Information Security Manager

Nortal

Poland

On-site

PLN 240,000 - 360,000

Full time

48 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nortal is seeking an Information Security Manager to strengthen security across a complex technology landscape and embed a security-first culture. You will partner with engineering, product, technology and business teams to identify risks and ensure effective controls across AWS Cloud and on‑prem environments.

As a trusted security advisor, you will guide policies, risk management, vulnerability handling and incident response, and help integrate security into Agile development to deliver secure

Responsibilities

  • Define and support the delivery of information security initiatives aligned with business priorities and the wider security strategy.
  • Act as a security partner and trusted advisor to technology and business stakeholders across the Domain.
  • Promote a security-first culture and embed secure ways of working across teams.
  • Provide expert guidance on security policies, standards, controls and best practices.
  • Identify, assess and manage information security risks, ensuring pragmatic and cost-effective mitigation.
  • Support the protection of TUI’s critical systems, applications, data and other information assets.
  • Ensure appropriate security assurance, testing and controls are in place across the technology landscape.
  • Work closely with engineering and delivery teams to embed security into Agile and software development processes.
  • Support security operations, including vulnerability management, patching and security monitoring.
  • Coordinate the effective management of security incidents and ensure lessons learned are translated into improvements.
  • Monitor and support remediation of audit findings and security control gaps.
  • Help reduce the organisation’s attack surface and proactively identify emerging security risks.
  • Report on the effectiveness of the security programme using agreed KPIs and drive continuous improvement.
  • Work across both AWS Cloud and on-premises environments, ensuring appropriate security controls are implemented and maintained.
  • Collaborate with security teams and stakeholders across TUI’s international organisation.

Job description

Overview

We are looking for an Information Security Manager to help strengthen security across a complex technology landscape and embed a security-first culture across the organisation. In this role, you will work closely with engineering, product, technology, and business teams to identify and manage security risks, ensure effective security controls, and support teams in delivering secure and resilient solutions.


As an experienced security professional with a strong technical background, you will act as a trusted security advisor to stakeholders across the organisation. You will provide expert guidance on security policies, standards, risk management, vulnerability management, incident response, and security assurance. You will also help integrate security into Agile development processes and ensure that security practices are consistently applied across AWS Cloud and on-premises environments.


You will collaborate with Security Architects, engineering teams, and other security specialists to address complex security challenges, improve security maturity, protect critical assets and data, and continuously strengthen the overall security posture.


About Nortal

We’re Nortal. We think big and create cutting-edge digital solutions with a global reach. And with 25 years of experience, 2,700+ professional experts, and half a billion people worldwide impacted by our work, we believe we’ve got the numbers to back up that statement.


Our global teams have played a significant role in many Fortune 500 companies’ projects and systems and have been the driving force of digital transformation for governments, healthcare institutions, and leading enterprises worldwide. We combine best-in-class strategic consulting with software engineering, data, and design practices to bring our visions to life.


About TUI

TUI is a global business with over 70,000 people on board, a great history and challenging plans for building a digital future. TUI is the largest leisure, travel and tourism company globally, and it owns travel agencies, hotels, airlines, cruise ships and retail shops.


Responsibilities


  • Define and support the delivery of information security initiatives aligned with business priorities and the wider security strategy.

  • Act as a security partner and trusted advisor to technology and business stakeholders across the Domain.

  • Promote a security-first culture and embed secure ways of working across teams.

  • Provide expert guidance on security policies, standards, controls and best practices.

  • Identify, assess and manage information security risks, ensuring pragmatic and cost-effective mitigation.

  • Support the protection of TUI’s critical systems, applications, data and other information assets.

  • Ensure appropriate security assurance, testing and controls are in place across the technology landscape.

  • Work closely with engineering and delivery teams to embed security into Agile and software development processes.

  • Support security operations, including vulnerability management, patching and security monitoring.

  • Coordinate the effective management of security incidents and ensure lessons learned are translated into improvements.

  • Monitor and support remediation of audit findings and security control gaps.

  • Help reduce the organisation’s attack surface and proactively identify emerging security risks.

  • Report on the effectiveness of the security programme using agreed KPIs and drive continuous improvement.

  • Work across both AWS Cloud and on-premises environments, ensuring appropriate security controls are implemented and maintained.

