CrawlJobs Logo

Business Continuity and Information Security Manager

Romania, Brasov · Job Posted May 29, 2026
Apply Position
Job Link Share

Job Description

Who we are: NTT DATA is a leading global provider of infrastructure and platform services, partnering with some of the world’s most innovative technology vendors. We help organizations modernize their IT landscapes, increase operational efficiency, and enable sustainable business growth through reliable and scalable platforms. We’re looking for passionate, curious, and motivated individuals to join our team and work with clients to translate complex technology into real business value—driving transformation, resilience, and long-term success.

Job Responsibility

  • Joining the team responsible for operating the European Commission’s Network Managed Services under the NMS III framework contract
  • Working in a large-scale, multi-site infrastructure environment across Brussels and Luxembourg
  • Managing responsibilities across business continuity, service continuity, and information security management
  • Acting as the main interface between the organisation and the customer for continuity and security-related matters
  • Leading crisis management escalations and supporting effective communication during major incidents
  • Developing, maintaining, and improving business continuity and disaster recovery strategies
  • Defining, testing, and improving continuity and disaster recovery scenarios
  • Ensuring agreed recovery objectives are met and gaps are addressed through continuous improvement
  • Managing continuity-related risks and maintaining clear process documentation
  • Planning and coordinating regular continuity and disaster recovery exercises
  • Auditing continuity and security processes to ensure compliance with policies, standards, and contractual requirements
  • Defining, implementing, and monitoring an information security strategy aligned with the customer’s security framework
  • Establishing and enforcing security policies across operational services
  • Conducting risk assessments, gap analyses, and business impact analyses
  • Recommending technical and organisational controls to reduce security and continuity risks
  • Supporting the development of a security incident management framework
  • Overseeing vulnerability assessments and coordinating mitigation actions
  • Tracking security and continuity performance indicators and reporting on progress
  • Coordinating with security directorates, auditors, customers, and internal teams
  • Supporting the selection, implementation, and lifecycle management of tools used for continuity and security management
  • Driving awareness and training activities for internal teams and customers

Requirements

  • Master’s degree ideally complemented by certifications such as ISO 27001 (ISO 27XXX) and ISO 22301 (ISO 223XX)
  • Minimum 3- 5 years of experience in security services, including a minimum of 3 years in information security management
  • Solid hands-on experience in business/service continuity management within security-focused environments (e.g., firewalls, proxies, reverse proxies, load balancers, remote access)
  • Good understanding of network environments such as SD-WAN (e.g., Juniper) is an advantage
  • Experience in risk management, audits, and compliance frameworks, with a strong grasp of regulatory requirements and security policy implementation
  • Experience with ISMS frameworks and have contributed to the development and deployment of security management systems
  • Clear and structured documentation, strong analytical and organisational skills, and the ability to manage complex environments
  • Ability to communicate effectively with both technical and non-technical stakeholders and demonstrate strong interpersonal skills
  • Excellent command of both spoken and written English, French would be considered a plus

Nice to have

  • Good understanding of network environments such as SD-WAN (e.g., Juniper)
  • French is a plus

What we offer

  • Smooth integration and a supportive mentor
  • Remote, Hybrid or Office work opportunities
  • Different working hours to suit your needs
  • Sponsored certifications, trainings and top e-learning platforms
  • Private Health Insurance – custom-made for you
  • Individual coaching sessions or accredited Coaching School
  • Epic parties or themed events for employees and their families

Looking for more opportunities?

Search for other job offers that match your skills and interests.

