Cybersecurity Governance Risk and Compliance Consultant
⚲ Warszawa
Do uzgodnienia
Wymagania
- cybersecurity GRC
- Cyber risk management
- ServiceNow GRC / IRM
- Risk Register Management
- Vulnerability Management
- Incident management
- Cloud Risk
- Third-Party Risk Management (TPRM)
Opis stanowiska
About Company:
Team Connect is Poland’s leading nearshore and offshore IT provider. Since 2008 we successfully create and develop software for our clients. We specialize in Agile and DevOps-based software development. From the analysis stage through implementation. We develop backend, frontend, and mobile applications.
For one of our clients, we are looking for a Cybersecurity Governance Risk and Compliance Consultant.
Location & Delivery Mode: Warsaw, hybrid – 30% onsite / 70% remote.
Experience Required: At least 9 years post-education, incl. 8+ years in a similar role.
Required Certificates:
At least 4 certifications among (must have):
[1] CISA (ISACA Certified Information Systems Auditor)
[2] CISM (ISACA Certified Information Security Manager)
[3] CRISC (ISACA Certified in Risk and Information Systems Control)
[4] CISSP (ISC2 Certified Information Systems Security Professional)
[5] CGRC (ISC2 Certified in Governance, Risk and Compliance)
[6] CSSLP (ISC2 Certified Secure Software Lifecycle Professional)
[7] CCSP (ISC2 Certified Cloud Security Professional)
[8] CISSP-ISSMP (ISC2 Certified Information Systems Security Management Professional)
[9] GSNA (GIAC Certified Systems and Network Auditor)
[10] GCCC (GIAC Certified Critical Controls)
[11] GIAC Certified ISO-27000 Specialist
[12] ISO 27001 Lead implementer or equivalent.
[13] ISO 27001 Lead Auditor or equivalent.
[14] ISO 27005 Risk Manager or equivalent.
or for any listed above, an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority)
Knowledge & Skills:
Knowledge:
[01] Cybersecurity related laws, regulations and legislations
[02] Cybersecurity standards, methodologies and frameworks
[03] Cybersecurity policies
[04] Legal, regulatory and legislative compliance requirements, recommendations and best practices
[05] Privacy impact assessment standards, methodologies and frameworks
Skills:
[06] Comprehensive understanding of the business strategy, models and products and ability to factor into legal, regulatory and standards’ requirements
[07] Carry out working-life practices of the data protection and privacy issues involved in the implementation of the organisational processes, finance and business strategy
[08] Lead the development of appropriate cybersecurity and privacy policies and procedures that complement the business needs and legal requirements; further ensure its acceptance, comprehension and implementation and communicate it between the involved parties
[09] Conduct, monitor and review privacy impact assessments using standards, frameworks, acknowledged methodologies and tools
[10] Explain and communicate data protection and privacy topics to stakeholders and users
[11] Understand, practice and adhere to ethical requirements and standards
[12] Understand legal framework modifications implications to the organisation’s cybersecurity and data protection strategy and policies
[13] Collaborate with other team members and colleagues
Specific Requirements:
[01] minimum 5+ years of experience in cybersecurity GRC, with clear focus on cybersecurity risk management
[02] Proven experience in designing or operatiationalising a cyber risk management framework
[03] Hands-on experience in using ServiceNow GRC (IRM / Risk / Policy and Compliance modules)
[04] Demonstrated experience maintaining and managing a cybersecurity risk register.
[05] Experience integrating risk management with: Vulnerability management, Incident management, Cloud risk, Third-party risk
[05] Experience contributing to cybersecurity maturity improvement programmes.
11. Typical Tasks & Responsibilities:
- Ensure compliance with and provide legal advice and guidance on data privacy and data protection standards, laws and regulations
- Identify and document compliance gaps
- Conduct privacy impact assessments and develop, maintain, communicate and train upon the privacy policies, procedures
- Enforce and advocate organisation’s data privacy and protection program
- Ensure that data owners, holders, controllers, processors, subjects, internal or external partners and entities are informed about their data protection rights, obligations and responsibilities
- Act as a key contact point to handle queries and complaints regarding data processing
- Assist in designing, implementing, auditing and compliance testing activities in order to ensure cybersecurity and privacy compliance
- Monitor audits and data protection related training activities
- Cooperate and share information with authorities and professional groups
- Contribute to the development of the organisation’s cybersecurity strategy, policy and procedures
- Develop and propose staff awareness training to achieve compliance and foster a culture of data protection within the organization
- Manage legal aspects of information security responsibilities and third-party relations"
Team Connect is Poland’s leading nearshore and offshore IT provider. Since 2008 we successfully create and develop software for our clients. We specialize in Agile and DevOps-based software development. From the analysis stage through implementation. We develop backend, frontend, and mobile applications.
For one of our clients, we are looking for a Cybersecurity Governance Risk and Compliance Consultant.
