This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Monitor legal, regulatory and normative developments applicable to E-REDES, namely NIS2/SRI2, the European Cybersecurity Network Code, the Cyber Resilience Act, the Cybersecurity Act and ISO/IEC 27001, assessing impacts and internal adaptation needs
Contribute to the management, operation and continuous improvement of the Information Security Management System, ensuring alignment with applicable legal, regulatory and normative requirements
Support the ongoing management of cybersecurity risk, including the identification, assessment, treatment, monitoring and reporting of relevant risks for the organisation
Collaborate in the definition, implementation, review and continuous improvement of cybersecurity policies, standards and procedures, ensuring alignment with EDP Group guidelines, market best practices and applicable legal, regulatory and normative requirements
Follow up on internal, external and certification audits, as well as other compliance assessments, supporting the definition, implementation and monitoring of the respective action plans.
Requirements
University degree in Computer Engineering, Information Systems Management, Cybersecurity or similar fields
Solid experience in Information Security Management Systems (ISMS/SGSI) and Business Continuity Management Systems (BCMS/SGCN)
Minimum of 5 years’ professional experience in relevant roles in cybersecurity, risk management or information security management systems
In-depth knowledge of ISO 27001 and ISO 22301 standards
Experience in audits, risk analysis and incident management
Ability to communicate with technical teams, management committees and regulatory authorities
Fluent command of English, both spoken and written
Dynamic and proactive profile, with strong initiative and a problem-solving mindset
Strong sense of responsibility, accuracy and attention to detail
Critical thinking, proactivity and decision-making ability in complex and regulated environments
Dynamic and proactive profile, with strong initiative and results orientation
Good teamwork and interpersonal skills
Knowledge of the European regulatory framework applicable to the energy and critical infrastructure sectors
Experience liaising with internal and external stakeholders in regulated environments
Relevant cybersecurity certifications, such as ISO 27001 Lead Implementer/Auditor, CISM or CISSP
Availability for occasional travel within Portugal and across Europe.