Senior Information Security Specialist

13 300 - 20 000 PLN/ mies.Umowa o pracę (brutto)
SeniorFull-time·Umowa o pracę
#359034·Dodano dziś·0
Źródło: nofluffjobs.com
Aplikuj teraz

Tech Stack / Keywords

ISO 27001GRCGDPRSOC-2Cloud securityAuditAI SecurityAWSCISACRISCCISMCISSPCCSPISO 9001ISO 27017ISO 27018ISO 22301BSI C5

Firma i stanowisko

SmartRecruiters is a company delivering an AI-powered hiring platform used by over 4,000 companies including LinkedIn, McDonald's, VISA, CD Projekt Red, and Allegro. In 2025, SmartRecruiters joined SAP to accelerate hiring innovation combining AI with SAP's ecosystem. The company uses an empowered product teams model responsible for business outcomes and customer satisfaction.


Wymagania

  • 5+ years of experience in information security, governance, risk, and/or compliance roles with a technical orientation
  • Demonstrated compliance or auditing experience with at least one major framework
  • Hands-on experience with incident response including security incident investigations, containment, and post-mortem processes
  • Solid understanding of controls auditing principles and evidence management
  • Technical understanding of cloud infrastructure (AWS preferred), networking fundamentals, identity management, and SaaS security architectures
  • Knowledge of risk management methodologies and experience conducting or supporting risk assessments
  • Ability to manage and deliver on multiple complex projects simultaneously with minimal supervision
  • Ability to investigate, question, and interpret internal and external IT security and compliance issues at both governance and technical levels
  • Strong understanding of technology, cloud-based products, and SaaS environments
  • Experience working across business units and geographical boundaries to engage engineering, business, and operational teams
  • Experience with ISO 27001
  • Excellent written and verbal communication skills in English

Nice to have:

  • Professional certifications such as CISA, CRISC, CISM, CISSP, CCSK, CCSP, or equivalent
  • Experience with ISO 9001, 27017, and 27018
  • Experience with ISO 22301 (Business Continuity), including BIA, BCP/DRP, and recovery testing
  • Experience with BSI C5 (Cloud Computing Compliance Criteria Catalogue) or similar cloud-specific compliance frameworks
  • Knowledge of AI security principles, experience with ISO 42001, or familiarity with the EU AI Act and its technical requirements
  • Experience with enterprise risk management frameworks and tools
  • Understanding of threat modelling methodologies and secure development lifecycle (SDLC) principles

Obowiązki

  • Identify manual, repetitive GRC processes and design automation blueprints to streamline them, including evidence collection, control monitoring, access reviews, policy enforcement checks, and compliance reporting
  • Build and maintain automated workflows using compliance platforms, scripting, or integration tools to reduce manual effort and improve audit-readiness
  • Develop reusable templates, playbooks, and standardized blueprints for recurring GRC activities (e.g., vendor assessments, internal audits, risk reviews) to ensure consistency and scalability
  • Collaborate with engineering and IT teams to integrate security and compliance checks into existing toolchains and CI/CD pipelines where applicable
  • Continuously evaluate and improve GRC tooling, data flows, and reporting to drive operational efficiency across the team
  • Manage stakeholder expectations and partner with internal teams to ensure effective management of IT risks and compliance obligations
  • Maintain regional and local stakeholder relationships, meeting schedules, minutes, and reports
  • Support the maintenance of the SOC 2 Type II framework, including evidence collection, control testing coordination, and audit support
  • Effectively manage ISO 27001 and ISO 22301 audit lifecycles and coordinate with stakeholders on ISMS and BCMS improvements
  • Support the maintenance and continuous improvement of the ISO 42001 (AI Management System) framework in alignment with the EU AI Act
  • Support vendor risk management activities, including third-party security assessments and due diligence reviews
  • Serve as a subject matter expert or key contributor for the Business Continuity Management System (BCMS), supporting the strategy, framework, and audit programme under ISO 22301
  • Support Business Impact Analysis (BIA), BCP/DRP development, recovery exercises, and continuity metrics management
  • Support AI security and compliance activities, including the assessment of AI-related risks, alignment with ISO 42001 controls, and regulatory readiness

Oferta

  • Sport subscription
  • Private healthcare
  • Small teams
  • International projects
  • Unlimited vacation days
  • Company shutdowns twice a year
  • Free coffee
  • Bike parking
  • Playroom
  • Shower
  • Free parking
  • In-house trainings
  • Modern office
  • Startup atmosphere
  • No dress code
  • Family events
  • Company parties
  • In-house hack days
Karta sportowa
Opieka zdrowotna
Szkolenia wewnętrzne
SmartRecruiters Inc.

SmartRecruiters Inc.

21 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz