No.1 LITHUANIA'S MOST VISITED JOB SITE

Assessment Specialist

2‌7‌0‌0‌-3‌8‌0‌0‌ €/mon. gross
CVbankas.lt calculator data. Edit »
Full-time
Vilnius - DarkGuard

Job description

Regulated organisations need confidence that the products they build, the applications they run and the suppliers they rely on are secure and compliant. You'll join DarkGuard's assessment team in Vilnius, working with clients in financial services and other regulated sectors across Europe and beyond. You'll assess designs, configurations, suppliers, products and vulnerability data, help clients get it right early, and stay with them until findings are fixed or formally risk-accepted.

The work varies from engagement to engagement. One month you may be assessing a product against the EU Cyber Resilience Act, the next reviewing a client's critical ICT suppliers or the architecture of a new application before go-live. We're looking for someone who enjoys that variety and can move between frameworks without losing rigour.

Key responsibilities include:

  • Carry out security and compliance assessments of applications, products, suppliers and environments against client, regulatory and framework requirements (e.g. ISO 27001, NIST CSF 2.0, NIS2, DORA, CRA)
  • Assess products with digital elements against CRA essential requirements, including secure-by-design evidence, SBOMs and vulnerability handling processes
  • Carry out third-party risk assessments of ICT service providers, software vendors and solution providers, from due diligence through to ongoing monitoring
  • Review high-level and low-level designs: architecture and network diagrams, configurations, server and environment setups
  • Review vulnerability data in context and help client teams set remediation priorities
  • Risk-rate findings, agree remediation with stakeholders and follow up until they are actioned or formally accepted
  • Write clear reports and present findings to client stakeholders, from engineers to compliance officers and senior management

Requirements

  • 2+ years in cybersecurity governance, risk and compliance, security assessment or audit, or a technical security role with substantial GRC exposure
  • Working knowledge of ISO 27001, NIST CSF 2.0 and GDPR, and familiarity with NIS2, DORA and the Cyber Resilience Act
  • Clear report writing: you can explain a technical or regulatory finding to a non-specialist
  • A delivery focus: you work to deadlines, and an assessment is finished when the client knows what to fix and in what order
  • Fluent English, written and spoken

Nice to have

  • ISO 27001 Lead Auditor, CISA or an equivalent certification, or working towards one
  • German, or another European language used in client work
  • Experience with GRC or third-party risk platforms such as OneTrust, ServiceNow IRM, Archer, Bitsight or Whistic
  • Exposure to product security, secure development lifecycle or IEC 62443 and other industrial/OT security standards
  • A background in regulated sectors such as financial services, energy or manufacturing

Data Protection

By applying I confirm that I have read and understood DarkGuard Privacy Policy (darkguard.com/privacy/)
By submitting this application, I agree for DarkGuard to store my personal data for up to 5 years in order to contact me about future opportunities. Consent can be withdrawn at any time by contacting us.

Salary

2700-3800 €/mon. gross

DarkGuard

At DarkGuard, we're on a mission to secure organisations where getting security right isn't optional: banking, insurance, energy and critical infrastructure.

We don't do checklists or box-ticking exercises. Our engagements build genuine security understanding and coverage, from the boardroom to the shop floor, from regulatory nuance to deep technical detail.

Our teams have led major transformations for some of the world's largest regulated enterprises. Now, we're looking for people who want to do the same: think broadly, collaborate internationally, and go deeper than "compliant."

You also might be interested in: