Supplier Cyber Assessor

Engenious

Kraków

Hybrid

PLN 193,000 - 248,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Private Medical Care – INTER Polska
Co-funded Multisport Card
Training and certification subsidies

Job summary

Engenious is seeking a Supplier Cyber Assessor to support Third-Party Cyber Risk Management. You will assess and manage cybersecurity risks across the supplier lifecycle, working with internal teams and suppliers to define remediation actions and monitor closure.

The role requires a solid understanding of cybersecurity frameworks, supplier risk, and regulatory requirements, including NIS2 and CRA, with opportunities to improve risk processes and tooling.

Qualifications

  • 2–3 years in cybersecurity or third‑party risk management.
  • Solid understanding of ISO 27001/27002/27005.
  • Knowledge of the NIST CSF and/or NIST 800-53.
  • Familiarity with NIS2 requirements and CRA implications.
  • Experience with security questionnaires or supplier risk management.

Responsibilities

  • Conduct and validate inherent risk assessments with stakeholders.
  • Perform cyber risk assessments for suppliers and identify gaps.
  • Assess supplier controls against cybersecurity and contractual requirements.
  • Ensure alignment with CSS and relevant standards and regulations.
  • Document and track remediation plans with timelines.
  • Record and escalate supplier non‑compliance when needed.
  • Collaborate with Sourcing, Legal, IT Security and Business teams.

Skills

Cyber risk assessment
GRC knowledge
Regulatory understanding
Stakeholder communication

Education

Bachelor's or Master's in IT/Cybersecurity

Tools

OneTrust
ServiceNow
BitSight

Job description

For our client, Engenious is looking for a Supplier Cyber Assessor to join the team and support their Third-Party Cyber Risk Management activities.The role is focused on assessing and managing cybersecurity risks related to third-party suppliers throughout the supplier lifecycle. You will work closely with internal stakeholders and suppliers to assess cyber risk, evaluate security controls, define remediation actions and monitor their closure.The position is particularly relevant for someone with a solid understanding of cybersecurity frameworks, supplier risk and regulatory requirements.

Responsibilities
  • Conduct and validate Inherent Risk Assessments (IRA) with internal stakeholders and determine supplier risk classification.
  • Perform detailed Cyber Risk Assessments to identify and evaluate supplier cybersecurity risks.
  • Assess supplier controls against applicable cybersecurity and contractual requirements.
  • Ensure alignment with the organisation's Cybersecurity Standard for Suppliers (CSS) and relevant frameworks and regulations, including ISO 27001/27002/27005, NIST CSF, NIST 800-53, NIS2 and the EU Cyber Resilience Act (CRA).
  • Assess relevant CRA requirements, including vulnerability management, secure-by-design practices and reporting obligations.
  • Communicate risk ratings, identified gaps, required actions and compliance expectations to relevant stakeholders.
  • Define, document and track risk-based remediation plans, including agreed timelines and regulatory deadlines.
  • Monitor supplier progress and ensure identified gaps are remediated and formally closed.
  • Record supplier non-compliance as an Issue, Risk or Exception in ServiceNow, where applicable.
  • Escalate high-risk or non-responsive suppliers in cooperation with relevant Category Managers.
  • Maintain effective working relationships with Sourcing, Category Management, Legal, IT Security and Business stakeholders.
  • Act as a trusted advisor on supplier cybersecurity risks, security requirements and regulatory expectations.
  • Conduct and document assessments using GRC platforms such as OneTrust.
  • Use external cybersecurity ratings, such as BitSight, to support supplier risk evaluation and continuous monitoring.
  • Identify opportunities to improve and automate risk assessment, monitoring, incident response and reporting processes.
Requirements
  • 2–3 years of professional experience in cybersecurity, IT risk, third-party risk management or a related area.
  • Good practical understanding of ISO 27001, ISO 27002 and ISO 27005.
  • Good understanding of the NIST Cybersecurity Framework and/or NIST 800-53.
  • Knowledge of NIS2 requirements and their practical implications for supplier cybersecurity.
  • Understanding of the EU Cyber Resilience Act (CRA), particularly in areas such as vulnerability management, secure-by-design requirements and reporting obligations.
  • Experience with cybersecurity assessments, risk assessments, security questionnaires or supplier risk management.
  • Strong analytical skills and the ability to translate technical and regulatory requirements into clear risk-based actions.
  • Good communication skills and confidence working with both technical and non-technical stakeholders.
  • Experience with GRC or risk management platforms such as OneTrust and/or ServiceNow will be an advantage.
  • Relevant cybersecurity, information security or risk management certifications are a plus.
  • Bachelor's or Master's degree in IT, Cybersecurity or a related field is preferred.
What can you expect
  • Rate: 140-180 PLN/h + VAT, depending on experience and skills
  • Team of passionate people who love what they do.
  • Opportunity to learn and grow.
  • Private Medical Care – INTER Polska.
  • Co-funded Multisport Card.
  • Possible training and certification subsidies.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Strategic Supplier Cyber Risk Assessor
Strategic Supplier Cyber Risk Assessor

Engenious • Kraków

Hybrid
PLN 193,000 - 248,000
Private Medical Care – INTER Polska
Co-funded Multisport Card
Training and certification subsidies
Cybersecurity Risk and Compliance Manager
Cybersecurity Risk and Compliance Manager

EY • Poland

Hybrid
PLN 80,000 - 110,000
Continuous learning opportunities
Flexible work options
Transformative leadership coaching
+1
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Warszawa

On-site
PLN 120,000 - 180,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Wrocław

On-site
PLN 180,000 - 240,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Poland

On-site
PLN 150,000 - 200,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Województwo kujawsko-pomorskie

On-site
PLN 110,000 - 170,000
(Cybersecurity) Threat and Controls Assessment Consultant
(Cybersecurity) Threat and Controls Assessment Consultant

Antal Poland • Kraków

Hybrid
PLN 180,000 - 240,000
B2B contract
Hybrid work model – 6 days per month
Lux Med private medical care
+2
Cybersecurity Consultant
Cybersecurity Consultant

Atos SE • Wrocław

On-site
PLN 120,000 - 190,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos Poland Global Services Sp. z o.o. • Województwo kujawsko-pomorskie

On-site
PLN 180,000 - 260,000
Manager - Cyber Security
Manager - Cyber Security

KK Group • Szczecin

Hybrid
PLN 180,000 - 300,000