Information Security & GRC Officer
Quick Summary
Manage, update, and improve the company’s ISMS, including policies, procedures, asset registers, and the Statement of Applicability (SoA). Secure SDLC Governance: Collaborate with tech leads,
We are a leading digital agency specializing in custom web development, enterprise e-commerce platforms, and high-performance digital products. We deliver end-to-end software solutions for major corporate clients, combining cutting-edge design with robust engineering. As we scale our enterprise operations, ensuring the highest standards of security, infrastructure governance, and compliance is our top priority.
We are seeking a dedicated Mid-level Information Security & GRC Officer to join our team on-site at our Athens offices.
In this role, you will be a key driver of our Information Security Management System (ISMS). You will be responsible for maintaining our ISO 27001 certification and aligning security policies with our complex hybrid environment (Azure Cloud & On-Premises VMware Private Cloud). Working directly alongside our Chief Information Security Officer (CISO) and our Data Protection Officer (DPO), you will bridge the gap between compliance frameworks like NIS2, secure development methodologies (Secure SDLC), and hands-on technical operations.
Responsibilities
~1 min read- →ISO 27001 & Compliance Ownership: Manage, update, and improve the company’s ISMS, including policies, procedures, asset registers, and the Statement of Applicability (SoA).
- →Secure SDLC Governance: Collaborate with tech leads, developers, and DevOps engineers to govern and maintain security controls throughout our software development lifecycle (Secure SDLC), embedding security into our CI/CD pipelines.
- →NIS2 Readiness & Compliance: Assist the CISO in assessing, adapting, and aligning the agency's security posture and reporting mechanisms to meet NIS2 directive obligations for both the company and our regulated clients.
- →Hybrid Infrastructure Governance: Collaborate with the infrastructure teams to ensure compliance controls are strictly maintained across our Azure Cloud setups and On-Premises VMware private cloud datacenters.
- →Collaboration with CISO & DPO: Work hand-in-hand with the CISO on overall security strategy and risk mitigation. Support the DPO in ensuring full GDPR compliance regarding client data handled within our development and hosting environments.
- →Risk Assessments: Execute asset-based and application-level information security risk assessments, maintaining and updating the corporate risk register.
- →Audit Management: Organize and execute internal audits, and act as the primary facilitator during annual external ISO 27001 certification audits.
- →Client & Vendor Procurement Support: Respond to complex technical security questionnaires (DDQs) from prospective enterprise clients and vet the security posture of third-party vendors.
Requirements
~1 min read- 3+ years of professional experience in Information Security, Governance, Risk & Compliance (GRC), IT Compliance, or IT Audit.
- Previous experience within a software development company, digital agency, or technology-driven environment will be considered a strong advantage.
- Proven hands-on experience in implementing, maintaining, and continuously improving ISO 27001 Information Security Management Systems (ISMS).
- Solid understanding of key regulatory and security frameworks, including GDPR, NIS2, and Secure Software Development Lifecycle (SSDLC) principles, with familiarity with OWASP guidelines and best practices.
- Good understanding of security requirements and risk considerations across hybrid IT environments, including Microsoft Azure, VMware virtualization, and private cloud infrastructure.
- ISO 27001 Lead Implementer or Lead Auditor certification is strongly preferred.
- Additional relevant certifications such as CompTIA Security+, CISA, CRISC, or equivalent will be considered a significant advantage.
- Strong analytical, risk assessment, and problem-solving skills, with the ability to translate security and compliance requirements into practical business and technical controls.
- Excellent technical documentation and reporting skills, with the ability to produce clear, structured, and professional security and compliance documentation.
- Fluency in both Greek and English, with excellent written and verbal communication skills.
- Ability to work effectively with technical and non-technical stakeholders, including development, infrastructure, IT, management, and external auditors.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- September 25, 2026
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 60%
- Scored at
- September 29, 2026
Signal breakdown
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.