At PMI, we are building a smoke‑free future and transforming our business through technology. The Information Security team supports corporate functions, ensuring secure, compliant and resilient solutions.
Manager Tech Information Security – IT Corporate Platform (CA, Legal and Risk)
Responsibilities
- Act as the first‑line technology security partner for CA, Legal and Risk Management platforms, ensuring security‑by‑design and privacy‑by‑design are embedded throughout the solution lifecycle.
- Translate PMI information security standards, policies and control expectations into practical actions for platform teams, product owners, vendors and delivery partners.
- Maintain active governance over security posture, key risk indicators, control evidence, vulnerabilities, remediation plans and recurring application security weaknesses.
- Support technology projects and platform evolutions by reviewing security documentation, architecture decisions, system configurations, access models, data protection requirements and risk acceptances.
- Partner with Information Security Second Line of Defense, SOC, IRM, audit teams and platform stakeholders to ensure risks are identified, assessed, documented and remediated in a timely and transparent way.
- Represent IT during internal audits, external audits and regulatory reviews, ensuring that evidence is accurate, complete and aligned with the actual control environment.
- Drive security awareness within Tech CA, Legal and Risk Management by coaching teams, promoting training, sharing lessons learned from incidents and reducing repeat vulnerabilities.
- Support cyber incident response for solutions in scope, from identification to containment, eradication and post‑incident improvement actions.
- Contribute to continuous improvement of IT processes by embedding robust security measures and IT controls that protect the confidentiality, integrity and availability of data and business processes.
Qualifications
- Expert in information security with at least 7 years of experience in information security, IT risk management, IT audit including SOX, cybersecurity governance or related disciplines within a large organization.
- Trusted advisor to IT management on information security aspects of company data processing, including access management, backup and resilience, IT controls, contractual and regulatory obligations, data protection, encryption and application security.
- Experience supporting enterprise applications, Corporate Management systems, SaaS platforms, cloud technologies and third‑party integrations with a preference for Corporate Affairs, Legal and Risk Management.
- Ability to support the IT organization and the wider business in adopting a risk‑based decision‑making culture, while managing risk and meeting regulatory compliance requirements as part of a governance, risk and compliance framework.
- Strong knowledge of technical and compliance aspects of security, including information security frameworks such as NIST and ISO/IEC 27000, security architecture, application security, identity and access management, cloud computing architectures, SOX, GDPR and PCI requirements.
- Possession of security certifications such as CISSP, CISA, CISM or CRISC is highly preferred.
- Strong communication and influencing skills, with the ability to translate technical risks into clear business language and work effectively across business, technology, compliance and security teams.
Benefits
- Wide range of trainings, optional language classes, further education and professional qualification support possibilities.
- Private medical and dental care and life insurance.
- Lunch card, Multisport and Cafeteria program.
- Hybrid model of work and flexible working arrangements.
- Employee pension plan.
- Free bike and car parking for employees.
- In this position you will earn no less than 21,800 PLN gross monthly.
Role Growth
- As PMI progresses on its business transformation journey, the Manager Tech Information Security will help drive adoption of PMI IT Security Standards to protect business processes, technology assets and data.
- The role will actively participate in securing the CA, Legal and Risk Management application portfolio, with opportunities to co‑design approaches and drive them together with colleagues across IT and Information Security.
- We see this role growing with the function and the company, and are looking for an experienced profile with the willingness to strengthen secure‑by‑design delivery across the IT organization.
Relocation support is not available for this job.
At PMI we run the business in line with ethical principles and encourage a SpeakUp culture. We care for equal chances and fair treatment. If you find anything that violates these principles in this job offer or the recruitment process, you may contact our Ethics and Compliance Team at PMIEthicsandCompliance@pmi.com. Read more about Ethics & Compliance at PMI – here.