Similar Jobs for

Business Continuity and Information Security Manager

8 matching positions

IT Service Continuity Manager

Ivy Partners is a Swiss consulting firm dedicated to helping businesses navigate...
Location
Location
Portugal , Lisboa
Salary
Salary:
Not provided
ivy.partners Logo
IVY Partners
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Comprehensive understanding of the Business Continuity Management lifecycle and IT Operations and IT Continuity Service Management
  • Familiar with Group Operational Resilience processes and tools
  • Possess expertise in IT Operations and IT Continuity Service Management, stakeholder management, and process improvement to enhance organizational resilience capabilities
  • Experience handling sensitive information related to company infrastructure, security incidents, and crisis responses with high levels of discretion and confidentiality
  • Skilled in Risk Management frameworks, including risk assessment, business impact analysis, and recovery strategies
  • Proficiency in data analysis and reporting, with basic skills in Excel (pivot tables, formulas, charts)
  • Experienced in drafting and updating resilience plans and training materials and are familiar with ITIL, ISO 22301, and ServiceNow
  • Comfortable working in a professional English environment and context
Job Responsibility
Job Responsibility
  • Strengthen Crisis Management, Business Continuity, and IT Service Continuity Management systems
  • Conduct comprehensive Business Impact Analyses (BIAs) to assess potential impacts of disruptions on critical business functions
  • Develop, update, and maintain Business Continuity Plans (BCPs) to ensure operational recovery and continuity
  • Design and deliver training programs to educate employees on crisis management protocols, covering various risks such as physical loss, cybersecurity threats, and polycrises
  • Promote a culture of preparedness through regular awareness campaigns that enhance staff response capabilities
  • Contribute to creating and maintaining all documentation required by the Operational Resilience Framework, including strategic documents, processes, recovery plans, catalogs of solutions, reports, and remediation plans
What we offer
What we offer
  • Taking care of our employees | Providing a supportive environment where everyone is valued, with training and development opportunities both in Switzerland and internationally
  • Creating a trust-based workplace | Working with us means building a relationship founded on transparency, professionalism, and commitment
  • Encouraging innovation | We combine technology and creativity to achieve impactful digital transformations
  • Embracing our responsibilities | The collective is at the heart of what we do, and we strive to make a positive impact
  • Fulltime
Read More
Arrow Right

Senior Manager IAM Enterprise Security

The IT Sr. Manager, Identity & Access Management is responsible for providing le...
Location
Location
Poland , Krakow
Salary
Salary:
Not provided
genpt.com Logo
Genuine Parts Company
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • BS/BA degree and specialized information security technical training required
  • A reputable security certification (CISSP, CISSP w/specialization HCISPP, GIAC, CISA, etc.) is required
  • A minimum of 6 years of progressive Information Security experience
  • A minimum of 3+ years of management experience leading information security
  • Identity & Access Management to include governance experience is required
  • In-depth knowledge of the information security industry and regulatory obligations (Sarbanes-Oxley (SOX), HIPAA, GLBA, PCI DSS, HITRUST, NIST Framework, etc.)
  • Working knowledge of Microsoft Active Directory
  • Ability to analyze all layers of the OSI model from the security stance
  • In-depth knowledge of networking technologies and architecture
  • ITIL familiarization - managing incidents, requests, and changes
Job Responsibility
Job Responsibility
  • Serves as an internal information security consultant to the enterprise
  • Include focus and expertise in Privileged Access Management (PAM), Customer Identity Access Management (CIAM), Identity Governance and Administration (IGA) and Employee Identity Access Management (EIAM) to include Single Sign on and Multi-factor authentication
  • Research and recommend solutions that meet security standards while ensuring functionality for business continuity
  • Develop security test scenarios for unit, process, function, integration, and acceptance testing
  • Design integration schema and linkage for multi-platform business and technological solutions
  • Evaluates the security of new technologies and assists with the plan to integrate them into the company environment
  • Help develop the policies and procedures in conjunction with the established IT governance channels to manage the use and operation of these systems
  • Recommend best practices for security controls without hindering functionality
  • Define the minimum access and identity configuration standards for all IT systems
  • Evaluates new and proposed security systems and technologies
What we offer
What we offer
  • We offer comprehensive benefit plans and programs designed to support your health and wellness, provide income protection and build financial security for your retirement
Read More
Arrow Right

Country Security Lead

The Country Security Lead (CSL) for ASML China acts as the local representative ...
Location
Location
China , Shanghai
Salary
Salary:
Not provided
asml.com Logo
ASML
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Minimum of 10 years (Information) Security experience
  • Minimum of 8 years experience with physical security
  • Minimum of 5 years IT working experience
  • Able to engage with Senior Leadership in China
  • Ability to build strong, trusting relationships with technical and non-technical user base
  • Highly-motivated, with a strong work ethic and able to work effectively under minimal supervision
  • Excellent verbal and written communication skills in English and Mandarin
  • Excellent multi-tasking skills
  • Enterprise Security risk expertise: Strong understanding of risk frameworks, strategic security risk mgt, policy management, and business continuity management
  • Security Risk mitigation & advisory: Ability to identify, assess, manage and monitor security risk mitigation strategies at a country level
Job Responsibility
Job Responsibility
  • Responsible for managing the China security organization on behalf of the CISO of ASML, driving the development and delivery of security services in China
  • Challenge and verify the adequate performance of security controls in China, against ASML and China risk appetite and as executed by the first line of responsibility in the sectors in China
  • Execute the central security strategy as determined by the CISO and adding country specific aspects to it to improve security maturity
  • Collaboration with the 1st line sector SRMs to identify, assess and mitigate security risks, overseeing and reporting via the China Virtual Security Team (VST)
  • Identify improvement opportunities together with the 1st line sector SRMs’ and the 2nd line team in terms of processes and activities
  • Provide necessary support for improvements and will act in a pivotal role to bring (security) teams together where needed
  • Overseeing the development of country specific response plans, assuring the timely and thorough handling of security indents under coordination of the central Security Operations Centre
  • Ensuring adherence to centrally determined or country specific laws and regulations related to information security
  • Act on behalf of the CISO of ASML and work closely together with the 1st line country SRM’s to define and execute a joined security roadmap for China
  • Assure the capabilities as required by the central Second Line Security, Intelligence Fusion Centre and Security Operations Center teams are developed and maintained, as well as organizing Security activities related to risk culture and awareness initiatives
  • Fulltime
Read More
Arrow Right

Director of Information Security

Jeeves is looking for a visionary and hands-on Director of Information Security ...
Location
Location
Mexico , Mexico City
Salary
Salary:
Not provided
tryjeeves.com Logo
Jeeves
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree in Computer Science, Information Security, or a related field
  • Master's degree preferred
  • 10+ years of progressive experience in information security
  • At least 5 years in a leadership or management role, preferably within a B2B SaaS or FinTech environment
  • Proven experience operating in a global organization with a strong understanding of diverse regulatory landscapes across North America, EMEA, and Latin America (Mexico, Colombia, Brazil)
  • Strong understanding of financial industry security regulations and compliance frameworks (e.g., PCI DSS, SOC 2, ISO 27001, NIST Cybersecurity Framework, GDPR, LGPD)
  • Deep technical expertise across a broad range of security domains, including network security, cloud security (AWS, Azure, GCP), application security, data security, identity and access management, and incident response
  • Experience with various security tools and technologies (SIEM, EDR, WAF, DLP, vulnerability scanners, etc.)
  • Excellent communication, interpersonal, and presentation skills, with the ability to articulate complex security concepts to technical and non-technical audiences, including executive leadership
  • Strong analytical and problem-solving skills, with a proactive and pragmatic approach to security
Job Responsibility
Job Responsibility
  • Develop, implement, and maintain a robust global information security strategy aligned with business objectives, regulatory requirements, and industry best practices
  • Lead the evolution of our security roadmap, identifying emerging threats, vulnerabilities, and opportunities for improvement
  • Provide expert guidance and leadership on all aspects of information security to executive management and key stakeholders
  • Oversee the design, implementation, and continuous improvement of security policies, standards, procedures, and guidelines across the organization
  • Manage and mature our security awareness and training programs for all employees
  • Develop and manage the information security budget and resource allocation
  • Establish and maintain an enterprise-wide information security risk management framework, conducting regular risk assessments and managing mitigation plans
  • Ensure compliance with relevant international, regional, and local data privacy and security regulations
  • Lead and coordinate external security audits and assessments
  • Oversee security operations, including vulnerability management, penetration testing, security monitoring, and incident detection and response
  • Fulltime
Read More
Arrow Right

