Cybersecurity Risk Manager (m/f)
ARCHE consulting · Remote, Poland
No Polish requiredPosted 12 days ago
Apply for this job
You apply off-site, with the employer or the job board. I never handle applications.
Lokalizacja - Polska cała Polska / praca zdalna - Kategoria Cyber Security Engineer Języki angielski About the employer
Our client is a global IT services and consulting company specializing in digital transformation, cloud, cybersecurity, and managed services for enterprise clients.
Responsibilities
- Developing and maintaining the organisation’s cybersecurity risk management strategy,
- maintaining and overseeing the inventory of organisational assets,
- identifying vulnerabilities, threats, and weaknesses affecting ICT systems,
- analysing the threat landscape, including attacker profiling and assessment of potential attack scenarios,
- conducting cybersecurity risk assessments and recommending appropriate mitigation measures,
- defining, implementing, and monitoring technical and organisational security controls,
- supporting business owners and management in making risk-informed decisions,
- monitoring the effectiveness of implemented security controls and overall risk exposure,
- reporting risk management outcomes to relevant stakeholders,
- overseeing the complete cybersecurity risk management lifecycle,
- ensuring that cybersecurity risks remain within the organisation’s acceptable risk tolerance levels,
- promoting a risk-aware and security-conscious culture across the organisation.
Requirements
- Minimum 9 years of professional experience in the IT domain,
- minimum 6 years of experience in cybersecurity, risk management, or GRC-related roles,
- higher education qualification corresponding to at least EQF Level 7,
- English language proficiency at minimum C1 level,
- possession of at least 4 cybersecurity, risk management, or compliance certifications required by the Contracting Authority,
- experience in conducting Business Impact Assessments (BIA),
- practical knowledge of risk assessment implementation within ServiceNow GRC,
- experience in preparing personal data protection and privacy-related documentation,
- ability to use graphical and technical threat modelling tools,
- experience in threat modelling for DevOps and DevSecOps environments,
- knowledge and practical understanding of Zero Trust Architecture principles,
- experience in implementing Secure Software Development Lifecycle (SSDLC) practices,
- experience in designing security controls for directory services.
What we offer
- B2B contract,
- long-term cooperation,
- remote work model.