Technology Risk & Security Manager (SCAR)

Cornerstone OnDemand Ltd.

Warszawa

Hybrid

PLN 312,000 - 335,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Monthly remote work allowance
Annual bonus

Job summary

Simon-Kucher is seeking a Technology Risk & Security Manager to lead risk assessment for new technologies, AI-enabled solutions, and SaaS/Cloud deployments across a global enterprise. You will partner with Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and business teams to ensure security controls and governance.

The role requires 5+ years in technology risk, cybersecurity, IT governance, or related fields, a Bachelor’s degree, and CISSP/CISM/CRISC or equivalent experience.

Qualifications

  • Experience in a complex global environment is preferred.
  • Bachelor’s Degree required – Technology, MIS, Cybersecurity, etc.
  • 5+ years of experience in technology risk, cybersecurity, IT governance, GRC, IT audit, security architecture, or technology consulting.
  • Strong knowledge of cybersecurity, technology risk management, compliance, enterprise IT governance, and emerging AI‑enabled technologies.
  • Experience assessing SaaS, cloud, third‑party, and AI‑enabled solutions and identifying risks and mitigation requirements.

Responsibilities

  • Manage end-to-end Technology Demand Intake and Risk Assessment for new technologies, platforms, tools, and AI‑enabled solutions.
  • Assess security, compliance, operational, vendor, and architecture risks; identify mitigation strategies and recommend risk treatment decisions.
  • Prepare executive‑ready reports and present findings to IT leadership, governance boards, and risk committees.
  • Partner with Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and business stakeholders to evaluate and approve technology solutions.
  • Ensure new technologies comply with security policies, controls, and integration requirements.
  • Maintain risk documentation, exception records, control evidence, and governance reporting while continuously improving intake processes.
  • Stay current on emerging technologies, AI, cybersecurity trends, regulatory requirements, and industry control frameworks.
  • Translate business requirements into security and compliance recommendations that enable timely technology decisions.
  • Communicate complex technical concepts through presentations, decision papers, and executive‑facing materials.
  • Facilitate collaboration across IT architecture, infrastructure, business teams, vendors, and other stakeholders.
  • Support vendor assessments, RFPs, technical evaluations, and solution reviews.
  • Contribute to cross‑functional IT projects by identifying dependencies, risks, and process improvements.
  • Work effectively in agile, global project environments with multiple priorities, and tight timelines.

Skills

Cybersecurity
Risk management
IT governance
GRC
Security architecture
Stakeholder management
AI-enabled tech
SaaS/Cloud assessment

Education

Bachelor’s Degree in Technology/MIS/Cybersecurity

Tools

CISSP
CISM
CRISC
ISO 27001 Lead Implementer

Job description

Technology Risk & Security Manager (SCAR)

In Poland - Warsaw or fully remote from Home

This role serves as the bridge between business demand, IT architecture, cybersecurity, SOC, audit, compliance, procurement, privacy, and implementation teams - operating within the company’s Technology Demand Intake Process, which is closely connected to implementation and lifecycle governance.This individual will focus on reviewing technical concepts, stand‑alone products, services, and AI‑enabled solutions that the company plans to implement or integrate into its complex global enterprise technology landscape, including SaaS, PaaS, SAP, and AI‑enabled platforms.You will be responsible for assessing and governing new technology demands, services, platforms, and AI‑enabled solutions through the organization’s technology intake process.The role ensures that security, compliance, architecture, operational, and business risks are identified, clearly documented, and addressed through effective and practical mitigation measures.

The salary for this position ranges from PLN 28 00 to PLN 30 000 gross per month under an employment contract (UoP), depending on the candidate’s relevant experience, skill set, level of expertise and overall fit for the role. Additional factors such as industry background, technical competencies and interview performance may also influence the final offer. The compensation package at Simon‑Kucher CBS consists of a gross base salary, a monthly remote work allowance and an annual bonus. The bonus is paid in December and is based on the results of a 360‑degree performance evaluation.

Please remember to submit your application in English. Other applications will not be considered. The candidate should have an EU work permit, we do not offer visa for this position.

