ºÚÁÏÉç

IT Compliance Cloud Analyst(Bucharest,RO)

Bucharest
Security, Engineering & Service Desk

Our mission is to help people integrate technology into everyday life and to enable innovation through technology.  We offer software development and infrastructure solutions, with advanced competences in Blockchain, Artificial Intelligence and Machine Learning. All our offices (in Western Europe or nearshore, in CEE) are located within the boundaries of the European Union.  We believe working in close cooperation with our clients and employees is the key to success; this means we offer people the best working environment in order to achieve the best results. We love entrepreneurial spirits and encourage people around us to be proactive and make the best decisions not only for business, but for their own personal development.   Our nearshore Romanian offices are in Bucharest (Victoriei Square) and Iasi (Palace) and, with over 9000 team members at group level, we make sure we are always close to our customers.  What you will be working on:  You will join an international technology environment and contribute to the design, implementation and continuous improvement of IT security, risk and compliance controls for cloud platforms.  You will work closely with platform owners, development teams, security specialists, risk and control functions, audit teams and business stakeholders to support the secure and compliant adoption of cloud services.  The role requires someone who can understand complex technical environments from both a high-level and detailed perspective, assess the associated risks and translate internal policies, regulatory requirements and security standards into practical and scalable controls.  You will contribute to strengthening the organization’s cloud control environment, improving consistency across platforms and ensuring that security and compliance requirements are properly embedded into technical solutions and delivery processes. #LI-DNI

  • Provide cybersecurity, IT risk and regulatory compliance guidance to platform owners, development teams and business stakeholders  
  • Support alignment with internal policies, risk frameworks and standards such as NIST, SOX, PCI-DSS and other relevant industry practices  
  • Perform IT risk assessments for new cloud platforms and significant changes to existing environments  
  • Identify key technology risks, evaluate the effectiveness of existing controls and recommend appropriate remediation actions  
  • Advise stakeholders on the design of sustainable, proportionate and scalable cloud controls  
  • Define and improve control requirements related to identity and access management, logging and monitoring, encryption, network security and configuration governance  
  • Develop and enhance cloud guardrails, standards and security control requirements  
  • Support the secure onboarding and consistent adoption of cloud services across multiple platforms  
  • Drive the continuous improvement and harmonization of cloud controls across the organization  
  • Collaborate with Security, Risk and Controls, Internal Audit, External Audit, Business Continuity, IT Disaster Recovery and Service Continuity teams  
  • Support internal and external audit engagements by preparing and providing the required documentation and evidence  
  • Monitor remediation plans and help ensure that identified control deficiencies are addressed within the agreed timelines  
  • Support SOX and PCI audit cycles  
  • Communicate risk assessment outcomes and control implementation updates to relevant governance and assurance stakeholders  
  • Build strong relationships with technical and business stakeholders and promote a risk-aware culture  
  • Adapt to evolving business priorities, stakeholder expectations and regulatory requirements 

What you need to succeed:

  • 5+ years of relevant experience in IT Risk, Cybersecurity, Cloud Compliance, IT Audit, Governance, Internal Controls or a similar field  
  • Strong experience in Cloud Security and Compliance across AWS, Azure, GCP or similar cloud environments  
  • Experience or solid knowledge of DevOps environments and modern software delivery practices  
  • Hands-on experience in one or more of the following areas: IT risk assessments, business analysis, auditing, corporate governance, risk management or internal controls  
  • Strong understanding of cloud risk and control domains, including identity and access management, logging and monitoring, encryption, network security and configuration governance  
  • Familiarity with a broad range of technologies, including internally developed applications, Windows, Linux, databases and GitLab or similar platforms  
  • Ability to assess risks, evaluate control effectiveness and provide practical and proportionate recommendations  
  • Good understanding of internal control requirements and experience applying them across different technology or business environments  
  • Experience working with regulatory and security frameworks such as NIST, SOX and PCI-DSS  
  • Strong stakeholder management and communication skills  
  • Ability to collaborate effectively with technical, risk, audit and business teams  
  • Ability to communicate complex security and risk topics to both technical and non-technical stakeholders  
  • Strong analytical mindset and the ability to understand complex technical dependencies  
  • Ability to break down large and complex activities into clear and manageable actions  
  • Independent and proactive working style, combined with strong teamwork skills  
  • Adaptable mindset and the ability to work effectively in a dynamic and changing environment  
  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Risk Management or a related field  
  • Advanced English communication skills 
  • Nice to have: 
  • AWS certifications or other relevant cloud certifications  
  • Certified Cloud Security Professional – CCSP  
  • Certificate of Cloud Security Knowledge – CCSK  
  • Other relevant ISC2 or Cloud Security Alliance certifications  
  • Experience working in international or large-scale enterprise environments  
  • Previous experience supporting internal or external audit engagements  
  • Experience with SOX or PCI-DSS control frameworks and audit cycles  
  • Exposure to high-availability, regulated or security-sensitive environments  
  • Knowledge of security-by-design and cloud governance principles 

What are we offering:

  • 22 working days as Annual Vacation plus 3 additional days off.    
  • Floating days 
  • Medical Insurance at Signal Iduna.    
  • Benefit Online platform access, with a 690 RON monthly allowance from which you can choose to invest in different wellbeing, financial or retail packages.    
  • Company performance-based annual bonus prorated according to the number of worked months in a year 
  • Financial support for the birth of your child or unhappy events.    
  • Learning and development opportunities - allocated budget for certifications and/or trainings. 
Your ambition will only grow together with *ºÚÁÏÉç, as you are given the space and context to develop.

Adrian Ilie

.NET Software Developer, *ºÚÁÏÉç Romania

Application flow

Do you have any questions about this role?

Let's connect.