Are you passionate about protecting organizations from evolving cyber threats while building strong security governance and risk management practices? Join KK Group and play a key role in strengthening our cybersecurity posture across the business.
We are looking for an experienced Cyber Security Manager who will drive security governance, risk management, compliance, and incident response initiatives while ensuring alignment with regulatory requirements, including NIS2, internal policies, and business objectives.
We are open to candidates based in the Szczecin area (hybrid) or working remotely from anywhere in Poland. We welcome applications from professionals across the country, with occasional travel to our Szczecin facility.
What You Will Be Doing
Governance & Reporting
- Develop, maintain, and oversee Information Security Policies aligned with regulatory and internal requirements.
- Provide regular cybersecurity status updates, risk reports, and incident summaries to senior leadership and the Management Board.
- Plan and coordinate mandatory cybersecurity awareness training for employees.
- Organize dedicated cybersecurity training sessions for management teams.
- Conduct periodic risk assessments covering key assets, systems, and business processes.
- Evaluate cybersecurity maturity and compliance of suppliers and service providers.
- Perform security reviews of new business initiatives and IT projects, ensuring Security by Design and Security by Default principles.
Incident Handling & Business Continuity
- Oversee security incident detection, triage, response, and post-incident reviews.
- Ensure timely reporting of significant incidents in line with regulatory requirements and reporting timelines.
- Supervise Business Continuity Planning (BCP) and Disaster Recovery (DR), including regular verification of backup effectiveness.
Audit & Compliance
- Plan, coordinate, and track security testing activities, including penetration tests and vulnerability assessments.
- Verify the effectiveness of technical and organizational security controls implemented across the company.
- Support internal and external audits related to cybersecurity, compliance, and risk management.
What We're Looking For
- 5-8+ years of experience in cybersecurity, IT security governance, risk management, compliance, or related areas.
- At least 2-3 years of experience in a lead, manager, or ownership role related to cybersecurity governance, risk, compliance, or security operations.
- Practical knowledge of NIS2, ISO 27001, Information Security Management Systems (ISMS), cybersecurity frameworks, and risk management methodologies.
- Experience conducting cybersecurity risk assessments, maintaining risk registers, validating controls, supporting audits, and tracking remediation activities.
- Strong understanding of incident response, escalation processes, post-incident reviews, and regulatory reporting obligations.
- Solid knowledge of IT infrastructure, networks, identity and access management, endpoint security, cloud security, backup and recovery, and security monitoring tools.
- Experience assessing supplier cybersecurity risks and supporting vendor risk management processes.
- Ability to translate technical cybersecurity risks into business impact and communicate effectively with both technical and non-technical stakeholders.
- Strong stakeholder management, communication, and relationship-building skills.
- A structured, proactive, and solutions-oriented mindset.
It would be great if you also have:
- Experience in manufacturing, industrial, or production environments.
- Familiarity with IEC 62443 principles.
- Professional certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Implementer/Auditor.
- Experience building or improving cybersecurity governance models, awareness programs, security roadmaps, and audit-ready evidence structures.
Help us build a secure and resilient future while driving meaningful cybersecurity initiatives across the organization.