Lead Analyst - Cybersecurity (SITRM)

Sysco

Poland

Hybrid

PLN 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Global cybersecurity team
Hybrid work Kraków office
Professional development

Job summary

Sysco in Kraków, Poland, seeks a Lead Analyst - Cybersecurity (SITRM) to execute and support its global SITRM program. This hybrid, full-time role is based in Kraków with standard local hours.

The successful candidate will assess supplier cyber risk across the lifecycle and partner with vendor management, technology, and business teams to reduce risk. A Bachelor's in IT and 6+ years in security risk are expected; strong communication and cross-functional skills are essential.

Qualifications

  • Bachelor’s degree in IT, information systems, computer science or related field.
  • 6+ years in IT audit, supplier IT risk or third-party security risk management.
  • Strong requirements gathering, process mapping and documenting.
  • Experience in application, network and cloud security assessments.
  • Familiar with third-party risk assessment methodologies and tools.
  • Knowledge of Shared Assessments TPRM practices and questionnaires.
  • Excellent written and verbal communication across stakeholders.

Responsibilities

  • Execute security risk assessments for suppliers across lifecycle and act as primary contact for international assessments.
  • Collaborate with stakeholders to review cybersecurity terms in supplier agreements.
  • Support program enhancements and train teams on changes.
  • Prepare and communicate monthly program metrics to stakeholders.
  • Provide input on third-party security controls, exceptions and remediation plans.

Skills

Security risk assessment
Vendor management
Stakeholder communication
Cloud security
IT audit
Cross-functional collaboration
Supply chain risk
Analytical thinking
Training & mentoring

Education

Bachelor’s Degree in IT

Tools

Archer

Job description

JOB DESCRIPTION

Lead Analyst - Cybersecurity (SITRM)

Location: Krakow, Poland (Hybrid)

Type: Full-time employment

Shift:9 amto5.00 PMlocal Poland time

Job Summary

This roleis responsible forexecuting and supporting Sysco’sglobalCybersecurity Supplier IT Risk Management(SITRM) Program

Responsibilities

  • Execute security risk assessment and analysis of suppliers across all stages of the supplier lifecycle and act as the primary point of contact for international supplier assessments and partner with global vendor management teams, technology, and business functions to educate and communicate cyber risk.

  • Collaborate with stakeholders to review Cybersecurity terms in supplier agreements

  • Support implementation and operationof program enhancement effortsincluding assessment process and technical requirements.Train team members and stakeholders on updated program and processes changes.

  • Prepare and communicate monthly program metrics andreportingto appropriate stakeholders.

  • Provide input on third party security controls, exceptions, and remediation plans to continuously improve assessmentprocessto reduce cyber risk.

  • Support implementation and operationof program enhancement effortsincluding assessment process and technical requirements.Train team members and stakeholders on updated program and processes changes.

Qualifications

  • Bachelor’s Degree in InformationTechnology,Information Systems,Computer Science or a relatedtechnicalfield of study.Related experience may be considered in lieu of required education.

  • 6 or more years of experience in IT audit, supplier IT risk, vendor, or third-party security risk management.

  • Solid experience in process improvement and re-engineering, business requirements capturing, and process flowcharts.

  • Solid experience in application, network, and cloud security domains and assessments.

  • Working experience third party security risk assessment methodologies and industry frameworks.

  • Working experience with third party security assessment and management tools (Archer preferred)

  • Knowledge of Shared Assessment Third-Party Risk Management practices and questionnaires.

  • Strong critical thinking and planning skills.

  • Experience in large enterprise environments.

  • Excellent oral and written communication and ability to engage with stakeholders across the enterprise.

Licenses/Certifications Required** :**

Certified Information on Systems Security Professional (CISSP), Certified Information Security Manager (CISM),Certified Information Systems Auditor (CISA),Shared Assessments Certified Third Party Risk Professional (CTPRP) or Certified Third Party Risk Assessor (CTPRA), Information Systems Security Architecture Professional (ISSAP),orInformation Systems Security Engineering Professional (ISSEP)

Technical Skills and Abilities

  • Strong verbal and written communication, negotiation, analytical, time management, organizational, and relationship management skills.

  • Comfortable dealing with ambiguity, making decisions with sub-optimal/incomplete information.

  • Ability to analyze and challenge current working methods to create improvements in processes andresult.

  • Experience working with cross functional teams.

  • Ability to work independently within a geographically dispersed team.

  • Understand andcomply withall applicable company policies.

Why Join Us

  • Be part of a global cybersecurity team protecting a dynamic enterprise environment.

  • Opportunity to work with modern security technologies and drive tool innovation.

  • Collaborative culture with professional development opportunities.

  • Hybrid work model with our Kraków office as the primary location.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Analyst - Cybersecurity (Risk Management & Compliance)
Senior Analyst - Cybersecurity (Risk Management & Compliance)

Sysco • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid work model
Global cybersecurity team
Senior Analyst – Cybersecurity (M&A),SITRM
Senior Analyst – Cybersecurity (M&A),SITRM

FHLB Des Moines • Województwo małopolskie

Hybrid
PLN 217,000 - 290,000
Professional development opportunities
Collaborative culture
Hybrid work model
Engineer - Cybersecurity
Engineer - Cybersecurity

Sysco • Poland

Hybrid
PLN 180,000 - 240,000
Project Manager - (Cyber)
Project Manager - (Cyber)

Sysco • Poland

Hybrid
PLN 140,000 - 200,000
Hybrid work model
Engineer - Cybersecurity (Vulnerability & Threat Management)
Engineer - Cybersecurity (Vulnerability & Threat Management)

FHLB Des Moines • Kraków

Hybrid
PLN 191,000 - 277,000
Hybrid Cyber Risk Lead – Global Supplier IT (SITRM)
Hybrid Cyber Risk Lead – Global Supplier IT (SITRM)

Sysco • Poland

Hybrid
PLN 180,000 - 240,000
Global cybersecurity team
Hybrid work Kraków office
Professional development
Architect - Cybersecurity
Architect - Cybersecurity

FHLB Des Moines • Kraków

Hybrid
PLN 260,000 - 380,000
Hybrid work model
Engineer - Cybersecurity
Engineer - Cybersecurity

FHLB Des Moines • Województwo małopolskie

Hybrid
PLN 90,000 - 120,000
Professional development opportunities
Hybrid work model
Collaborative culture
Engineer - Cybersecurity (Vulnerability & Threat Management)
Engineer - Cybersecurity (Vulnerability & Threat Management)

Sysco Corporation • Poland

Hybrid
PLN 40,000 - 60,000
Professional development opportunities
Collaborative culture
Modern security technologies
Senior Network Cybersecurity Engineer (f/m/x)
Senior Network Cybersecurity Engineer (f/m/x)

Sii Poland • Warszawa

On-site
PLN 180,000 - 260,000
Profit sharing
Regular events and trips
Medical care
+2