I&T GRC Information Security Specialist

DS Smith

Kraków

On-site

PLN 120,000 - 180,000

Full time

13 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

DS Smith is seeking an I&T GRC professional to support information security controls, risk management, and awareness initiatives across the organization. The role involves documentation for ISO27001 and EU NIS2, and collaboration with IT and business stakeholders to improve security posture.

You will engage with customers and suppliers on assurance requirements, and may travel up to 20% for on-site engagements. Fluency in English is required.

Qualifications

  • Good working knowledge of information and cybersecurity domains and standards (e.g., NIST CSF, ISO27001).
  • Experience delivering/working within ISO27001, NIST CSF frameworks and third-party risk management processes.
  • Experience with GRC platforms and Microsoft tooling; ability to train and awareness campaigns.

Responsibilities

  • Support creation of information and cybersecurity documentation for certification and compliance (ISO27001, EU NIS2).
  • Own or support information security controls managed by I&T GRC, including risk process management and awareness campaigns.
  • Respond to customer security assurance requirements and supplier security schedules.

Skills

NIST CSF knowledge
ISO27001 knowledge
Information security frameworks
Communicating IT/InfoSec concepts
Analytical/problem-solving
Time management
Travel readiness

Education

Computer Science or Information Security degree
ISO27001 lead / ISC2 certification advantageous

Tools

GRC platforms
Microsoft tooling
Phishing simulation tools

Job description

Location - Krakow
Why is this job for you:

The I&T GRC function supports the CISO and IT leadership across a range of information security, cybersecurity and technology risk controls, in support of IT, business, regulatory and customer requirements. Reporting to the Head of I&T GRC or direct report thereof, the role provides internal information security control consultancy and assessment, supports business and IT stakeholder third party risk management arrangements and operates agreed I&T GRC operated processes or controls.

You will:

Support creation information and cybersecurity documentation (standards, processes, or guidance) in support of certification and compliance goals in the context of external certification and regulatory compliance requirements (e.g., ISO27001 and EU NIS2 implementation) Own or support assigned agreed information security controls operated by I&T GRC e.g., aspects of information security management, risk process management, training and awareness in collaboration with wider team, support desktop simulations Respond to customer security assurance requirements, and supplier security schedule / assurance

You have:
  • Good working knowledge of recognised information and cybersecurity domains, and standards such as the NIST CSF, ISO27001 or similar
  • Experience in: delivering and working within frameworks such as ISO27001, NIST CSF or similar information security controls design and documentation, assessment and/or assurance information security customer questionnaires, supplier assurance and third-party risk management facilitating risk and control processes, or cyber scenario desktop simulations planning and delivering information security awareness campaigns
  • Working knowledge / practical experience of GRC platforms and/or use of Microsoft tooling, training and awareness or simulated phishing tools
  • Strong analytical and problem-solving skills
  • Effective time management skills and ability to plan against multiple competing demands
  • Ability to build effective working relationships across technology and business stakeholders providing GRC advice and support
  • Ability to communicate IT, information security or cybersecurity concepts to non-IT stakeholders.
  • Professional or academic qualification in relevant subject e.g., Computer Science, Information Security and/or goals to work toward certifications such as ISO27001 lead, ISC2 certifications, CISM, CRISC would be advantageous
  • Fluency in English
  • The role may include occasional planned travel (‘on-site’ visits) to DS Smith sites (international) in support of the business engagement outlined. Ability to travel up to 20%

We are DS Smith, together with International Paper, we are a global leader in sustainable packaging solutions and other fibre-based products. We believe a better, more sustainable tomorrow is possible with the right people, who challenge and support one another to enact positive change. We employ more than 60,000 colleagues in North America and Europe, Middle East and Africa (EMEA), who are experts in innovation, manufacturing, design, sales, sustainability, supply chain, and much more. Together with our customers, we make the world safer and more productive, one sustainable packaging solution at a time. Become part of a world-leading organisation and do your best work with us!

As the journey continues of bringing together the strengths of both organisations, during your candidate experience you may engage with our colleagues from International Paper! You could visit an International Paper or DS Smith site or office.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith Europe • Kraków

On-site
PLN 150,000 - 210,000
Security Analyst
Security Analyst

DS Smith • Kraków

On-site
PLN 100,000 - 150,000
GRC & Information Security Specialist - ISO27001/NIST CSF
GRC & Information Security Specialist - ISO27001/NIST CSF

DS Smith • Kraków

On-site
PLN 120,000 - 180,000
GRC Information Security Specialist — ISO27001 & Risk Controls
GRC Information Security Specialist — ISO27001 & Risk Controls

DS Smith Europe • Kraków

On-site
PLN 150,000 - 210,000
IT Business Analyst SAP FICO (CO-PA & Costing)
IT Business Analyst SAP FICO (CO-PA & Costing)

DS Smith • Kraków

On-site
PLN 180,000 - 270,000
Senior Analyst - Cybersecurity (Risk Management & Compliance)
Senior Analyst - Cybersecurity (Risk Management & Compliance)

Sysco • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid work model
Global cybersecurity team
Procurement Category Manager – Logistics
Procurement Category Manager – Logistics

DS Smith • Kraków

On-site
PLN 120,000 - 190,000
GRC Consultant
GRC Consultant

Webellian • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid work model
On-site presence occasionally
Private medical care
+2
IT Business Analyst SAP FICO (Invoice Automation ReadSoft)
IT Business Analyst SAP FICO (Invoice Automation ReadSoft)

DS Smith • Kraków

On-site
PLN 180,000 - 240,000
IT GRC Analyst
IT GRC Analyst

KK Group • Szczecin

On-site
PLN 120,000 - 190,000