Information Security Officer

Elevate Our Security Posture: Join Us as an Information Security Officer. Are yo...
Location
Location
Poland , Łódź
Salary
Salary:
Not provided
arrive.com Logo
Arrive
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree in Computer Science, Information Security, or a related field
  • 5+ years of experience in an information security role, with at least 2 years in a leadership position
  • Relevant certifications (CRISC, CISSP, CISA, CISM) are preferred
  • Strategic Mindset: Deep understanding of business goals and objectives, with the ability to align cybersecurity risk management with overall business strategy
  • Risk Management Expertise: Proven ability to identify, assess, and prioritize cybersecurity risks
  • Technical Proficiency: In-depth knowledge of cybersecurity principles, security controls, incident response, and industry frameworks
  • Communication & Collaboration: Excellent communication skills, with the ability to translate complex technical concepts for non-technical audiences
  • Leadership: Proven ability to lead and mentor a team of security professionals
  • Thrive in a Fast-Paced Environment: Experience contributing to and managing cybersecurity within a high-growth company
Job Responsibility
Job Responsibility
  • Risk Management: Proactively identify, assess, and mitigate security risks and vulnerabilities
  • Security Awareness: Develop and deliver engaging training programs to educate employees on security best practices
  • Compliance: Ensure adherence to relevant security standards and regulations (ISO 27001, PCI DSS, GDPR)
  • Policy & Procedure Development: Lead the creation and maintenance of clear and concise security policies and procedures
  • Third-Party Risk Management: Assess and manage the security posture of third-party vendors and partners
  • Data Protection: Define requirements and contribute to implementing Data Loss Prevention (DLP) solutions
  • Security Frameworks: Contribute to the adoption and implementation of industry-leading security frameworks (NIST, CIS)
  • Business Partnership: Collaborate closely with business units to understand their security needs and align with the overall security strategy
  • GRC Program: Operate and mature our Governance, Risk, and Compliance (GRC) program
  • Leadership & Collaboration: Lead and mentor a team of security professionals, fostering a culture of collaboration and continuous improvement
Read More
Arrow Right

Information Security Consultant

PGI is seeking experienced Information Security Consultants to join our contract...
Location
Location
United Kingdom , London
Salary
Salary:
Not provided
pgitl.com Logo
Protection Group International
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Proven people and relationship management skills
  • Demonstrable experience providing Information Assurance consultancy
  • Experience in or knowledge of the PCI DSS standard, NIST CSF, DORA, GDPR/DPA
  • ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, Business Continuity or Cloud Security accreditations are highly desirable
  • Experience in conducting risk assessments and forming risk management policies
  • Excellent verbal and written communication skills, with the ability to present to clients and business stakeholders
  • A positive approach to problem-solving and possesses the ability to work smart and collaboratively to prioritise and set deadlines
Job Responsibility
Job Responsibility
  • Engaging confidently with clients relating to solving Information Security Governance, Risk, and Compliance problems
  • Providing hands-on compliance and consultancy services across a range of requirements for clients, such as ISO 27001, business continuity, data protection, DORA, or other regulatory compliance needs, including IASME Cyber Essentials
  • Support colleagues in delivery by also assisting with: Information Security Management System (ISMS) design and implementation
  • GDPR gap assessments and implementation support
  • PCI DSS scoping, gap assessments, implementation guidance, and compliance reporting
  • Maturity Assessments
  • Third-party / supplier assurance reviews
  • Providing expertise to enhance our international capacity-building offer and value
  • Contribute towards the maintenance of PGI’s own accreditations, including ISO 27001, ISO 9001 and business continuity as well as compliance with data protection regulations
  • Maintaining your own continuing professional development, keeping up to date with security industry trends and best practices
Read More
Arrow Right

