Central Cyber Governance, Risk - Bucharest
1 zi în urmă

Descrierea jobului
About EQUANS
Equans is a global leader in energy and services, with €19.2 billion in annual revenue* and nearly 800,000 yearly projects across continents. With 90,000 skilled employees, the company delivers expertise in electrical and thermal engineering, HVAC, refrigeration, robotics, energy performance, digital solutions, IT and cybersecurity.
Within this ecosystem, the Corporate Cyber GRC function provides the foundational governance, risk management, compliance framework, awareness initiatives and third‑party oversight that shape the Group's overall cybersecurity posture.
What Makes This Role Truly Exciting
- You operate at the highest strategic level: this is a Corporate level position, shaping the rules, standards and cyber direction for the entire Equans Group.
- A transversal and high impact role: your work influences 90,000 employees at worldwide scale.
- A genuinely diverse scope: governance, risk management, compliance, methodologies, audits, awareness, project support… no repetitive routines here.
- A role of influence: you help define policies, structure practices, and shape Group‑wide cybersecurity expectations.
- Strong autonomy: you contribute ideas, drive initiatives, challenge approaches and help the organization evolve.
- A global environment: daily interactions with entities worldwide, each with unique operational realities and maturity levels.
- Top‑management visibility: your reporting and analyses support executive‑level decision‑making.
- Perfect for curious, agile and versatile minds: ideal if you enjoy switching contexts and navigating complexity.
Why Join the Corporate Cyber GRC Team?
- You help shape Group‑wide cybersecurity strategy.
- You work across borders, business units and disciplines.
- You learn constantly thanks to the role's diversity and global exposure.
- You join a supportive, ambitious and pragmatic team.
- You unlock strong career development opportunities, both within cybersecurity and across the broader Equans organisation.
Your mission
As a Corporate Cyber Governance, Risk & Compliance Analyst, you contribute to designing, maintaining and steering the Group's cybersecurity governance framework. Reporting directly to the Group Head of Cyber GRC, you work closely with entities worldwide to ensure alignment, coherence and continuous improvement of the overall cyber posture.
Your purpose: set the direction, drive consistency, and support change across a global, multi‑expertise organization.
Your ResponsibilitiesGovernance & Policy Framework
- Organize and coordinate governance committees with CISOs across the Group.
- Define, maintain, and evolve Group cybersecurity policies and standards.
- Ensure alignment with ISO 27000, regulatory requirements and legislative developments.
- Support entities in understanding, applying and operationalizing Group expectations.
Cyber Risk Management
- Deploy and continuously improve the Group's risk management methodologies, including third‑party assessments.
- Consolidate Group‑wide risk insights and produce executive‑level reporting.
- Manage, document and monitor cybersecurity exceptions within the risk framework.
Compliance & Audit Follow‑Up
- Coordinate Group level audit and compliance initiatives.
- Drive and monitor remediation plans to ensure issues are properly addressed.
Awareness & Culture Change
- Roll out Group cybersecurity awareness initiatives and contribute to developing a strong security culture.
- Support managers and operational teams in adopting best practices and embedding cyber reflexes into daily operations.
Support to Strategic Projects
- Ensure cybersecurity is embedded in Group and entity projects.
- Act as a trusted GRC advisor for IT, Digital and Business stakeholders.
Coordination Across Entities
- Collaborate with local cybersecurity leads to support and challenge their practices.
- Foster harmonisation and strengthen overall Group cyber maturity.
Your profile
Education & Experience
- Familiarity with ISO 27000 standards,
- Experience in cybersecurity (no need for 10+ years, but you must understand the fundamentals well).
- Without being a technical expert, you have enough hands‑on exposure to IT or cybersecurity topics to understand project contexts, constraints and risks.
SKILLS
- Broad understanding of cybersecurity domains and the role of each stakeholder.
- Ability to simplify, communicate and influence diverse audiences — from field teams to executives.
- Strong analytical and synthesis skills; curiosity to explore varied contexts.
- Capacity to design simple, pragmatic and efficient processes and policies.
MINDSET
- Naturally curious, eager to learn, and comfortable adapting to new challenges.
- At ease in complex, international and fast‑evolving environments.
- Versatile, autonomous, and capable of constructive challenge.
- Strong sense of ownership and initiative.
Locuri de muncă similare
About EQUANS · Equans is a global leader in energy and services, with €19.2 billion in annual revenue* and nearly 800,000 yearly projects across continents. With 90,000 skilled employees, the company delivers expertise in electrical and thermal engineering, HVAC, refrigeration, r ...
