Senior GRC Analyst & Information Security Officer

Northland Power, Inc.

Poland

On-site

PLN 180,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Pension plan
Health insurance
Wellbeing program
Birthday off

Job summary

Northland Power, Inc. is seeking an Information Security Officer & Senior Security Analyst, GRC, to oversee information security governance, risk, and compliance in IT and OT, with emphasis on EU NIS2 and Poland's KSC Act.

Based in Warsaw, the role combines regulatory oversight with strategic security leadership, reporting to the Head of IT/OT Security & Compliance. You will implement ISMS, manage regulatory liaison activities, and drive security program maturity across global teams while

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Engineering, or a related field.
  • 5+ years of cybersecurity experience with a focus on governance, risk, and compliance (GRC).
  • Experience implementing and managing NIS2, the Polish KSC Act, ISO 27001, or similar regulatory and security frameworks.
  • Professional certifications such as CISSP, CISM, CRISC, and/or ISO 27001 Lead Implementer/Auditor are preferred.
  • Strong understanding of cyber risk management frameworks (e.g., NIST CSF, ISO 27005), IT/OT security controls, and regulatory compliance requirements.
  • Experience supporting critical infrastructure, energy, industrial, or OT/ICS environments is preferred.
  • Proven audit, risk assessment, stakeholder management, and cybersecurity advisory experience.
  • Fluency in Polish and English.
  • Self-motivated, collaborative, hands-on professional with strong judgement, prioritization skills, and a passion for cybersecurity and critical infrastructure protection.

Responsibilities

  • Lead the implementation and ongoing management of critical infrastructure and information security compliance programs, including NIS2 and the Polish KSC Act.
  • Maintain and continuously improve the ISMS, ensuring compliance with regulatory, corporate, and industry standards (e.g., ISO 27001).
  • Serve as the primary liaison with regulators and critical infrastructure protection authorities, ensuring timely incident reporting, audit readiness, and regulatory compliance.
  • Identify, assess, and manage cyber and information security risks across IT and OT environments, including oversight of the enterprise cyber risk register and risk treatment activities.
  • Develop and maintain cybersecurity policies, standards, and governance frameworks, ensuring alignment between local regulatory requirements and global security practices.
  • Oversee compliance monitoring, internal and external audits, incident management, and the implementation of corrective actions.
  • Provide cybersecurity advisory support to business leaders and operational teams, embedding security requirements into business operations, projects, and strategic initiatives.
  • Manage third-party cybersecurity risk, including vendor assessments, due diligence, and ongoing oversight of critical service providers.
  • Deliver cybersecurity awareness and regulatory training programs and promote a strong security culture across the organization.
  • Drive continuous improvement of governance, risk, compliance, and security control effectiveness through metrics, reporting, and maturity assessments.

Skills

Methodical and organized
Collaborative
Independent
Eager and adaptable
Strong communicator

Education

Bachelor's degree in Information Security, Computer Science, Engineering, or a related field

Job description

Who We Are

At Northland, we're enablers of change, united by our journey to transform the energy sector into the foundation for a sustainable future. Since our inception, we've been early movers in the energy industry, adopting new initiatives that pave the way for communities across the globe and helping forge their path towards a carbon-neutral landscape. We're a different kind of independent power producer. As developers, owners and operators who are at the forefront of the energy transition, we're uniquely positioned to leave a lasting impact in the regions where we operate. We've expanded our business across Canada, the United States, Latin America, Europe and Asia to become a global leader, all by bringing together industry experts to find solutions with an entrepreneurial mindset. While our work powers communities across the globe, Northland is powered by our people.

Reporting to the Head of IT/OT Security & Compliance, the Information Security Officer & Senior Security Analyst, GRC, is responsible for information security governance, risk management, and compliance across IT and OT environments, with a primary focus on the EU NIS2 Directive and Poland's National Cybersecurity System Act (KSC Act).

As the local information security authority and regulatory liaison for Poland, this role ensures compliance with local legal and regulatory requirements while aligning them with the organization's global information security framework. The position serves as a trusted advisor to business leaders, maintains an auditable information security compliance posture, and supports the organization's obligations as an essential or important entity under applicable critical infrastructure protection legislation.

The role is also a member of the global IT/OT Governance, Risk, and Compliance (GRC) team, contributing to the broader enterprise security program.

This position will be based in our Warsaw office. Additionally, this role will be 4 days in office per week, with one flexible day available for employees to work from home.

Key Responsibilities
  • Lead the implementation and ongoing management of critical infrastructure and information security compliance programs, including NIS2 and the Polish KSC Act.
  • Maintain and continuously improve the Information Security Management System (ISMS), ensuring compliance with regulatory, corporate, and industry standards (e.g., ISO 27001).
  • Serve as the primary liaison with regulators and critical infrastructure protection authorities, ensuring timely incident reporting, audit readiness, and regulatory compliance.
  • Identify, assess, and manage cyber and information security risks across IT and OT environments, including oversight of the enterprise cyber risk register and risk treatment activities.
  • Develop and maintain cybersecurity policies, standards, and governance frameworks, ensuring alignment between local regulatory requirements and global security practices.
  • Oversee compliance monitoring, internal and external audits, incident management, and the implementation of corrective actions.
  • Provide cybersecurity advisory support to business leaders and operational teams, embedding security requirements into business operations, projects, and strategic initiatives.
  • Manage third-party cybersecurity risk, including vendor assessments, due diligence, and ongoing oversight of critical service providers.
  • Deliver cybersecurity awareness and regulatory training programs and promote a strong security culture across the organization.
  • Drive continuous improvement of governance, risk, compliance, and security control effectiveness through metrics, reporting, and maturity assessments.
Who You Are
  • Methodical and organized: You naturally work in a methodical way and relish the opportunity to add structure and order to your work. This will help with the competing priorities you will be managing.
  • Collaborative: You build relationships and enjoy working as a team player to get things done.
  • Independent: You are an independent thinker and naturally set your own timescales and milestones to ensure you meet your objectives. You know when you need to ask for help and are comfortable doing so.
  • Eager and adaptable: You are eager to learn and expand your skillset, and comfortable adapting to changing priorities in a fast-paced and deadline-driven environment.
  • A strong communicator: You have exceptional oral and written communication skills.
Qualifications and Experience
  • Bachelor's degree in Information Security, Computer Science, Engineering, or a related field.
  • 5+ years of cybersecurity experience with a focus on governance, risk, and compliance (GRC).
  • Experience implementing and managing NIS2, the Polish KSC Act, ISO 27001, or similar regulatory and security frameworks.
  • Professional certifications such as CISSP, CISM, CRISC, and/or ISO 27001 Lead Implementer/Auditor are preferred.
  • Strong understanding of cyber risk management frameworks (e.g., NIST CSF, ISO 27005), IT/OT security controls, and regulatory compliance requirements.
  • Experience supporting critical infrastructure, energy, industrial, or OT/ICS environments is preferred.
  • Proven audit, risk assessment, stakeholder management, and cybersecurity advisory experience.
  • Strong communication, presentation, and relationship management skills, with the ability to translate regulatory requirements into practical business controls.
  • Fluency in Polish and English.
  • Self-motivated, collaborative, hands-on professional with strong judgment, prioritization skills, and a passion for cybersecurity and critical infrastructure protection.
What\'s In It for You
  • Thoughtful benefits - A pension plan and health insurance are just a couple of the benefits you'll have access to.
  • Wellbeing first - Staying true to our taking care of ourselves and each other value, you will have access to our global Wellness Program.
  • Birthdays off - You will get your birthday off work so you can celebrate however you choose. This is a paid day off to do what is important to you!

We hire talented and passionate people from different backgrounds. If you're excited about a role but your past experience doesn't align perfectly with this job description, we still encourage you to apply. Learn more about our diversity, inclusion and belonging commitments.

Northland Power is an equal opportunity employer and we are committed to creating a fair, inclusive and accessible environment. As part of our commitment we work to ensure our application process is accessible to all candidates. If you require special assistance or accommodation during the hiring process, please notify a member of the HR Department.

We use AI-enabled tools to help identify applications that meet job-related criteria. All applications are reviewed and decisions are made by people.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Poland GRC & ISMS Lead - NIS2 & Regulatory Security
Poland GRC & ISMS Lead - NIS2 & Regulatory Security

Northland Power, Inc. • Poland

Hybrid
PLN 180,000 - 260,000
Pension plan
Health insurance
Wellbeing program
+1
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Wrocław

On-site
PLN 180,000 - 240,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Opole

On-site
PLN 160,000 - 260,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Warszawa

On-site
PLN 120,000 - 180,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Poland

On-site
PLN 150,000 - 200,000
Senior PowerBI Analytics Engineer
Senior PowerBI Analytics Engineer

Westinghouse Electric Company LLC • Kraków

Hybrid
PLN 127,000 - 159,000
Hybrid work model
Private Medical Care
Private Group Insurance
+1
Senior Cloud Platform Engineer (AWS) - Landing Zone
Senior Cloud Platform Engineer (AWS) - Landing Zone

Nordea • Województwo pomorskie

Hybrid
PLN 180,000 - 300,000
Hybrid working model
Growth opportunities
Diversity and inclusion
Senior Cloud Platform Engineer (AWS) - Landing Zone
Senior Cloud Platform Engineer (AWS) - Landing Zone

Nordea • Gdynia

Hybrid
PLN 210,000 - 320,000
Senior Platform Security Engineer (100% Remote within Poland)
Senior Platform Security Engineer (100% Remote within Poland)

Docplanner • Poland

Hybrid
PLN 80,000 - 100,000
Private healthcare plan
Multisport card co-financing
Free English and Spanish classes
+1
Security Specialist / Specjalista ds. bezpieczeństwa i administracji
Security Specialist / Specjalista ds. bezpieczeństwa i administracji

SQUAD • Wrocław

On-site
PLN 70,000 - 110,000
Private medical insurance
Vacation and holidays
Performance bonus