This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking an experienced IT Policy, Compliance, and Assurance Consultant to lead the establishment and operationalization of IT governance practices. The role focuses on designing standard IT policies, enforcing controls, ensuring adherence, and setting up compliance assurance frameworks aligned with NIST, ISO 27001, and DORA across a complex application landscape.
Job Responsibility:
IT Policy Framework & Implementation: Create and work in existing IT Policy Framework tailored for a multi-application environment
Update policies for categories like information security, incident management, cyber security and data protection
IT Policy Controls & Automation: Implement and automate IT policy controls to monitor compliance and mitigate risks proactively
Map control objectives to relevant systems and applications
IT Policy Adherence: Build dashboards and scorecards to monitor policy adherence across 200–300 applications
Conduct periodic compliance reviews and track exceptions
Provide user training and guidance for developers, QA teams, and app owners
Stakeholder Engagement: Interface with application teams, enterprise architects, security and QA leaders
Drive cross-functional compliance alignment across in-house and third-party systems
Requirements:
3-5 years of experience in IT compliance & GRC (Governance, Risk & Compliance) Platform
Experience working in complex environments with multiple systems or distributed architectures
Good knowledge of: IT policy design and enforcement
NIST and ISO 27001 implementation
DORA principles and ICT risk management (preferred)
Prior experience coordinating across QA, development, and infrastructure teams
Nice to have:
Familiarity or training in DORA compliance is a strong plus