Ekspert/Ekspertka ds. Architektury Odporności IT/Cyberbezpieczeństwa (DORA)
Tech Stack / Keywords
Firma i stanowisko
Astek is a global partner in engineering and IT consulting established in 1988 in France, supporting international clients in digital transformation and product development. The group has over 10,000 employees engaged daily in diverse technological and engineering projects.
Wymagania
- Practical knowledge of the DORA regulation and ability to translate regulatory requirements into IT architecture, operational processes, and control mechanisms.
- Experience designing and implementing ICT resilience solutions.
- Knowledge of digital resilience testing methods.
- Ability to create and maintain documentation confirming regulatory compliance and effectiveness of implemented controls.
- Experience with hybrid environments including on-premise infrastructure, cloud solutions, networks, directory services, applications, and integrations.
- Skill in mapping dependencies among business processes, IT services, applications, data, infrastructure, and suppliers.
- Practical knowledge of information security and cyber risk management.
- Ability to identify, assess, record, and prioritize technological risks.
Nice to have:
- Experience in the financial, insurance, payment sectors, or other highly regulated environments.
- Familiarity with standards and methodologies: ISO 27001, ISO 22301, ISO 27005, NIST, CSF, NIST SP 800-53, COBIT, ITIL.
- Experience designing high availability architectures, multi-region solutions, active-active replication, and fault zone separation.
- Certifications such as CISM, CISSP, CISA.
Obowiązki
- Designing, developing, and maintaining IT architecture compliant with DORA requirements.
- Defining and implementing a target resilience model for the ICT environment.
- Planning and executing technology, IT services, and key platform development.
- Creating and maintaining architectural standards, technical documentation, and technology principles.
- Leading transformational initiatives involving architectural, technological, or organizational changes.
- Analyzing and optimizing information security and cybersecurity management models.
- Identifying, monitoring, and mitigating technological and cyber risks.
- Defining and enforcing security policies for systems, services, data, and IT infrastructure.
- Implementing measures to increase organizational resilience against failures, incidents, and cyber threats.
- Supervising compliance with security requirements, handling non-compliance, and monitoring corrective actions.
- Collaborating with CIO, CTO, CISO, service owners, and executive management on strategic IT initiatives.
- Preparing reports, analyses, recommendations, and management materials regarding IT environment status.
- Coordinating cooperation between IT, cybersecurity, and business teams.
- Overseeing the execution of agreed actions, decisions, and obligations in technology and security areas.
Benefity
- Long-term cooperation.
- Technical training, certifications, and skill development.
- Mentoring at Competence Center with opportunities to participate in conferences and share knowledge.
- Clear career path.
- Employee benefits package (Multisport, private health care, life insurance).
- Friendly work atmosphere, integration events, and team-building meetings.
- Referral bonus up to 7000 PLN.
Inne informacje
The data controller is ASTEK Polska sp. z o.o. based in Warsaw. Candidates have rights to access, correction, deletion, restriction, objection, data portability, and complaint filing regarding personal data. Data is processed for recruitment purposes, with mandatory data required by labor law and additional data based on consent. Consent may be withdrawn anytime. Data recipients include Just Join IT and other entities involved in recruitment processing. Whistleblower procedures apply as described at https://astek.pl/sygnalisci/. Detailed privacy policy: http://astek.pl/polityka-prywatnosci.
Astek
147 aktywnych ofert