Pracuj.pl Stacjonarnie Senior

Security Engineer (ISO 27001)

Creativestyle Polska Sp. z o.o.

⚲ Kraków, Podgórze

20 000–28 000 zł brutto / mies.

Opis stanowiska

Nasze wymagania:
YOU'RE OUR KIND OF PERSON IF YOU...
have 5+ years of experience in IT security, including hands-on experience with ISO 27001 ISMS (whether implementing it from scratch or helping maintain a certified security management system)
are comfortable owning risk management end-to-end: analysing risks, maintaining the Risk Register and planning effective mitigation actions
have hands-on experience in areas such as MDM, EDR, Linux hardening, GitLab/CI-CD security, AWS security fundamentals, and centralised logging
are familiar with GDPR in the context of information security (including Art. 28, 32, 33 and DPIA from an operational, not legal, perspective)
understand web application security (OWASP Top 10, secure SDLC practices) well enough to collaborate with technology teams and help shape secure development standards
thrive in an autonomous role, feel comfortable making security decisions and take full ownership of the results
are fluent in Polish and English and feel comfortable

Mile widziane:
BONUS POINTS IF YOU:
hold certifications such as ISO 27001 Lead Implementer / Lead Auditor (highly preferred), CISSP, CISM or CRISC
have experience working in a software house or agency environment, supporting multiple clients in a contract-based model and sharing ownership of successful outcomes
are familiar with the e-commerce world (Magento / Shopware) and have a basic understanding of PCI-DSS from a service provider perspective
have knowledge of NIS2, DORA or the AI Act, speak German, or have experience with customer security audits
have completed at least one full ISO 27001 implementation cycle, from initial setup to certification

O projekcie:
We're looking for a Security Engineer who likes having an impact and enjoys taking responsibility 🦸🏻‍♂️ 🦸🏻‍♀️
If implementing ISMS/GRC, building security processes and taking care of technical security is your thing, you'll have the chance to own this area, shape its future and leave your mark on it. We're counting on your expertise, hands-on mindset and best practices to help us build a strong and mature security function together.
Because this role also covers physical security and on-site work, we'd love to work with someone based in Kraków in a hybrid model. Working remotely from anywhere in Poland is also possible, as long as you're happy to visit the office regularly.
We believe great teams are built on diversity and inclusion. That's why we're creating a workplace where everyone feels welcome and can be their authentic selves. We encourage applications from all people, regardless of gender, age, background, sexual orientation, religion, or disability.

Zakres obowiązków:
ISMS OPERATIONS (~60%)
Own and operate the risk management process: risk workshops, Risk Register and Risk Treatment Plan maintenance, Statement of Applicability (SoA) preparation
Write, maintain and review security policies and procedures in collaboration with process owners across the organisation
Collect and organise audit evidence; execute recurring activities from the ISMS Operational Calendar
Lead preparation for the certification audit; support internal, external and customer audits
Own customer security questionnaires and supplier security reviews
Run the security awareness programme in collaboration with HR
Own the security roadmap; shape the security function over time (priorities, budget input, future hires)
TECHNICAL IMPLEMENTATION (~40%)
MDM/EDR rollout and administration (macOS ABM, configuration baselines, full-disk encryption), in collaboration with the Internal IT team
Hardening and monitoring of self-hosted GitLab; centralised logging and monitoring; vulnerability management
Incident response: build the procedure, coordinate incident handling, conduct post-mortems
Support secure SDLC (SAST/SCA in CI/CD, secrets management), working alongside our technology teams
Physical security of the offices (access control, monitoring), in collaboration with Office Crew

Oferujemy:
If this job makes you excited and you see yourself and your skillset in it, we should definitely meet and talk (including salary ranges 🙂). For an employment contract (UoP), the salary range is PLN 20 000 - 27 000 gross. Your final salary will be shaped by your skills, experience, engagement and collaboration quality. The role comes with wide privileged access, security decision-making responsibilities and close collaboration across the organization - meaning that UoP contract provides the most transparent and stable framework for both sides.
If you prefer B2B cooperation model, we’re happy to discuss it together. Due to the nature of the role, terms are agreed individually. Please indicate this in the application form and we’ll get back to you in the next step to align on the details.
People & atmosphere. Technically not a benefit, but always the first answer when someone talks about creativestyle - so we keep it
Home office. No stress! The world keeps spinning even if you stay home sometimes
PLN 3 000 annual training budget (for whatever boosts your skills) + language courses. Your growth = our growth
MacBook Pro, all the tools you need and a big monitor on top
Medicover + Multisport Plus. Rybnik office: gym in K1 building (no excuses, just the elevator!), Kraków: 4' away... on foot
Office life: game consoles, a billiards/ping-pong league, and a themed lunch every month
An old mill in Zabłocie turned loft office. Spacious, comfortable, stylish and a rooftop as a bonus
Great access. By bike, horse, fast tram or train (Kraków Zabłocie station). HR crew might just show up on a broomstick
CS gear corner. Need speakers or a podcast studio? Just take it. “Company” doesn’t mean “not for you”
Even more good stuff

🔍 Dekoder Ogłoszenia

🟡
JESTEŚ NASZYM CZŁOWIEKIEM, JEŚLI:
To próba stworzenia luźnej atmosfery, ale w praktyce oznacza to listę twardych wymagań, które kandydat musi spełnić.
🔴
Masz na swoim koncie 5+ lat w security IT, w tym 2+ lata z ISO 27001 ISMS (wdrożenie lub utrzymanie certyfikacji)
Wymagane jest konkretne doświadczenie z ISO 27001, co może być trudne do znalezienia i może oznaczać, że firma dopiero zaczyna wdrażać lub utrzymywać ten standard.
🔴
Możesz się pochwalić sporym doświadczeniem w pracy z ryzykiem: od analizy, przez prowadzenie rejestru, aż po planowanie działań ograniczających ryzyka
Oczekuje się kompleksowego podejścia do zarządzania ryzykiem, co może oznaczać dużą odpowiedzialność i potrzebę samodzielnego tworzenia procesów.
🟡
Twoim atutem jest znajomość RODO w kontekście bezpieczeństwa informacji (art. 28, 32, 33 oraz DPIA w podejściu operacyjnym, a nie prawnym)
Firma szuka kogoś, kto potrafi zastosować przepisy RODO w praktyce bezpieczeństwa IT, a nie tylko zna ich treść, co wymaga głębszego zrozumienia niż tylko teoretyczna wiedza.
🔴
Cechuje Cię wysoka autonomia - swoboda w podejmowaniu decyzji dotyczących bezpieczeństwa i gotowość do brania za nie pełnej odpowiedzialności
Oznacza to, że będziesz musiał samodzielnie podejmować kluczowe decyzje dotyczące bezpieczeństwa i ponosić za nie pełną odpowiedzialność, co może być obciążające.