Cybersecurity Risk Manager

Ayesa Digital

Warszawa

On-site

PLN 240,000 - 360,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ayesa Digital is recruiting a Cybersecurity Risk & GRC Specialist to join an international EU project, focusing on risk management, governance, risk assessment, compliance, and controls implementation. You will collaborate with cybersecurity, IT, and business stakeholders to assess risks and support risk-informed decisions across the organisation.

The role requires experience in cybersecurity risk management, GRC, and compliance, with a strong focus on international projects and European

Qualifications

  • 9+ years in IT environments.
  • 6+ years in cybersecurity risk, GRC or related roles.
  • CEFR C1 English with certification.
  • Experience with risk assessment, controls, and compliance.

Responsibilities

  • Perform cybersecurity risk assessments and analysis.
  • Implement and maintain risk management frameworks and controls.
  • Support risk-informed decision-making with stakeholders.
  • Promote awareness of cybersecurity controls across the org.
  • Evaluate risk-sharing and treatment options.
  • Monitor effectiveness of controls and drive improvements.
  • Consolidate quality, cybersecurity, and risk practices.

Skills

Cybersecurity
Risk management
GRC
Security controls
Threat modeling
Stakeholder management
English C1

Education

EQF Level 7

Tools

NIST
ISO 27001
COBIT

Job description

Every professional in our company is vital to us. Thanks to their talent, we continue to expand; today, we are a global team of over 11,000 people working toward a common goal.

Ayesa Digital is currently participating in high-impact European Union projects designed to address major European challenges and drive innovation and digital transformation. These are strategic technological projects based on collaborative initiatives that stand out for their international focus and strong commitment to socially-oriented results.

We are currently looking for a Cybersecurity Risk & GRC Specialist to join an international project supporting the European Border and Coast Guard Agency.

The role will focus on cybersecurity risk management, governance, risk assessment, compliance, and the implementation and monitoring of cybersecurity controls, helping ensure that information systems, business assets, and processes are adequately protected against cyber threats and vulnerabilities.

You will work in a multicultural and international environment, collaborating with cybersecurity, IT, business, and other stakeholders to assess risks, implement appropriate controls, and support risk-informed decision-making across the organisation.

If you are an experienced cybersecurity professional specialised in risk management, GRC, compliance, and cybersecurity controls, looking for an international career opportunity within European institutions, this is your place.

What You Will Do (Responsibilities)
  • Perform cybersecurity risk assessments and analysis to identify threats, categorise assets, assess vulnerabilities, and determine appropriate mitigation measures.
  • Implement and maintain cybersecurity risk management frameworks, methodologies, guidelines, and processes in line with applicable regulations and international standards.
  • Support business asset owners, executives, and other stakeholders in making risk-informed decisions to manage and mitigate cybersecurity risks.
  • Promote awareness and understanding of cybersecurity controls among employees, business owners, and relevant stakeholders.
  • Contribute to building and maintaining a cybersecurity risk-aware organisational environment.
  • Analyse and consolidate the organisation's quality, cybersecurity, and risk management practices.
  • Define, implement, monitor, and test the effectiveness of cybersecurity controls.
  • Assess cyber threats, vulnerabilities, and associated risks using appropriate threat taxonomies, vulnerability repositories, and risk assessment methodologies.
  • Evaluate and recommend appropriate risk-sharing and risk-treatment options in accordance with organisational policies and best practices.
  • Support the design and implementation of technical and organisational controls to appropriately mitigate cybersecurity risks.
  • Monitor the effectiveness of implemented controls and identify areas for continuous improvement.
What We Are Looking For (Requirements)
  • Minimum EQF Level 7 qualification in Cybersecurity, Information Security, Computer Science, IT, Engineering, Risk Management, or a related field.
  • At least 9 years of professional experience in IT-related environments.
  • At least 6 years of professional experience in a similar cybersecurity risk, GRC, information security, or cybersecurity management position.
  • Minimum C1 level of English according to the CEFR, supported by a recognised certification.
  • Strong knowledge of cybersecurity risk management frameworks, standards, methodologies, tools, guidelines, and best practices.
  • Advanced knowledge of cybersecurity risk assessment and analysis.
  • Knowledge of cyber threats, threat taxonomies, vulnerabilities, and vulnerability repositories.
  • Knowledge of risk treatment and risk-sharing options and related best practices.
  • Knowledge of technical and organisational cybersecurity controls used to mitigate cybersecurity risks.
  • Experience in monitoring, implementing, and testing the effectiveness of cybersecurity controls.
  • Strong ability to analyse and consolidate quality, cybersecurity, and risk management practices.

