Webellian
Webellian
New

GRC Consultant

Brak informacji o wynagrodzeniu
SeniorFull-time·B2B
#392282·Dodano 7 dni temu·1
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

Governance, Risk & Compliance (GRC)ISO/IEC 27001:2022 implementation (ISMS)NIS2 & Polish Cybersecurity Act (uKSC)Cybersecurity Risk ManagementThird-Party Risk Management (TPRM)Security Policies & GovernanceCompliance & Audit Readiness

Firma i stanowisko

Webellian is a digital transformation and IT consulting company working with clients in insurance, banking, healthcare, retail, and manufacturing sectors. The company focuses on cybersecurity and governance, offering consulting services through engineers and senior advisors.

Wymagania

  • Over 7 years of experience in Governance, Risk & Compliance (GRC), Information Security, or Cybersecurity Governance.
  • Hands-on experience implementing or maintaining an Information Security Management System (ISMS) based on ISO/IEC 27001:2022 or similar frameworks.
  • Current working knowledge of NIS2 and the Polish Cybersecurity Act (uKSC), with practical application experience.
  • Experience supporting cybersecurity compliance and regulatory governance initiatives.
  • Practical experience managing cybersecurity risk registers and risk treatments.
  • Skilled in facilitating workshops and engaging with business stakeholders and senior management.
  • Good understanding of cybersecurity governance, compliance frameworks, and risk management best practices.
  • Native or fluent Polish language proficiency.
  • Professional proficiency in English.

Obowiązki

  • Support implementation and continuous improvement of an ISO/IEC 27001:2022-compliant Information Security Management System (ISMS).
  • Develop and maintain information security policies, standards, procedures, and governance documentation.
  • Build and maintain cybersecurity risk registers including risk identification, assessment, and treatment plans.
  • Conduct cybersecurity risk assessments and Business Impact Analyses (BIA), facilitate workshops with business stakeholders.
  • Map security controls against ISO/IEC 27001:2022, NIS2, and other regulatory requirements.
  • Coordinate Third-Party Risk Management (TPRM) activities, including vendor security assessments.
  • Collaborate with internal stakeholders on information security requirements in supplier contracts.
  • Maintain IT asset inventories and document business processes and data flows.
  • Contribute to vulnerability management planning and compliance evidence collection.
  • Develop and maintain incident response and business recovery documentation.
  • Prepare documentation and evidence for internal and external compliance audits.
  • Work closely with client stakeholders to ensure successful delivery of cybersecurity governance and compliance initiatives.

Benefity

  • Contract under Polish law: B2B or employment contract (Umowa o Pracę).
  • Private medical care, group insurance, and Multisport card.
  • English language classes.
  • Hybrid work model with occasional on-site presence.
  • Opportunity to work with experienced cybersecurity professionals on international projects.
  • Exposure to complex cybersecurity governance and compliance programs in regulated environments.
  • Continuous learning and professional development.
  • International, collaborative working environment with long-term growth opportunities.
Opieka zdrowotna
Ubezpieczenie
Karta sportowa
Kursy językowe
Webellian

Webellian

22 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz