About this role
Work tasks: About the Role We are looking for a Cybersecurity Advisor to join our Security Consulting team in Estonia. In this role, you will help clients strengthen their information security and cybersecurity capabilities by advising on governance, risk management, compliance, and security improvement initiatives. You will work closely with key stakeholders to develop practical security solutions aligned with business objectives and regulatory requirements. Responsibilities Advise clients on information security and cybersecurity topics Develop and improve Information Security Management Systems (ISMS) Support implementation of frameworks such as ISO/IEC 27001, E-ITS, CIS Controls, and NIST CSF Prepare policies, procedures, risk assessments, and management reports Conduct security maturity assessments and audits Support clients in audit preparation and compliance activities Deliver security awareness training and workshops Assist with client engagements, project scoping, and service presentations Contribute to service development and knowledge sharing Who Are We Looking For? We are looking for someone with a proactive mindset, strong communication skills, and a genuine interest in cybersecurity. You can confidently engage with both technical and business stakeholders, understand risk management principles, and translate technical risks into business-relevant recommendations. You have a solid understanding of IT infrastructure, networks, cloud technologies, and modern security practices. Requirements Experience in information security, cybersecurity, risk management, or a related field Knowledge of frameworks such as ISO/IEC 27001, E-ITS, CIS Controls, NIST CSF, or similar Experience creating security documentation, policies, and procedures Experience conducting risk assessments and recommending security controls Strong stakeholder management and communication skills Project coordination or project management experience Excellent Estonian and English, both written and spoken This role requires residence in Estonia and occasional on-site work with clients. Nice to Have Experience in security consulting, information security management, or similar roles Knowledge of information security and data protection regulations Experience with audits, maturity assessments, and gap analyses Experience with third-party risk management Relevant certifications such as CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Implementer/Auditor A degree in cybersecurity, information technology, or a related field What We Offer Flexible and hybrid working arrangements Training, mentorship, and professional development opportunities The opportunity to learn from cybersecurity experts across the NEVERHACK Group A diverse range of clients and projects Participation in strategic cybersecurity and digital transformation initiatives A modern office, additional paid vacation days, and a choice between sports compensation or private health insurance We offer: What do we offer? - Flexible work arrangements and hybrid work options - Training, mentoring, and support for professional development - Opportunities to learn from experienced cybersecurity specialists in Estonia and across the NEVERHACK Group - A diverse client portfolio and projects spanning various industries - Participation in strategic cybersecurity projects and digital transformation initiatives - The chance to take responsibility and shape a more secure future for clients - A modern, well-equipped office with free snacks and drinks - 5 additional paid vacation days after the first year of employment - A choice between a sports allowance and health insurance - A healthy balance between client work, learning, and personal life Other requirements: - Strong communication skills and the ability to manage relationships with various stakeholders - Analytical thinking, problem-solving skills, and attention to detail Option to work from home: No