In our factory in Szczecin, we are looking for an IT GRC Analyst (Governance, Risk and Compliance). This role focuses on managing security-related projects, maintaining the Information Security Management System (ISMS), assessing risks across networks, servers, and services, and ensuring alignment with regulatory and internal requirements. The position plays a key role in supporting secure operations, regulatory compliance, and the continuous improvement of the organisation’s security governance framework.
Responsibilities
Governance & Project Management
- Provide project management support across KK for security, risk, and compliance initiatives.
- Coordinate cross-functional stakeholders to ensure timely delivery of GRC-related projects. Support integration of governance and risk requirements into ongoing and new initiatives.
- Identify, assess, and manage risks related to networks, servers, and services across both IT and OT environments.
- Maintain risk assessments and risk treatment plans in collaboration with technical and business stakeholders.
- Support continuous risk monitoring and reporting.
Systems Development & Change Support
- Contribute to development and improvement of existing systems from a GRC perspective.
- Support governance and risk requirements in new projects and system implementations.
- Ensure security, risk, and compliance considerations are embedded throughout project lifecycles.
Information Security Management System (ISMS)
- Act as a key contributor and responsible party for maintaining the Information Security Management System (ISMS).
- Support definition, maintenance, and improvement of security policies, standards, and procedures.
- Ensure alignment of the ISMS with applicable standards and regulatory requirements.
Internal Audit & Compliance Assurance Plan
- Perform, and support internal audits related to information security and compliance.
- Document audit findings and track remediation actions.
Our Requirements:
- Experience with IT governance, risk management, and compliance activities.
- Knowledge of IT and OT environments, including networks, servers, and services.
- Familiarity with ISMS frameworks and internal audit practices.
- Understanding of regulatory and compliance requirements affecting information security.
- Strong documentation, coordination, and stakeholder communication skills.
- Familiarity with the ISO2700X standard