(Cybersecurity) Threat and Controls Assessment Consultant

Antal Poland

Kraków

Hybrid

PLN 180,000 - 240,000

Full time

41 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

B2B contract
Hybrid work model – 6 days per month
Lux Med private medical care
Contractor Care Specialist
International cybersecurity projects

Job summary

Antal Poland is seeking a Senior Cybersecurity Threat Analyst to join a global cybersecurity environment. You will focus on threat modelling, security assessments and identifying vulnerabilities and control gaps across diverse technology landscapes.

In this hybrid Kraków-based role, you will translate technical findings into business risks and practical recommendations, collaborating with developers, architects and business stakeholders to strengthen security across on-premises, cloud and

Qualifications

  • Several years of professional experience in cybersecurity or information security.
  • Hands-on threat modelling and security assessments.
  • Ability to translate security issues into business risks and practical recommendations.
  • Experience with security assessment of complex enterprise environments.

Responsibilities

  • Perform threat modelling and threat & control assessments for services across on-premise, cloud and external environments.
  • Identify potential security threats, vulnerabilities and control gaps.
  • Collaborate with developers, architects and technical leads to understand end-to-end solutions and risks.
  • Assess existing security controls and recommend improvements.
  • Translate security findings into clear business risks and recommendations.
  • Provide security input throughout the SDLC from design to implementation.
  • Contribute to design and development of secure technology solutions with practical recommendations.
  • Evaluate security implications of new technologies and products.
  • Collaborate with stakeholders to address security issues.
  • Contribute to improving security assessment processes and tools.
  • Keep up to date with evolving technologies and threats.
  • Support an international, collaborative security community.

Skills

cybersecurity concepts
threat modelling
risk management
SDLC security
communication skills
stakeholder management
analytical thinking
teamwork
adaptive to change
independent work

Tools

AWS
Azure
GCP

Job description

Threat and Controls Assessment Consultant

Work model: Hybrid – 6 days per month from the Kraków office

Contract: B2B

About the role

We are looking for a Senior Cybersecurity Threat Analyst to join a global cybersecurity environment and play a key role in identifying security threats, assessing controls and helping technology teams build secure solutions.

In this role, you will focus on threat modelling, security assessments and identifying vulnerabilities and control gaps across a diverse technology landscape, including applications, databases, networks, infrastructure and cloud environments.

You will work closely with developers, architects, technical leads and business stakeholders, translating technical security findings into clear business risks and practical recommendations.

This is a hands‑on role for someone who combines a strong technical cybersecurity background with excellent analytical and communication skills.

What you will do
  • Perform threat modelling and threat & control assessments for technology services and solutions across on-premise, cloud and external environments.
  • Identify potential security threats, vulnerabilities and control gaps across applications, databases, networks and infrastructure.
  • Work closely with developers, architects and technical leads to understand end-to‑end solutions and identify security risks.
  • Assess existing security controls and recommend appropriate improvements.
  • Translate technical security findings into clear and actionable business risks and recommendations.
  • Provide security input throughout the software development lifecycle (SDLC), from design through implementation and support.
  • Contribute to the design and development of technology solutions by providing practical security recommendations.
  • Evaluate security implications of new technologies, products and solutions and provide technical recommendations.
  • Collaborate with cybersecurity and technology stakeholders to investigate and address potential security issues.
  • Contribute to the continuous improvement of security assessment processes, methodologies and tools.
  • Keep up to date with emerging technologies, cybersecurity threats, industry trends and best practices.
  • Support a collaborative, international environment and contribute to knowledge sharing across the wider cybersecurity community.
What we are looking for
Cybersecurity & risk expertise
  • Several years of professional experience in cybersecurity, information security or a related technology field.
  • Hands‑on experience with threat modelling and security assessments.
  • Strong understanding of cybersecurity concepts, principles and best practices.
  • Good understanding of risk and control management.
  • Ability to identify and assess threats, vulnerabilities and control weaknesses.
  • Experience translating technical security issues into business risks and practical recommendations.
  • Experience with security assessment of complex enterprise technology environments.
Strong technical background
  • Good understanding of application design and architecture.
  • Knowledge of application, network and host security.
  • Good understanding of cloud security and practical experience with at least one major cloud platform: AWS, Azure or GCP.
  • Strong understanding of the Software Development Lifecycle (SDLC), with a focus on security.
  • Understanding of modern Generative AI and Agentic AI systems and their associated security risks.
  • Good understanding of emerging technologies and related cybersecurity threats.
  • Experience with security processes, methodologies and continuous improvement.
  • Strong communication skills and the ability to work effectively with both technical and non-technical stakeholders.
  • Ability to explain complex security topics in a clear and business‑oriented way.
  • Experience working in international and multicultural environments.
  • Strong stakeholder management skills and the ability to influence and provide recommendations.
  • Ability to work independently while also being an effective team player.
  • Strong analytical, problem‑solving and decision‑making skills.
  • Comfortable working in a fast‑paced environment where priorities and requirements may change.
Certifications