Candidates must hold at least 4 of the following certifications:

  • CISA – ISACA Certified Information Systems Auditor.
  • CISM – ISACA Certified Information Security Manager.
  • CRISC – ISACA Certified in Risk and Information Systems Control.
  • CISSP – ISC2 Certified Information Systems Security Professional.
  • CGRC – ISC2 Certified in Governance, Risk and Compliance.
  • CSSLP – ISC2 Certified Secure Software Lifecycle Professional.
  • CCSP – ISC2 Certified Cloud Security Professional.
  • CISSP-ISSMP – ISC2 Certified Information Systems Security Management Professional.
  • GSNA – GIAC Certified Systems and Network Auditor.
  • GCCC – GIAC Certified Critical Controls.
  • GIAC Certified ISO-27000 Specialist.
What We Offer
  • Opportunity to work on a prestigious European Union project
  • An international, innovative, and multicultural working environment.
  • Exposure to European institutional cybersecurity, risk management, and critical IT environments.
  • The opportunity to work with cybersecurity governance, risk, compliance, and security control frameworks in a European institutional context.
  • Continuous support from a team of experts working on EU projects.
  • Opportunity to develop your professional career in an international cybersecurity

If you are an experienced cybersecurity professional with a strong background in risk management, GRC, security controls, and compliance, and you are looking for a new challenge within an international European project, we would love to hear from you!

In accordance with Organic Law 3/2007 of March 22, the company is committed to promoting the defense and effective application of the principle of equality between men and women, preventing any type of labor discrimination based on sex, and guaranteeing equal entry opportunities. Furthermore, we promote diversity and reject any discrimination based on race, gender, functional diversity, religion, sexual orientation, gender identity, or any other personal or social condition, striving to build an inclusive and enriching environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Global Cyber Risk & GRC Specialist
Global Cyber Risk & GRC Specialist

Ayesa Digital • Warszawa

On-site
PLN 240,000 - 360,000
Cybersecurity Manager | EU Institutions Project
Cybersecurity Manager | EU Institutions Project

SEIDOR • Warszawa

On-site
PLN 180,000 - 240,000
Cybersecurity Risk Manager (EU Security Environment)
Cybersecurity Risk Manager (EU Security Environment)

Aricoma • Warszawa

On-site
PLN 180,000 - 320,000
Data Center Technician
Data Center Technician

Ayesa Digital • Warszawa

On-site
PLN 119,000 - 199,000
Rate per day: €XXX – €XXX
Cybersecurity Vulnerability Analyst
Cybersecurity Vulnerability Analyst

ARHS • Warszawa

On-site
PLN 180,000 - 260,000
Cybersecurity Risk Manager
Cybersecurity Risk Manager

SEIDOR • Warszawa

On-site
PLN 180,000 - 280,000
Cybersecurity Risk and Compliance Manager
Cybersecurity Risk and Compliance Manager

EY • Poland

Hybrid
PLN 80,000 - 110,000
Continuous learning opportunities
Flexible work options
Transformative leadership coaching
+1
Cyber Security Risk Analyst
Cyber Security Risk Analyst

Euroclear • Kraków

On-site
PLN 254,000 - 383,000
Cyber Security Risk Analyst
Cyber Security Risk Analyst

Euroclear • Poland

On-site
PLN 190,000 - 297,000
Security Specialist
Security Specialist

SOFTSWISS • Suchy Las

On-site
PLN 80,000 - 110,000
Private health insurance
Sports benefits
Mental Health Program
+6