frameworks
- Map organizational security processes and technical controls against established governance frameworks
- Lead operational governance reviews and track actionable deliverables across internal and client-facing teams
Risk management operations and TPRM
- Conduct end-to-end security risk assessments, vulnerability analyses, and threat modeling exercises
- Maintain enterprise risk registers, track Corrective Action Plans (CAPs), and drive risk remediation efforts
- Execute Third-Party Risk Management (TPRM) evaluations, including vendor Due Diligence Questionnaires (DDQs) and risk assessments
- Assist in facilitating tabletop, Business Continuity (BCP), and Disaster Recovery (DRP) exercises
Regulatory and framework compliance
- Execute gap assessments, control mapping, and readiness reviews for major regulatory frameworks, including ISO/IEC 27001, NIST CSF, NIS2, DORA, GDPR, and PCI DSS
- Coordinate formal internal and external audit workflows, serving as a primary point of contact for gathering and validating evidentiary artifacts
- Track compliance metrics and assist in tracking Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs)
Documentation, reporting and client delivery
- Author professional security reports, risk summaries, and compliance briefings for operational stakeholders and management
- Maintain GRC tools, control libraries, and documentation repositories
- Synthesize technical data into executive-ready dashboards and operational reports
- Support junior team members by providing guidance on standard GRC methodologies and client deliverables
Communication and stakeholder management
- Act as a direct technical liaison between security engineering teams, internal stakeholders, and external clients
- Facilitate risk workshops, stakeholder interviews, and compliance review meetings with confidence and professionalism
- Interface effectively with external auditors and regulatory assessors during evaluations
What we are looking for
- Bachelor's degree in cybersecurity, information technology, information security, risk management, or equivalent practical experience
- 2 to 4 years of dedicated experience in GRC, IT audit, or information security consulting
- A functional understanding of cybersecurity principles, IT infrastructure, and cloud environments
- Strong working knowledge of ISO/IEC 27001, NIST CSF, GDPR, and NIS2 / DORA requirements
- Hands-on experience with GRC platforms, compliance management tools, and risk software
- High attention to detail and strong technical writing capabilities
Nice to have
- ISO 27001 Lead Implementer or Lead Auditor certification
- CGRC, CISA, CRISC or GRCP certification, held or actively being pursued
Not quite your role? We still want to hear from you.
Send us a note about what you do and the kind of work you want. The best people rarely fit a job ad.