What makes us special:
  • Manage the end‑to‑end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI‑enabled solutions.
  • Assess security, compliance, operational, vendor, and architecture risks; identify mitigation strategies and recommend risk treatment decisions.
  • Prepare executive‑ready reports and present findings to IT leadership, governance boards, and risk committees.
  • Partner with Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and business stakeholders to evaluate and approve technology solutions.
  • Ensure new technologies comply with security policies, controls, and integration requirements.
  • Maintain risk documentation, exception records, control evidence, and governance reporting while continuously improving intake processes.
  • Stay current on emerging technologies, AI, cybersecurity trends, regulatory requirements, and industry control frameworks.
  • Translate business requirements into security and compliance recommendations that enable timely technology decisions.
  • Communicate complex technical concepts through presentations, decision papers, and executive‑facing materials.
  • Facilitate collaboration across IT architecture, infrastructure, business teams, vendors, and other stakeholders.
  • Support vendor assessments, RFPs, technical evaluations, and solution reviews.
  • Contribute to cross‑functional IT projects by identifying dependencies, risks, and process improvements.
  • Work effectively in agile, global project environments with multiple priorities and tight timelines.
How you will create an impact:
  • Manage the end‑to‑end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI‑enabled solutions.
  • Assess security, compliance, operational, vendor, and architecture risks; identify mitigation strategies and recommend risk treatment decisions.
  • Prepare executive‑ready reports and present findings to IT leadership, governance boards, and risk committees.
  • Partner with Security, IT, Architecture, Procurement, Legal, Privacy, Audit, and business stakeholders to evaluate and approve technology solutions.
  • Ensure new technologies comply with security policies, controls, and integration requirements.
  • Maintain risk documentation, exception records, control evidence, and governance reporting while continuously improving intake processes.
  • Stay current on emerging technologies, AI, cybersecurity trends, regulatory requirements, and industry control frameworks
  • Translate business requirements into security and compliance recommendations that enable timely technology decisions.
  • Communicate complex technical concepts through presentations, decision papers, and executive‑facing materials.
  • Facilitate collaboration across IT architecture, infrastructure, business teams, vendors, and other stakeholders.
  • Support vendor assessments, RFPs, technical evaluations, and solution reviews.
  • Contribute to cross‑functional IT projects by identifying dependencies, risks, and process improvements.
  • Work effectively in agile, global project environments with multiple priorities, and tight timelines.
Your profile:
  • Experience in a complex global environment, comparable consulting or service industries is preferred.
  • Bachelor’s Degree required – preferred in the area of Technology, MIS, Cybersecurity, etc.
  • 5+ years of experience in technology risk, cybersecurity, IT governance, GRC, IT audit, security architecture, or technology consulting.
  • Strong knowledge of cybersecurity, technology risk management, compliance, enterprise IT governance, and emerging AI‑enabled technologies.
  • Experience assessing SaaS, cloud, third‑party, and AI‑enabled solutions, with the ability to identify risks, mitigation strategies, and implementation requirements.
  • Experience improving governance processes, workflows, standards, and risk management practices.
  • Knowledge of security and governance frameworks such as ISO 27001, SOC 2, ITIL, or similar.
  • Experience with security controls, risk assessments, compliance, audit support, and governance approval processes.
  • Ability to evaluate platform architecture, integrations, identity and access management, data flows, encryption, logging, monitoring, and operational security.
  • Understanding of enterprise architecture, cloud security, vendor risk management, and secure technology implementation.
  • Strong stakeholder management skills with experience working across IT, Security, Architecture, Compliance, Privacy, Legal, Procurement, Audit, and business teams.
  • Experience preparing executive‑level presentations, risk reports, and decision‑ready documentation, and presenting recommendations to senior leadership.
  • Experience evaluating third‑party vendors, cloud platforms, SaaS solutions, and managed services within global IT environments.
  • Experience supporting technology onboarding, vendor risk assessments, procurement, RFPs, and cross‑functional technology initiatives.
  • Ability to manage risks, remediation activities, project dependencies, and implementation progress across the technology lifecycle.
  • CISSP, CISM, CRISC, CISA, CCSP, ISO 27001 Lead Implementer/Auditor, or equivalent certification (or comparable hands‑on experience).
About Simon‑Kucher

Simon‑Kucher is a global consultancy with more than 2,200 employees in 30+ countries. Our sole focus is on unlocking better growth that drives measurable revenue and profit for our clients. As a trusted commercial advisor, we combine deep consulting expertise, growth specialization, and technology to scale impact. We optimize every lever of commercial strategy – product, pricing, innovation, marketing, sales, and digital – based on deep insights into what customers value and are willing to pay for. With over 40 years of experience in monetization, we are regarded as the world’s leading commercial growth and pricing specialist. simon‑kucher.com

We believe in building a culture that embraces diversity, equity, and inclusion, creating an environment in which our people feel valued, are able to be themselves and feel their contribution matters. If we get that right, remarkable things will happen; people will grow faster, innovate, feel valued, and create better outcomes for everyone – our people, our clients and, of course, our business.

Your personal contact:

Karolina Ratajczyk
karolina.ratajczyk@simon‑kucher.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior HR Coordinator
Senior HR Coordinator

Simon-Kucher • Warszawa

Hybrid
PLN 134,000 - 162,000
Remote work allowance
Annual bonus
Enterprise Integration Architect – SAP, Paas, SaaS & AI-enabled Systems
Enterprise Integration Architect – SAP, Paas, SaaS & AI-enabled Systems

Simon-Kucher • Warszawa

Hybrid
Remote work allowance
Performance bonus
Expert Group Accounting
Expert Group Accounting

Simon-Kucher • Warszawa

Hybrid
PLN 156,000 - 179,000
Remote work allowance
Annual bonus
IT Project Management Consultant (Inhouse)
IT Project Management Consultant (Inhouse)

Simon-Kucher • Warszawa

Hybrid
Monthly remote work allowance
Annual performance bonus
Comprehensive health benefits
Digital & Social Media Marketing Associate
Digital & Social Media Marketing Associate

Simon-Kucher • Warszawa

Hybrid
Remote work allowance
Annual bonus
Health benefits
Junior website operations / Junior web developer
Junior website operations / Junior web developer

Cornerstone OnDemand Ltd. • Warszawa

Hybrid
PLN 89,000 - 100,000
Flexible working
Hybrid working
Sabbaticals
+2
Junior website operations / web developer
Junior website operations / web developer

Simon-Kucher • Warszawa

Hybrid
PLN 89,000 - 100,000
Hybrid working
Remote work allowance
Annual bonus
SAP Security Manager / Senior Manager
SAP Security Manager / Senior Manager

PwC Polska • Warszawa

Hybrid
PLN 280,000 - 520,000
Hybrid work model
Mentoring and training
Certification co-financed by PwC
+2
Cybersecurity Risk and Compliance Manager
Cybersecurity Risk and Compliance Manager

EY • Poland

Hybrid
PLN 80,000 - 110,000
Continuous learning opportunities
Flexible work options
Transformative leadership coaching
+1
Technology Digital Strategy Manager (She/He/They)
Technology Digital Strategy Manager (She/He/They)

Accenture Poland • Warszawa

Hybrid
PLN 280,000 - 360,000
Private medical care
Life insurance
Company car