Security Governance & Compliance Specialist
Sofia, BG, 1766
Amusnet is a leading provider recognized for offering best-performing products and innovative solutions in gaming globally. With a portfolio of 300+ casino games, our company delivers engaging online entertainment across 2,000+ websites in 35+ markets. The dedication to innovation and technology also extends to the production of premium slot cabinets, where our games seamlessly integrate with cutting-edge hardware solutions. We continue to expand our network of offices, and our team now consists of 1,300+ industry professionals. As we grow, we're looking for Security Governance & Compliance Specialist!
As a Security Governance & Compliance Specialist, you will lead security audits and assessments across Amusnet and help keep our Information Security Management System effective, current and audit-ready throughout the year.
You will manage audit engagements end-to-end, maintain and evolve the ISMS governance framework, coordinate evidence and remediation, and handle security assurance requests from our clients.
This is a hands-on GRC role for someone who can turn requirements into practical controls, challenge evidence where needed and keep multiple stakeholders moving toward a successful outcome.
THE PERFECT TEAM MEMBER IS INSPIRED TO:
- Lead external security audits and assessments end-to-end, including ISO 27001/27017, market-specific security audits and IT audit engagements
- Maintain and continuously improve the ISMS documentation framework, including policies, standards, procedures and guidelines, from drafting through review and approval
- Plan and perform ISO 27001 internal audit activities, control testing and follow-up
- Coordinate audit evidence across technical and business teams, ensuring quality, traceability and continuous audit readiness
- Track remediation actions to closure, challenge control owners where needed and validate supporting evidence
- Manage security questionnaires and assurance requests from clients and partners, ensuring accurate and consistent responses
- Use GRC tooling, automation and AI-assisted workflows to streamline evidence collection, audit preparation, reporting and other repetitive GRC activities
- Support gap assessments and implementation activities for new security standards or market-specific requirements when needed
THE SKILLS THAT WILL GRAB OUR ATTENTION:
- 3+ years of experience in Information Security, IT Audit, GRC or a closely related field
- Strong hands-on knowledge of ISO/IEC 27001 and experience maintaining or operating an ISMS
- Proven experience coordinating external audits and performing internal audit or control assurance activities
- Strong ability to produce clear security governance documentation and translate requirements into practical actions for control owners
- Good understanding of common technical security controls and the ability to assess supporting evidence critically
- Strong stakeholder management, organisation and communication skills across both technical and business teams
- Relevant university degree or equivalent practical experience
SKILLS CONSIDERED AS AN ADVANTAGE:
- Experience with SOC 2 or security requirements in regulated industries
- Experience with GRC platforms, compliance automation or evidence-management tooling
- Relevant certifications such as ISO 27001 Lead Auditor/Lead Implementer, CISA, CISM or CISSP
- Experience in iGaming, fintech, financial services, telecoms or another multi-market regulated environment
THE REASONS TO JOIN OUR TEAM:
- Excellent remuneration package
- Performance-based bonuses
- Private health insurance
- Card for Public Transportation
- Multisport card
- Corporate discounts
- Parking – early bird option
- 25 days of annual paid leave
- Performance review process
- Internal & external training programs
- Team buildings & local company events
- Work-life balance
- Inspiring & supportive colleagues
- Culture that encourages creativity & talent
If you are interested, please send us your CV.
All applications will be treated strictly confidential.
Only short-listed candidates will be contacted.
Thank you for applying!