2 zile în urmă
ID233355 Junior Consultant (Cyber Governance, Risk and Controls) within Cyber Team
Doar pentru membrii înregistrați
KPMG in Romania is part of a global network of professional services firms providing Audit Tax and Advisory solutions. We pride ourselves on running our business as effectively as we help our clients grow theirs. · ...
2 săptămâni în urmă
We are looking for an AI Security & Resilience Support Specialist to support Third Party Security Assessments (TPSA) for vendors involved in solution delivery, · with a strong focus on AI-related, architectural, and security risks. The role enables informed vendor risk decisions ...
3 săptămâni în urmă
We are looking for an AI Security & Resilience Support Specialist to support Third Party Security Assessments (TPSA) for vendors involved in solution delivery, with a strong focus on AI-related architectural and security risks. · Inherent risk identification · Control gap analysi ...
3 săptămâni în urmă
We are looking for an AI Security & Resilience Support Specialist to support Third Party Security Assessments (TPSA) for vendors involved in solution delivery, · Deliver end-to-end TPSA outcomes for vendors engaged in solution delivery, · </li></ul> ...
1 săptămână în urmă
Drives the development and alignment of information (data, analysis and reporting) frameworks and governance strategies across P&C Operations. · ...
1 lună în urmă
The Data Quality Lead is responsible for defining and executing the data quality strategy across Insurance Business Unit. · Lead and mentor a cross-functional community of Data Quality Experts and Data Stewards. · ...
1 lună în urmă
The RoleDieser Rolle ist für die Projektsteuerung und -kontrolle verantwortlich. Die Position ist für die Anordnung von Projektgovernance-rahmenbedingungen zuständig und stellt sicher, dass konsistentes Ausführungsdisziplin besteht.Auf der Grundlage eines Analyseergebnisses werde ...
1 lună în urmă
The Data Quality Lead is responsible for defining and executing the data quality strategy across Insurance Business Unit. · ...
1 lună în urmă
What is the context? · Company has outsourced its IT to Company : infrastructure and business applications development. Allianz Trade is a regulated insurance company. Solvency II regulation requires the implementation of a strong framework for the risk management of IT Applicat ...
2 zile în urmă
What is the context? · Company has outsourced its IT to Company : infrastructure and business applications development. Allianz Trade is a regulated insurance company. Solvency II regulation requires the implementation of a strong framework for the risk management of IT Applicati ...
1 zi în urmă
+Risk Manager at ALTEN Romania. · +Coordinate the risk assessment process for outsourced activities. · Evaluate supplier-related risks and implemented mitigation measures. · ,,<il.Defining.and.reviewing.risk_controls_for_outsourced_activities<li_establishing._and.validating_KPIs, ...
6 zile în urmă
The Independent Validation Unit (IVU) is a team required by the European Central Bank (ECB) to validate and report on the bank's adherence and progress with Basel Committee on Banking Supervision's standard number 239 (BCBS 239). We are part of the second line of defense and resi ...
1 lună în urmă
We are a team required by the European Central Bank (ECB) to validate and report on the bank's adherence and progress with Basel Committee on Banking Supervision's standard number 239 (BCBS 239). We reside within the Non-Financial Risk (NFR) domain. · The primary purpose of the t ...
2 săptămâni în urmă
We are looking for a Manager – Risk Assessment to lead third-party and ICT risk management for outsourced activities. · ...
4 zile în urmă
We are looking for a manager to lead third-party and ICT risk management for outsourced activities. · Coordinating the risk assessment process for outsourced activities. · Defining and updating the control framework and monitoring indicators. · ...
3 zile în urmă
The Independent Validation Unit (IVU) is a team required by the European Central Bank (ECB) to validate and report on ING's adherence and progress with Basel Committee on Banking Supervision's standard number 239 (BCBS 239). · We provide advisory services that aim to improve Data ...
1 lună în urmă
We are looking for an Independent Validation Unit Expert to join our team. The successful candidate will have experience in audit, risk management, data management, or regulatory compliance within financial services. They will conduct independent validation of Risk Data Aggregati ...
2 săptămâni în urmă
This is an internal consultant position in the commercial area working part time. · Proposes for approval the commercial strategy of the nuclear project aligned with investment financing and governance strategy. · ...
4 săptămâni în urmă
The Data Quality Lead is responsible for defining and executing the data quality strategy across Insurance Business Unit.To be part of Société Générale Global Solution Centre and Insurance business line, means to work in a dynamic and active environment where your work has a real ...
1 lună în urmă