Manager - Cyber Security

KK Group

Szczecin

Hybrid

PLN 180,000 - 300,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

KK Group is seeking a Cyber Security Manager to drive governance, risk management and incident response while aligning with NIS2, ISO 27001, and internal policies. The role supports hybrid work from Szczecin or remote Poland, with occasional travel to the Szczecin facility.

You will lead policy development, risk reporting, training programs, supplier risk assessments, and security reviews of new initiatives. A strong security leadership mindset is essential.

Qualifications

  • 5–8+ years in cybersecurity, IT security governance, risk management or compliance.
  • 2–3 years in a lead/manager role related to governance, risk, compliance or security operations.
  • Practical knowledge of NIS2, ISO 27001 ISMS, frameworks and risk methodologies.
  • Experience with risk assessments, risk registers, control validation and remediation tracking.
  • Strong incident response, escalation, post-incident reviews and regulatory reporting.
  • Solid understanding of IT infrastructure, networks, IAM, cloud security, backups and monitoring.

Responsibilities

  • Governance: develop and oversee information security policies aligned with laws and internal rules.
  • Reporting: provide cybersecurity status, risk and incident summaries to senior leadership.
  • Training: plan and coordinate mandatory cybersecurity awareness programs.
  • Management training: organize dedicated security training for leadership teams.
  • Risk: conduct periodic risk assessments across assets, systems and processes.
  • Vendor: assess supplier cybersecurity risks and track remediation actions.
  • Security reviews: evaluate new initiatives for Security by Design and Default.
  • Incident & BC/DR: oversee incident detection, response, and post-incident reviews.
  • Audits: support internal/external audits related to cybersecurity and risk.

Skills

NIS2 compliance
ISO 27001 ISMS
Risk assessment
Incident response
Governance & reporting
Vendor risk management
Stakeholder communication

Job description

Are you passionate about protecting organizations from evolving cyber threats while building strong security governance and risk management practices? Join KK Group and play a key role in strengthening our cybersecurity posture across the business.

We are looking for an experienced Cyber Security Manager who will drive security governance, risk management, compliance, and incident response initiatives while ensuring alignment with regulatory requirements, including NIS2, internal policies, and business objectives.

We are open to candidates based in the Szczecin area (hybrid) or working remotely from anywhere in Poland. We welcome applications from professionals across the country, with occasional travel to our Szczecin facility.

What You Will Be Doing
Governance & Reporting
  • Develop, maintain, and oversee Information Security Policies aligned with regulatory and internal requirements.
  • Provide regular cybersecurity status updates, risk reports, and incident summaries to senior leadership and the Management Board.
  • Plan and coordinate mandatory cybersecurity awareness training for employees.
  • Organize dedicated cybersecurity training sessions for management teams.
  • Conduct periodic risk assessments covering key assets, systems, and business processes.
  • Evaluate cybersecurity maturity and compliance of suppliers and service providers.
  • Perform security reviews of new business initiatives and IT projects, ensuring Security by Design and Security by Default principles.
Incident Handling & Business Continuity
  • Oversee security incident detection, triage, response, and post-incident reviews.
  • Ensure timely reporting of significant incidents in line with regulatory requirements and reporting timelines.
  • Supervise Business Continuity Planning (BCP) and Disaster Recovery (DR), including regular verification of backup effectiveness.
Audit & Compliance
  • Plan, coordinate, and track security testing activities, including penetration tests and vulnerability assessments.
  • Verify the effectiveness of technical and organizational security controls implemented across the company.
  • Support internal and external audits related to cybersecurity, compliance, and risk management.
What We're Looking For
  • 5-8+ years of experience in cybersecurity, IT security governance, risk management, compliance, or related areas.
  • At least 2-3 years of experience in a lead, manager, or ownership role related to cybersecurity governance, risk, compliance, or security operations.
  • Practical knowledge of NIS2, ISO 27001, Information Security Management Systems (ISMS), cybersecurity frameworks, and risk management methodologies.
  • Experience conducting cybersecurity risk assessments, maintaining risk registers, validating controls, supporting audits, and tracking remediation activities.
  • Strong understanding of incident response, escalation processes, post-incident reviews, and regulatory reporting obligations.
  • Solid knowledge of IT infrastructure, networks, identity and access management, endpoint security, cloud security, backup and recovery, and security monitoring tools.
  • Experience assessing supplier cybersecurity risks and supporting vendor risk management processes.
  • Ability to translate technical cybersecurity risks into business impact and communicate effectively with both technical and non-technical stakeholders.
  • Strong stakeholder management, communication, and relationship-building skills.
  • A structured, proactive, and solutions-oriented mindset.
It would be great if you also have:
  • Experience in manufacturing, industrial, or production environments.
  • Familiarity with IEC 62443 principles.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Implementer/Auditor.
  • Experience building or improving cybersecurity governance models, awareness programs, security roadmaps, and audit-ready evidence structures.

Help us build a secure and resilient future while driving meaningful cybersecurity initiatives across the organization.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Governance Lead Remote/Hybrid
Cyber Security Governance Lead Remote/Hybrid

KK Group • Szczecin

Hybrid
PLN 180,000 - 300,000
IT Security Analyst
IT Security Analyst

KK Group • Szczecin

On-site
PLN 110,000 - 170,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos SE • Wrocław

On-site
PLN 120,000 - 190,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos Poland Global Services Sp. z o.o. • Województwo kujawsko-pomorskie

On-site
PLN 180,000 - 260,000
GRC Consultant
GRC Consultant

Webellian • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid work model
On-site presence occasionally
Private medical care
+2
IT Engineer Cyber Security (m/k)
IT Engineer Cyber Security (m/k)

SMA Solar Technology AG • Poland

On-site
PLN 90,000 - 130,000
IT GRC Analyst
IT GRC Analyst

KK Group • Szczecin

On-site
PLN 120,000 - 190,000
Cybersecurity Risk and Compliance Manager
Cybersecurity Risk and Compliance Manager

EY • Poland

Hybrid
PLN 80,000 - 110,000
Continuous learning opportunities
Flexible work options
Transformative leadership coaching
+1
Information Security Officer
Information Security Officer

Tradevest GmbH • Warszawa

On-site
PLN 180,000 - 280,000
Cyber Security Engineer (Vulnerability Management)
Cyber Security Engineer (Vulnerability Management)

KION Business Services Polska • Kraków

On-site
PLN 180,000 - 260,000
Private medical care
MyBenefit Cafeteria Platform
Group Life Insurance
+3