Cyber Security Compliance Analyst

Posted 6 Days Ago
Be an Early Applicant
2 Locations
In-Office
Senior level
Industrial • Manufacturing
The Role
Maintains cybersecurity compliance controls, audit evidence, governance documentation, vulnerability remediation, access reviews, and security awareness campaigns. Supports GDPR, NIS2, SAP, SWIFT, and GITC compliance; coordinates audits, tracks findings, reports security metrics, reviews segregation-of-duties violations, and collaborates with IT, OT, legal, privacy, and business stakeholders.
Summary Generated by Built In

Key Responsibilities

Maintain and continuously improve the compliance control set, the supporting evidence and the documentation required by regulatory and audit obligations (GDPR,NIS2, SAP security audits, SWIFT and GITC), covering:
ØApplication change management and software development life cycle controls
ØSecurity hardening and vulnerability patching of operating systems and databases
ØIT user access permissions and periodic user access reviews
ØGeneral user access — security audit logs, monitoring evidence and review
ØPrivileged user access (ie Firefighter usage) and privileged activity review
ØGovernance and review of operating systems and databases privileged access
ØPassword policies and baseline identity controls (SSO/MFA principles)
ØSoftware compliance and security — web vulnerability management
ØSWIFT Customer Security Programme (CSP) compliance
Run the day-to-day operation of the global security awareness programme: plan and launch phishing simulations and training campaigns, follow up completion, and report on results
ØTrack training completion and phishing click/report rates, and propose improvements to campaign content, targeting and follow-up
Collaborate with the SAP Basis Security & Authorization team to review and report SoD violations
Coordinate the global vulnerability management process: consolidate scan results, prioritise on risk, track remediation with infrastructure, application and OT owners,and escalate overdue or high-risk items
Prepare the monthly, quarterly and annual compliance, vulnerability and awareness reports for the Global Security & Compliance Manager and for Carmeuse IT leadership
Support internal and external audits (including GITC): prepare evidence packs, coordinate control owners, support walkthroughs, and track findings through to closure
Maintain the security governance documentation (policies, standards, procedures, control narratives and the exception register) and participate in ITSC and cyber security team meetings
Ensure that Carmeuse's regulatory and audit compliance controls are secure and auditable, in
line with the established security, audit and regulatory requirements (GDPR, NIS2, SAP security audits, SWIFT and GITC)
Operate the global security awareness and vulnerability management follow-up processes, driving measurable improvement in employee behaviour and remediation performance
Maintain the compliance documentation, metrics and reporting used by the Global Security & Compliance Manager and by IT leadership

Key performance indicators :

Compliance and audit findings closed on time; vulnerability remediation

performance against the agreed SLAs (critical / high); security awareness results (training completion rate, phishing simulation click and report rates); timeliness and quality of the compliance evidence, metrics and reporting.

 

Required

Bachelor’s degree in engineering / technology in Information Security, Computer Science, IT or a related field
At least 8 years of experience in IT or cyber security, with hands-on exposure to compliance, audit support and reporting (a GRC or internal audit background is an advantage)
Working knowledge of regulatory and audit frameworks (GDPR, NIS2, SAP security audits, SWIFT,GITC);
Mandatory certification: CISA
ISO 27001 or CIPM are a plus
Language: English (written & spoken)
Cyber security governance, control frameworks and audit evidence expectations
Regulatory and industry compliance topics: GDPR, NIS2, SAP security audits and SWIFT
compliance
User access, Segregation of Duties and identity and access fundamentals (SSO/MFA principles)
Vulnerability management principles (risk-based prioritisation, remediation lifecycle, reporting)
and security awareness platforms such as KnowBe4

Skills

Problem solving, with attention to detail in controls, evidence and documentation
Written and oral communication skills — able to explain technical topics to non-technical stakeholders
Organization & planning — able to track many actions through to closure and hold a reporting cadence
Microsoft desktop applications (Excel, Word, PowerPoint) and compliance reporting/dashboarding
Cross-functional collaboration with IT, OT, Legal & Privacy and business owners; pragmatic and outcome-focused

Skills Required

  • Bachelor's degree in engineering, technology, information security, computer science, IT, or a related field
  • At least 8 years of experience in IT or cybersecurity
  • Hands-on experience with compliance, audit support, and reporting
  • Working knowledge of GDPR, NIS2, SAP security audits, SWIFT, and GITC
  • CISA certification
  • Knowledge of cybersecurity governance, control frameworks, and audit evidence expectations
  • Knowledge of user access, segregation of duties, and identity and access fundamentals including SSO and MFA
  • Knowledge of vulnerability management, risk-based prioritization, remediation lifecycle, and reporting
  • Experience with security awareness platforms such as KnowBe4
  • English language proficiency, written and spoken
  • ISO 27001 certification or knowledge
  • CIPM certification or knowledge
  • GRC or internal audit background
  • Microsoft Excel, Word, PowerPoint, and compliance reporting or dashboarding experience
  • Strong problem-solving, communication, organization, planning, and cross-functional collaboration skills
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
6,300 Employees
Year Founded: 1860

What We Do

Founded in 1860 and headquartered in Belgium, Carmeuse is a global leader in the manufacture of lime, limestone, and mineral-based products. The company serves industrial, construction, and soil improvement applications worldwide, operating 114 sites and 62 quarries. Beyond material supply, Carmeuse provides integrated equipment and engineering services to optimize customer processes, improve safety, and reduce CO2 emissions.

Similar Jobs

Coursera + Udemy  Logo Coursera + Udemy

Content Marketing Manager

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
India
1500 Employees
106K-143K Annually

Boeing Logo Boeing

Engineering Manager

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
170000 Employees
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees

Similar Companies Hiring

Fortune Brands Innovations Thumbnail
Manufacturing
Deerfield, IL
10000 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account