Lead Analyst - Cybersecurity (SITRM)

sysco

Warszawa

Hybrid

PLN 180,000 - 260,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Global cybersecurity team
Professional development opportunities

Job summary

Sysco seeks an experienced cybersecurity professional to lead the SITRM program in Krakow, Poland. The role focuses on executing security risk assessments for suppliers and coordinating with global vendor management, technology, and business functions to educate on cyber risk.

Responsibilities include negotiating cybersecurity terms in supplier agreements, implementing program enhancements, and delivering monthly metrics to stakeholders.

Qualifications

  • Bachelor's degree in Information Technology, Information Systems, Computer Science or related technical field.
  • 6+ years of IT audit, supplier IT risk, vendor, or third-party security risk management.

Responsibilities

  • Execute security risk assessment and analysis of suppliers across the lifecycle; primary contact for international supplier assessments.
  • Collaborate with stakeholders to review cybersecurity terms in supplier agreements.
  • Support program enhancements including assessment process and technical requirements; train team members on changes.
  • Prepare and communicate monthly program metrics and reporting to stakeholders.
  • Provide input on third-party security controls, exceptions, and remediation plans to improve the assessment process.
  • Support implementation and operation of program enhancements; train team on updated processes.

Skills

IT audit
Vendor risk
Cloud security
Security controls
Communication skills
Third-party risk

Education

Bachelor's in IT/CS

Tools

Archer

Job description

JOB DESCRIPTION

Location: Krakow, Poland (Hybrid)

Type: Full-time employment

Shift: 9 am to 5 .00 PM local Poland time

Job Summary

This role is responsible for executing and supporting Sysco's global Cybersecurity Supplier IT Risk Management (SITRM) Program

Responsibilities
  • Execute security risk assessment and analysis of suppliers across all stages of the supplier lifecycle and act as the primary point of contact for international supplier assessments and partner with global vendor management teams, technology, and business functions to educate and communicate cyber risk.
  • Collaborate with stakeholders to review Cybersecurity terms in supplier agreements
  • Support implementation and operation of program enhancement efforts including assessment process and technical requirements. Train team members and stakeholders on updated program and processes changes.
  • Prepare and communicate monthly program metrics and reporting to appropriate stakeholders.
  • Provide input on third party security controls, exceptions, and remediation plans to continuously improve assessment process to reduce cyber risk.
  • Support implementation and operation of program enhancement efforts including assessment process and technical requirements. Train team members and stakeholders on updated program and processes changes.
Qualifications
  • Bachelor ' s Degree in Information Technology , Information Systems, Computer Science or a related technical field of study . Related experience may be considered in lieu of required education .
  • 6 or more years of experience in IT audit, supplier IT risk, vendor, or third-party security risk management.
  • Solid e xperience in process improvement and re-engineering, business requirements capturing, and process flowcharts .
  • Solid experience in application, network, and cloud security domains and assessments.
  • Working experience third party security risk assessment methodologies and industry frameworks.
  • Working experience with third party security assessment and management tools (Archer preferred)
  • Knowledge of Shared Assessment Third-Party Risk Management practices and questionnaires.
  • Strong critical thinking and planning skills.
  • Experience in large enterprise environments .
  • Excellent oral and written communication and ability to engage with stakeholders across the enterprise.
Licenses/Certifications Required :

Certified Information on Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Shared Assessments Certified Third Party Risk Professional (CTPRP) or Certified Third Party Risk Assessor (CTPRA), Information Systems Security Architecture Professional (ISSAP), or Information Systems Security Engineering Professional (ISSEP)

Technical Skills and Abilities
  • Strong verbal and written communication, negotiation, analytical, time management, organizational, and relationship management skills.
  • Comfortable dealing with ambiguity, making decisions with sub-optimal/incomplete information.
  • Ability to analyze and challenge current working methods to create improvements in processes and result .
  • Experience working with cross functional teams .
  • Ability to work independently within a geographically dispersed team.
  • Understand and comply with all applicable company policies .
Why Join Us
  • Be part of a global cybersecurity team protecting a dynamic enterprise environment.
  • Opportunity to work with modern security technologies and drive tool innovation.
  • Collaborative culture with professional development opportunities.
  • Hybrid work model with our Kraków office as the primary location.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Analyst – Cybersecurity (M&A),SITRM
Senior Analyst – Cybersecurity (M&A),SITRM

FHLB Des Moines • Województwo małopolskie

On-site
PLN 217,233 - 289,644
Professional development opportunities
Collaborative culture
Hybrid work model
Senior Analyst – Cybersecurity (M&A),SITRM
Senior Analyst – Cybersecurity (M&A),SITRM

Sysco • Polska

Hybrid
PLN 180,000 - 300,000
Hybrid work model
Engineer - Cybersecurity (Vulnerability & Threat Management)
Engineer - Cybersecurity (Vulnerability & Threat Management)

FHLB Des Moines • Kraków

On-site
PLN 191,164 - 276,125
Hybrid Cyber Risk Lead – Global Supplier IT (SITRM)
Hybrid Cyber Risk Lead – Global Supplier IT (SITRM)

Sysco • Poland

Hybrid
PLN 180,000 - 240,000
Global cybersecurity team
Hybrid work Kraków office
Professional development
Cyber Risk Lead - SITRM Specialist (Hybrid)
Cyber Risk Lead - SITRM Specialist (Hybrid)

sysco • Warszawa

Hybrid
PLN 180,000 - 260,000
Hybrid work model
Global cybersecurity team
Professional development opportunities
Architect - Cybersecurity
Architect - Cybersecurity

sysco • Warszawa

Hybrid
PLN 180,000 - 280,000
Architect - Cybersecurity
Architect - Cybersecurity

FHLB Des Moines • Kraków

On-site
PLN 260,000 - 380,000
Hybrid work model
Engineer - Cybersecurity
Engineer - Cybersecurity

FHLB Des Moines • Województwo małopolskie

On-site
PLN 90,000 - 120,000
Professional development opportunities
Hybrid work model
Collaborative culture
Engineer - Cybersecurity (Vulnerability & Threat Management)
Engineer - Cybersecurity (Vulnerability & Threat Management)

Sysco Corporation • Poland

On-site
PLN 40,000 - 60,000
Professional development opportunities
Collaborative culture
Modern security technologies
(Cybersecurity) Threat and Controls Assessment Consultant
(Cybersecurity) Threat and Controls Assessment Consultant

Antal Poland • Kraków

Hybrid
PLN 180,000 - 240,000
B2B contract
Hybrid work model – 6 days per month
Lux Med private medical care
+2