Security Risk Manager(REF5603Q)
HybridBudapest, Budapest, Hungary
Job Summary
Operate and continuously improve the security risk management process, methodologies, and related policies while ensuring alignment with group-level standards. Act as a trusted advisor to supported legal entities on risk topics, providing hands-on guidance during identification, assessment, and treatment. Train and upskill local risk managers on processes and policies, and support their professional usage of the GRC platform. Identify, create, and manage security risks in cooperation with stakeholders, monitor mitigation actions, and ensure all risks are properly documented and audit-ready. Prepare Top 10 risk reports, quarterly summaries, and ad-hoc deliverables to provide management with insights on trends. Bachelor's or Master's degree required with 3–7+ years of experience in Information Security or GRC roles within large enterprise environments. Remote work available only within Hungary.
Required Qualifications
- Bachelor's or Master's degree in Information Security, Computer Science, Engineering, Business Informatics, or a related field
- High-level English language knowledge (spoken and written)
- At least mid-level German language proficiency
- 3–7+ years of experience in Information Security / Cybersecurity / Risk Management / GRC roles
- Experience in large enterprise or multinational environments
- Strong understanding of information security risk management frameworks (e.g. ISO 27005, NIST RMF)
- Knowledge of information security standards (e.g. ISO 27001, NIST, CIS)
- Ability to apply security governance principles in practical, business-aligned ways
- Strong communication and stakeholder management skills
- Ability to explain security and risk topics in business-friendly language
- Structured, proactive, and solution-oriented mindset
- Experience in training, coaching, or enablement activities
- Experience working in a shared service or internal consulting model
- CRISC, CISM, CISSP
- COBIT, ITIL or similar governance-related certifications
- Hands-on experience with GRC tools (e.g. ServiceNow, Archer, OneTrust, or similar)
- Remote working within Hungary
Desired Qualifications
- Experience working in a shared service or internal consulting model is an advantage
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.