Overview
Senior Information Security Consultant Jobs in Sofia, Sofia City, Bulgaria at Defendara
Title: Senior Information Security Consultant
Company: Defendara
Location: Sofia, Sofia City, Bulgaria
Location: Bulgaria, Sofia preferred
Work model: Remote-first / home office
Employment type: Full-time
Experience level: 4+ years
We are looking for an Information Security Consultant to strengthen our team’s capabilities in governance, risk, and compliance.
This role is focused on designing, implementing, and improving Information Security Management Systems for clients in the industrial sector, with a strong emphasis on ISO 27001 certification projects and NIS2 compliance readiness.
You will work closely with clients across IT, OT, legal, and management teams to help them build practical information security governance that works in real business environments.
What you will work on
You will support and lead client projects related to ISMS implementation, ISO 27001 certification, NIS2 readiness, and information security risk management.
Your main responsibilities will include:
- Leading and supporting ISO 27001 implementation and certification projects
- Guiding clients through gap analyses, ISMS design, documentation, and audit preparation
- Advising industrial-sector clients on NIS2 compliance requirements
- Supporting scope determination, obligation mapping, and the development of technical and organizational measures
- Developing and maintaining ISMS documentation, including information security policies, risk treatment plans, Statements of Applicability, and management review materials
- Conducting information security risk assessments in line with ISO 27005
- Supporting clients in building and maintaining structured risk registers
- Collaborating with client stakeholders across IT, OT, legal, and management levels
- Helping embed information security governance into operational processes
- Supporting internal and external audit activities
- Acting as a liaison during certification audits and coordinating corrective action processes
What we are looking for
We are looking for someone with:
- 4+ years of hands-on experience in information security, GRC, or a related field
- Direct exposure to ISO 27001 implementation or auditing
- Solid understanding of ISMS principles
- Knowledge of the ISO/IEC 27000 family
- Understanding of information security risk management frameworks
- Working knowledge of NIS2 requirements and their implications for operators of essential and important entities
- Interest or experience in industrial or critical infrastructure contexts
- Ability to translate regulatory and normative requirements into practical measures for technical and non-technical stakeholders
- Strong analytical, documentation, and stakeholder communication skills
- Structured, self-directed working style suited to a remote and consulting environment
- Fluent English
Bonus points if you have
- A bachelor’s degree in Information Security, Computer Science, Engineering, or a related field
- ISO 27001 Lead Implementer or Lead Auditor certification, or an equivalent qualification
- Experience working with clients in manufacturing, energy, utilities, critical infrastructure, or other industrial sectors
- Familiarity with adjacent frameworks and regulations such as IEC 62443, GDPR, or the EU Cyber Resilience Act
- Fluent German
What we offer
We are a young and growing startup working at the forefront of industrial cybersecurity. This is a role where you can take real responsibility, learn quickly, and contribute to meaningful projects from day one.
You will get:
- Rapid learning and growth: Work on meaningful client engagements across ISMS governance, regulatory compliance, and industrial security
- Close mentorship: Collaborate directly with founders who bring decades of cybersecurity expertise
- Career development: Build valuable experience in ISO 27001, NIS2, risk management, audits, and consulting work in a high-demand field
- Innovative environment: Be part of a team helping industrial companies prepare for today’s cybersecurity and regulatory challenges
- Flat hierarchy: Work in a collaborative environment where your ideas, ownership, and contribution matter
- Above-average compensation: We are looking for strong talent and offer compensation that reflects the value you bring
This role is a good fit if
You enjoy structure, documentation, standards, and practical implementation. You can turn complex regulatory and security requirements into clear actions for clients, and you are comfortable communicating with both technical teams and management stakeholders.