Public Group logo
Public Group

grc expert

Aug 3, 2026 · Public Group

Κηφισιά·Aug 3, 2026
ΚηφισιάHybridΠληροφορικήPermanentFull Time
JOBILY AI SUMMARY

What you'll do

  • Develop and maintain cybersecurity policies, standards, and procedures aligned with frameworks and regulations
  • Facilitate cybersecurity and technology risk assessments and maintain risk registers
  • Participate in risk and vulnerability assessments and translate findings into improvement plans
  • Support compliance initiatives including DPIAs, Third-Party Risk Assessments, and EU AI Act readiness
  • Coordinate and support internal, external, and cyber insurance audits
  • Oversee third-party cybersecurity risk management processes
  • Review business terms in contracts and highlight areas for improvement
  • Contribute to governance and SLA design for contract management
  • Support legal and partner interfaces on contracts, NDAs, and Technical & Organizational Measures
  • Take ownership of delivery within assigned workstreams and ensure quality and timely execution
  • Participate in project management of GRC engagements
  • Provide time and effort estimates and contribute to technical writing of proposals
  • Facilitate training sessions and workshops to raise cybersecurity awareness
  • Communicate clearly with technical, business, and legal stakeholders

Key requirements

  • 2+ years' experience
  • Knowledge of cybersecurity frameworks and regulations including NIST CSF, GDPR, NIS2, PCI DSS, EU AI Act
  • Experience with risk assessments, vulnerability assessments, and Third-Party Risk Assessments
  • Skills in audit support and Cyber Insurance audits
  • Experience in IT contract management and governance including SLAs and business terms review
  • Project management skills related to GRC engagements
  • Strong communication skills and stakeholder management
  • Cybersecurity / Information Security / Computer Sciencepreferred

Benefits

  • Competitive compensation and benefits package including performance-based bonus scheme, comprehensive life and health insurance, flexible hybrid working model, psychological support, career growth opportunities, continuous learning programs, employee wellness activities, transport shuttle, and exclusive employee app access.

About the job

At Publicnext, we are strengthening our cybersecurity governance, risk, and compliance (GRC) function and looking for a GRC Expert to join the team. Working closely with and reporting directly to the CISO, you will help us mature our risk management and resilience across cybersecurity, privacy, business continuity, AI compliance, and third-party risk.

This is a hands-on delivery role with real ownership. You will run assessments, maintain our risk and compliance posture against recognized frameworks, and support the growing intersection of GRC and IT contract management, reviewing business terms, shaping governance and SLAs, and ensuring our internal and third-party arrangements meet our standards.

Responsibilities:

  • Develop and maintain cybersecurity policies, standards, and procedures aligned to recognized frameworks and regulations (NIST CSF, GDPR, NIS2, PCI DSS, EU AI Act).

  • Facilitate cybersecurity and technology risk assessments; maintain risk registers and track remediation activities to closure.

  • Participate in risk assessments, vulnerability assessments, and gap analyses, and translate findings into practical improvement plans.

  • Support compliance initiatives including DPIAs, TPRAs (Third-Party Risk Assessments), and EU AI Act readiness.

  • Coordinate and support internal and external audits and Cyber Insurance audits.

  • Oversee third-party cybersecurity risk management processes, ensuring internal teams and vendors adhere to our standards.

  • Review contracts' business terms and highlight areas for improvement.

  • Contribute to the design of governance and SLAs for contract management.

  • Support the legal and partner interface on contracts, NDAs, and Technical & Organizational Measures (TOMs).

  • Take ownership of delivery within your assigned workstreams and deliverables, ensuring quality and timely execution.

  • Participate in the project management of ongoing GRC engagements.

  • Provide time and effort estimates for prospective engagements and contribute to the technical writing of proposals and offers.

  • Facilitate training sessions and workshops to drive cybersecurity awareness across the organization.

  • Communicate clearly with technical specialists, business leaders, and legal/compliance stakeholders.

Requirements:

  • 2-4 years of experience in cybersecurity, information security, compliance, or GRC-related functions.

  • Solid understanding of cybersecurity frameworks and regulatory requirements (NIST CSF, GDPR, NIS2, PCI DSS, EU AI Act).

  • Experience supporting audits, assessments, and control-maturity activities.

  • Familiarity with IT project management principles and related methodologies.

  • Experience with or exposure to IT contract management (reviewing terms, SLAs, governance).

  • Strong analytical and problem-solving abilities.

  • Ability to communicate technical and cyber-risk concepts to both technical and non-technical audiences, including executives.

  • Strong stakeholder management and cross-functional collaboration skills.

  • A team player who supports and helps drive common goals.

  • Languages: Greek and English (both required, written and spoken).

  • Professional certifications such as ISO 27001 Lead Auditor (ISO27001-LA), CISM, CISA, or similar.

  • Experience working within regulated environments.

  • Prior exposure to Contract Management roles or IT business-facing roles.

What we offer:

  • 💼 Competitive compensation & benefits package

  • 💰 Performance-based bonus scheme

  • 🧑‍⚕️ Comprehensive life & health insurance

  • 🏡 Flexible hybrid working model – to support your work-life balance

  • 🧡 Psychological support via a professional helpline for you and your family

  • 🚀 Career growth opportunities in a role that evolves with you

  • 🎉 Valuable experience in a well-known and fast-growing organization

  • 📚 Continuous learning and upskilling through tailored programs

  • 🏃🏽‍♂️ Employee Wellness Program – office Pilates & sports teams (padel, football, volleyball & more)

  • 🚗 Alternative transportation with company shuttle buses to our offices

  • 📲 Exclusive access to our employee app, OrangeGen, packed with tools, news & perks

Public Group
Public Group
Company Profile

About the company

Public Group strategically invests to create an ecosystem of innovative scaleups around its Omnichannel Retail business, with the objective to provide exciting customer experiences and foster Entrepreneurship in Greece.

We bring together technology, talent & entrepreneurship to create value in the Greek market. We are advocates of Strategic Synergies, Bold Entrepreneurship & the Power of Human Will.

Our role is to help our subsidiaries or investee companies grow and their founders to succeed through capital and creative synergies.

We also aspire to play a positive role in promoting Greek-based entrepreneurship, as well as provide an environment for talent development

Workplace
Hybrid
Sector
Πληροφορική
Employment Type
Permanent
Work Time
Full Time
Public Group
Public Group
Company Profile

About the company

Public Group strategically invests to create an ecosystem of innovative scaleups around its Omnichannel Retail business, with the objective to provide exciting customer experiences and foster Entrepreneurship in Greece.

We bring together technology, talent & entrepreneurship to create value in the Greek market. We are advocates of Strategic Synergies, Bold Entrepreneurship & the Power of Human Will.

Our role is to help our subsidiaries or investee companies grow and their founders to succeed through capital and creative synergies.

We also aspire to play a positive role in promoting Greek-based entrepreneurship, as well as provide an environment for talent development