Location & Delivery Mode: Warsaw, hybrid – 30% onsite / 70% remote.
Experience Required: At least 9 years post-education, incl. 8+ years in a similar role.
Required Certificates:
At least 4 certifications among (must have):
[1] CISA (ISACA Certified Information Systems Auditor)
[2] CISM (ISACA Certified Information Security Manager)
[3] CRISC (ISACA Certified in Risk and Information Systems Control)
[4] CISSP (ISC2 Certified Information Systems Security Professional)
[5] CGRC (ISC2 Certified in Governance, Risk and Compliance)
[6] CSSLP (ISC2 Certified Secure Software Lifecycle Professional)
[7] CCSP (ISC2 Certified Cloud Security Professional)
[8] CISSP-ISSMP (ISC2 Certified Information Systems Security Management Professional)
[9] GSNA (GIAC Certified Systems and Network Auditor)
[10] GCCC (GIAC Certified Critical Controls)
[11] GIAC Certified ISO-27000 Specialist
[12] ISO 27001 Lead implementer or equivalent.
[13] ISO 27001 Lead Auditor or equivalent.
[14] ISO 27005 Risk Manager or equivalent.
or for any listed above, an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority)
Knowledge & Skills:
Knowledge:
[01] Cybersecurity related laws, regulations and legislations
[02] Cybersecurity standards, methodologies and frameworks
[03] Cybersecurity policies
[04] Legal, regulatory and legislative compliance requirements, recommendations and best practices
[05] Privacy impact assessment standards, methodologies and frameworks
Skills:
[06] Comprehensive understanding of the business strategy, models and products and ability to factor into legal, regulatory and standards’ requirements
[07] Carry out working-life practices of the data protection and privacy issues involved in the implementation of the organisational processes, finance and business strategy
[08] Lead the development of appropriate cybersecurity and privacy policies and procedures that complement the business needs and legal requirements; further ensure its acceptance, comprehension and implementation and communicate it between the involved parties
[09] Conduct, monitor and review privacy impact assessments using standards, frameworks, acknowledged methodologies and tools
[10] Explain and communicate data protection and privacy topics to stakeholders and users
[11] Understand, practice and adhere to ethical requirements and standards
[12] Understand legal framework modifications implications to the organisation’s cybersecurity and data protection strategy and policies
[13] Collaborate with other team members and colleagues
Specific Requirements:
[01] minimum 5+ years of experience in cybersecurity GRC, with clear focus on cybersecurity risk management
[02] Proven experience in designing or operatiationalising a cyber risk management framework
[03] Hands-on experience in using ServiceNow GRC (IRM / Risk / Policy and Compliance modules)
[04] Demonstrated experience maintaining and managing a cybersecurity risk register.
[05] Experience integrating risk management with: Vulnerability management, Incident management, Cloud risk, Third-party risk
[05] Experience contributing to cybersecurity maturity improvement programmes.
11. Typical Tasks & Responsibilities:
- Ensure compliance with and provide legal advice and guidance on data privacy and data protection standards, laws and regulations
- Identify and document compliance gaps
- Conduct privacy impact assessments and develop, maintain, communicate and train upon the privacy policies, procedures
- Enforce and advocate organisation’s data privacy and protection program
- Ensure that data owners, holders, controllers, processors, subjects, internal or external partners and entities are informed about their data protection rights, obligations and responsibilities
- Act as a key contact point to handle queries and complaints regarding data processing
- Assist in designing, implementing, auditing and compliance testing activities in order to ensure cybersecurity and privacy compliance
- Monitor audits and data protection related training activities
- Cooperate and share information with authorities and professional groups
- Contribute to the development of the organisation’s cybersecurity strategy, policy and procedures
- Develop and propose staff awareness training to achieve compliance and foster a culture of data protection within the organization
- Manage legal aspects of information security responsibilities and third-party relations"
🔍 Dekoder Ogłoszenia
🔴
Poland’s leading nearshore and offshore IT provider
Firma pozycjonuje się jako lider, ale nie podaje konkretnych danych ani skali działalności, co może sugerować, że jest to raczej aspiracja niż faktyczny dominujący status na rynku.
🔴
At least 4 certifications among (must have)
Wymóg posiadania aż 4 certyfikatów z długiej listy może być próbą odfiltrowania kandydatów, którzy nie poświęcili znaczącej ilości czasu i pieniędzy na rozwój w obszarze GRC.
🔴
or for any listed above, an equivalent alternative cert
Otwiera furtkę do negocjacji lub interpretacji, co może oznaczać, że firma jest elastyczna, ale też może prowadzić do sytuacji, gdzie 'równoważne' certyfikaty nie są w pełni akceptowane.
🔴
30% onsite / 70% remote
Chociaż podano konkretne proporcje, 30% pracy stacjonarnej w Warszawie może oznaczać częste dojazdy i konieczność dostosowania się do harmonogramu klienta, nawet jeśli większość pracy jest zdalna.