Senior Governance, Risk and Compliance Engineer
- Роль
- Безопасность
- Опыт
- Синьор
- Занятость
- Полная занятость
Доступно для: CY, PL, PT only. Укажите, откуда вы работаете, чтобы проверить доступность.
Коротко по делу
Senior GRC / information security governance specialist with 3+ years in GRC, IT audit or IT risk. Needs ISO 27001 knowledge, exposure to DORA/GDPR/PCI DSS, audit experience, regulated financial services background, and strong written English. Location: Limassol, Cyprus or remote from Poland or Portugal.
Ключевые навыки
Обязательные навыки
Желательные навыки
Обязательные языки
Last Updated: 14 May 2026
What are the purposes of this Privacy Notice
This privacy notice explains, amongst other, what information/data we collect about you, how we use it and what are your rights and choices in relation to the personal information we hold about you under Regulation (EU) 2016/679 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data [General Data Protection Regulation (“EU GDPR”)] and, where applicable, the UK General Data Protection Regulation (“UK GDPR”) as supplemented by the Data Protection Act 2018.
This policy applies to the Data Subjects who are accessing or applying to use the services payabl. offers or may offer in the future, either on their own account or on behalf of a business, potential personnel, suppliers or other person that may interact with payabl., including through our subsidiaries, such as our UK entity, where the processing of personal data falls within the scope of UK data protection law.
Who we are
PAYABL. CY LIMITED ("PAYABL. CY") is a limited liability company duly registered under the laws of the Republic of Cyprus, with registration number HE 289380 having its registered address at Agiou Athanasiou 4, Agios Athanasios, Limassol, 4104, Cyprus. PAYABL. CY is authorised by the Central Bank of Cyprus (“CBC”) under licence number 115.1.2.9/2018, to provide payment services in accordance with the provisions of the Provision and Use of Payment Services and Access to Payment Systems Laws of 2018, as amended (the “PI Law”).
For Data Subjects located in the United Kingdom, services may also be offered via our wholly-owned UK subsidiary, PAYABL. UK LIMITED ("PAYABL. UK"), a company registered in England and Wales with company registration number 13639825 and registered address at Napier House, 24 High Holborn, London, England, WC1V 6AZ. PAYABL. UK is an authorised Electronic Money Institution ("EMI") supervised by the Financial Conduct Authority ("FCA") under license number 967259.
PAYABL. CY is the primary data controller for the processing activities covered by this Privacy Notice, and PAYABL. UK is also a data controller responsible for personal data processed in the UK as a licensed entity. PAYABL. CY and PAYABL. UK are hereinafter referred to as “us”, “we”, “payabl.”
payabl. is committed to protect your privacy and confidentiality by complying with the national Data protection regulations and protect its Data Subject’s (referred to as “Data Subject”, “You”, “Your”, “Yours”) by keeping their personal data secure against theft damage or any misuse either knowingly or unknowingly.
Here at payabl., we respect your privacy and how your personal data is used, that’s why we encourage you to read this policy carefully.
We have appointed a Data Protection Officer and the contact details are as follows for contact purposes: Agiou Athanasiou 4, Agios Athanasios, Limassol, 4104, Cyprus, phone +357 25332590 and email address: dataprotection@payabl.com.
What Personal data we collect about you
Depending on the way you interact with payabl. we collect your personal data when:
- You fill in our forms and applications;
- Communicate with us;
- Respond or complete any of our surveys;
- Use any of our services & products, including our mobile application;
- Use our Wi-Fi services when visiting authorised Company locations;
- Connect with any member of our team;
- Apply for a job position;
- Visit our premises;
- Participate in any event and competitions we organise;
- Contact us for any reason.