Industry-recognised cybersecurity certifications are an advantage, such as:

  • CISSP
  • CISM
  • CRISC
  • Cloud Security certifications
What we offer
  • B2B contract
  • Hybrid work model – 6 days per month from the Kraków office
  • Lux Med private medical care
  • Dedicated support from a Contractor Care Specialist
  • Opportunity to work on complex, international cybersecurity initiatives
  • Exposure to modern technologies, cloud environments and emerging AI security challenges
  • A collaborative environment with opportunities for professional development
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineer - Cybersecurity (Vulnerability & Threat Management)
Engineer - Cybersecurity (Vulnerability & Threat Management)

Sysco Corporation • Poland

Hybrid
PLN 40,000 - 60,000
Professional development opportunities
Collaborative culture
Modern security technologies
Penetration Tester
Penetration Tester

Antal Poland • Kraków

Hybrid
PLN 180,000 - 240,000
Hybrid work model
Private medical care (LuxMed)
MyBenefit platform
+1
Senior Vulnerability Management Specialist
Senior Vulnerability Management Specialist

Antal Poland • Kraków

Hybrid
PLN 180,000 - 280,000
Hybrid working model
Lux Med private medical care
Contractor Care specialist
+1
Senior Cyber Security Engineer
Senior Cyber Security Engineer

HeadHR • Warszawa

On-site
PLN 250,000 - 350,000
Private healthcare with rehabilitation
Extra parental days (6/yr)
Cafeteria
+1
Cybersecurity Specialist - Warszawa, Gdańsk, Gdynia
Cybersecurity Specialist - Warszawa, Gdańsk, Gdynia

Diverse CG Sp. z o.o. Sp.k. • Poland

Remote
PLN 150,000 - 200,000
Private medical care
Co-financing for sports card
Dedicated consultant support
Cybersecurity Specialist - Warszawa, Gdańsk, Gdynia
Cybersecurity Specialist - Warszawa, Gdańsk, Gdynia

DCG Poland • Poland

Remote
PLN 120,000 - 180,000
Private medical care
Co-financing for sports card
Dedicated consultant support
Cybersecurity Risk and Compliance Manager
Cybersecurity Risk and Compliance Manager

EY • Poland

Hybrid
PLN 80,000 - 110,000
Continuous learning opportunities
Flexible work options
Transformative leadership coaching
+1
Principal Security Researcher
Principal Security Researcher

ALTEN • Kraków

On-site
PLN 180,000 - 240,000
Medicover medical care
Medicover dental care
Medicover Benefits platform
+5
Cybersecurity Specialist / Administrator
Cybersecurity Specialist / Administrator

RMM Consulting Group • Warszawa

On-site
PLN 65,000 - 100,000
Flexible hours
Initial 230 working days
Potential extensions up to 920 days
Senior Penetration Tester
Senior Penetration Tester

ALTEN • Kraków

Hybrid
PLN 180,000 - 260,000
Medicover medical care
Medicover dental care
Medicover Benefits platform
+5