Security Engineer
Cybersecurity Risk Manager
Warsaw
Apply on the employer's siteRole description
About The Job
We are a large company with a start-up spirit. We organize ourselves into expert knowledge Units that collaborate with each other.
That's why we are looking for curious individuals who are motivated by challenges and eager to grow personally and professionally, to join our team and make a positive impact on the world through technology.
ARE YOU UP FOR THE CHALLENGE?
We want you to be a part of our team, from
Warsaw
, as a
Cybersecurity Risk Manager.
WHAT WILL YOU DO IN YOUR DAY-TO-DAY?
- Develop an organization’s cybersecurity risk management strategy
- Manage an inventory of organization’s assets
- Identify and assess cybersecurity-related threats and vulnerabilities of ICT systems
- Identification of threat landscape including attackers’ profiles and estimation of attacks’ potential
- Assess cybersecurity risks, and propose most appropriate risk treatment options, including security controls, and risk mitigation and avoidance that best address organizations’ strategy
- Monitor effectiveness of cybersecurity controls and risk levels
- Ensure that all cybersecurity risks remain at an acceptable level for the organization’s assets
- Develop, maintain, report and communicate complete risk management cycle
WHAT DO WE EXPECT FROM YOU?
The Consultant Must Demonstrate Experience In
- 10+ years of experience
- Certifications: At least four internationally recognized certifications—subject to Contracting Authority approval—from CISA, CISM, CRISC, CISSP, CGRC, CSSLP, CCSP, CISSP-ISSMP, GSNA, GCCC, GIAC ISO 27000, ISO 27001 Lead Implementer/Auditor, ISO 27005 Risk Manager, or equivalents.
- Cybersecurity risk management: Conduct risk and business-impact assessments; identify threats, assets, and vulnerabilities; and select, implement, test, and monitor appropriate controls.
- Governance and compliance: Apply cybersecurity frameworks, standards, methodologies, and regulatory requirements while consolidating organizational quality and risk practices.
- Risk culture and communication: Enable risk-informed executive decisions, promote employee compliance, build cybersecurity awareness, and communicate findings to stakeholders.
- Specialized expertise: ServiceNow GRC, data-protection documentation, graphical and programmatic threat modelling, and DevOps threat modelling.
- Security architecture: Design Zero Trust architectures, secure software-development lifecycles, and controls protecting directory services.
- Risk treatment: Assess, propose, and manage suitable risk-sharing and mitigation options.
Will you join us in humanizing technology?
This is a saved copy of a posting published elsewhere. Postings get taken down without notice — check the employer's site before applying. mentors.coach is not the hiring party.