Senior Cybersecurity GRC Consultant
⚲ Warszawa
10 008 - 10 668 EUR netto (B2B) | 9 261 - 9 933 EUR brutto (UoP)
Wymagania
- GRC
- Compliance
- Risk Management
- CISA
- ISO 27001
Opis stanowiska
At Ayesa Digital, we grow with you!
Every professional in our company is vital to us. Thanks to their talent, we continue to expand; today, we are a global team of over 11,000 people working toward a common goal.
Ayesa Digital is currently participating in high-impact European Union projects designed to address major European challenges and drive science and innovation. These are strategic technological projects based on collaborative initiatives that stand out for their international focus and a strong commitment to socially oriented results.
If you are an enthusiastic professional looking for a new career challenge, this is your place. We are looking to incorporate a Senior Cybersecurity GRC Consultant. Leap — we are waiting for you!
What You Will Do (Responsibilities):
• Lead and support cybersecurity governance, risk, compliance, privacy, and data protection initiatives across the organization.
• Ensure compliance with cybersecurity, data protection, privacy, and regulatory requirements, providing expert guidance on applicable laws, regulations, and industry standards.
• Identify, assess, document, and monitor cybersecurity and compliance risks, maintaining an accurate and up-to-date cybersecurity risk register.
• Design, implement, maintain, and continuously improve cybersecurity risk management frameworks, processes, and controls.
• Conduct and oversee privacy impact assessments, compliance reviews, and risk assessments using recognized methodologies, standards, and frameworks.
• Develop, maintain, communicate, and promote cybersecurity, privacy, and data protection policies, procedures, and governance frameworks.
• Collaborate with business stakeholders, technology teams, and third parties to ensure cybersecurity and privacy requirements are effectively integrated into organizational processes.
• Manage and utilize ServiceNow GRC (IRM, Risk, Policy & Compliance modules) to support governance, risk, and compliance activities.
• Integrate cybersecurity risk management practices with vulnerability management, incident management, cloud risk management, and third-party risk management programmes.
• Support audits, compliance assessments, control testing activities, and remediation initiatives.
• Deliver awareness, training, and communication activities to promote a strong cybersecurity and data protection culture.
• Act as a key point of contact for cybersecurity governance, compliance, risk, and privacy-related matters.
• Contribute to cybersecurity maturity improvement programmes and the ongoing development of the organization's cybersecurity strategy.
What We Are Looking For (Requirements):
• Master's degree (Level 7) or equivalent qualification in Cybersecurity, Information Security, Information Technology, Law, Risk Management, or a related discipline.
• Minimum 9 years of relevant professional experience within cybersecurity, information security, governance, risk, compliance, or privacy domains.
• Minimum 8 years of experience in a similar Cybersecurity GRC, Risk Management, Compliance, or Information Security Governance role.
• English proficiency at C1 level or higher.
Certifications
Candidates must hold at least four of the following internationally recognized certifications (or accepted equivalents):
• CISA (Certified Information Systems Auditor)
• CISM (Certified Information Security Manager)
• CRISC (Certified in Risk and Information Systems Control)
• CISSP (Certified Information Systems Security Professional)
• CGRC (Certified in Governance, Risk and Compliance)
• CSSLP (Certified Secure Software Lifecycle Professional)
• CCSP (Certified Cloud Security Professional)
• CISSP-ISSMP
• GSNA (GIAC Systems and Network Auditor)
• GCCC (GIAC Critical Controls Certification)
• GIAC Certified ISO-27000 Specialist
• ISO 27001 Lead Implementer
• ISO 27001 Lead Auditor
• ISO 27005 Risk Manager
Technical Expertise
• Strong knowledge of cybersecurity laws, regulations, and legislative requirements.
• Deep understanding of cybersecurity standards, frameworks, methodologies, and best practices.
• Knowledge of cybersecurity governance, risk management, and compliance principles.
• Understanding of privacy impact assessment frameworks, methodologies, and regulatory obligations.
• Proven experience in cybersecurity GRC environments, with a strong focus on cybersecurity risk management.
• Demonstrated experience designing, implementing, or operationalising cyber risk management frameworks.
• Hands-on experience with ServiceNow GRC (IRM, Risk, Policy & Compliance modules).
• Experience maintaining and managing cybersecurity risk registers.
• Strong understanding of integrating risk management processes with vulnerability management, incident management, cloud risk, and third-party risk programmes.
• Experience contributing to cybersecurity maturity assessments and improvement initiatives.
What We Offer:
• Prestigious projects within European institutions.
• International, innovative, and multicultural environments.
• Continuous support from a team of experts in EU projects.
• 💰 Rate: 476,55€ - 508€ per day
If you are ambitious, enthusiastic, and seeking a new professional challenge in international projects with real-world impact, this is the place for you!
In accordance with Organic Law 3/2007 of March 22, the company is committed to promoting the defense and effective application of the principle of equality between men and women, preventing any type of labor discrimination based on sex, and guaranteeing equal entry opportunities. Furthermore, we promote diversity and reject any discrimination based on race, gender, functional diversity, religion, sexual orientation, gender identity, or any other personal or social condition, striving to build an inclusive and enriching environment.
Every professional in our company is vital to us. Thanks to their talent, we continue to expand; today, we are a global team of over 11,000 people working toward a common goal.
Ayesa Digital is currently participating in high-impact European Union projects designed to address major European challenges and drive science and innovation. These are strategic technological projects based on collaborative initiatives that stand out for their international focus and a strong commitment to socially oriented results.
If you are an enthusiastic professional looking for a new career challenge, this is your place. We are looking to incorporate a Senior Cybersecurity GRC Consultant. Leap — we are waiting for you!
What You Will Do (Responsibilities):
• Lead and support cybersecurity governance, risk, compliance, privacy, and data protection initiatives across the organization.
• Ensure compliance with cybersecurity, data protection, privacy, and regulatory requirements, providing expert guidance on applicable laws, regulations, and industry standards.
• Identify, assess, document, and monitor cybersecurity and compliance risks, maintaining an accurate and up-to-date cybersecurity risk register.
• Design, implement, maintain, and continuously improve cybersecurity risk management frameworks, processes, and controls.
• Conduct and oversee privacy impact assessments, compliance reviews, and risk assessments using recognized methodologies, standards, and frameworks.
• Develop, maintain, communicate, and promote cybersecurity, privacy, and data protection policies, procedures, and governance frameworks.
• Collaborate with business stakeholders, technology teams, and third parties to ensure cybersecurity and privacy requirements are effectively integrated into organizational processes.
• Manage and utilize ServiceNow GRC (IRM, Risk, Policy & Compliance modules) to support governance, risk, and compliance activities.
• Integrate cybersecurity risk management practices with vulnerability management, incident management, cloud risk management, and third-party risk management programmes.
• Support audits, compliance assessments, control testing activities, and remediation initiatives.
• Deliver awareness, training, and communication activities to promote a strong cybersecurity and data protection culture.
• Act as a key point of contact for cybersecurity governance, compliance, risk, and privacy-related matters.
• Contribute to cybersecurity maturity improvement programmes and the ongoing development of the organization's cybersecurity strategy.
What We Are Looking For (Requirements):
• Master's degree (Level 7) or equivalent qualification in Cybersecurity, Information Security, Information Technology, Law, Risk Management, or a related discipline.
• Minimum 9 years of relevant professional experience within cybersecurity, information security, governance, risk, compliance, or privacy domains.
• Minimum 8 years of experience in a similar Cybersecurity GRC, Risk Management, Compliance, or Information Security Governance role.
• English proficiency at C1 level or higher.
Certifications
Candidates must hold at least four of the following internationally recognized certifications (or accepted equivalents):
• CISA (Certified Information Systems Auditor)
• CISM (Certified Information Security Manager)
• CRISC (Certified in Risk and Information Systems Control)
• CISSP (Certified Information Systems Security Professional)
• CGRC (Certified in Governance, Risk and Compliance)
• CSSLP (Certified Secure Software Lifecycle Professional)
• CCSP (Certified Cloud Security Professional)
• CISSP-ISSMP
• GSNA (GIAC Systems and Network Auditor)
• GCCC (GIAC Critical Controls Certification)
• GIAC Certified ISO-27000 Specialist
• ISO 27001 Lead Implementer
• ISO 27001 Lead Auditor
• ISO 27005 Risk Manager
Technical Expertise
• Strong knowledge of cybersecurity laws, regulations, and legislative requirements.
• Deep understanding of cybersecurity standards, frameworks, methodologies, and best practices.
• Knowledge of cybersecurity governance, risk management, and compliance principles.
• Understanding of privacy impact assessment frameworks, methodologies, and regulatory obligations.
• Proven experience in cybersecurity GRC environments, with a strong focus on cybersecurity risk management.
• Demonstrated experience designing, implementing, or operationalising cyber risk management frameworks.
• Hands-on experience with ServiceNow GRC (IRM, Risk, Policy & Compliance modules).
• Experience maintaining and managing cybersecurity risk registers.
• Strong understanding of integrating risk management processes with vulnerability management, incident management, cloud risk, and third-party risk programmes.
• Experience contributing to cybersecurity maturity assessments and improvement initiatives.
What We Offer:
• Prestigious projects within European institutions.
• International, innovative, and multicultural environments.
• Continuous support from a team of experts in EU projects.
• 💰 Rate: 476,55€ - 508€ per day
If you are ambitious, enthusiastic, and seeking a new professional challenge in international projects with real-world impact, this is the place for you!
In accordance with Organic Law 3/2007 of March 22, the company is committed to promoting the defense and effective application of the principle of equality between men and women, preventing any type of labor discrimination based on sex, and guaranteeing equal entry opportunities. Furthermore, we promote diversity and reject any discrimination based on race, gender, functional diversity, religion, sexual orientation, gender identity, or any other personal or social condition, striving to build an inclusive and enriching environment.
🔍 Dekoder Ogłoszenia
🟡
At Ayesa Digital, we grow with you!
Firma podkreśla rozwój zawodowy pracowników, co może oznaczać możliwości awansu lub szkoleń, ale też presję na ciągłe podnoszenie kwalifikacji.
🟡
Every professional in our company is vital to us.
Chociaż brzmi to miło, może sugerować, że oczekuje się od każdego pracownika dużej samodzielności i odpowiedzialności za swoje zadania.
🔴
high-impact European Union projects
Projekty unijne często charakteryzują się dużą biurokracją, długimi cyklami realizacji i specyficznymi wymaganiami formalnymi.
🟡
a strong commitment to socially oriented results
Może to oznaczać, że projekty mają na celu rozwiązywanie problemów społecznych, co może wiązać się z dodatkowymi wymaganiami poza technicznymi.
🟡
Leap — we are waiting for you!
Zachęta do szybkiego aplikowania, która może sugerować pilną potrzebę obsadzenia stanowiska.