The information we collect are the following:
| Information that you provide us directly: | |
|---|---|
| Personal identification data | First name and surname;Date of birth;Gender;Your image or a recording of you;Marital status;Country of residency;Immigration status and work permit;Passport number;Identification number;Driver license number;Taxpayer Identification NumberAny other information provided in your CV. |
| Contact details | Email address;Telephone number;Social media account contact details;Postal / Billing / Residential address. |
| Identification documents | Identity (ID) or passport information;Residence permit;Driver’s license. |
| Financial data | Bank account and payment card details;Payment account number;IBAN;Account number;Bank or issuer details;CVC;Card expiration date;Billing and invoicing information. |
| Information collected from the use of our products, services, website and mobile application by You: | |
|---|---|
| Transaction data | Alternative Payment Method used;Crypto Asset Services used;Transaction and fraud monitoring information such as transaction values and volumes, IP address, geo-location;Virtual Card usage data (e.g. transaction detail, time, amount etc);Open Banking & BaaS (Banking as a Service) services used (e.g. Account identifiers & information, Payment initiation data, API logs & interaction data); |
| Technical data | internet protocol (IP) address;location and geo location;browser type and version;time zone settings;browser plug in types and versions;device type (e.g. mobile, tablet, desktop);mobile device identifier (e.g. UUID) and login credentials;Blockchain related identifiers and metadata;operating system and platform and other technology on the devices you use to access our website. |
| Usage Data | information on your use of our website or mobile application;clickstream through and from our website and app including date and time;keywords/search terms used to land on our website;Uniform Resource Locator (URL);length of visit;page interaction information;products and services you viewed or searched for page response times;download errors;downloadable materials you used on our website;any phone number used to call payabl. customer service number. |
| Marketing data | your preferences in receiving marketing materials, newsletters, email campaigns;your communication preferences;any consent or permission you have given us. |
| Information we collect from other sources: | |
|---|---|
| Information from Others | we collect personal data from third parties, such as credit reference agencies, fraud prevention agencies, sanctions and transaction risk information obtained about our customer such as:credit score;business name and address;business ID;financial statements;list of PEPs (Political Exposed Persons);sanctions. |
| Information from social media | publicly accessible comments and opinions through internet searches;posts on social media sites, such as LinkedIn or Facebook or Instagram, when we conduct general searches about you. |
| Information from publicly available sources | information and contact details from publicly available sources such as:social media networking sites;online registries or directories;websites or enhanced due diligence checks;security searches;KYC purposes. |
| Information from our CCTV | For the purposes of security, protection of property, and crime prevention and detection, our offices are monitored by Closed-Circuit Television (CCTV). The CCTV system is positioned to cover all entry and exit points of the premises thus your image may be recorded when entering or exiting our offices. Video footage is retained securely for a limited period, typically, after which it is automatically overwritten, unless required for an ongoing investigation or legal process. |
| Records of our discussions | if you contact us or we contacted you;stream of our communication;when you apply for an employment position with us, we will ask you for information relevant to your application. |
| Information from using our Guest Wi-Fi services | your email address when you register;the domain name from which you have accessed our Wi-Fi;your MAC address and device name;the date and time you accessed our Wi-Fi;your data usage;type of device and location and proximity of your wireless device in the property, arrival and departure time;cookies which enable tracking or provide other information regarding your interaction with the Wi-Fi;the web browser that you are using and the IP addresses accessed using our Wi-Fi. |
Marketing activities and events
You may also provide Us with your personal information at a marketing event or through marketing activities organized by the Company. This personal information may include: first and last name, company name, job title, work email address, work address, phone number and the content of your request.
If you attend an in-person or virtual event or agree to be recorded in a telephone or video meeting, we may record some or all of that event or meeting. For events, we may also document the event by taking photos or interviewing you at the event. We use this information for business and marketing purposes and training purposes based on your consent.
Where applicable, such processing is carried out in accordance with the EU GDPR and/or UK GDPR. If you do not wish to be recorded or photographed, please inform a member of staff in advance of the event or during the session.
Data We Collect from Potential Candidates
When you apply for a position at payabl., you may share your personal data with us through a number of channels, including our online application forms, email, phone, social media, in person, or via a recruitment agency. We may also receive information about you from third parties as part of the recruitment process, such as recruitment agencies or professional references.
While the categories below cover the main types of information we collect, please note that any additional personal data, including sensitive data (such as health, religious beliefs, or ethnic origin), which you voluntarily choose to disclose to us in your CV, during interviews, or throughout the recruitment process, will also be collected and used solely to evaluate your candidacy, communicate with you, and (where applicable) make arrangements for interviews and reasonable adjustments for your application.
What we collect
The personal data we collect and process in the context of recruitment may include:
- Identity and contact details — such as your full name, email address, phone number, and location.
- Application and background information — including your CV, cover letter, education history, professional qualifications, certifications, and current and previous employment history.
- Recruitment process records — including interview notes, assessments, evaluations, and any correspondence exchanged during the process.
- Video interview recordings — where interviews are conducted through our online recruitment platform, sessions may be recorded for evaluation and internal review purposes. You will be informed prior to any recording taking place.
- AI-assisted assessment data — we use technology tools that support our recruiters with structured note-taking and interview summaries during or after interview sessions. These tools assist our team in capturing key information accurately. Any outputs generated are reviewed by a human recruiter and do not constitute automated decision-making that produces legal or similarly significant effects about you.
- Pre-employment verification information — such as reference letters and, where relevant to the role and permitted by applicable law, a criminal record certificate. This is typically requested at a later stage of the process and only where necessary.
- Accessibility and adjustment information — if you choose to share information about a disability or any other condition requiring reasonable adjustments during the recruitment process, we will handle this data with the utmost care and in accordance with applicable law. Sharing this information is entirely voluntary and will only be used to support your participation in the process.
How long we keep your data
If your application is not successful, we will retain your personal data and CV for a period of two (2) years from the conclusion of the recruitment process. We do this so that we may consider your profile for future suitable opportunities at payabl., unless you request earlier deletion or withdraw your consent where applicable.
