SatoshiLabs
Security Compliance Specialist
Prague, Czech RepublicFull-timeGlobal
š Midš Hybrid
ActivePosted within the last 30 days
Job Description
[AI-summarized by JobStash]
You will support multiple areas of security and compliance, focusing on practical, operational tasks. You will assess supply chain cybersecurity risks, design and implement access control policies, and manage user account lifecycle. You will coordinate and execute security and compliance audits, analyze findings, and drive corrective actions. You will assist in risk identification and mitigation, conduct reviews of data processing activities for GDPR compliance, and help maintain IT asset inventories and classification. You will work with HR and other departments to embed security awareness and apply data classification consistently.
Requirements
- ā2+ years experience in a security and/or compliance role with IT focus
- āKnowledge of ISMS
- āKnowledge of ISO 27001
- āKnowledge of CRA
- āKnowledge of NIS2
- āAbility to communicate security concepts to technical and non-technical stakeholders
- āAttention to detail
- āStrong issue-resolution skills
- āProficiency in English
Responsibilities
- āConduct assessments of IT systems supply chain cybersecurity risks
- āDevelop and enforce security standards and protocols for suppliers
- āMonitor and evaluate cybersecurity practices of suppliers and partners
- āSupport design and implementation of access control policies and procedures
- āManage user account setup modification and revocation
- āPerform regular access reviews to ensure least-privilege
- āCoordinate and execute security and compliance audits
- āAnalyze audit and test results to identify vulnerabilities and non-compliance
- āRecommend and follow up on corrective actions
- āIdentify and evaluate risks to data and information systems
- āDevelop strategies and rules to mitigate identified risks
- āConduct regular reviews of data processing activities
- āSupport implementation of data protection policies with focus on GDPR
- āMaintain inventory of IT assets and ensure correct classification and management
- āParticipate in development and enforcement of asset lifecycle policies
- āCollaborate with HR to define roles and integrate into access management
- āSupport embedding cybersecurity awareness into the organization
- āHelp implement a data classification framework and handling procedures
- āEnsure consistent application of the data classification scheme across departments
Benefits & Perks
- āOption to receive part of compensation in bitcoin
- āFlexible working hours
- āBudget for professional development
- āRegular company events
- āRenovated offices with gym
- āOn-site massages
- āFoosball table
- āBilliards
- āPlayStation
- ā3D printer
- āFree on-site parking
- āMultiSport card
- āCompany mobile phone tariff
Tech Stack
data securityGDPRdata classificationCRArisk managementNIS2Security standardsISMSISO 27001access control