Get more replies from employers
Send a job-specific resume in minutes.
Webellian is seeking a GRC Consultant to join our Cybersecurity team and support governance, risk, and compliance initiatives for an international client in the energy sector.
You will implement ISMS aligned with ISO/IEC 27001:2022, help establish control frameworks, and collaborate with stakeholders to prepare for audits and regulatory reviews.
Webellian is a well-established Digital Transformation and IT consulting company committed to creating a positive impact for our clients. We strive to make a meaningful difference in diverse sectors such as insurance, banking, healthcare, retail, and manufacturing. Our passion for cutting-edge and disruptive technologies, as well as our shared values and strong principles, are what motivate us. We are a community of engineers and senior advisors who work with our clients across industries, playing a deep and meaningful role in accelerating and realizing their vision and strategy.
We are looking for aGRC Consultant to join our Cybersecurity team and support the implementation of cybersecurity governance and regulatory compliance initiatives for one of our international clients operating in the energy sector.
In this role, you will support the implementation of anInformation Security Management System (ISMS)aligned with an international cybersecurity governance framework while ensuring compliance with applicable Polish cybersecurity regulations. You will help establish aunified control framework that satisfies both corporate security requirements and local regulatory obligations.
Working closely with client stakeholders, you will drive Governance, Risk & Compliance (GRC) activities, facilitate workshops, coordinate risk management processes, and prepare the organization for internal and external audits. This is an excellent opportunity for someone who enjoys combining cybersecurity, governance, compliance, and stakeholder management in an international environment.
Support the implementation and continuous improvement of anISO/IEC 27001:2022-compliant Information Security Management System (ISMS).
Develop and maintain information security policies, standards, procedures, and governance documentation.
Build and maintain cybersecurity risk registers, including risk identification, assessment, treatment plans, ownership, and follow-up.
Conduct cybersecurity risk assessments, Business Impact Analyses (BIA), and facilitate workshops with business stakeholders.
Map security controls againstISO/IEC 27001:2022, NIS2, and other applicable regulatory and organizational requirements.
Coordinate Third-Party Risk Management (TPRM) activities, including vendor security assessments and supplier risk classification.
Collaborate with internal stakeholders to define and review information security requirements in supplier contracts.
Build and maintain IT asset inventories and support the documentation of business processes and data flows.
Contribute to vulnerability management planning and compliance evidence collection.
Develop and maintain incident response and business recovery documentation.
Prepare documentation and evidence required for internal and external compliance audits.
Work closely with client stakeholders to ensure the successful delivery of cybersecurity governance and compliance initiatives.
7+ years of experience in Governance, Risk & Compliance (GRC), Information Security, or Cybersecurity Governance.
Hands‑on experience implementing or maintaining an Information Security Management System (ISMS) based onISO/IEC 27001:2022 or a similar information security framework.
Current working knowledge of NIS2 and the Polish Cybersecurity Act (uKSC), with experience applying their requirements in cybersecurity governance, compliance, or ISMS initiatives.
Experience supporting cybersecurity compliance or regulatory governance initiatives.
Practical experience managing cybersecurity risk registers and risk treatment processes.
Experience facilitating workshops and working directly with business stakeholders and senior management.
Good understanding of cybersecurity governance, compliance frameworks, and risk management best practices.
Native or fluent Polish (required).
Professional proficiency in English.
Experience working inEnergy, Utilities, Manufacturing, or other industrial environments.
Basic understanding ofOperational Technology (OT) / Industrial Control Systems (ICS)environments.
Experience withGRC platforms, such as Eramba, ServiceNow IRM, OneTrust, Archer, or Lansweeper.
Experience inThird-Party Risk Management (TPRM), including vendor security assessments and supplier risk management.
Professional certifications, such as:
CISM
CRISC
CISA
Benefits such as private medical care, group insurance, and Multisport card.
Hybrid work model with occasional on-site presence.
Opportunity to work with experienced cybersecurity professionals on international projects.
Exposure to complex cybersecurity governance and compliance programmes in a regulated environment.
Continuous learning and professional development.
International, collaborative working environment with opportunities for long-term growth.
Join a growing team of dedicated professionals! We love to pass on the knowledge to grow excellence, speak our minds without playing politics, and just enjoy hanging around together. If you share our passions - we want to meet you!