IT GRC Analyst

KK Group

Szczecin

On-site

PLN 120,000 - 190,000

Full time

9 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

KK Group in Szczecin is looking for an IT GRC Analyst to manage security projects, maintain the ISMS, and assess risks across networks, servers and services in IT and OT environments.

You will embed governance, risk and compliance into project lifecycles and support internal audits and regulatory requirements while driving continuous improvement of the security governance framework.

Qualifications

  • Experience with IT governance, risk management and compliance activities.
  • Knowledge of IT and OT environments (networks, servers, services).
  • Familiarity with ISMS frameworks and internal audit practices.

Responsibilities

  • Provide project management support across KK for security, risk, and compliance initiatives.
  • Coordinate cross-functional stakeholders to ensure timely delivery of GRC-related projects and integrate governance and risk into initiatives.
  • Identify, assess and manage risks related to networks, servers and services across IT and OT environments.
  • Maintain risk assessments and risk treatment plans in collaboration with technical and business stakeholders.
  • Support continuous risk monitoring and reporting.
  • Contribute to development and improvement of existing systems from a GRC perspective.
  • Support governance and risk requirements in new projects and system implementations.
  • Ensure security, risk and compliance considerations are embedded throughout project lifecycles.
  • Act as a key contributor for maintaining the ISMS and aligning it with standards and regulatory requirements.
  • Perform and support internal audits related to information security and compliance; document findings and remediation actions.

Job description

In our factory in Szczecin, we are looking for an IT GRC Analyst (Governance, Risk and Compliance). This role focuses on managing security-related projects, maintaining the Information Security Management System (ISMS), assessing risks across networks, servers, and services, and ensuring alignment with regulatory and internal requirements. The position plays a key role in supporting secure operations, regulatory compliance, and the continuous improvement of the organisation’s security governance framework.

Responsibilities
Governance & Project Management
  • Provide project management support across KK for security, risk, and compliance initiatives.
  • Coordinate cross-functional stakeholders to ensure timely delivery of GRC-related projects. Support integration of governance and risk requirements into ongoing and new initiatives.
  • Identify, assess, and manage risks related to networks, servers, and services across both IT and OT environments.
  • Maintain risk assessments and risk treatment plans in collaboration with technical and business stakeholders.
  • Support continuous risk monitoring and reporting.
Systems Development & Change Support
  • Contribute to development and improvement of existing systems from a GRC perspective.
  • Support governance and risk requirements in new projects and system implementations.
  • Ensure security, risk, and compliance considerations are embedded throughout project lifecycles.
Information Security Management System (ISMS)
  • Act as a key contributor and responsible party for maintaining the Information Security Management System (ISMS).
  • Support definition, maintenance, and improvement of security policies, standards, and procedures.
  • Ensure alignment of the ISMS with applicable standards and regulatory requirements.
Internal Audit & Compliance Assurance Plan
  • Perform, and support internal audits related to information security and compliance.
  • Document audit findings and track remediation actions.
Our Requirements:
  • Experience with IT governance, risk management, and compliance activities.
  • Knowledge of IT and OT environments, including networks, servers, and services.
  • Familiarity with ISMS frameworks and internal audit practices.
  • Understanding of regulatory and compliance requirements affecting information security.
  • Strong documentation, coordination, and stakeholder communication skills.
  • Familiarity with the ISO2700X standard
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Analyst
IT Security Analyst

KK Group • Szczecin

On-site
PLN 110,000 - 170,000
GRC Consultant
GRC Consultant

Webellian • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid work model
On-site presence occasionally
Private medical care
+2
I&T GRC Information Security Specialist
I&T GRC Information Security Specialist

DS Smith Europe • Kraków

On-site
PLN 150,000 - 210,000
Senior Analyst - Cybersecurity (Risk Management & Compliance)
Senior Analyst - Cybersecurity (Risk Management & Compliance)

Sysco • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid work model
Global cybersecurity team
IT GRC & ICFR Compliance Lead
IT GRC & ICFR Compliance Lead

Sii Polska • Poland

On-site
PLN 180,000 - 240,000
Senior GRC Analyst
Senior GRC Analyst

OANDA Corporation • Kraków

On-site
PLN 180,000 - 230,000
Information Security Officer
Information Security Officer

Tradevest GmbH • Warszawa

On-site
PLN 180,000 - 280,000
IT Compliance Manager (f/m/x)
IT Compliance Manager (f/m/x)

Sii Polska • Poland

On-site
PLN 180,000 - 240,000
IT Engineer Cyber Security (m/k)
IT Engineer Cyber Security (m/k)

SMA Solar Technology AG • Poland

On-site
PLN 90,000 - 130,000
IT GRC & ICFR Compliance Lead
IT GRC & ICFR Compliance Lead

Sii Poland • Piła

On-site
PLN 150,000 - 210,000
Great Place to Work
Strong professional growth
Global client exposure
+2