Cybersecurity Risk Manager | Warsaw
TechTree's client is hiring an experienced Cybersecurity Risk Manager to join a large-scale IT security programme supporting a major EU agency in Warsaw.
This is a senior, high-impact opportunity for someone with deep cybersecurity risk experience who wants to operate in a highly regulated, mission-critical environment protecting critical assets and infrastructure.
- Location: Warsaw, Poland
- Work model: 100% on-site
- Employment: Contract
- Initial term: 12 months, with potential extensions up to 48 months
- Estimated compensation: €60,000–€90,000
- Level: Mid-Senior
What You'll Do
You’ll own the cybersecurity risk-management lifecycle end to end, from asset identification and threat assessment through to control design, monitoring and executive reporting.
Key responsibilities include:
- Develop and maintain the organisation's cybersecurity risk-management strategy
- Manage asset inventories and risk assessments
- Identify cybersecurity threats and vulnerabilities
- Assess threat landscapes and attacker capabilities
- Recommend risk-treatment strategies, controls and mitigation measuresMonitor control effectiveness and residual risk
- Produce Business Impact Assessments and risk-management documentation
- Communicate risk clearly to executives and senior stakeholders
- Help build an organisation-wide risk-aware security culture
What We're Looking For
- 9+ years of overall IT experience
- 6+ years in cybersecurity risk management
- Master's degree or higher
- C1-level English
- At least 4 recognised cybersecurity or risk certifications, such as CISA, CISM, CRISC, CISSP, CGRC, CSSLP, CCSP, CISSP-ISSMP, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor or ISO 27005 Risk Manager
- Strong experience implementing risk-management frameworks and leading risk assessments
- Ability to present technical risk in clear, executive-level terms
- Willingness to work 100% on-site in Warsaw
- Eligibility and willingness to undergo CONFIDENTIEL UE / EU CONFIDENTIAL security clearance
Strong advantages
- ServiceNow GRC
- Business Impact Assessments
- Personal data protection documentation
- Threat modelling
- Zero Trust Architecture
- Secure SDLC
- DevOps security
- Directory Services defence controls