Cybersecurity Risk and Compliance Manager

EY

Poland

On-site

PLN 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Continuous learning opportunities
Flexible work options
Transformative leadership coaching
Inclusive company culture

Job summary

EY in Poland is seeking a Cybersecurity Risk and Compliance Manager. The role entails evaluating and enhancing cybersecurity programs, developing risk management strategies, and analyzing compliance with standards such as ISO 27001.

With a focus on project execution, you will ensure high-quality delivery and manage team collaboration. This position requires significant experience, excellent interpersonal skills, and proficiency in English.

Qualifications

  • Minimum 8 years of experience in cybersecurity risk management.
  • Proven expertise in delivering complex risk assessments and strategic mitigation plans.
  • Strong project management skills with effective stakeholder communication.

Responsibilities

  • Evaluate clients' cybersecurity and risk management programs.
  • Develop and implement risk management strategies.
  • Conduct compliance and control evaluations against regulations.
  • Manage Third Party Risk Management processes.

Skills

Cybersecurity risk management
Third Party Risk Management (TPRM)
Analytical and problem-solving abilities
Project management

Education

Relevant cybersecurity certifications (CISSP, CISM)
Minimum 8 years of experience in cybersecurity

Job description

Cybersecurity Risk and Compliance Manager

Location: Wrocław - 2 days office / 3 days remote

The opportunity

As a Manager within our Cybersecurity Risk, Compliance & Resilience (CRCR) competency, you will play a pivotal role in assisting EY clients in evaluating the effectiveness and efficiency of their cybersecurity and resiliency programs. Your focus will be on aligning these programs with business growth and operational strategies. In addition to conducting compliance and control evaluations, you will be instrumental in developing and implementing risk management strategies and business continuity plans, ensuring organizations are well-prepared to respond effectively to incidents and disruptions. You will identify deficiencies and provide actionable recommendations and guidelines to enhance cyber resilience. This role is not solely about overseeing others, you will be expected to bring your hands‑on experience to the forefront, directly contributing to project delivery and execution, while also managing and coordinating efforts as needed.

Your key responsibilities
  • Evaluate and assess the effectiveness of clients' cybersecurity and risk management programs.
  • Develop and implement risk management strategies.
  • Conduct compliance and control evaluations, ensuring adherence to regulations and standards such as ISO 27001 and NIST.
  • Perform audits or reviews of Information Security Management Systems (ISMS) and IT general controls.
  • Manage Third Party Risk Management (TPRM) processes.
  • Provide domain knowledge in cybersecurity, including governance, IT infrastructure security, and risk management.
  • Actively participate in hands‑on project delivery, ensuring technical and operational tasks are completed with high quality and aligned to client expectations.
  • Collaborate with engagement team members, fostering teamwork and responsibility.
  • Set up governance frameworks for cybersecurity services, ensuring alignment with organizational objectives.
  • Develop and monitor Key Performance Indicators (KPIs) to measure the effectiveness of cybersecurity services.
  • Oversee service delivery processes, ensuring high‑quality service and client satisfaction.
  • Work on offer preparation, discussing client needs, preparing proposals, and actively pursuing and securing project engagements.
  • Balance direct hands‑on involvement with team coordination, ensuring seamless execution of both technical tasks and broader project objectives.
Skills and attributes for success

Minimum 8 years of experience in cybersecurity risk management, with proven expertise in overseeing and delivering complex risk assessments, threat modelling, and strategic mitigation planning including, but not limited to below areas:

  • Assuring the conformity to regulations, norms and standards such as ISO 27001, NIST or any other ISMS governance systems.
  • Implementation of the risk management plans.
  • Experience in Third Party Risk Management (TPRM).
  • Domain knowledge in Cybersecurity, including governance, IT infrastructure security and risk management, cyber program assessments including cyber transformation and enterprise resilience.
  • Demonstrate excellent interpersonal skills, inspire teamwork and responsibility with engagement team members.
  • Strong analytical and problem‑solving abilities, with a keen eye for detail.
  • Excellent interpersonal skills, with the ability to inspire teamwork and collaboration.
  • Strong project management skills, including:
    • Project planning and resource management, ensuring alignment with client and organizational objectives.
    • Budgeting and work estimation (e.g., man‑days estimation, resource allocation).
    • Effective stakeholder communication, ensuring alignment of expectations and facilitating decision‑making.
To qualify for the role, you must have
  • Excellent command of the English language; other languages would be an asset.
  • Analytical and problem‑solving abilities, observant with an eye for detail.
  • Ability to liaise with stakeholders and manage multiple priorities effectively.
  • Proven experience in both hands‑on technical work and project leadership/coordinating responsibilities.
Ideally, you'll also have
  • One or more certificate from the following: CISSP, CISM, CRISC, CGRC, ISO/IEC 27001 Lead Implementer, ISO/IEC 27005 Risk Manager, or any other recognized and equivalent certification in risk management, and cybersecurity.
  • Knowledge about Digital Operational Resilience Act (DORA), NIS2 directive, EU Cybersecurity Act, EU AI Act, and/or other relevant EU regulations.
What we offer
  • Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
  • Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
  • Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Risk & Compliance Consultant
Senior Cybersecurity Risk & Compliance Consultant

EY • Katowice

Hybrid
PLN 200,000 - 320,000
Cybersecurity Risk and Compliance Manager at EY
Cybersecurity Risk and Compliance Manager at EY

EY • Katowice

Hybrid
PLN 260,000 - 380,000
Cybersecurity Project Manager
Cybersecurity Project Manager

Ernst & Young Advisory Services Sdn Bhd • Katowice

Hybrid
PLN 180,000 - 280,000
Cybersecurity Project Manager
Cybersecurity Project Manager

EY • Katowice

Hybrid
PLN 180,000 - 260,000
Continuous learning
Flexible work
Leadership development
+1
Vulnerability & Application Security Engineer
Vulnerability & Application Security Engineer

EY • Wrocław

Hybrid
PLN 120,000 - 180,000
Vulnerability & Application Security Engineer
Vulnerability & Application Security Engineer

EY • Katowice

Hybrid
PLN 120,000 - 180,000
Continuous learning
Career growth
Flexible work options
+1
Senior Consultant for Cyber Security
Senior Consultant for Cyber Security

EY • Katowice

On-site
PLN 150,000 - 200,000
Continuous learning opportunities
Flexible work arrangements
Diverse and inclusive culture
Cybersecurity Risk Manager | Warsaw
Cybersecurity Risk Manager | Warsaw

C&D Talent Advisory - Academy • Gliwice

On-site
PLN 260,000 - 390,000
Cybersecurity Risk Manager | Warsaw
Cybersecurity Risk Manager | Warsaw

C&D Talent Advisory - Academy • Katowice

On-site
PLN 258,000 - 388,000
Cybersecurity Risk Manager | Warsaw
Cybersecurity Risk Manager | Warsaw

C&D Talent Advisory - Academy • Łódź

On-site
PLN 258,000 - 388,000