GRC Consultant

Webellian

Poland

Hybrid

PLN 180,000 - 240,000

Full time

12 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model
On-site presence occasionally
Private medical care
Group insurance
Multisport card

Job summary

Webellian is seeking a GRC Consultant to join our Cybersecurity team and support governance, risk, and compliance initiatives for an international client in the energy sector.

You will implement ISMS aligned with ISO/IEC 27001:2022, help establish control frameworks, and collaborate with stakeholders to prepare for audits and regulatory reviews.

Qualifications

  • 7+ years of experience in GRC, Information Security, or Cybersecurity Governance.
  • Hands-on ISMS implementation or maintenance experience.
  • Current knowledge of NIS2 and Polish Cybersecurity Act (uKSC).
  • Experience supporting cybersecurity compliance or regulatory governance initiatives.
  • Experience with cybersecurity risk registers and risk treatment processes.
  • Experience facilitating workshops with business stakeholders and executives.
  • Fluent Polish and professional English.

Responsibilities

  • Support ISMS implementation and continuous improvement per ISO/IEC 27001:2022.
  • Develop and maintain security policies, standards, procedures, and governance docs.
  • Build and maintain cybersecurity risk registers, including risk identification and treatment.
  • Conduct risk assessments and facilitate workshops with stakeholders.
  • Map security controls against ISO/IEC 27001:2022, NIS2, and other requirements.
  • Coordinate Third-Party Risk Management activities and vendor security reviews.
  • Collaborate with stakeholders to define security requirements in contracts.
  • Prepare evidence for internal and external audits.
  • Develop incident response and business recovery documentation.

Skills

GRC
ISMS
ISO/IEC 27001:2022
NIS2
Polish Cybersecurity Act (uKSC)
Third-Party Risk Management
Workshop Facilitation
English Proficiency
Polish (native)

Tools

Eramba
ServiceNow IRM
OneTrust
Archer
Lansweeper

Job description

Webellian is a well-established Digital Transformation and IT consulting company committed to creating a positive impact for our clients. We strive to make a meaningful difference in diverse sectors such as insurance, banking, healthcare, retail, and manufacturing. Our passion for cutting-edge and disruptive technologies, as well as our shared values and strong principles, are what motivate us. We are a community of engineers and senior advisors who work with our clients across industries, playing a deep and meaningful role in accelerating and realizing their vision and strategy.

About the position

We are looking for aGRC Consultant to join our Cybersecurity team and support the implementation of cybersecurity governance and regulatory compliance initiatives for one of our international clients operating in the energy sector.

In this role, you will support the implementation of anInformation Security Management System (ISMS)aligned with an international cybersecurity governance framework while ensuring compliance with applicable Polish cybersecurity regulations. You will help establish aunified control framework that satisfies both corporate security requirements and local regulatory obligations.

Working closely with client stakeholders, you will drive Governance, Risk & Compliance (GRC) activities, facilitate workshops, coordinate risk management processes, and prepare the organization for internal and external audits. This is an excellent opportunity for someone who enjoys combining cybersecurity, governance, compliance, and stakeholder management in an international environment.

Key responsibilities:

Support the implementation and continuous improvement of anISO/IEC 27001:2022-compliant Information Security Management System (ISMS).

Develop and maintain information security policies, standards, procedures, and governance documentation.

Build and maintain cybersecurity risk registers, including risk identification, assessment, treatment plans, ownership, and follow-up.

Conduct cybersecurity risk assessments, Business Impact Analyses (BIA), and facilitate workshops with business stakeholders.

Map security controls againstISO/IEC 27001:2022, NIS2, and other applicable regulatory and organizational requirements.

Coordinate Third-Party Risk Management (TPRM) activities, including vendor security assessments and supplier risk classification.

Collaborate with internal stakeholders to define and review information security requirements in supplier contracts.

Build and maintain IT asset inventories and support the documentation of business processes and data flows.

Contribute to vulnerability management planning and compliance evidence collection.

Develop and maintain incident response and business recovery documentation.

Prepare documentation and evidence required for internal and external compliance audits.

Work closely with client stakeholders to ensure the successful delivery of cybersecurity governance and compliance initiatives.

Required Experience & Skills

7+ years of experience in Governance, Risk & Compliance (GRC), Information Security, or Cybersecurity Governance.

Hands‑on experience implementing or maintaining an Information Security Management System (ISMS) based onISO/IEC 27001:2022 or a similar information security framework.

Current working knowledge of NIS2 and the Polish Cybersecurity Act (uKSC), with experience applying their requirements in cybersecurity governance, compliance, or ISMS initiatives.

Experience supporting cybersecurity compliance or regulatory governance initiatives.

Practical experience managing cybersecurity risk registers and risk treatment processes.

Experience facilitating workshops and working directly with business stakeholders and senior management.

Good understanding of cybersecurity governance, compliance frameworks, and risk management best practices.

Native or fluent Polish (required).

Professional proficiency in English.

Nice to have

Experience working inEnergy, Utilities, Manufacturing, or other industrial environments.

Basic understanding ofOperational Technology (OT) / Industrial Control Systems (ICS)environments.

Experience withGRC platforms, such as Eramba, ServiceNow IRM, OneTrust, Archer, or Lansweeper.

Experience inThird-Party Risk Management (TPRM), including vendor security assessments and supplier risk management.

Professional certifications, such as:

CISM

CRISC

CISA

What we offer

Benefits such as private medical care, group insurance, and Multisport card.

Hybrid work model with occasional on-site presence.

Opportunity to work with experienced cybersecurity professionals on international projects.

Exposure to complex cybersecurity governance and compliance programmes in a regulated environment.

Continuous learning and professional development.

International, collaborative working environment with opportunities for long-term growth.

Join a growing team of dedicated professionals! We love to pass on the knowledge to grow excellence, speak our minds without playing politics, and just enjoy hanging around together. If you share our passions - we want to meet you!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Analyst & Information Security Officer
Senior GRC Analyst & Information Security Officer

Northland Power, Inc. • Poland

Hybrid
PLN 180,000 - 260,000
Pension plan
Health insurance
Wellbeing program
+1
Cybersecurity Governance Risk and Compliance Consultant
Cybersecurity Governance Risk and Compliance Consultant

RMM Consulting Group • Warszawa

On-site
PLN 180,000 - 300,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos SE • Wrocław

On-site
PLN 120,000 - 190,000
Cybersecurity Risk and Compliance Manager
Cybersecurity Risk and Compliance Manager

EY • Poland

Hybrid
PLN 80,000 - 110,000
Continuous learning opportunities
Flexible work options
Transformative leadership coaching
+1
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Warszawa

On-site
PLN 120,000 - 180,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Poland

On-site
PLN 150,000 - 200,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Opole

On-site
PLN 160,000 - 260,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Wrocław

On-site
PLN 180,000 - 240,000
Senior Cybersecurity Risk & Compliance Consultant
Senior Cybersecurity Risk & Compliance Consultant

EY • Katowice

Hybrid
PLN 200,000 - 320,000
Senior Consultant for Cyber Security
Senior Consultant for Cyber Security

EY • Poland

Hybrid
PLN 150,000 - 250,000
Continuous learning
Flexible success definition
Transformative leadership
+1