IT Risk Consultant with European languages

Ernst & Young Advisory Services Sdn Bhd

Katowice

Hybrid

PLN 180,000 - 240,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

EY GDS Poland is seeking an IT Risk & Compliance Consultant to join an international team delivering IT regulatory compliance and cybersecurity maturity services to global clients. The role is based in Katowice with 2 days in the office and 3 days remote.

You will translate regulatory requirements into practical IT controls, supporting organizations across ISO 27001, NIST CSF, PCI DSS, HIPAA, GDPR, COBIT and ITIL, while contributing to audit-ready documentation and governance processes.

Qualifications

  • 3–5 years of IT risk, cybersecurity, or compliance experience.
  • University degree in Information Technology, Computer Science, Cybersecurity or related field.
  • English working proficiency (B2+).
  • Working proficiency in at least one additional language: French, German, Spanish, Dutch or Italian.

Responsibilities

  • Support design and review of IT regulatory and compliance frameworks across ISO 27001, NIST CSF, PCI DSS, HIPAA, HITRUST, GDPR, COBIT, ITIL.
  • Perform cyber/IT maturity assessments, gap assessments and control mapping with remediation roadmaps.
  • Assist with ISO 27001 programs including ISMS scoping, risk assessment and audit readiness.
  • Support PCI DSS assessments including cardholder data environment reviews and evidence preparation.
  • Draft policies, standards, governance frameworks, RACI models and senior management reports.

Skills

Analytical skills
Regulatory interpretation
Communication skills
Documentation & reporting
Cross-framework experience

Education

University degree in IT/CS/Cybersecurity

Tools

ISO 27001
NIST CSF
PCI DSS

Job description

IT Risk Consultant with European languages

Other locations: Primary Location Only

Date: 4 Sept 2026

Requisition ID: 1739179

Location: Katowice - 2 days in office / 3 days remote

Let us introduce you the job offer by EY GDS Poland, part of EY’s global integrated service delivery network.

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.

Join EY and help build a better working world.

The opportunity

As an IT Risk & Compliance Consultant in Digital Risk at EY GDS Poland you will join a high-performing, international team delivering IT regulatory compliance, cybersecurity maturity and IT control framework services to leading global clients.

You will translate regulatory, sector and framework requirements into practical IT and security controls, supporting organizations in designing, assessing and enhancing their compliance and risk management capabilities across multiple frameworks and jurisdictions.

Your key responsibilities

As a Consultant, you will contribute to regulatory compliance, cyber maturity and framework implementation engagements. Your responsibilities will include:

  • Supporting design and review of IT regulatory and compliance frameworks across ISO 27001, NIST CSF, PCI DSS, HIPAA, HITRUST, GDPR, COBIT, ITIL
  • Performing cyber / IT maturity assessments, gap assessments and control mapping, including development of remediation roadmaps
  • Assisting with ISO 27001 programs, including ISMS scoping, risk assessment, Statement of Applicability, control implementation and audit readiness
  • Supporting PCI DSS assessments, including review of cardholder data environments, security controls and evidence preparation
  • Contributing to HIPAA / HITRUST and regulated-data compliance projects in healthcare and life sciences environments
  • Drafting policies, standards, governance frameworks, RACI models and senior management reports
  • Identifying control gaps and supporting remediation planning and execution
  • Collaborating with stakeholders across IT, security, compliance and business teams to deliver high-quality, audit-ready documentation
Skills and attributes for success
  • Strong analytical and problem-solving skills with attention to detail
  • Ability to interpret regulatory requirements and translate them into practical, risk-based controls
  • Strong communication skills with the ability to explain compliance and risk topics to business and technical stakeholders
  • Structured approach to documentation, policy design and reporting
  • Proactive mindset and willingness to work across multiple frameworks and regulatory environments
  • Confident to deal with senior level contacts, internally and externally
  • Able to effectively summarize and conclude on work, applying appropriate documentation standards
  • Able to effectively prioritize and execute tasks in a high-pressure environment
To qualify for the role, you must have
  • 3–5 years of relevant experience in IT risk, cybersecurity, compliance or assurance
  • A university degree in Information Technology, Computer Science, Cybersecurity or a related field
  • English working proficiency (B2 and above)
  • Working proficiency (B2 and above) in at least one additional language: French, German, Spanish, Dutch or Italian

