An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Allegro.eu S.A. is seeking a Junior Information Security Specialist to assist in threat monitoring, basic risk analyses, and implementing security measures across the Allegro Group.
The role emphasizes governance, risk, and compliance within a growing cybersecurity team. You will help ensure policy compliance, support training initiatives, and contribute to regulatory adherence including GDPR, NIS2, and other standards.
The Junior Information Security Specialist supports the Information Security Team in protecting confidential data by monitoring threats, performing basic risk analysis tasks, and implementing security measures as well as monitoring policy compliance. They participate in maintaining compliance with internal policies and regulations, ensuring that basic security standards are met on a daily basis. This role is crucial for maintaining foundational security practices while providing the specialist with valuable experience to grow and develop further in the Cybersecurity field with an emphasis on the governance, risk, and compliance (GRC) domain.
Main responsibilities:
Security Policy: Assist with developing its provisions and monitoring the compliance level across Group Companies.
Data Policy: Monitor compliance with its provisions and help define rules for sharing data outside the Allegro Group.
Non-Disclosure Agreements (NDAs) & third parties: Conduct basic security risk reviews for NDAs and third-party data-sharing requests, advising Group Companies accordingly.
Security awareness: Support the delivery of mandatory and non-mandatory training courses and initiatives to ensure appropriate levels of data security awareness among employees and contractors of Group Companies.
Regulatory compliance: Assist with verifying the security measures used by Group Companies to ensure compliance with applicable security policies and regulations (DORA, NIS2, MAR, AI Act, GDPR, etc.) as well as information security principles, frameworks, and policies.
Risk management: Provide basic support to employees of Group Companies in the identification and evaluation of various information security risks.
Physical security: Assist in defining physical security requirements for offices and supervision of their implementation.
Incident management: Support the development of incident response procedures and participate in administrative and operational handling of incidents.
Corrective actions: Recommend basic corrective and improvement actions for Group Companies and monitor the process of their implementation.
Experience: 0.5–2 years of experience (including internships or work placements) in information security, data protection, compliance, IT audit, or technical/legal consulting.
Education: Degree (completed or in progress) in Law, Administration, Cybersecurity, Computer Science, IT Management, or a related field is preferred.
GRC foundations: Basic understanding of information security management principles, risk assessment methodologies, and regulatory compliance.
Regulatory awareness: Familiarity with major regulations (e.g. DORA, NIS2, AI Act, MAR, GDPR) and standard security frameworks (e.g. ISO/IEC 27001, NIST).
Agreement review: Ability to review security and privacy contractual provisions (such as NDAs and data-sharing agreements) to identify organisational risk and to ensure appropriate security for various collaboration scenarios, both internal (within the Allegro Group) as well as external ones.
Languages: Very good spoken and written English enabling seamless work with technical/legal documentation, regulations, and within an international team.
Soft skills: Strong communication skills and diplomacy (ability to translate technical/legal requirements into clear business language), paired with analytical thinking and strong attention to detail.
Get to know our team, take a peek at our office life and check out what else we do at Allegro.