SECURITY SPECIALIST

Date: Jul 21, 2026

Location: Prague, CZ

Company: asahiceeur

Junior Security Specialist

 

About Asahi

Asahi Europe & International is part of Asahi Group Holdings, a global beer, spirits, soft drinks and food group with leading positions in European and Asia-Pacific markets, listed on the Tokyo Stock Exchange, Japan.

Asahi Europe & International runs 19 production facilities across 8 countries in Europe and is the custodian of some of the best beer brands in the world, including Asahi Super Dry, Pilsner Urquell, Peroni Nastro Azzurro, Grolsch and Kozel.

Within the Asahi Group, Asahi Europe & International is also responsible for developing and managing export markets globally, outside of Asia and Oceania. Covering 80+ markets and with over 10,000 passionate colleagues, we are well positioned to inspire people around the world to drink better.

 

Position Overview & Purpose

The Junior Security Specialist will support Asahi Europe & International’s information security programme by contributing to day-to-day security operations across vulnerability management, IT general controls compliance reporting, cybersecurity risk management and incident support.

This role is ideal for a detail-oriented and analytically minded professional who is eager to grow within a structured cybersecurity environment. You will work closely with the Technical Security Lead and wider #digital teams to help strengthen the organisation’s security posture, improve visibility of risks and vulnerabilities, and support audit readiness across key IT controls.

 

What you will deliver

  • Perform regular vulnerability scans across servers, endpoints and network infrastructure using tools such as Tenable Nessus, Microsoft Defender for Endpoint or equivalent platforms.
  • Analyse vulnerability scan results and help prioritise remediation based on CVSS scores, exploitability and business impact.
  • Prepare clear and actionable remediation reports for technical teams and system owners.
  • Coordinate with #digital operations and system owners to track patching activities and ensure timely remediation in line with agreed SLA targets.
  • Maintain the vulnerability management platform, monitor remediation progress and escalate overdue items to the Technical Security Lead.
  • Validate that applied patches have effectively resolved identified vulnerabilities through re-scanning and evidence collection.
  • Contribute to the continuous improvement of patch management policies and procedures.
  • Support the preparation and delivery of General IT Controls evidence packs for internal and external audits, including J-SOX, NIST or equivalent frameworks.
  • Collect and review control evidence from system owners related to identity and access management, change management, backup and recovery, and security monitoring.
  • Maintain accurate and up-to-date records in the GRC platform to support audit readiness throughout the year.
  • Assist in coordinating responses to auditor requests, ensuring completeness, accuracy and timely delivery of submitted documentation.
  • Identify control gaps or deficiencies, document findings and track remediation actions through to closure.
  • Prepare periodic compliance status dashboards and metrics reports for the Technical Security Lead, CISO and relevant stakeholders.
  • Collaborate with the Internal Controls team to ensure that #digital operates in line with current internal control documentation standards.
  • Support cybersecurity risk assessments for business units, systems and third-party vendors in line with the organisation’s risk management framework.
  • Maintain and update the cybersecurity risk register, ensuring risk ratings, owners and treatment plans are current and accurately documented.
  • Support the development and review of risk treatment plans, including risk acceptance, mitigation, transfer and avoidance decisions.
  • Monitor the external threat landscape and share relevant threat intelligence updates with the team.
  • Contribute to the annual security risk assessment cycle, including asset inventory reviews, threat modelling sessions and control effectiveness evaluations.
  • Prepare risk summary reports and presentations to support decision-making by senior security and business stakeholders.
  • Support the investigation of security breaches in the areas of access management and cybersecurity, including cooperation on disciplinary or legal matters where required within the region’s #digital areas of responsibility.

 

Experience & Qualification Requirements

We are looking for an early-career cybersecurity professional with strong attention to detail, analytical thinking and a motivation to build expertise in a corporate security environment.

 

You will ideally bring:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, a related field, or equivalent professional experience.
  • 0–2 years of professional experience in cybersecurity, IT audit, IT risk or a related area.
  • Hands-on experience or academic exposure to vulnerability scanning tools such as Tenable, Microsoft Defender for Endpoint or equivalent platforms.
  • Basic understanding of vulnerability scanning, vulnerability analysis and the patch management lifecycle.
  • Familiarity with ITGC frameworks such as SOX, SOC 2 or ISO 27001.
  • Understanding of cybersecurity risk assessment methodologies.
  • Basic knowledge of security tools and SIEM concepts.
  • Familiarity with GRC platforms such as ServiceNow GRC, Archer or OneTrust would be an advantage.
  • Strong written and verbal communication skills.
  • Analytical and critical thinking skills.
  • High attention to detail and thoroughness.
  • Ability to manage multiple priorities and follow up on actions through to completion.
  • Collaborative mindset and ability to work with cross-functional teams.
  • High level of integrity and professional discretion.
  • Good working knowledge of MS Office, especially Excel for reporting and data analysis.

 

Relevant certifications would be an advantage, but are not required. These may include:

  • CompTIA Security+
  • CompTIA CySA+
  • CRISC Associate level
  • ISO 27001 Foundation or Lead Implementer
  • Systems Security Certified Practitioner, SSCP

 

The role is based in a standard office environment with hybrid or remote work options available, subject to organisational policy. Occasional support outside of normal business hours may be required in response to security incidents.

 

You will interact with a wide range of internal and external stakeholders, including business stakeholders and end users, AEI IS functional teams, ServiceDesk, HR, internal audit, legal, security and access management vendors, infrastructure, application, Basis and project teams.

 

 

 

We are committed to nurturing a workplace where we celebrate and respect difference, and support everyone to be true to who they are! At Asahi Europe and International we believe you can SHINE AS YOU ARE - no matter your age, gender, ethnicity, sexual orientation, disabilities, religion, or beliefs. We want to support you to be courageous in your individuality and to know that whoever you are and whatever your circumstances, you can belong with us without having to conform.