- Company Name
- imec
- Job Title
- Information Security Specialist
- Job Description
-
**Job title**
Information Security Specialist
**Role Summary**
Lead the development and enforcement of the organization’s information security strategy, ensuring compliance with global standards and regulations. Manage risk assessment, policy creation, incident response, and vendor security to protect critical information assets and support business objectives.
**Expectations**
- Demonstrate expertise in ISO 27001, NIS2, TISAX, CyFun, NIST, EU Cyber Resilience Act and related frameworks.
- Deliver actionable risk assessments, policy artefacts, and incident responses within established timelines.
- Communicate complex security concepts to technical and non‑technical stakeholders.
- Work independently and collaboratively across business, IT, procurement, and legal teams.
**Key Responsibilities**
1. **Governance** – Translate security strategy into policies, procedures, and standards; act as liaison between security office and business units.
2. **Risk Management** – Conduct risk assessments on applications, technologies, processes; identify controls, produce risk reports, track mitigation.
3. **Compliance** – Maintain control mappings, support internal/external audits (ISO 27001, NIS2, TISAX, etc.), and ensure adherence to security policies.
4. **Incident Response** – Coordinate incident handling, prepare summaries and post‑incident reports, drive improvement actions and lessons‑learned closure.
5. **Vendor & Third‑Party Security** – Lead onboarding and periodic reassessments; review SOC, ISO certificates, questionnaires; collaborate with Procurement and Legal on security clauses.
**Required Skills**
- Minimum 3 years in information security management or consulting.
- Deep knowledge of ISO 27000 series, NIS2, TISAX, CyFun, NIST, and EU Cyber Resilience Act (preferred).
- Strong analytical, critical‑thinking, and risk‑identification abilities.
- Excellent written and verbal communication for technical and business audiences.
- Detail‑oriented, organized, proactive, and solution‑oriented mindset.
**Required Education & Certifications**
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or related field.
- Valid certifications such as ISO 27001 Lead Implementer, CISSP, CISM, or GRC‑specific credentials preferred.
---