Location
Warsaw, Poland
Security Clearance
EU RESTRICTED
Deadline for Application
18.06 .2026 r.
Minimum Level of Education
Level 7
Minimum English Language Skills (CEFR)
C1
Minimum IT Relevant Professional Experience (years)
9
Minimum Experience at Similar Position (years)
6
Required Certificates
o r equivalent certification recognized internationally (subject to acceptance as a valid credential by the Contracting EU-I).
- At least 4 certifications among:
- CISSP (Certified Information Systems Security Professional)
- CISA (Certified Information Systems Auditor)
- CISM (Certified Information Security Manager)
- GSNA (GIAC Certified Systems and Network Auditor)
- GCCC (GIAC Certified Critical Controls)
- ISO 27001 Lead implementer
- ISO 27001 Lead Auditor
- ISO 27005 Risk Manager
- CAP ((ISC)2 Certified Authorization Professional)
- CRISC (ISACA Certified in Risk and Information Systems Control)
- CISSP-ISSMP ((ISC)2 Certified Information Systems Security Management Professional)
- GIAC Certified ISO-27000 Specialist
Knowledge
- Perform risks assessments and analysis to identify threats, categorise assets, and rate system vulnerabilities so that they can implement effective controls
- Implement cybersecurity risk management frameworks, methodologies and guidelines and ensure compliance with regulations and standards
- Enable business assets owners, executives, and other stakeholders to make risk informed decisions to manage and mitigate risks
- Enable employees to understand, embrace and follow the controls
- Build a cybersecurity risk-aware environment
- Advanced knowledge of risk management frameworks, standards, methodologies, tools, guidelines and best practices
- Knowledge of cyber threats, threats taxonomies and vulnerabilities repositories
- Knowledge of risk sharing options and best practices
- Knowledge of state of the art technical and organisational controls that appropriately mitigate cybersecurity risks
- Knowledge of monitoring, implementing and testing the effectiveness of the controls
Skills
- Analyse and consolidate organisation’s quality and risk management practices
- Communicate, present and report to relevant stakeholders
- Propose and manage risk sharing options
Specific Requirements
- Experience in making Business Impact Assessments
- Knowledge on risk assessment implementation in GRC Service Now
- Experience in preparing personal data protection documentation
- Experience in tools for graphical and programmatic threat modelling.
- Experience in threat modelling for DevOps
- Experience in designing Zero Trust Architecture
- Experience in Securing Software Development Lifecycle
- Experience in designing controls for defending Directory Services
Typical Tasks And Responsibilities
- Developing an organisation’s cybersecurity risk management strategy
- Managing an inventory of the organisation’s assets
- Identifying and assessing cybersecurity-related threats and vulnerabilities of ICT systems
- Identifying the threat landscape, including attackers’ profiles, and estimating the potential of attacks
- Assessing cybersecurity risks and proposing the most appropriate risk treatment options, including security controls and risk mitigation and avoidance measures that best address the organisation’s strategy
- Monitoring the effectiveness of cybersecurity controls and risk levels
- Ensuring that all cybersecurity risks remain at an acceptable level for the organisation’s assets
- Developing, maintaining, reporting on, and communicating the complete risk management cycle.
Contact Information
VECTOR SYNERGY sp. z o.o., ul. Marcelińska 90, 60-324 Poznań, NIP PL7811857270, REGON 301575740, KRS: 0000369575
Rejestr Przedsiębiorców KRS prowadzony przez Sąd Rejonowy Poznań – Nowe Miasto i Wilda w Poznaniu, VIII Wydział Gospodarczy KRS, kapitał zakładowy wynosi: 73.852,80 złotych wpłacony w całości, TEL +48 616684500, FAX +48 616684501, www.vectorsynergy.com , info@vectorsynergy.com