Information Security Officer

Tradevest GmbH

Warszawa

On-site

PLN 180,000 - 280,000

Full time

12 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Tradevest GmbH in Warsaw is looking for an Information Security Officer to own the security strategy and protect our data, systems and the client trust across the group. The role emphasizes resilience against evolving threats and proactive collaboration with stakeholders.

You will coordinate security objectives with executive leadership, establish, operate and advance our ISMS using the group’s GRC software, and create clear guidelines.

Qualifications

  • 3+ years of practical information security experience in a fast-growing company.
  • Certifications such as CISA, CISM, or ISO 27001 Lead Auditor preferred.
  • Strong knowledge of DORA, NIS2, and related regulatory requirements.

Responsibilities

  • In collaboration with management, align security objectives with group strategy.
  • Advise on information security issues and provide regular status reports.
  • Establish, operate and develop the ISMS framework using our GRC software.
  • Create and update security guidelines and procedures according to MaRisk, DORA and local regulations.
  • Plan, coordinate and execute audit procedures per multi-year audit plan.
  • Coordinate risks remediation and incident prevention measures.
  • Record and coordinate handling of information security incidents and follow-up.
  • Support risk analyses with process, information and risk owners.
  • Assist in emergency tests and update the emergency manual with owners.
  • Coordinate awareness and training on information security for target groups.
  • Assess cybersecurity posture of ICT third-party providers and review certifications.
  • Plan, coordinate and evaluate penetration testing and digital operational resilience testing under DORA.

Skills

Information security
Stakeholder collaboration
Auditing

Education

CISA / CISM / ISO 27001 Lead Auditor

Tools

GRC software

Job description

Your role

Take ownership of our information security strategy and help protect what matters most: our data, our systems, and the trust our clients place in us. In this role, you'll ensure all Group companies meet the highest security standards and stay resilient against emerging threats.


Your mission and responsibilities
  • Continuous coordination of information security objectives with the strategic objectives of the Tradevest Group.
  • Work directly with the management advising them on information security issues and provide regular reports on the status of information security.
  • Establishment, operation and further development of our information management system (ISMS) based on the GRC software we use.
  • Creating and updating security guidelines and procedures in accordance with current standards and legal requirements (MaRisk, DORA etc.) arising from the different regulatory jurisdictions we operate in, such as Germany and Poland.
  • Creation, coordination and implementation of audit procedures based on a multi-year audit plan.
  • Coordination and follow-up of measures to address risks and prevent information security incidents..
  • Recording and coordinating the handling of information security incidents as well as the corresponding analysis and follow-up of incidents.
  • Coordinating the ongoing and on-demand performance of information risk analyses and related activities in close cooperation with process, information and risk owners.
  • Supporting the implementation and documentation of emergency tests and updating the emergency manual in close cooperation with the process, information and risk owners.
  • Coordination of target group-oriented awareness-raising and training measures on the topic of information security.
  • Assessing the technical security posture of critical ICT third-party service providers in coordination with the Group's outsourcing management, including review of relevant certifications (e.g., ISO 27001, SOC 2)
  • Planning, coordinating and evaluating the results of penetration testing and digital operational resilience testing pursuant to Art. 24–27 DORA

Your qualifications and experience
  • At least three years of practical experience in the role of information security officer or in a comparable position in the field of information security in a fast-growing company.
  • Certifications such as CISA, CISM, or ISO 27001 Lead Auditor are highly preferred.
  • Very good knowledge of legal and regulatory requirements such as DORA (Digital Operational Resilience Act), NIS2 etc.
  • Strong business acumen combined with an intuition for proactive collaboration with stakeholders across the company and group entities.
  • Experience in implementing security strategies, policies, procedures, and standards.
  • Extensive knowledge of current and emerging cyber security technologies, document management and security operations.

Contract

B2B


Location

Warsaw

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Officer: ISMS & Regulatory Risk
Senior Information Security Officer: ISMS & Regulatory Risk

Tradevest GmbH • Warszawa

On-site
PLN 180,000 - 280,000
Head of Information Security and Compliance
Head of Information Security and Compliance

PulseRise Technologies LTD • Warszawa

Hybrid
PLN 400,000 - 640,000
Head of Information Security and Compliance
Head of Information Security and Compliance

PulseRise Technologies • Warszawa

Hybrid
PLN 320,000 - 520,000
Hybrid work
Security Senior Expert (ICT Regulatory Compliance) & Business Partner
Security Senior Expert (ICT Regulatory Compliance) & Business Partner

Provident Polska • Warszawa

On-site
PLN 180,000 - 280,000
Stable employment
Polish market experience
IT Audit & Cybersecurity Specialist
IT Audit & Cybersecurity Specialist

Square One Resources Limited • Warszawa

Hybrid
PLN 74,000 - 124,000
Hybrid work
IT Security Specialist
IT Security Specialist

Experis ManpowerGroup Sp. z o.o. • Poland

Hybrid
Medicover healthcare package
Multisport card
Access to an e-learning platform
+1
IT Information Security Manager (Security Policies Area)
IT Information Security Manager (Security Policies Area)

HeadHR • Wrocław

On-site
PLN 70,000 - 90,000
Attractive salary based on an employment contract
Medical package
Sports card
+1
IT Engineer Cyber Security (m/k)
IT Engineer Cyber Security (m/k)

SMA Solar Technology AG • Poland

On-site
PLN 90,000 - 130,000
Principal Consultant — IT & Cybersecurity
Principal Consultant — IT & Cybersecurity

7N Sp. z o. o. • Warszawa

Hybrid
PLN 320,000 - 520,000
Medical care
Multisport card
Life insurance
Regulatory Compliance Manager
Regulatory Compliance Manager

emagine Polska • Warszawa

On-site
PLN 248,000 - 276,000