About Seidor
SEIDOR helps organizations transform and stay competitive through technology and innovation, always putting people first. With over 8,000 professionals in 45 countries, we are a diverse and inclusive global team committed to talent, equal opportunities, and sustainable growth.
#HumanizingTechnology
About Seidor
SEIDOR helps organizations transform and stay competitive through technology and innovation, always putting people first. With over 8,000 professionals in 45 countries, we are a diverse and inclusive global team committed to talent, equal opportunities, and sustainable growth.
Will you join us in humanizing technology?
We want you to be a part of our team as a Cybersecurity Risk Manager (CSRM), providing services on-site in Warsaw
WHAT WILL YOU DO IN YOUR DAY-TO-DAY?
- Develop and maintain the organisation's cybersecurity risk management strategy.
- Manage an inventory of the organisation's assets and support their risk categorisation.
- Identify and assess cybersecurity-related threats and vulnerabilities affecting ICT systems.
- Analyse the threat landscape, including attackers' profiles and the potential impact of attacks.
- Perform cybersecurity risk assessments and propose appropriate risk treatment options, security controls, mitigation measures and avoidance strategies.
- Monitor the effectiveness of cybersecurity controls and evolving risk levels.
- Ensure cybersecurity risks remain at an acceptable level for the organisation's assets.
- Develop, maintain, report and communicate the complete cybersecurity risk management cycle.
- Enable asset owners, executives and other stakeholders to make risk-informed decisions.
- Help employees understand, adopt and follow cybersecurity controls, supporting a risk-aware environment.
Requirements
- Minimum education level: Master's Degree.
- Required certifications:
At least 4 certifications from the following list: CISA, CISM, CRISC, CISSP, CGRC, CSSLP, CCSP, CISSP-ISSMP, GSNA, GCCC, GIAC Certified ISO-27000 Specialist, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, ISO 27005 Risk Manager.
- Minimum 9 years of relevant IT professional experience.
- Minimum 6 years of experience in a similar position.
- Advanced knowledge of cybersecurity risk management frameworks, standards, methodologies, tools, guidelines and best practices.
- Experience performing risk assessments and analysis to identify threats, categorise assets and rate system vulnerabilities.
- Knowledge of cyber threats, threat taxonomies and vulnerability repositories.
- Knowledge of risk-sharing options and current technical and organisational controls used to mitigate cybersecurity risks.
- Knowledge of monitoring, implementing and testing the effectiveness of cybersecurity controls.
- Ability to analyse and consolidate organisational quality and risk-management practices.
- Ability to propose and manage risk-sharing options.
Specific Experience Required
- Experience in Business Impact Assessments.
- Knowledge of risk assessment implementation in GRC ServiceNow.
- Experience preparing personal data protection documentation.
- Experience with graphical and programmatic threat-modelling tools.
- Experience in threat modelling for DevOps.
- Experience designing Zero Trust Architecture.
- Experience securing the Software Development Lifecycle (SDLC).
- Experience designing controls for defending Directory Services.