CyprusTech.Careers logoCyprusTech.Careers
Salary guide
Get started — it's freeSign in
Jobs/Information Security Risk Officer
XM
XMCurated· 5H AGO

Information Security Risk Officer

Nicosia Hybrid FULL TIME

Skills & requirements

ISO 27001

About the role

Information Security Risk Officer

About the role

XM is looking for an experienced Information Security Risk Officer to join its Information Security Governance, Risk and Compliance team in Cyprus.

In this role, you will help identify, assess and manage information-security risks across the organisation’s infrastructure, applications, technologies, internal processes and third-party relationships.

You will conduct risk assessments, review security controls, maintain risk documentation and work with internal teams to develop practical remediation plans. You will also contribute to security projects and help ensure that the company’s information-security practices remain aligned with regulatory requirements and recognised industry frameworks.

What you’ll be doing

  • Plan and carry out information-security risk assessments across IT infrastructure, applications, technologies and third-party services.

  • Review internal security controls, processes, procedures and policies.

  • Identify weaknesses, control gaps and areas of non-compliance.

  • Develop practical and proportionate recommendations for reducing identified risks.

  • Analyse existing and emerging risks at operational, tactical and strategic levels.

  • Reassess previously identified risks and evaluate the effectiveness of implemented controls.

  • Maintain the organisation’s information-security risk register.

  • Support the continued development of the Information Security Risk Management Programme.

  • Work with internal stakeholders to define remediation actions and target completion dates.

  • Monitor the implementation and progress of agreed risk-treatment plans.

  • Escalate significant or unresolved information-security risks when necessary.

  • Prepare reports documenting identified risks, remediation work and outstanding actions.

  • Produce regular metrics and reports covering the organisation’s overall security posture.

  • Communicate security risks clearly to technical teams, business stakeholders and management.

  • Contribute to information-security projects and regulatory-compliance initiatives.

What we’re looking for

  • A Bachelor’s or Master’s degree in Information Security, Cybersecurity, Computer Science or another relevant discipline.

  • At least three years of professional experience in information-security risk management or security-risk assessment.

  • Experience conducting structured technical and organisational risk assessments.

  • Knowledge of IT operations and security controls.

  • Understanding of physical, network, host and application security.

  • Familiarity with security architecture, virtualisation and cloud infrastructure.

  • Knowledge of information-security regulations, standards and risk-management frameworks.

  • The ability to identify risks and develop practical, cost-conscious recommendations.

  • Experience maintaining risk registers and monitoring remediation plans.

  • Strong analytical, organisational and project-management skills.

  • The ability to work independently with limited supervision.

  • The ability to collaborate effectively with technical and non-technical teams.

  • Confidence communicating security risks to different levels of management.

  • The ability to explain technical security concepts to non-technical audiences.

  • Excellent written and spoken English.

  • The ability to remain organised and effective in a fast-paced environment.

Skills that would be an advantage

  • CRISC certification.

  • CGRC certification.

  • CISSP certification.

  • Experience working with ISO 27001.

  • Experience applying ISO 27005 risk-management guidance.

  • Familiarity with the NIST Cybersecurity Framework.

  • Familiarity with NIST SP 800-53.

  • Knowledge of the Digital Operational Resilience Act.

  • Knowledge of GDPR and data-protection risk requirements.

  • Experience assessing cloud services or third-party technology providers.

  • Experience working in financial services, fintech or another regulated industry.

Work arrangement

This is a full-time hybrid position available in either Limassol or Nicosia, Cyprus.

Applicants must select their preferred location and confirm whether they are legally authorised to work permanently in that location.

Benefits

The benefits offered for this position include:

  • An attractive remuneration package.

  • Private health insurance.

  • Access to a corporate pension fund.

  • Continuous personal and professional development.

  • International training opportunities.

  • An intellectually engaging work environment.

The complete package and applicable eligibility conditions should be confirmed directly with XM during the recruitment process.

Recruitment process

The expected recruitment process includes:

  1. An introductory conversation with the Talent Acquisition team.

  2. A first interview with members of the Information Security team.

  3. A final interview.

The exact process may vary depending on the candidate and business requirements.

About XM

XM is an international financial-services and online-trading brand with teams working across technology, information security, compliance, data, finance, operations and customer experience.

The Information Security GRC team helps the organisation manage security risks, maintain appropriate controls and respond to regulatory and operational requirements.

How to apply

Applicants should apply through XM’s official careers page and submit an up-to-date CV.

Your application should clearly demonstrate:

  • Your experience conducting information-security risk assessments.

  • The types of infrastructure, applications or third parties you have assessed.

  • Your experience identifying control gaps and recommending remediation actions.

  • Your knowledge of ISO 27001, ISO 27005, NIST, DORA or GDPR.

  • Your experience maintaining risk registers and monitoring remediation plans.

  • Your ability to communicate technical risks to management and non-technical stakeholders.

  • Any relevant certifications, including CRISC, CGRC or CISSP.

  • Experience working in financial services or another regulated environment.

Applicants must also provide their preferred location, current location, city of residence, permanent work-authorisation status and annual gross salary expectations in euros.

LinkedIn, GitHub, portfolio and other professional links may be included but are not mandatory.

XM may use artificial-intelligence tools to assist with parts of the recruitment process, including reviewing application materials. Final hiring decisions are made by human members of the recruitment team.

Applications are processed directly by XM. cyprustech.careers is presenting this vacancy for informational purposes and is not acting as the employer or recruitment agency for this position.