Information Security Specialist
Job description
Location: Skopje
About the role
This role accelerates professional growth under mentorship and later transitions into a direct-report position.
Security professionals protect systems, data, and users. They review code, run tests, monitor threats, and respond to incidents. The field spans application security, infrastructure security, and governance. Security work is careful, evidence based, and constantly evolving. Security teams work in a landscape of constant change, with new threats and new rules every year. Most companies invest heavily in training and tooling for their teams.
Key facts
What you'll do
Security control monitoring operates through documented workflows to ensure consistent ISMS adherence.
AI inventory accuracy supports organization-wide compliance and risk visibility.
System impact assessments are facilitated and supported, with data collected for risk registers and remediation metrics tracked. Assessment outcomes guide control decisions and resource prioritization across the business.
Due diligence findings influence procurement decisions and ongoing vendor risk management.
Company-wide annual security and AI acceptable-use training is updated, delivered, and completion tracked. Training records demonstrate organizational compliance and client assurance on security behaviors.
Documentation quality enables consistent audits and clear process execution across teams.
Communications reduce repeated inquiries and strengthen security culture across the organization.
Collaboration enables execution and tracking of technical security measures aligned with business priorities.
Incident documentation and timely resolution limit business impact and support post-incident reviews.
Accurate responses protect business opportunities and maintain client confidence in security practices.
Business units are engaged practically to learn day-to-day operations and apply ISO frameworks. Practical insights help tailor security support to real workflows and emerging risks.
Software vendors are managed during procurement, with security stances verified and evidence packages organized. Evidence readiness streamlines audits and client due diligence reviews.
Executive reporting clarifies posture and directs focus toward high-value remediation.
Automation allows the lean security team to operate more efficiently and consistently.
Requirements
1-3 years of experience in information security compliance, governance, auditing, or a related assurance role is required. Relevant professional experience demonstrates applied security judgment in operational contexts.
Understanding of IT environments or technology concepts is beneficial but not required. Foundational IT knowledge supports effective coordination with technical teams.
Basic theoretical or working knowledge of Information Security principles (ISO 27001, SOC 2, or CIS controls) is required. Framework knowledge guides control selection and measurement.
Organizational, documentation, and stakeholder communication skills must be excellent. Clear outreach to engineering and product teams gathers accurate asset information.
A growth mindset and high coachability are required for deep learning in AI security compliance (ISO 42001). Coachability accelerates adaptation to evolving standards and tools.
Practical notes
The role is hybrid, based in Croatia or North Macedonia. Work is conducted onsite, remotely, and in shared offices according to team needs.
Travel may be required within regions to support clients and business units. Time zones and local regulations influence assignment specifics.
Team collaboration occurs across global security, systems, product, and IT functions. Coordination aligns security initiatives with enterprise objectives.
Typical interview steps
Security interviews usually include a technical assessment, a threat modeling exercise, and behavioral rounds. Candidates may be asked to review a code sample for vulnerabilities or design a secure system. Practical knowledge and clear risk communication are the core skills. Interviewers often ask how you triage and communicate risk. Showing calm judgment under pressure matters as much as technical depth.
Career growth
Security careers grow from analyst or engineer to senior, staff, and leadership roles. Specializations include cloud security, application security, and security operations. Certifications help early; demonstrated impact matters later. Security careers reward specialization and a track record of finding and fixing real issues. Written communication of risk is a core skill at senior levels.