Strength. Care. Growth
You will know we are the right place for you, if you are driven by:
- Opportunities to learn and build your career.
- Meaningful work in a stable and fast-paced company.
- Diversity of people, projects, and platforms.
- A supportive, fun, and inspiring place to work.
This job can be performed by all countries within our A1 footprint.
Role Overview:
We are seeking a highly motivated and detail-oriented Security Assurance Expert to join our Information Security Office in Security Assurance team. In this role, you will evaluate the implementation of internal cyber security controls, international standards (e.g., ISO 27001/2), and regulatory requirements such as NIS2, Local country regulations, build connections between needs and possibilities.
You will work as part of a centralized, international team responsible for conducting assurance activities across the A1 Group, assessing adherence to established security frameworks, and managing the lifecycle of identified risks and gaps. Your work will directly contribute to the continuous improvement of our security posture across all business units.
Role Insightst:
- Evaluate and assess effectiveness of security controls against internal governance framework, ISO standards, and regulatory frameworks (e.g., NIS2, DORA..).
- Conduct compliance assessments of systems and processes.
- Identify control gaps or non-conformities and provide actionable recommendations to mitigate risks.
- Collaborate with system owners and business stakeholders to develop remediation plans and track implementation progress.
- Support audits and regulatory inspections by providing documentation, evidence, and expert insight as required.
- Contribute to assurance metrics and dashboards, reporting on compliance status, trends, and risk exposure.
- Assist in developing and enhancing assurance methodologies and control frameworks in line with evolving standards and regulations.
- Actively contribute to a culture of continuous improvement, knowledge sharing, and cross-group collaboration.
What Makes You Unique:
- Bachelor’s degree in Information Security, Computer Science, Information Technology, Business Informatics, Organizational Science or related field.
- 2+ years of experience in assurance / compliance roles, IT or security audit, security consulting or similar.
- Strong understanding of ISO standards (at least 27001, 27002).
- Familiarity with NIS2, DORA, GDPR, and other applicable regulatory frameworks.
- Experience managing audit/assurance findings and working with stakeholders to close gaps.
- Solid understanding of security controls and governance models.
- Excellent analytical, documentation, and communication skills.
- Fluent in English.
Nice to Have:
- Professional certifications such as ISO 27001 Lead Auditor/Implementer, CISSP, CISA, CISM, or similar.
- Familiarity with security maturity models and control assessments.
- German and Balkan language skills.
Job code: AFU020P209
Job classification: P2 - 9, KV4, PT 3/2