Cybersecurity: Governance, Risk and Compliance Specialist

Innergo

Gdynia

Hybrid

PLN 180,000 - 300,000

Full time

12 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Co-financing for private medical care
Life insurance
Sports card

Job summary

Innergo is seeking a Cybersecurity: Governance, Risk and Compliance Specialist to oversee IT controls, risk, and compliance. The role involves coordinating global IT control assessments, supporting SOX and GDPR initiatives, and working with IT and Legal teams to ensure regulatory alignment.

The ideal candidate has 3+ years in IT governance, risk or compliance, strong knowledge of NIST and privacy principles, and experience with audit processes and relevant tools like ServiceNow and SAP GRC.

Qualifications

  • Bachelor’s degree or equivalent with 3+ years in IT governance, risk, compliance.
  • Familiarity with NIST, privacy, and regulatory requirements.
  • Experience with IT general controls evaluations and external auditors.

Responsibilities

  • Monitor IT access reviews and SOX related activities.
  • Validate segregation of duties in critical applications.
  • Coordinate IT controls assessments with business and IT teams.
  • Engage in projects ensuring compliance with policies and security requirements.
  • Assist with vulnerability assessment and SOX audit processes.
  • Follow procedures and maintain audit documentation.
  • Participate in incident response activities.
  • Develop and support IT Governance, Risk and Compliance processes.
  • Assess applications, vendors, and processes from cybersecurity and privacy perspectives.
  • Work with IT and Legal to ensure GDPR, SoX, etc., compliance.

Skills

Security frameworks (NIST)
Regulatory requirements
IT governance and risk management
IT compliance
Privacy assessment (GDPR)
Communication with management
Auditing and SOX
Analytical capabilities
Collaboration across disciplines
English communication

Education

Bachelor’s degree in information technology or legal or equivalent years of experience
ISACA CISM
ISACA CRISC
ISACA CGEIT
(ISC)2 CISSP

Tools

ServiceNow
SAP GRC

Job description

Cybersecurity: Governance, Risk and Compliance Specialist

JOIN INNERGO AS:

Cybersecurity: Governance, Risk and Compliance Specialist

JOB FUNCTIONS:
  • M onitor user access to IT systems by performing the following: Semiannual access reviews, Termination validation procedures, IT Privilege access reviews
  • Validate that access to critical functions within key applications is appropriately segregated (Segregation of Duties – SOD)
  • Establish effective communication processes with the business and regional IT teams to coordinate the global assessment of IT controls
  • Integrally engage in projects making sure that they comply with O-I policies and security requirements
  • Assist with independent vulnerability assessment and SoX audit processes
  • Follow documented procedures and retain necessary audit documentation
  • Participate in the incident response activities in accordance with established procedures
  • Develop and support IT Governance processes
  • Develop and support IT Risk Management processes
  • Develop and support IT Compliance processes
  • Assessing applications, vendors, and processes from a Cybersecurity and Privacy perspective
  • Work with the IT and Legal teams to ensure compliance with regulations (SoX, GDPR, DOL, etc).
POSITION REQUIREMENTS:
  • Bachelor’s degree in information technology or legal or equivalent years of experience
  • Understanding of security frameworks (NIST), and regulatory requirements – governance, risk management, privacy, and data security
  • Understanding of security protocols and standards
  • Solid knowledge of information security principles, practices
  • Minimum 3 years of experience working in Information Technology/IT and Data Governance, IT Risk Management, IT Compliance
  • Minimum 3 years of experience working with IT general computer control evaluations, remediation, and with external auditors
  • Intermediate knowledge related to privacy assessment (GDPR)
  • Understanding of the industry’s control frameworks and leading practices
  • Experience in evaluating system security requirements
  • Knowledge of system functions, security policies, technical security safeguards, and operational security measures
  • Knowledge of industry-leading practices, security frameworks, policies, and standards
  • Intermediate operational knowledge of ServiceNow
  • Intermediate operational knowledge of SAP GRC
  • Ability to determine priorities, makes discretionary decisions and determines when to notify management
  • Ability to work well with people from many different disciplines with varying degrees of technical experience
  • Experience in communicating and presenting to a management-level audience
  • Organized, responsive, and highly thorough problem solver
  • Detail oriented
  • Demonstrated analytical capabilities
  • Self-starter and strong collaboration skills
  • Experience in effective communication with customers, employees, and management
  • Have high integrity and be able to maintain the confidentiality of work performed
  • Must be able to communicate in English – both written and verbal.
ADDITIONAL QUALIFICATIONS:
  • ISACA Certified Information Security Manager (CISM)
  • ISACA Certified in Risk & Information System Controls (CRISC)
  • ISACA Certified in the Governance of Enterprise IT (CGEIT)
  • (ISC)2 Certified Information Systems Security Professional (CISSP).
WE OFFER:
  • Necessary for work tools
  • Co-financing for private medical care, life insurance, sports card
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Risk & Compliance Strategist
Cyber Risk & Compliance Strategist

Innergo • Gdynia

Hybrid
PLN 180,000 - 300,000
Co-financing for private medical care
Life insurance
Sports card
Information Security Engineer
Information Security Engineer

YDU JC Air Cond & Ref Inc.- Dubai • Warszawa

On-site
PLN 160,000 - 220,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos SE • Wrocław

On-site
PLN 120,000 - 190,000
IT Risk & Compliance Consultant
IT Risk & Compliance Consultant

Jobtailor • Katowice

On-site
PLN 120,000 - 180,000
Senior IT Risk & Audit Compliance Analyst
Senior IT Risk & Audit Compliance Analyst

DCG Poland • Łódź

On-site
PLN 180,000 - 260,000
Private medical care
Co-financing for the sports card
Constant consultant support
Cybersecurity Risk Manager
Cybersecurity Risk Manager

SEIDOR • Warszawa

On-site
PLN 180,000 - 280,000
GRC Consultant
GRC Consultant

Webellian • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid work model
On-site presence occasionally
Private medical care
+2
CyberSecurity Specialist
CyberSecurity Specialist

SEIDOR • Warszawa

On-site
PLN 180,000 - 260,000
Cybersecurity Governance Risk and Compliance Consultant
Cybersecurity Governance Risk and Compliance Consultant

RMM Consulting Group • Warszawa

On-site
PLN 180,000 - 300,000
I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith Europe • Kraków

On-site
PLN 150,000 - 210,000