If you do not wish your data to be retained beyond the conclusion of the current process, you may contact us at any time to request its deletion.
Our Legal Basis for using your personal data
In accordance with the EU GDPR and, where applicable, the UK GDPR, we must always have a valid legal basis to process your personal data.
The legal basis may vary from one of the following:
- the performance of a contract with you: we will need certain personal information to perform our contract and provide our services to you;
- compliance with our legal & regulatory obligations: we are subject to a number of such obligations emanating from laws and statutory obligations (AML - Anti-Money Laundering laws, KYC obligations);
- legitimate interest: in some cases, we may collect and use your personal data because we have a legitimate interest to do so and its reasonable when balanced with your rights and freedoms (initiating legal claims or preparing our defence in litigation procedures, CCTV systems in order to prevent crime or fraud);
- Consent: when you have given us your prior written consent to collect and use your data.
With whom we may share your personal data
In order for us to perform and comply with our contractual and statutory obligations your personal data may be provided to various service providers and third parties, only in cases we have a legal basis to do so. Such service providers and third parties enter into contractual agreements with payabl. in order to ensure confidentiality of your personal data and compliance with the EU GDPR, UK GDPR and local laws and regulations.
Recipients of your personal data may be:
| Type of Recipients | Why we share your personal data |
|---|---|
| Supervisory authorities, law enforcement agencies without your prior consent e.g. Central Bank of Cyprus, the European Central Bank, tax authorities, Cyprus Security Exchange Commission (CySec), Financial Conduct authorit |
Чем предстоит заниматься
- Develop, maintain and continuously improve information security policies, standards and procedures aligned with ISO 27001 and regulatory requirements
- Operate the policy lifecycle: approval workflows, periodic reviews, ownership and version control across the document estate
- Maintain the information security risk register: risk identification, assessment, treatment tracking and formal acceptance
- Prepare risk reporting for management and governance committees, and track remediation to closure
- Support compliance activities under DORA, PSD2/EBA ICT guidelines, GDPR and PCI DSS across licensed entities
- Contribute to operational resilience work for the UK entity under FCA requirements
- Run the third-party risk management lifecycle: due diligence, security questionnaires, risk rating, onboarding gates and periodic reassessment
- Maintain the vendor register and contractual security requirements together with Legal
- Coordinate internal and external audits, including Big-4 ICT audits, regulator requests and PCI QSA cycles
- Manage the audit calendar
- Own evidence collection and maintain an evidence library for reuse across audits, certifications and client questionnaires
- Administer and develop the GRC platform: control monitoring, automated evidence collection, framework mapping and reporting
- Apply AI tooling to day-to-day GRC work, including policy drafting, gap analysis, evidence assembly and questionnaire responses
- Help automate recurring processes
- Contribute to the AI governance Programme by assessing AI vendors, supporting the AI system register and aligning with emerging requirements such as the EU AI Act
Что требуется
- 3+ years of experience of similar experience in GRC, information security governance, IT audit or IT risk management
- Working knowledge of ISO/IEC 27001; exposure to DORA, GDPR or PCI DSS
- Experience in regulated financial services, including payments, e-money, banking, fintech, or advisory work for such companies
- Hands-on experience with audits — coordinating them, preparing evidence, remediating findings
- Familiarity with GRC platforms or a strong interest in compliance automation
- Strong written English — your output goes to auditors, regulators and senior stakeholders
- Ability to manage multiple workstreams against fixed deadlines
- Preferred: Certifications such as CISA, CRISC, CISM, CIPP/E or ISO 27001 Lead Auditor / Lead Implementer
- Preferred: Direct experience with DORA implementation, EBA outsourcing guidelines or FCA operational resilience
- Preferred: Experience implementing or administering a GRC platform, e.g. Vanta, ServiceNow GRC, OneTrust or similar
- Preferred: Familiarity with ISO 42001, the EU AI Act or AI risk management
- Preferred: Light scripting or workflow automation skills using low-code tools
Преимущества
- Provident Fund after probation
- Annual Learning Budget for professional development after probation
- €150 monthly Wolt allowance
- SportsBenefits membership with access to gyms and sports facilities
- Potential eligibility for a company car after one year, performance and availability permitting
- Complimentary parking space near the office
- 25 days of vacation + public holidays + 10 days of sick leave
- Exclusive local discount card
- Tickets for events such as Beonix and basketball games
- Free Greek language classes twice a week
- Company celebrations bringing colleagues from all offices together
- Opportunities to participate in international company events and initiatives
payabl. empowers businesses to grow through payments innovation and banking services. Our ambition is to expand our strong portfolio of global financial services and make them all accessible through our unified platform, payabl.one. As a licensed financial company with principal membership with card schemes, we specialize in global payments and multi-currency banking solutions.