GRC & Information Security Specialist - ISO27001/NIST CSF

DS Smith

Kraków

On-site

PLN 120,000 - 180,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

DS Smith is seeking an I&T GRC professional to support information security controls, risk management, and awareness initiatives across the organization. The role involves documentation for ISO27001 and EU NIS2, and collaboration with IT and business stakeholders to improve security posture.

You will engage with customers and suppliers on assurance requirements, and may travel up to 20% for on-site engagements. Fluency in English is required.

Qualifications

  • Good working knowledge of information and cybersecurity domains and standards (e.g., NIST CSF, ISO27001).
  • Experience delivering/working within ISO27001, NIST CSF frameworks and third-party risk management processes.
  • Experience with GRC platforms and Microsoft tooling; ability to train and awareness campaigns.

Responsibilities

  • Support creation of information and cybersecurity documentation for certification and compliance (ISO27001, EU NIS2).
  • Own or support information security controls managed by I&T GRC, including risk process management and awareness campaigns.
  • Respond to customer security assurance requirements and supplier security schedules.

Skills

NIST CSF knowledge
ISO27001 knowledge
Information security frameworks
Communicating IT/InfoSec concepts
Analytical/problem-solving
Time management
Travel readiness

Education

Computer Science or Information Security degree
ISO27001 lead / ISC2 certification advantageous

Tools

GRC platforms
Microsoft tooling
Phishing simulation tools

Job description

DS Smith is seeking an I&T GRC professional to support information security controls, risk management, and awareness initiatives across the organization. The role involves documentation for ISO27001 and EU NIS2, and collaboration with IT and business stakeholders to improve security posture.

You will engage with customers and suppliers on assurance requirements, and may travel up to 20% for on-site engagements. Fluency in English is required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Information Security Specialist — ISO27001 & Risk Controls
GRC Information Security Specialist — ISO27001 & Risk Controls

DS Smith Europe • Kraków

On-site
PLN 150,000 - 210,000
I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith Europe • Kraków

On-site
PLN 150,000 - 210,000
I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith • Kraków

On-site
PLN 120,000 - 180,000
Senior GRC Analyst: InfoSec Governance & Risk
Senior GRC Analyst: InfoSec Governance & Risk

OANDA • Kraków

On-site
PLN 180,000 - 280,000
IT GRC Analyst
IT GRC Analyst

KK Group • Szczecin

On-site
PLN 120,000 - 190,000
ISO 27001 InfoSec & Compliance Specialist
ISO 27001 InfoSec & Compliance Specialist

Devonshire • Warszawa

On-site
PLN 180,000 - 280,000
International team
Professional development
Real impact on projects
+2
Senior Cyber GRC & ISO 22301 Specialist
Senior Cyber GRC & ISO 22301 Specialist

Arup • Kraków

On-site
PLN 180,000 - 280,000
IT Security Compliance Specialist | ISO 27001
IT Security Compliance Specialist | ISO 27001

Jobtailor • Warszawa

On-site
PLN 90,000 - 120,000
Senior Security GRC Architect - Fintech (Hybrid)
Senior Security GRC Architect - Fintech (Hybrid)

Capital • Warszawa

Hybrid
PLN 280,000 - 420,000
Competitive Salary
Hybrid work model
Generous time off
+2
Lead ISO GRC & IMS Architect (Remote)
Lead ISO GRC & IMS Architect (Remote)

Hyland • Katowice

Hybrid
PLN 337,000 - 350,000
Fully remote work
Flexible working hours
Private healthcare
+3