Key Responsibilities
• Maintain and continuously improve the compliance control set, the supporting evidence and the documentation required by regulatory and audit obligations (GDPR,NIS2, SAP security audits, SWIFT and GITC), covering:
Ø Application change management and software development life cycle controls
Ø Security hardening and vulnerability patching of operating systems and databases
Ø IT user access permissions and periodic user access reviews
Ø General user access — security audit logs, monitoring evidence and review
Ø Privileged user access (ie Firefighter usage) and privileged activity review
Ø Governance and review of operating systems and databases privileged access
Ø Password policies and baseline identity controls (SSO/MFA principles)
Ø Software compliance and security — web vulnerability management
Ø SWIFT Customer Security Programme (CSP) compliance
• Run the day-to-day operation of the global security awareness programme: plan and launch phishing simulations and training campaigns, follow up completion, and report on results
Ø Track training completion and phishing click/report rates, and propose improvements to campaign content, targeting and follow-up
• Collaborate with the SAP Basis Security & Authorization team to review and report SoD violations
• Coordinate the global vulnerability management process: consolidate scan results, prioritise on risk, track remediation with infrastructure, application and OT owners,and escalate overdue or high-risk items
• Prepare the monthly, quarterly and annual compliance, vulnerability and awareness reports for the Global Security & Compliance Manager and for Carmeuse IT leadership
• Support internal and external audits (including GITC): prepare evidence packs, coordinate control owners, support walkthroughs, and track findings through to closure
• Maintain the security governance documentation (policies, standards, procedures, control narratives and the exception register) and participate in ITSC and cyber security team meetings
• Ensure that Carmeuse's regulatory and audit compliance controls are secure and auditable, in
• line with the established security, audit and regulatory requirements (GDPR, NIS2, SAP security audits, SWIFT and GITC)
• Operate the global security awareness and vulnerability management follow-up processes, driving measurable improvement in employee behaviour and remediation performance
• Maintain the compliance documentation, metrics and reporting used by the Global Security & Compliance Manager and by IT leadership
Key performance indicators :
Compliance and audit findings closed on time; vulnerability remediation
performance against the agreed SLAs (critical / high); security awareness results (training completion rate, phishing simulation click and report rates); timeliness and quality of the compliance evidence, metrics and reporting.
Required
• Bachelor’s degree in engineering / technology in Information Security, Computer Science, IT or a related field
• At least 8 years of experience in IT or cyber security, with hands-on exposure to compliance, audit support and reporting (a GRC or internal audit background is an advantage)
• Working knowledge of regulatory and audit frameworks (GDPR, NIS2, SAP security audits, SWIFT,GITC);
• Mandatory certification: CISA
• ISO 27001 or CIPM are a plus
• Language: English (written & spoken)
• Cyber security governance, control frameworks and audit evidence expectations
• Regulatory and industry compliance topics: GDPR, NIS2, SAP security audits and SWIFT
• compliance
• User access, Segregation of Duties and identity and access fundamentals (SSO/MFA principles)
• Vulnerability management principles (risk-based prioritisation, remediation lifecycle, reporting)
• and security awareness platforms such as KnowBe4
Skills
• Problem solving, with attention to detail in controls, evidence and documentation
• Written and oral communication skills — able to explain technical topics to non-technical stakeholders
• Organization & planning — able to track many actions through to closure and hold a reporting cadence
• Microsoft desktop applications (Excel, Word, PowerPoint) and compliance reporting/dashboarding
• Cross-functional collaboration with IT, OT, Legal & Privacy and business owners; pragmatic and outcome-focused