I&T GRC Information Security Specialist

DS Smith Plc

Kraków

On-site

PLN 180,000 - 240,000

Full time

16 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

DS Smith Plc in Kraków seeks an I&T GRC professional to support information security and technology risk controls. You will contribute to certification and regulatory compliance efforts, including ISO27001 and NIS2, while working with CISO and IT leadership.

You will help design and assess security controls, manage third-party risk, and respond to customer assurance requests. Strong knowledge of standards and hands-on GRC tooling are essential.

Qualifications

  • Experience working in large, multinational, cross-functional teams supporting IT and business stakeholders.
  • Knowledge of recognised information and cybersecurity standards such as the NIST CSF, ISO27001, Information Security Forum SOGP.
  • Experience in information security controls design, documentation, assessment and/or assurance.
  • Experience handling information security customer questionnaires, supplier assurance and third-party risk management.
  • Hands-on experience with GRC platforms and Microsoft tooling including Power BI on SharePoint capabilities.
  • Familiarity with security domains such as policy frameworks, IT risk management and IT resilience.
  • Professional or academic qualification in relevant subject (CS, InfoSec, Legal or Data Protection).
  • Willingness to travel up to 20% and fluency in English.
  • Desire to achieve relevant certifications (CISSP, CISA, CISM) when applicable.

Responsibilities

  • Create information and cybersecurity documentation to support certification and regulatory requirements (e.g., ISO27001, EU NIS2).
  • Own or support information security controls and risk processes in collaboration with the I&T GRC team; assist with training and awareness.
  • Respond to customer security assurance requests and manage supplier security schedules.

Skills

GRC platforms
Power BI
Microsoft tooling
Information security
Risk management
ISO27001
Third-party risk management
Security training
Security certifications

Education

Information security / CS / Legal or Data Protection

Tools

GRC platforms
Power BI
SharePoint
Microsoft tooling

Job description

Why Is This Job For You

The I&T GRC function supports the CISO and IT leadership across a range of information security, cybersecurity and technology risk controls, in support of IT, business, regulatory and customer requirements.


Location – Krakow

The I&T GRC function supports a repeat? The I&T GRC function supports the CISO and IT leadership across a range of information security, cybersecurity and technology risk controls, in support of IT, business, regulatory and customer requirements. Reporting to the Head of I&T GRC or direct report thereof, the role provides internal information security control consultancy and assessment. Reporting to the Head of I&T GRC or direct report thereof, the role provides internal security controls consultancy and assessment, supports business and IT stakeholder third party risk management arrangements and operates greed I&T GRC operated processes or controls.


You Will


  • Create information and cybersecurity documentation (standards, processes, or guidance) in support of certification and compliance goals in the context of external certification and regulatory compliance requirements (e.g., ISO27001 and EU NIS2 implementation)

  • Own or support assigned agreed information security controls operated by I&T GRC e.g., risk process management, aspects of training and awareness in collaboration with wider team, support for desktop simulations

  • Respond to customer security assurance requirements. Supplier security schedule / assurance


You Have


  • Experience of working in large, multi-national and cross-functional teams supporting IT and business stakeholders

  • Good working knowledge of recognised information and cybersecurity standards such as the NIST CSF, ISO27001, Information Security Forum SOGP

  • Experience of information security controls design and documentation, assessment and/or assurance

  • Experience information security customer questionnaires, supplier assurance and third-party risk management

  • Hands on experience of GRC platforms and/or use of Microsoft tooling e.g., Power BI building on SharePoint capabilities

  • Knowledge of or practical experience of the range of information security and cyber security domains e.g.:

  • Security policy frameworks (e.g., policy, standards, guidelines, procedures)

  • IT and cyber security risk management process management and tools

  • IT resilience and recovery

  • Experience of configuring or administering GRC platforms and/or use of Microsoft tooling e.g., Power BI building on SharePoint capabilities, or security tools such as training and awareness or simulated phishing tools

  • Professional or academic qualification in relevant subject e.g., Computer Science, Information Security, Legal or Data Protection topics

  • Has achieved or has ambition to achieve relevant certification e.g., Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information Security Management (CISM) or related

  • Ability to travel up to 20%

  • Fluency in English

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith Europe • Kraków

On-site
PLN 150,000 - 210,000
I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith • Kraków

On-site
PLN 120,000 - 180,000
GRC Consultant
GRC Consultant

Webellian • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid work model
On-site presence occasionally
Private medical care
+2
GRC Information Security Specialist - ISO27001/NIS2 Focus
GRC Information Security Specialist - ISO27001/NIS2 Focus

DS Smith Plc • Kraków

On-site
PLN 180,000 - 240,000
Information Security Officer
Information Security Officer

Tradevest GmbH • Warszawa

On-site
PLN 180,000 - 280,000
Senior GRC Analyst
Senior GRC Analyst

OANDA Corporation • Kraków

On-site
PLN 180,000 - 230,000
Manager - Cyber Security
Manager - Cyber Security

KK Group • Szczecin

Hybrid
PLN 180,000 - 300,000
Architect - Cybersecurity
Architect - Cybersecurity

sysco • Warszawa

Hybrid
PLN 180,000 - 280,000
Lead Analyst - Cybersecurity (SITRM)
Lead Analyst - Cybersecurity (SITRM)

sysco • Warszawa

Hybrid
PLN 180,000 - 260,000
Hybrid work model
Global cybersecurity team
Professional development opportunities
IT Engineer Cyber Security (m/k)
IT Engineer Cyber Security (m/k)

SMA Solar Technology AG • Poland

On-site
PLN 90,000 - 130,000