Caritas Schweiz
Adligenswilerstrasse 15
6002
Luzern
Workplace
Caritas Schweiz
CH-6002
Luzern
Switzerland
Doing the right thing. We are active in Switzerland and 20 countries on four continents. Join us with a commitment to help us bring about a more caring society, as
GRCS Engineer 40-70 % (m/w/d)
We are looking for a Governance, Risk, Compliance and Security (GRCS) Engineer to work within Service Family Teams and support the implementation of GRCS requirements in ICT & Digital Services The role acts as the operational link between the GRCS Office and the Service Families, translating strategic security and compliance guidelines into concrete, technical and procedural implementation. The role focuses on embedding cybersecurity, data protection, and compliance controls into day-to-day business activities, ensuring alignment with organisational risk appetite, internal policies, and regulatory requirements. Senior stakeholders are engaged mainly for escalation and governance decisions, not as daily counterparts.
Duty
- Work within Service Family Teams supporting functions such as HR, Fundraising, Programs, Finance, Research, and International Cooperation
- Translate and transfer GRCS Office guidelines and standards into specific, implementable requirements for the assigned Service Families
- Implement and monitor security controls and compliance measures within business processes
- Perform business risk assessments, protection needs analyses, DPIAs, and third-party risk and provider audits?
- Classify operational risks within defined thresholds and escalate where tolerance limits are exceeded
- Design and implement internal control systems (ICS) within the assigned Service Families
- Support Service e.g. Service, Project & Provider Manager, in ensuring “security by design” in service development and lifecycle management
- Provide operational support in analysing and resolving security incidents impacting the Service Families
- Prepare and compile documentation and evidence for internal and external audits
- Contribute structured input to GRCS reporting, risk dashboards, and compliance transparency
- Support cross-organisational initiatives from a GRCS implementation perspective
Requirement
- Cybersecurity Governance, Risk, Compliance & Security (GRCS)
- Risk assessments, protection needs analysis, DPIAs
- Control design and implementation (ICS)
- Understanding of Service DevOps and service lifecycle processes (ITIL, SIAM)
- Audit preparation and evidence management
- Clear documentation and structured communication
- Ability to work embedded in cross-functional service teams
Your Application