  • Collaborate with security teams and stakeholders across TUI’s international organisation.


Qualifications


  • Proven experience leading or managing an information security capability within a large or complex organisation.

  • Strong technical understanding of information security, with previous experience in a technical security role.

  • Hands-on understanding of security within AWS Cloud environments.

  • Good knowledge of security within Agile software development and delivery processes.

  • Strong understanding of security operations and incident management across Cloud and on-premises environments.

  • Experience implementing or operating an Information Security Management System (ISMS) within a large organisation.

  • Good understanding of information security risk management, governance, controls and assurance.

  • Knowledge of international regulatory requirements, particularly data protection and privacy.

  • Familiarity with recognised security standards and frameworks such as ISO 27001, NIST, PCI DSS, OWASP and ITIL.

  • Strong understanding of vulnerability management, patching and security assurance.

  • Excellent stakeholder management and communication skills, with the ability to influence both technical and non-technical audiences.

  • Strong organisational and planning skills, with the ability to prioritise effectively and drive security initiatives to completion.

  • A pragmatic, commercial approach to security risk and decision-making.

  • Strong problem-solving skills and the ability to develop practical solutions to complex security challenges.

  • Ability to work effectively in an international, cross-functional environment.

  • A collaborative and proactive approach, with a focus on continuous improvement.


Certifications


  • AWS Cloud Practitioner or equivalent AWS certification

  • ISO 27001 Lead Implementer

  • CISSP

  • CISM

  • CISA

  • CompTIA Security+

  • CISMP

  • Following the applicable legal regulations, particularly Directive (EU) 2019/1937 of the European Parliament and of the Council on the protection of persons reporting breaches of Union law and its implementation into Polish law under the Act of December 4, 2021, on the Protection of Persons Reporting Breaches of Law (Journal of Laws 2021, item 2105), including Articles 4-6 governing whistleblower protection and reporting procedures, the company has implemented a Whistleblower Support Policy, ensuring anonymity, protection, and support for individuals reporting irregularities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Nortal • Kraków

Hybrid
PLN 180,000 - 260,000
24 working days vacation
11 national holidays
Health care: up to 10 paid sick days &
+6
Head of IT
Head of IT

SQUAD Ukraine Limited • Wrocław

On-site
Performance-based bonuses
Continuous growth opportunities
Private medical insurance
+1
Security Transformation Consultant (regular/senior) (She/He/They)
Security Transformation Consultant (regular/senior) (She/He/They)

Accenture • Warszawa, Łódź, Kraków, Wrocław

Hybrid
PLN 180,000 - 280,000
Permanent contract
Professional development
Private medical care
+3
Security Transformation Consultant (regular/senior) (She/He/They)
Security Transformation Consultant (regular/senior) (She/He/They)

Accenture Poland • Warszawa

Hybrid
PLN 180,000 - 240,000
Permanent employment contract
Private medical care
Life insurance
+2
IAM (IGA BAU) Engineer
IAM (IGA BAU) Engineer

Nortal • Poland

On-site
PLN 180,000 - 240,000
Security Operations Specialist
Security Operations Specialist

Keepit • Kraków

On-site
PLN 140,000 - 210,000
Official employment – Umowa o pracę
4 vacation days extra per year
3 days sick leave per year
+8
Application Security Specialist (regular/senior) (She/He/They)
Application Security Specialist (regular/senior) (She/He/They)

Accenture • Warszawa, Kraków, Wrocław, Łódź

Hybrid
PLN 180,000 - 260,000
Private medical care
Life insurance
Employee share purchase plan
+2
Head of Information Security & Compliance
Head of Information Security & Compliance

C&D Talent Advisory • Lublin

Hybrid
PLN 345,000 - 517,000
Private healthcare
Sport card
Life insurance
+1
Security Transformation Architect with German
Security Transformation Architect with German

VM.PL Software House • Wrocław

Hybrid
PLN 150,000 - 200,000
Remote work
Comprehensive benefits including healthcare
Company-sponsored language courses
Application Security Engineer
Application Security Engineer

AXA IT Solutions • Poland

Hybrid
PLN 180,000 - 240,000
Personal development
International environment
English work environment
+9