CyberSecurity Risk Manager

Arhs Group

Warszawa

On-site

PLN 420,000 - 640,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Arηs Group, Part of Accenture, specializes in managing complex public sector IT projects including cybersecurity, analytics, and cloud solutions. The role focuses on developing and maintaining the organisation’s cybersecurity risk management strategy and performing risk assessments across ICT systems.

You will identify threats, design controls, support regulatory compliance, and enable risk-informed decision making with executive stakeholders.

Qualifications

  • 9+ years IT experience with 6+ years in cybersecurity risk management or related roles.
  • Master's degree in ICT field.
  • At least 4 listed certifications (e.g., CISA, CISM, CRISC, CISSP, CGRC, CSSLP, CCSP, CISSP-ISSMP).
  • Excellent English, C1+ desirable.
  • Deep knowledge of risk management frameworks, standards, regulatory requirements, threats, vulnerabilities, risk assessment methodologies, risk treatment, and security controls.
  • Experience with governance, risk and compliance processes, including ServiceNow GRC and data protection documentation.

Responsibilities

  • Develop and implement cybersecurity risk management strategy and framework.
  • Conduct risk assessments, asset categorization, vulnerability analysis, and risk treatment recommendations.
  • Identify threats and update risk registers and threat models for ICT systems and DevOps environments.
  • Perform Business Impact Assessments to support risk-based decisions.
  • Design, monitor, and evaluate controls to keep risks at acceptable levels.
  • Promote a security-conscious culture and communicate findings to stakeholders.

Skills

Cybersecurity risk management
Information security governance
Threat modelling
Security controls design
Zero Trust Architecture
Communication skills

Education

Master's degree in ICT

Tools

ServiceNow GRC

Job description

Arηs Group, Part of Accenture, specializes in the management of complex public sector IT projects, including systems integration, informatics and analytics, solution implementation and program management. Our team helps lead clients through digital and information systems design, bringing expertise in a variety of areas ranging from software development, data science and security management to machine learning, cloud, and mobile development.
Arηs Group was acquired by Accenture in July 2024.

Job Description
  • Develop and maintain the organisation’s cybersecurity risk management strategy
  • Conduct cybersecurity risk assessments and analyses to identify threats, categorise assets, assess vulnerabilities, and recommend risk treatment options
  • Identify and assess cybersecurity-related threats and vulnerabilities of ICT systems and maintain awareness of the evolving threat landscape
  • Perform Business Impact Assessments and support cybersecurity risk-based decision making
  • Design, implement, monitor, and evaluate cybersecurity controls to ensure risks remain at acceptable levels
  • Implement and maintain cybersecurity risk management frameworks, methodologies, standards, and best practices
  • Support compliance with security, risk, governance, and regulatory requirements
  • Enable business stakeholders, asset owners, and executives to make risk-informed decisions
  • Promote a cybersecurity risk-aware culture across the organisation
  • Develop and maintain cybersecurity risk registers, reports, metrics, and documentation
  • Support threat modelling activities for systems, applications, and DevOps environments
  • Contribute to the design of Zero Trust Architecture and security controls for critical enterprise services, including Directory Services
  • Support personal data protection and information security governance initiatives
  • Communicate risk management activities, findings, and recommendations to relevant stakeholders
Qualifications
  • Minimum 9 years of relevant IT professional experience, with at least 6 years in a cybersecurity risk management, information security governance, cybersecurity architecture, or similar role.
  • Minimum education level: Level 7 (Master's degree or equivalent) in an ICT-relevant field.
  • At least 4 of the following certifications:
    • CISA (Certified Information Systems Auditor)
    • CISM (Certified Information Security Manager)
    • CRISC (Certified in Risk and Information Systems Control)
    • CISSP (Certified Information Systems Security Professional)
    • CGRC (Certified in Governance, Risk and Compliance)
    • CSSLP (Certified Secure Software Lifecycle Professional)
    • CCSP (Certified Cloud Security Professional)
    • CISSP-ISSMP (Certified Information Systems Security Management Professional)
    • GSNA (GIAC Certified Systems and Network Auditor)
    • GCCC (GIAC Certified Critical Controls)
    • GIAC Certified ISO-27000 Specialist
    • ISO 27001 Lead Implementer
    • ISO 27001 Lead Auditor
    • ISO 27005 Risk Manager
    • or equivalent, internationally recognized certification
  • Excellent verbal and written communication in English, C1+ certificate desirable
  • Advanced knowledge of cybersecurity risk management frameworks, methodologies, standards, regulatory requirements, tools, best practices, cyber threats, threat taxonomies, vulnerabilities, risk assessment methodologies, risk treatment strategies, and security controls.
  • Experience performing cybersecurity risk assessments, cyber risk analysis, Business Impact Assessments, threat modelling activities, and monitoring the effectiveness of security controls within enterprise environments.
  • Experience implementing cybersecurity governance, risk and compliance processes, including ServiceNow GRC, personal data protection documentation, and organisational risk management practices.
  • Experience designing and assessing security architectures and controls, including Zero Trust Architecture, Secure Software Development Lifecycle (Secure SDLC), threat modelling for DevOps environments, and security controls for Directory Services.
  • Ability to analyse and consolidate organisational risk management and quality management practices, propose and manage risk treatment, risk mitigation and risk-sharing strategies, and communicate recommendations to technical and non-technical stakeholders, including senior management.
  • Excellent communication, documentation, analytical, problem-solving, and stakeholder management skills, with the ability to work independently and provide expert guidance on cybersecurity risk management matters.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Project Manager
Cybersecurity Project Manager

ARHS • Warszawa

On-site
PLN 240,000 - 380,000
Cybersecurity Vulnerability Analyst
Cybersecurity Vulnerability Analyst

ARHS • Warszawa

On-site
PLN 180,000 - 260,000
Strategic Cyber Risk Manager
Strategic Cyber Risk Manager

Arhs Group • Warszawa

On-site
PLN 420,000 - 640,000
Cybersecurity Program Manager: Lead IT Security Projects
Cybersecurity Program Manager: Lead IT Security Projects

ARHS • Warszawa

On-site
PLN 240,000 - 380,000
Solutions Architect
Solutions Architect

ARHS • Warszawa

On-site
PLN 180,000 - 260,000
Cybersecurity Risk Manager
Cybersecurity Risk Manager

SEIDOR • Warszawa

On-site
PLN 180,000 - 280,000
Cybersecurity Risk Manager (EU Security Environment)
Cybersecurity Risk Manager (EU Security Environment)

Aricoma • Warszawa

On-site
PLN 180,000 - 320,000
Cybersecurity Risk Manager
Cybersecurity Risk Manager

C&D Talent Advisory • Rzeszów

On-site
PLN 258,000 - 388,000
Cybersecurity Risk Manager
Cybersecurity Risk Manager

C&D Talent Advisory • Wrocław

On-site
PLN 258,000 - 388,000
Cybersecurity Risk Manager
Cybersecurity Risk Manager

C&D Talent Advisory • Województwo pomorskie

On-site
PLN 258,000 - 388,000