Senior Cybersecurity & Compliance Specialist
Brak informacji o wynagrodzeniu
SeniorFull-time
#425133·Dodano 4 dni temu·4
Źródło: nofluffjobs.comTech Stack / Keywords
CybersecurityZarządzanie ryzykiem bezpieczeństwaUKSCNIS2RODOISO/IEC 27001ISO 22301Active DirectoryDokumentacjaKomunikatywnośćUmiejętności analityczneOcena ryzykaS46CSIRTNASKNISTCISOWASPMITRE ATT&CKAudyty bezpieczeństwaCISSPCISMCISAISO/IEC 27001 Lead AuditorSIEMEDR/XDRVulnerability managementDLP
Firma i stanowisko
Intelligent Logistic Solutions Sp. z o.o. (ILS Sp. z o.o.) is a global shared service provider for key internal clients belonging to Pelion SA. The company's main activities include managing IT projects, IT support, cybersecurity, database services, business application support, data center services, network infrastructure, IT education activities, and software development.
Wymagania
- Several years of professional experience in IT Security, Cybersecurity, or Security Compliance
- Practical knowledge of security risk management
- Experience in handling and analyzing security incidents
- Knowledge of vulnerability management processes
- Familiarity with cybersecurity regulations, especially UKSC, NIS2, and RODO
- Knowledge of at least two security standards, particularly ISO/IEC 27001 and ISO 22301
- Understanding of access and permissions management in Active Directory
- Experience preparing documentation, procedures, analyses, and reports for management
- Ability to independently manage assigned topics from problem identification to solution implementation
- Strong communication skills and ability to collaborate with technical and business stakeholders
- Analytical thinking and risk assessment skills
- Independence, responsibility, and good work organization
Nice to have:
- Practical knowledge of the S46 system used in the National Cybersecurity System
- Experience cooperating with CSIRT/NASK and other institutions and regulators
- Experience fulfilling reporting and obligations under UKSC/NIS2
- Familiarity with best practices and standards such as NIST, CIS Controls, OWASP, and MITRE ATT&CK
- Experience with security and compliance audits
- Experience developing and maintaining an information security management system
- Certifications: CISSP, CISM, CISA, or ISO/IEC 27001 Lead Auditor / Lead Implementer
- Knowledge of tools like SIEM, EDR/XDR, vulnerability management, or DLP
Obowiązki
- Developing and improving IT security architecture adapted to organizational needs
- Identifying requirements from regulations, standards, and internal security policies
- Collaborating with IT teams, system owners, and other organizational units on security matters
- Representing the organization with external entities, CSIRT, and regulators
- Coordinating and handling security incidents, especially critical ones
- Preparing incident reports and remediation recommendations
- Monitoring organizational security status and advising management
- Maintaining and updating the IT security risk register
- Executing vulnerability management processes including monitoring vulnerabilities, risk assessment, and remediation oversight
- Creating, reviewing, updating, and implementing security policies, procedures, and instructions
- Participating in access approval processes and supervising proper access management
- Overseeing active accounts in Active Directory, including privileged and technical accounts
- Supervising multi-factor authentication (MFA/2FA) enforcement
- Participating in security assessments for new systems and applications
- Evaluating security of IT changes as per current procedures
- Preparing quarterly, annual, and periodic IT security reports
- Preparing ad-hoc reports and analyses for management
- Planning and conducting security training and awareness activities
- Participating in business continuity and emergency response activities
- Improving the information security management system
Benefity
- Opportunity to influence IT security development within the organization
- Autonomy and responsibility for managed areas
- Participation in projects related to cybersecurity, regulations, and IT environment development
- Collaboration with IT teams, business units, and management
- Opportunity for professional development and obtaining industry certifications
- Work on real cybersecurity and risk management challenges
- Benefits package including private healthcare, sports card, group insurance, and medication insurance
- Sport subscription
- Private healthcare
- Free coffee
- Canteen
- Bicycle parking
- Free beverages
- Free lunch
Karta sportowa
Opieka zdrowotna
Napoje w biurze
Firmowa stołówka
Parking dla rowerów
Intelligent Logistic Solutions Sp. z o.o.
4 aktywne oferty