3 days ago
Deloitte is a worldwide leader in Professional Services with a presence in more than 150 countries and territories. Since 2018, Deloitte has been operating its Competence Center in Thessaloniki with satellites in the cities of Patras, Heraklion, and Ioannina - which are model hubs of expertise, training, and innovation, specializing in cutting-edge exponential technologies, in which graduates and young professionals undergo immersive experiences, continuous learning, gaining practical insights and hands-on training that empower them to navigate the complexities of the digital landscape.
Deloitte is an ideal working environment for both young and senior professionals who want to take the next step in their careers, offering them a supportive and international working environment that leverages their expertise and potential. Its corporate culture is based on trust and collaboration and ensures diversity and inclusion so that everyone feels part of a great team.
We are currently seeking for ambitious team players to become part of our Governance, Risk & Compliance (GRC) team within our Technology & Transformation department in Thessaloniki.
• Tailored to clients’ needs, risk profiles, and business objectives.
• Including vulnerability identification, control effectiveness, risk analysis, and risk quantification, providing actionable recommendations.
• IEC 62443, supporting compliance with legal and regulatory obligations.
• Including policies, standards, methodologies, controls, and governance structures.
• Strengthening detection, response, recovery, and overall cyber resilience.
• Including BIA, continuity strategies, recovery planning, crisis management, and testing.
• By evaluating critical services, processes, technology dependencies, third parties, and recovery capabilities.
• Including governance structures, policies, roles and responsibilities, risk assessments, controls, and oversight mechanisms.
• Including AI risk classification, data and model governance, security, and third-party risks.
• Translating complex cyber and technology risks into practical business solutions.
• Helping clients address emerging risks.
• Providing technical guidance, reviewing deliverables, and supporting professional development.
• To deliver integrated cybersecurity, risk, compliance, AI, and resilience solutions.
• Translating relevant developments into actionable client insights.
• Academic background (BSc/MSc) related to Information Technology, Computer Science, Cybersecurity, or any other IT-related major.
• 2+ years of relevant working experience.
• Solid professional experience in cybersecurity strategy, risk management, compliance, and governance.
• Strong knowledge of cybersecurity frameworks, risk quantification methodologies, including DORA, NIS2, ISO, IEC standards, and related regulatory requirements.
• Proven ability to manage multiple stakeholders, engage effectively with executive leadership, and communicate complex cybersecurity concepts clearly to both technical and non-technical audiences.
• Demonstrated experience in leading project teams, managing client engagements, and mentoring junior colleagues.
• Strong analytical and problem-solving skills, with a proactive, results-oriented mindset.
• Excellent interpersonal, communication, and client relationship management skills.
• Relevant professional certifications such as CISSP, CISM, CIPP/E, ISO 27001 Lead Auditor/Implementer, CCSK, CCSP, and advanced cloud certifications across AWS, Microsoft Azure, and Google Cloud.
• Familiarity with ServiceNow GRC, RSA Archer, OneTrust, or Power BI is a plus.
• Advanced expertise in IT and OT risk assessments, third-party risk management, and cybersecurity maturity assessment.
• Hands-on experience in the development, implementation, and testing of Incident Response Plans.
• Strong knowledge of cloud security principles and architecture across leading cloud platforms, including AWS, Microsoft Azure, and Google Cloud.
• Proficiency in German or French is considered a strong advantage.