Home

Resume

Jobs

My applications

Requests

Education

Career advice

Companies

Salary Calculator


Terms & Conditions

Privacy Policy

© 2026 All Rights Reserved

Junior Governance, Risk and Compliance (GRC) Consultant

●

3 days ago

Greece, Kentriki Makedonia, Thessaloniki
Full Time
Entry-Level
Hybrid

Basic Information

Deloitte is a worldwide leader in Professional Services with a presence in more than 150 countries and territories. Since 2018, Deloitte has been operating its Competence Center in Thessaloniki with satellites in the cities of Patras, Heraklion, and Ioannina - which are model hubs of expertise, training, and innovation, specializing in cutting-edge exponential technologies, in which graduates and young professionals undergo immersive experiences, continuous learning, gaining practical insights and hands-on training that empower them to navigate the complexities of the digital landscape.

 

Deloitte is an ideal working environment for both young and senior professionals who want to take the next step in their careers, offering them a supportive and international working environment that leverages their expertise and potential. Its corporate culture is based on trust and collaboration and ensures diversity and inclusion so that everyone feels part of a great team.

 

We are currently seeking for ambitious team players to become part of our Governance, Risk & Compliance (GRC) team within our Technology & Transformation department in Thessaloniki.

Responsibilities

• Tailored to clients’ business needs, risk profiles, and organizational objectives.
• To identify vulnerabilities, assess potential impacts, and recommend appropriate remediation and mitigation measures.
• By ensuring that cybersecurity practices are aligned with applicable regulations, legislation, and industry standards, including ISO 27001, DORA, NIS2, NIST, and IEC.
• To support effective detection, response, containment, and recovery from cybersecurity incidents, minimizing operational disruption and potential business impact.
• To understand business priorities and ensure that cybersecurity strategies and controls are aligned with organizational objectives.
• Designed to protect the confidentiality, integrity, and availability of sensitive information and critical systems.
• To deliver integrated cybersecurity and risk solutions that address client requirements and business challenges.
• For both technical and non-technical stakeholders.
• To support clients in adapting their security strategies and maintaining an effective cybersecurity posture.

Requirements

GDPR Compliance
ISO Compliance
Regulatory Compliance

• Academic background (BSc/MSc) related to Information Technology, Computer Science, Cybersecurity, or any other IT-related major.
• Knowledge of cybersecurity strategies, risk and compliance assessments, cybersecurity frameworks, and risk quantification.
• Demonstrate a strong interest in cybersecurity, with a willingness to stay informed about emerging threats, trends, technologies, regulations, and industry frameworks.
• Be a self-motivated and collaborative team player, capable of contributing effectively to project teams and delivering high-quality outcomes.
• Demonstrate strong interpersonal and relationship-building skills, with the ability to develop and maintain effective relationships with clients and colleagues.
• Possess strong analytical and problem-solving skills, with the ability to translate complex findings into clear and actionable insights for diverse audiences across different cultures, levels of technical expertise, and seniority.

Good to have

• Having background/familiarity or previous work experience in cyber field.
• Relevant professional certifications are highly valued, including CompTIA Security+, ISO 27001 Lead Auditor, IEC 62443, Microsoft Azure Fundamentals, relevant AWS or Google Cloud certifications.
• Familiarity with ServiceNow GRC, RSA Archer, OneTrust or Power BI is a plus.
• Familiarity/Good knowledge (of some) of the following areas would be a plus:
• Regulatory & Compliance: DORA (Digital Operational Resilience Act), NIS2 Directive (Network and Information Security Directive), ISO 27001 (Information Security Management Systems), IEC 62443.
• Risk Management: IT, OT and Third-Party risk assessments.
• Frameworks & Maturity Models: Cybersecurity frameworks, maturity assessments, and capability models.
• Incident Preparedness: Incident response planning, readiness, and management.
• Cloud Security: Core security principles and controls across major cloud platforms, including AWS, Microsoft Azure, and Google Cloud.

About the company

-

About the company

-

Deloitte

Deloitte

Information Technology
Risk & Compliance