Cybersecurity Manager | EU Institutions Project
SEIDOR · Warsaw, Poland
You apply off-site, with the employer or the job board. I never handle applications.
#HumanizingTechnology
ABOUT SEIDOR
SEIDOR helps organizations transform and stay competitive through technology and innovation, always putting people first. With over 8,000 professionals in 45 countries, we are a diverse and inclusive global team committed to talent, equal opportunities, and sustainable growth.
Will you join us in humanizing technology?
We want you to be a part of our team as a Cybersecurity Risk Manager (CSRM), providing services on-site in Warsaw
.
WHAT WILL YOU DO IN YOUR DAY-TO-DAY?
-
Develop and maintain the organisation's cybersecurity risk management strategy.
-
Manage an inventory of the organisation's assets and support their risk categorisation.
-
Identify and assess cybersecurity-related threats and vulnerabilities affecting ICT systems.
-
Analyse the threat landscape, including attackers' profiles and the potential impact of attacks.
-
Perform cybersecurity risk assessments and propose appropriate risk treatment options, security controls, mitigation measures and avoidance strategies.
-
Monitor the effectiveness of cybersecurity controls and evolving risk levels.
-
Ensure cybersecurity risks remain at an acceptable level for the organisation's assets.
-
Develop, maintain, report and communicate the complete cybersecurity risk management cycle.
-
Enable asset owners, executives and other stakeholders to make risk-informed decisions.
-
Help employees understand, adopt and follow cybersecurity controls, supporting a risk-aware environment.
-
Minimum education level: Master's Degree.
-
Required certifications:
At least 4 certifications from the following list: CISA, CISM, CRISC, CISSP, CGRC, CSSLP, CCSP, CISSP-ISSMP, GSNA, GCCC, GIAC Certified ISO-27000 Specialist, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, ISO 27005 Risk Manager.
- Minimum 9 years of relevant IT professional experience.
- Minimum 6 years of experience in a similar position.
- Advanced knowledge of cybersecurity risk management frameworks, standards, methodologies, tools, guidelines and best practices.
- Experience performing risk assessments and analysis to identify threats, categorise assets and rate system vulnerabilities.
- Knowledge of cyber threats, threat taxonomies and vulnerability repositories.
- Knowledge of risk-sharing options and current technical and organisational controls used to mitigate cybersecurity risks.
- Knowledge of monitoring, implementing and testing the effectiveness of cybersecurity controls.
- Ability to analyse and consolidate organisational quality and risk-management practices.
- Ability to propose and manage risk-sharing options.
Specific experience required:
- Experience in Business Impact Assessments.
- Knowledge of risk assessment implementation in GRC ServiceNow.
- Experience preparing personal data protection documentation.
- Experience with graphical and programmatic threat-modelling tools.
- Experience in threat modelling for DevOps.
- Experience designing Zero Trust Architecture.
- Experience securing the Software Development Lifecycle (SDLC).
- Experience designing controls for defending Directory Services.