Working experience in at least one of the following areas:

  • ISO 27001 implementation or audit
  • PCI DSS or payment security assessments
  • HIPAA / HITRUST or healthcare compliance
  • IT regulatory compliance or external assurance engagements

Understanding at least one of the following frameworks or domains:

  • ISO 27001 / ISMS
  • NIST CSF or NIST 800-53
  • PCI DSS / payment security
  • GDPR / data protection
  • COBIT, ITIL
  • DORA, NIS2
Ideally, you’ll also have
  • Experience in cyber maturity assessments or security benchmarking
  • Understanding of risk taxonomy, control libraries and remediation planning
  • Experience working in regulated industries or multi-jurisdiction environments
  • Experience with policy drafting, governance models and executive reporting

Experience profile:

  • Background in IT risk, cybersecurity, compliance, audit or advisory
  • Past experience in at least one of the following industries: banking, payments, financial services, healthcare, pharma, retail, e-commerce, energy, utilities, transport, telecom or critical infrastructure sectors
  • Experience with regulatory reviews, certifications or compliance programs is a strong advantage

Certifications:

  • At least one of the following certifications: ISO 27001, ISO 27005, ISO 31000
  • Additional certifications such as HITRUST, COBIT or ITIL are an advantage
What we look for

We are looking for proactive and detail-oriented professionals who can translate complex regulatory requirements into practical controls, while supporting clients in building effective, scalable and evidence-driven compliance and risk management frameworks.

What we offer

EY Global Delivery Services (GDS) is a dynamic and truly global delivery network. We work across nine locations – Argentina, Hungary, India, the Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom – and with teams from all EY service lines, geographies and sectors, playing a vital role in the delivery of the EY growth strategy. From accountants to coders to advisory consultants, we offer a wide variety of fulfilling career opportunities that span all business disciplines. In GDS, you will collaborate with EY teams on exciting projects and work with well-known brands from across the globe. We’ll introduce you to an ever-expanding ecosystem of people, learning, skills and insights that will stay with you throughout your career.

  • Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
  • Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
  • Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
  • Diverse and inclusive culture:You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
About EY

EY | Building a better working world

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

In compliance with the requirements of the Whistleblower Protection Act, our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions. Any misconduct should be reported through the EY Ethics Hotline.

EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Digital Risk - IT Risk & Compliance Consultant
Digital Risk - IT Risk & Compliance Consultant

EY • Katowice

Hybrid
PLN 180,000 - 240,000
Digital Risk - IT Transformation Risk Consultant
Digital Risk - IT Transformation Risk Consultant

Ernst & Young Advisory Services Sdn Bhd • Katowice

Hybrid
PLN 180,000 - 260,000
Senior Cybersecurity Risk & Compliance Consultant
Senior Cybersecurity Risk & Compliance Consultant

Ernst & Young Advisory Services Sdn Bhd • Katowice

Hybrid
PLN 180,000 - 240,000
CBS Security Consultant - SDLC
CBS Security Consultant - SDLC

Ernst & Young Advisory Services Sdn Bhd • Wrocław

Hybrid
PLN 180,000 - 280,000
Senior Digital Identity & Privileged Access Management Consultant
Senior Digital Identity & Privileged Access Management Consultant

Ernst & Young Advisory Services Sdn Bhd • Katowice

Hybrid
PLN 120,000 - 190,000
Continuous learning
Career development
Global exposure
+1
Cybersecurity Risk and Compliance Manager at EY
Cybersecurity Risk and Compliance Manager at EY

EY • Katowice

Hybrid
PLN 260,000 - 380,000
CBS Security Consultant - SDLC
CBS Security Consultant - SDLC

EY • Wrocław

Hybrid
PLN 180,000 - 240,000
Senior Cybersecurity Risk & Compliance Consultant
Senior Cybersecurity Risk & Compliance Consultant

EY • Katowice

Hybrid
PLN 200,000 - 320,000
Digital Risk - IT Transformation Risk Consultant
Digital Risk - IT Transformation Risk Consultant

EY • Katowice

Hybrid
PLN 180,000 - 270,000
Senior Cloud Security Consultant
Senior Cloud Security Consultant

Ernst & Young Advisory Services Sdn Bhd • Wrocław

Hybrid
PLN 180,000 - 280,000