GRC Information Security Specialist - ISO27001/NIS2 Focus

DS Smith Plc

Kraków

On-site

PLN 180,000 - 240,000

Full time

9 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

DS Smith Plc in Kraków seeks an I&T GRC professional to support information security and technology risk controls. You will contribute to certification and regulatory compliance efforts, including ISO27001 and NIS2, while working with CISO and IT leadership.

You will help design and assess security controls, manage third-party risk, and respond to customer assurance requests. Strong knowledge of standards and hands-on GRC tooling are essential.

Qualifications

  • Experience working in large, multinational, cross-functional teams supporting IT and business stakeholders.
  • Knowledge of recognised information and cybersecurity standards such as the NIST CSF, ISO27001, Information Security Forum SOGP.
  • Experience in information security controls design, documentation, assessment and/or assurance.
  • Experience handling information security customer questionnaires, supplier assurance and third-party risk management.
  • Hands-on experience with GRC platforms and Microsoft tooling including Power BI on SharePoint capabilities.
  • Familiarity with security domains such as policy frameworks, IT risk management and IT resilience.
  • Professional or academic qualification in relevant subject (CS, InfoSec, Legal or Data Protection).
  • Willingness to travel up to 20% and fluency in English.
  • Desire to achieve relevant certifications (CISSP, CISA, CISM) when applicable.

Responsibilities

  • Create information and cybersecurity documentation to support certification and regulatory requirements (e.g., ISO27001, EU NIS2).
  • Own or support information security controls and risk processes in collaboration with the I&T GRC team; assist with training and awareness.
  • Respond to customer security assurance requests and manage supplier security schedules.

Skills

GRC platforms
Power BI
Microsoft tooling
Information security
Risk management
ISO27001
Third-party risk management
Security training
Security certifications

Education

Information security / CS / Legal or Data Protection

Tools

GRC platforms
Power BI
SharePoint
Microsoft tooling

Job description

DS Smith Plc in Kraków seeks an I&T GRC professional to support information security and technology risk controls. You will contribute to certification and regulatory compliance efforts, including ISO27001 and NIS2, while working with CISO and IT leadership.

You will help design and assess security controls, manage third-party risk, and respond to customer assurance requests. Strong knowledge of standards and hands-on GRC tooling are essential.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith Europe • Kraków

On-site
PLN 150,000 - 210,000
GRC & Information Security Specialist - ISO27001/NIST CSF
GRC & Information Security Specialist - ISO27001/NIST CSF

DS Smith • Kraków

On-site
PLN 120,000 - 180,000
GRC Information Security Specialist — ISO27001 & Risk Controls
GRC Information Security Specialist — ISO27001 & Risk Controls

DS Smith Europe • Kraków

On-site
PLN 150,000 - 210,000
I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith • Kraków

On-site
PLN 120,000 - 180,000
I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith Plc • Kraków

On-site
PLN 180,000 - 240,000
Senior Cyber GRC & ISO 22301 Specialist
Senior Cyber GRC & ISO 22301 Specialist

Arup • Kraków

On-site
PLN 180,000 - 280,000
Cybersecurity Consultant - NIS2 & ISO 27001 Specialist
Cybersecurity Consultant - NIS2 & ISO 27001 Specialist

Atos Poland Global Services Sp. z o.o. • Województwo kujawsko-pomorskie

On-site
PLN 180,000 - 260,000
GRC Consultant
GRC Consultant

Webellian • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid work model
On-site presence occasionally
Private medical care
+2
Senior GRC & Cyber Risk Lead for FinTech
Senior GRC & Cyber Risk Lead for FinTech

OANDA Corporation • Kraków

On-site
PLN 180,000 - 230,000
Senior GRC Analyst
Senior GRC Analyst

OANDA Corporation • Kraków

On-site
PLN 180,000 - 230,000