Cybersecurity Risk Manager (K/M)
Tech Stack / Keywords
Firma i stanowisko
Fabrity S.A. is a dynamic technology company specializing in software engineering, generative artificial intelligence, and industrial Internet of Things (IoT). They develop comprehensive solutions to help businesses automate processes, improve operational efficiency, and make key decisions through effective data analysis. Fabrity supports organizations with digital transformation using leading platforms like ServiceNow, Microsoft Power Platform, and their proprietary low-code product, Fastive. Their clients come from diverse industries including pharmaceuticals, healthcare, financial services, manufacturing, automotive, and retail, with brands such as ABB, Bayer, Carrefour, PKO BP, Dormakaba, Sanofi, Toyota Bank, Frontex, Liebherr, Pepsico, and Saint-Gobain.
Wymagania
- Minimum 9 years of professional IT experience, including at least 6 years in a similar role.
- Active security clearance at EU RESTRICTED level or equivalent.
- Experience conducting business impact assessments (BIA).
- Practical knowledge in implementing risk assessments in GRC tools such as ServiceNow.
- Experience in preparing data protection documentation concerning RODO/GDPR.
- Experience in conceptual and tool-based threat modeling.
- Practical experience with threat modeling in DevOps/CI/CD environments.
- Knowledge and experience designing Zero Trust architecture.
- Experience securing the software development lifecycle (Secure SDLC).
- Ability to design security control mechanisms, especially for directory services like AD/LDAP.
Certification requirements:
- Hold at least 4 certifications among: CISSP, CISA, CISM, GSNA, GCCC, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, ISO 27005 Risk Manager, CAP, CRISC, CISSP-ISSMP, GIAC ISO 27000 Specialist, or equivalent recognized certifications.
Obowiązki
- Identify current threat landscape, including profiling potential attackers and assessing attack scenarios and capabilities.
- Conduct risk assessments for IT systems using recognized methodologies such as ITSRM², EBIOS, MAGERIT, and tools like PILAR, FENCE, or proprietary solutions.
- Develop and update ICT security policies and procedures, focusing on information and personal data protection.
- Analyze existing cybersecurity processes, standards, and tools to recommend risk management improvements.
- Provide advisory and conduct training for ICT teams, especially development teams, on secure software development including security by design.
- Support defining security requirements, threat modeling, code reviews, security testing, and the implementation of control mechanisms, including for cloud and AI-based solutions.
Benefity
- Benefits within a cafeteria system.
- Cooperation based on a B2B contract.
- Remuneration of 200-280 PLN/hour net plus VAT.
- Services performed on-site at the client's office in Warsaw.
- Engagement in a project with a real impact on the client's business direction.
- Services provided for a prestigious public institution.
Fabrity S.A.
75 aktywnych ofert