Security Compliance Officer

Shiji Group

Katowice

On-site

PLN 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Private medical care
Group life insurance
Multisport card

Job summary

Shiji Group, a global technology leader for hospitality, seeks a Security & Compliance professional to manage the security control framework, conduct risk assessments, and drive audits and policy development. You will work with a global security team to ensure compliance with ISO27001/27018, PCI DSS, GDPR and related standards.

The role requires 3+ years of experience in security/compliance, strong English, and project-management skills.

Qualifications

  • At least 3 years of commercial experience in security/compliance roles.
  • Experience with audits, risk analysis, security reviews and verification activities.
  • Knowledge of security frameworks like ISO27001, ISO27018, PCI DSS, NIST CSF, SOC2, GDPR.
  • Experience in creating/managing security documentation, control frameworks and policies.
  • Experience in project management.
  • Good spoken and written English.
  • Self-motivated with strong attention to detail.

Responsibilities

  • Manage security control framework and map standards to the framework.
  • Input to security governance processes.
  • Ensure compliance with security standards and regulations.
  • Lead security processes: incident, continuity, vulnerability, change, physical security.
  • Manage information security risk and monitor actions.
  • Conduct security controls reviews, access reviews, compliance checks.
  • Oversee internal audits and improve security posture.
  • Maintain documentation for ISO27001/27018, SOC2, GDPR etc.
  • Develop and update security policies and procedures.
  • Identify new compliance requirements and advise stakeholders.
  • Collaborate with security team to align programs with compliance.
  • Assist with vendor risk assessments and access provisioning.

Skills

Security governance
Risk analysis
Internal audits
Policy development
Project management
English communication

Tools

ISO27001
ISO27018
PCI DSS
NIST CSF
SOC2
GDPR

Job description

Shiji is a global technology company dedicated to providing innovative solutions for the hospitality industry, ensuring seamless operations for hoteliers day and night.

Built on the Shiji Platform—the only truly global hotel technology platform—Shiji’s cloud-based portfolio includes Property Management System, Point-of-Sale, guest engagement, distribution, payments, and data intelligence solutions for over 91,000 hotels worldwide, including the largest chains.

The best hotels run on Shiji — day and night.

Responsibilities
  • Manages security control framework, map standards and requirements to the framework.
  • Provides input to the security governance processes.
  • Ensures that the processes within the company are compliant with all relevant security frameworks, standards and regulations.
  • Implementing and supervising security processes including among the others incident management, business continuity management, vulnerability management, change management, physical security etc.
  • Manages information security risk process, analyses risks, provides input to the process and monitors the required actions recommended by the process.
  • Conducting selected security controls, access and permission reviews, compliance checks etc.
  • Manages and conducts the internal audits within the company, ensuring that the audits and results improve the security posture of the company but also answer the standards requirements.
  • Manages operational documentation required by all relevant standards and regulations including ISO27001, ISO27018 standards, SOC2 reporting, GDPR and other personal data protection regulations etc.
  • Manages security policies and procedures, creates them, updates, reviews and ensures they are effective and properly implemented across the whole company.
  • Identify, research, and evaluate new compliance requirements and present them to relevant stakeholders
  • Provides advisory regarding legal requirements in case of security aspects but also related to other business areas relevant for the company.
  • Works together with security team members to ensure successful security programs align with compliance requirements.
  • Assist with daily activities and functions of the security team such as assessing vendors for security risk and provisioning application access.
Requirements
  • At least 3 years of commercial experience in the areas listed above or in a similar role.
  • Skills in conducting internal audits, risks analysis, security reviews and other verification activities related to security frameworks and standards.
  • Experience and knowledge of security frameworks, standards and regulations like ISO27001, 27018 & PCI DSS, NIST Cybersecurity Framework, SOC2, GDPR and others.
  • Experience in creating and managing security documentation, security control frameworks, polices and procedures and tuning these policies to reflect business and security requirements.
  • Experience in project management.
  • Good spoken and written English.
  • Self-motivation and attention to details.
Nice to have
  • Technical understanding of the security solutions, endpoint protection etc.
  • Understanding of the cloud environment and ability to map security requirements to the cloud solutions.
What Do We Offer?
  • Private medical care, including a dental package, for you and your family
  • Group life insurance for you and your partner
  • Multisport card as part of the Worksmile package
Work & Growth
  • 40 hours for professional development during work hours
  • Access to platforms like: OpenUp, Pluralsight and GoodHabitz
  • Worksmile cafeteria with 525 points per month
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC/NOC Specialist
SOC/NOC Specialist

Shiji Group • Katowice

Hybrid
PLN 80,000 - 120,000
Private medical care
Group life insurance
Multisport card
Senior Frontend Developer
Senior Frontend Developer

Shiji Group • Katowice

On-site
PLN 120,000 - 180,000
Private medical care (including dental
Group life insurance
Multisport card
+1
DevOps Engineer
DevOps Engineer

Shiji Group • Katowice

Hybrid
PLN 180,000 - 240,000
Private medical care
Group life insurance
Multisport card
Senior Software Developer
Senior Software Developer

Shiji Group • Katowice

On-site
PLN 120,000 - 180,000
Private medical care including dental
Group life insurance
Multisport card
Security Compliance Strategist
Security Compliance Strategist

Shiji Group • Katowice

On-site
PLN 120,000 - 180,000
Private medical care
Group life insurance
Multisport card
Senior Cloud Infrastructure Engineer
Senior Cloud Infrastructure Engineer

Shiji Group • Katowice

On-site
Private medical care
Group life insurance
Multisport card
+2
Intern, Legal & Privacy
Intern, Legal & Privacy

Shiji Group • Katowice

On-site
PLN 20,000 - 31,000
Private medical care (dental)
Group life insurance
Multisport card
Junior Infrastructure Security Engineer
Junior Infrastructure Security Engineer

Shiji Group • Katowice

On-site
PLN 140,000 - 210,000
Glasses subsidy
Free parking near office
Private medical care
+8
Senior QA Engineer (Reporting Team)
Senior QA Engineer (Reporting Team)

Shiji Group • Katowice

Hybrid
PLN 90,000 - 130,000
Private medical care, including a牙dENT
Group life insurance for you and your…
Multisport card as part of the Worksmi
+2
Senior QA Engineer (Meridian)
Senior QA Engineer (Meridian)

Shiji Group • Katowice

Hybrid
PLN 110,000 - 150,000
Private medical care (including dental
Group life insurance
Multisport card