I&T GRC Information Security Specialist

DS Smith Europe

Kraków

On-site

PLN 150,000 - 210,000

Full time

13 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

DS Smith Europe seeks an information security and GRC professional to support certification and compliance efforts, collaborate with IT leadership, and manage security controls and risk processes. The role includes engaging with customers and suppliers to meet assurance requirements and may involve on-site visits.

Candidates should have strong knowledge of ISO27001, NIST CSF, and related frameworks, with fluency in English and the ability to communicate complex security concepts to non-IT

Qualifications

  • Good working knowledge of recognised information and cybersecurity domains, and standards such as the NIST CSF, ISO27001 or similar.
  • Experience delivering and working within frameworks such as ISO27001, NIST CSF or similar.
  • Experience in information security controls design, documentation, assessment or assurance.
  • Experience with information security customer questionnaires and third-party risk management.
  • Ability to communicate IT/information security concepts to non-IT stakeholders.

Responsibilities

  • Support creation of information and cybersecurity documentation in support of certification and regulatory compliance (e.g., ISO27001 and EU NIS2).
  • Own or support information security controls operated by I&T GRC, including risk process management and awareness in collaboration with the team.
  • Respond to customer security assurance requirements and supplier assurance schedules.

Skills

GRC knowledge
ISO27001/NIST CSF
English fluency
Stakeholder communication
Information security concepts
Analytical skills

Education

Relevant qualification in Computer Science or Information Security

Tools

GRC platforms
Microsoft tooling

Job description

Location – Krakow
Why is this job for you:

The I&T GRC function supports the CISO and IT leadership across a range of information security, cybersecurity and technology risk controls, in support of IT, business, regulatory and customer requirements.

Reporting to the Head of I&T GRC or direct report thereof, the role provides internal information security control consultancy and assessment, supports business and IT stakeholder third party risk management arrangements and operates agreed I&T GRC operated processes or controls.

You will:
  • Support creation information and cybersecurity documentation (standards, processes, or guidance) in support of certification and compliance goals in the context of external certification and regulatory compliance requirements (e.g., ISO27001 and EU NIS2 implementation)
  • Own or support assigned agreed information security controls operated by I&T GRC e.g., aspects of information security management, risk process management, training and awareness in collaboration with wider team, support desktop simulations
  • Respond to customer security assurance requirements, and supplier security schedule / assurance
You have:
  • Good working knowledge of recognised information and cybersecurity domains, and standards such as the NIST CSF, ISO27001 or similar
Experience in:
  • delivering and working within frameworks such as ISO27001, NIST CSF or similar
  • information security controls design and documentation, assessment and/or assurance
  • information security customer questionnaires, supplier assurance and third-party risk management
  • facilitating risk and control processes, or cyber scenario desktop simulations
  • planning and delivering information security awareness campaigns
  • Working knowledge / practical experience of GRC platforms and/or use of Microsoft tooling, training and awareness or simulated phishing tools
  • Strong analytical and problem-solving skills
  • Effective time management skills and ability to plan against multiple competing demands
  • Ability to build effective working relationships across technology and business stakeholders providing GRC advice and support
  • Ability to communicate IT, information security or cybersecurity concepts to non-IT stakeholders.
  • Professional or academic qualification in relevant subject e.g., Computer Science, Information Security and/or goals to work toward certifications such as ISO27001 lead, ISC2 certifications, CISM, CRISC would be advantageous
  • Fluency in English
  • The role may include occasional planned travel (‘on-site’ visits) to DS Smith sites (international) in support of the business engagement outlined. Ability to travel up to 20%
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith • Kraków

On-site
PLN 120,000 - 180,000
GRC Consultant
GRC Consultant

Webellian • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid work model
On-site presence occasionally
Private medical care
+2
GRC & Information Security Specialist - ISO27001/NIST CSF
GRC & Information Security Specialist - ISO27001/NIST CSF

DS Smith • Kraków

On-site
PLN 120,000 - 180,000
GRC Information Security Specialist — ISO27001 & Risk Controls
GRC Information Security Specialist — ISO27001 & Risk Controls

DS Smith Europe • Kraków

On-site
PLN 150,000 - 210,000
IT GRC Analyst
IT GRC Analyst

KK Group • Szczecin

On-site
PLN 120,000 - 190,000
Head of Information Security and Compliance
Head of Information Security and Compliance

PulseRise Technologies • Warszawa

Hybrid
PLN 320,000 - 520,000
Hybrid work
Senior Analyst - Cybersecurity (Risk Management & Compliance)
Senior Analyst - Cybersecurity (Risk Management & Compliance)

Sysco • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid work model
Global cybersecurity team
Head of Information Security and Compliance
Head of Information Security and Compliance

PulseRise Technologies LTD • Warszawa

Hybrid
PLN 400,000 - 640,000
Senior GRC Analyst
Senior GRC Analyst

OANDA Corporation • Kraków

On-site
PLN 180,000 - 230,000
Senior Cyber GRC & ISO 22301 Specialist
Senior Cyber GRC & ISO 22301 Specialist

Arup • Kraków

On-site
PLN 180,000 - 280,000