Audytor/Audytorka IT/OT
Tech Stack / Keywords
Firma i stanowisko
COIG S.A. is seeking an IT/OT Auditor to support both external clients and the internal organization in maintaining compliance with security standards such as ISO 27001 and ISO 22301, as well as regulatory requirements arising from the NIS2 Directive and the National Cybersecurity System Act (KSC).
Wymagania
- Experience in IT/OT audits (minimum 1–2 years).
- Very good knowledge of ISO 27001 and ISO 22301 standards.
- Lead Auditor certification for ISO 27001 and/or ISO 22301.
- Practical knowledge of NIS2 Directive and current/upcoming KSC legislative requirements.
- Familiarity with cybersecurity processes, incident management, risk analysis, and OT/ICS environments.
- Ability to collaborate with technical and business teams.
- Analytical skills and capability to create clear documentation.
Nice to have:
- Certifications: CISA, CISSP, IEC 62443, CRISC.
- Experience in regulatory or implementation projects related to NIS2/KSC.
Obowiązki
- Conduct security audits in IT and OT areas for external clients and internally.
- Verify compliance with ISO 27001 and ISO 22301 standards.
- Perform risk analyses according to ISO 27005, NIS2, and KSC.
- Create, update, and maintain ISMS documentation (policies, procedures, instructions).
- Analyze and assess compliance with NIS2 requirements, including risk management, incident reporting, and technical and organizational measures.
- Support organizational adaptation to KSC requirements, including classification processes, incident reporting, and cybersecurity measures.
- Identify risks and prepare recommendations for corrective actions for IT/OT environments.
- Prepare audit reports and present results to business and technical stakeholders.
- Support technical teams in implementing security mechanisms and legal regulatory requirements.
- Develop new procedures and standards in collaboration with stakeholders.
- Monitor changes in NIS2 and KSC regulations and market best practices.
Benefity
- Employment based on a permanent employment contract in a stable, continuously developing company.
- Specialized training.
- Additional benefits package including private healthcare, access card to sports facilities, and fruit Tuesdays.
- Friendly work atmosphere.
Inne informacje
Administrator
The entity responsible for the processing of personal data is WASKO S.A. nr KRS 0000026949, contact: 44-100 Gliwice, ul. Berbeckiego 6, [email protected].
Data Protection Officer contact: [email protected].
Personal data will be processed for the purpose of conducting the current recruitment process. Providing data required by law is mandatory; providing other data is voluntary.
Data may be disclosed to entities supporting the Administrator in recruitment.
Data will be stored until the recruitment process ends, or for 12 months if consent is given for future processes.
Candidates have rights to access, correction, restriction, deletion, data portability, complaint submission.
Consent can be withdrawn at any time without affecting prior lawful processing.
Automated decision-making or profiling will not be performed on personal data.
Legal basis for processing refers to relevant articles of the Polish labor code and GDPR.
COIG
2 aktywne oferty