We are looking for a Information Security Specialist to act as a key guardian of our digital ecosystem.
In this role, you will ensure that security and PCI compliance are embedded across all stages of development, enabling teams to build secure, scalable, and innovative digital products.
We are looking for a Information Security Specialist to act as a key guardian of our digital ecosystem.
In this role, you will ensure that security and PCI compliance are embedded across all stages of development, enabling teams to build secure, scalable, and innovative digital products.
Tasks
We are looking for a Information Security Specialist to act as a key guardian of our digital ecosystem. In this role, you will ensure that security and PCI compliance are embedded across all stages of development, enabling teams to build secure, scalable, and innovative digital products.
- Identify, assess, and mitigate IT security risks across systems and processes
- Establish and maintain a risk management framework including risk identification, evaluation, treatment, and tracking
- Perform regular risk assessments, define risk mitigation plans, and ensure follow-up on remediation actions
- Drive vulnerability management, including identification, prioritization, and remediation of security vulnerabilities
- Define security requirements for interfaces, processes, software development, and related technologies, and operate tools to enforce them
- Continuously improve the Information Security Management System and support ISO 27001 certification
- Act as the main contact person for all IT Security-related topics
- Support internal and external audits on implemented IT security measures
Behind the scenes
Benefits
Vacation / Christmas bonus
Special deals with selected partners
Employee events
Hybrid working possible
Flexible working hours
Mentoring
Vacation / Christmas bonus, Special deals with selected partners , Employee events, Hybrid working possible, Flexible working hours, Mentoring
Requirements
- At least 2 years of experience as an IT Security Expert
- Professional experience with PCI DSS in technical, compliance, or audit functions
- Strong understanding of risk management principles and security risk frameworks
- Proven experience in risk assessments, risk treatment, and vulnerability management processes
- Knowledge of standards: OWASP ASVS, OWASP Top 10, CWE Top 25
- Ability to analyze and identify security issues and implement effective solutions
- Good understanding of cloud architectures, modern development practices, and digital product ecosystems is a plus
- Experience with Container Security and DevSecOps
- Familiarity with frameworks such as ISO 27001, NIST, COBIT, or ITIL is a plus
- Experience working in cross-functional teams in an agile environment
- Very good command of English language
Company
About Lufthansa Industry Solutions Sh.p.k.
Share with your Social Media Account
Click on one of the following icons:
To copy the link, click the following icon:
employee_referral_text
employee_referral_text_icons
