In this role, you will
- Own and coordinate the company’s information security programme, priorities, and improvement roadmap
- Maintain and develop security governance, policies, procedures, risk registers, and incident response documentation
- Assess security risks, identify control gaps, and translate findings into practical, prioritised actions
- Work with security tools and platforms such as XDR/EDR, SIEM, vulnerability management, MDM, and security awareness platforms
- Coordinate security improvements with IT, legal, and external partners
- Support ISO 27001, NIS2, audits, regulatory requirements, and third-party or supplier risk management activities
- Evaluate security vendors and services, monitor their effectiveness, and coordinate specialised security activities when external expertise is required
- Investigate security alerts and coordinate an effective response to security incidents
- Communicate security risks, priorities, and decisions clearly to technical and non-technical stakeholders
What you will bring
- At least 4 years of experience in information security, cybersecurity, or a similar technical field
- Practical experience managing information security activities in a business environment
- Strong understanding of security governance, risk management, compliance, and common security controls
- Experience with ISO 27001 or a similar security framework, together with familiarity with NIS2 requirements
- Familiarity with threat frameworks such as MITRE ATT&CK and modern detection and response methodologies
- Hands-on experience across several security areas, such as endpoint security, vulnerability management, or incident response
- Ability to work with security platforms at an operational level, including reviewing alerts, assessing coverage, identifying gaps, and coordinating improvements
- Experience creating or maintaining security policies, procedures, risk registers, and incident response documentation
- Ability to investigate security alerts and coordinate incident response activities
- Strong understanding of common cyber threats, attack methods, and security controls
- Ability to assess risks, set priorities, and create structure in environments where processes are still developing
- Experience working with security vendors, auditors, consultants, or managed service providers
- Ability to communicate security risks clearly to both technical and non-technical stakeholders
- Strong ownership, independence, and a structured approach to work
- Fluency in both Lithuanian and English languages, written and spoken
Nice to have:
- Relevant certifications such as CISSP, CISM, Security+, CCSP, ISO 27001 Lead Implementer, or similar
- Experience with endpoint security, vulnerability management, or security awareness tools
- Experience with phishing simulations, secure software development, application security, or third-party risk management
- Experience in a technology, SaaS, software development, fintech, or regulated environment
What we offer
- A working culture that is high performing, ambitious, collaborative and fun
- Health insurance
- Flexible working hours
- Bonus for referrals
- Employee-led workshops and office perks
- Extra vacation days: 2 after working at NFQ for two years and 4 after four years on our team
- Unlimited WFH (work from home) policy
- For those who dream of traveling: WFA (work from anywhere) possibilities in NFQ - approved countries