Senior Information Security Compliance Analyst

We're looking for a technically grounded Senior IS Compliance Analyst who speaks...
Location
Location
United States , Chicago
Salary
Salary:
90000.00 - 130000.00 USD / Year
blumeglobal.com Logo
Blume Global
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Hands-on experience in technical security roles such as Security Operations, Incident Response, Security Analysis, penetration testing, or similar
  • Practical knowledge of security tools, SIEM platforms, vulnerability management, and security monitoring
  • and ability to read and understand security logs, configurations, and technical documentation
  • 6+ years of total experience with significant time in GRC
  • Working knowledge of ISO 27001, NIST frameworks, SOC 1/2, and GDPR requirements
  • Experience developing and implementing information security policies and controls
  • ISO 27001:2022 Lead Implementer and Lead Auditor certification
Job Responsibility
Job Responsibility
  • Lead technical security assessments and integration of acquired companies, mapping their security architectures and controls to our GRC frameworks, identifying gaps, and building remediation roadmaps that address both technical security and compliance alignment
  • Bridge technical security and business stakeholders by evaluating risks through a technical lens, working alongside security engineering teams to translate GRC requirements into practical security measures, and communicating effectively across technical and non-technical audiences
  • Develop and harmonize security policies and control frameworks across acquired entities, ensuring they're both audit ready and operationally sound, while translating between technical security requirements and governance documentation
  • Own customer security questionnaire responses by leveraging your hands-on security background to provide detailed, accurate answers and collaborating with infrastructure, application security, and operations teams to gather technical evidence
  • Drive continuous improvement of our GRC program through technical security enhancements, meaningful security and compliance metrics, and process improvements that increase both control effectiveness and operational efficiency
What we offer
What we offer
  • health and welfare benefits
  • tuition assistance
  • 401K savings and other retirement programs
  • employee assistance programs
Read More
Arrow Right

Information Security Analyst

The Information Security Analyst will play a key role in safeguarding the organi...
Location
Location
United States , Atlanta
Salary
Salary:
Not provided
oceanbluecorp.com Logo
Ocean Blue Solutions
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s degree in information security, Cybersecurity, IT, or related field
  • or equivalent 1 year
  • or Preference will be given to candidates with relevant State of Georgia Experience
  • Hands-on experience with Splunk, CrowdStrike Falcon, and Tenable Nessus/Tenable.sc.
  • Strong understanding of CUI protection requirements and compliance frameworks (NIST, FISMA, IRS Pub 1075, CMS, SSA)
  • Experience with incident response, vulnerability management, and risk assessments
  • Strong analytical, documentation, and communication skills
Job Responsibility
Job Responsibility
  • Conduct continuous monitoring of enterprise systems using CrowdStrike (EDR), Splunk (SIEM), and Tenable (Vulnerability Management)
  • Detect, investigate, and respond to potential threats and incidents impacting CUI and overall system security
  • Maintain dashboards, alerts, and reports to ensure proactive detection and escalation of risks
  • Perform ongoing vulnerability assessments with Tenable, track remediation efforts, and validate closure of findings
  • Support patch management and configuration management processes to reduce the attack surface
  • Deliver metrics and risk posture updates to leadership
  • Maintain and update System Security Plans (SSPs) to document the implementation of security controls
  • Support external and internal audits (IRS, CMS, SSA, NIST, FISMA) by providing required evidence, documentation, and remediation tracking
  • Assist in compliance with evolving frameworks (e.g., NIST SP 800-53 Rev. 5)
  • Triage, analyze, and document security incidents across enterprise systems
Read More
Arrow Right