Get more replies from employers
Send a job-specific resume in minutes.
EY GDS Poland is hiring an Information Security Analyst – Associate/Senior Associate to join the security team in Poland. The role involves supporting security reviews, vulnerability management, and risk-based assessments across EY’s technology landscape from Wrocław or Katowice, with a hybrid work model (2 days in office, 3 days remote).
You will work on application and network security testing, compliance with standards, and third‑party assurance activities.
Location: Wrocław / Katowice – 2 days in office, 3 days remote
Let us introduce you to the job offer by EY GDS Poland – a member of the global integrated service delivery center network by EY. Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security, and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The Technology Assurance, Risk, and Policy (TARP) function within Information Security strives to create and promote a holistic Governance, Risk, and Compliance (GRC) program by building a robust, resilient, and proactive governance framework, supported by a strategic risk‑management approach and stringent compliance structures. It aims to integrate and align its GRC initiatives with the global firm’s objectives and emerging threats within the cybersecurity landscape.
The Technology Assurance team provides security assurance on EY’s deployed technology to internal and external stakeholders. Team members act as subject‑matter experts across a number of information and cyber‑security disciplines that include application and network penetration testing, vulnerability identification, information security audits, compliance with cyber‑security and regulatory frameworks, and coordination of security audits and assessments. All applications must pass through a security review prior to EY production usage. Security certification checks the compliance of the application against EY security standards. The team develops overall strategy and implements various technical attacks and penetration assessments, information security audits such as HITRUST, SOC 1 and SOC 2, to provide third‑party assurance to EY’s clients and senior leadership. It oversees and leads the technical audit process, including third‑party external assessments of client‑facing critical business applications, M365 Teams Apps, network, cloud configuration reviews, infrastructure reviews, UK Cyber Essentials Plus Certification and UK IT Health Check Certification. The team also manages and maintains the firm’s ISO 27001 certifications and is responsible for end‑to‑end delivery of attestation audits like SOC 1 and SOC 2. Technical compliance to regulatory frameworks such as International Standard on Quality Management (ISQM) is also a responsibility of the team.
An Information Security Analyst will work closely with team leads to assist with one of the security functional areas described above.
In compliance with the requirements of the Whistleblower Protection Act, our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions. Any misconduct should be reported through the EY Ethics Hotline.