Cyber Specialist
Brak informacji o wynagrodzeniu
SeniorFull-time
#438784·Dodano 7 dni temu·0
Źródło: AristocratTech Stack / Keywords
ISO 27001NIST CSFNIST 800-53CIS ControlsPCI DSSNIS2OWASPCISSPCISACRISC
Firma i stanowisko
Aristocrat Poland LLC is a gaming company focused on delivering entertainment through play. The position is hybrid-based in Krakow, Poland, at the Unity Tower office.
Wymagania
- Bachelor's degree in Cybersecurity, Information Security, Information Systems, Risk Management, Audit, Computer Science, or related field, or equivalent experience.
- Minimum 5+ years' experience in cybersecurity, IT risk, IT audit, compliance, third-party risk management, or security assessments.
- Proven experience conducting independent security assessments and detailing risk-based findings.
- Experience reviewing architecture and infrastructure security controls, vendor documentation, SOC reports, audit artifacts, remediation plans, and compliance evidence.
- Experience collaborating within enterprise technology, cloud platforms, and third-party service vendors.
- At least one certification from CISSP, CISA, CRISC, GIAC (others preferred).
- Experience performing vendor risk assessments or third-party security reviews.
- Experience supporting audits, examinations, or client assurance activities.
- Familiarity with cloud security, application security, identity and access management, and data protection controls.
- Experience using GRC, workflow, ticketing, or evidence management platforms.
Obowiązki
- Perform technical security assessments of web apps, mobile apps, APIs, applications, systems, cloud services, technology platforms, business processes, and third-party solutions.
- Evaluate application security controls, including authentication, authorization, session management, encryption, secrets management, logging, and secure configuration practices.
- Develop risk-based security recommendations balancing operational needs and business objectives.
- Document findings, conclusions, and risk decisions professionally.
- Review evidence supporting security controls and evaluate control efficiency.
- Produce executive-ready assessment summaries, threat analysis, and remediation recommendations.
- Present findings to both technical and non-technical audiences.
- Support reporting on assessment activity, emerging risks, remediation efforts, and security trends.
- Review vendor security questionnaires, SOC reports, certifications, penetration testing reports, and security documentation.
- Evaluate security measures of vendors, SaaS providers, cloud providers, and technology partners.
- Partner with Procurement, Legal, business teams, and vendors to resolve security concerns and detail residual risk.
- Assist with internal audits, external audits, client assurance requests, and regulatory examinations.
- Maintain current knowledge of ISO 27001, NIST CSF, NIST 800-53, CIS Controls, PCI DSS, NIS2, OWASP, GLI, and applicable regulations.
- Contribute to improving security assessment processes, templates, standards, and reporting.
Benefity
- Hybrid work arrangement: three days per week in Krakow office with flexibility on in-office days.
- Competitive pay and benefits package including potential annual bonuses, incentives, paid time off, retirement plans, and insurance coverage.
- Compensation tailored based on skills, experience, qualifications, and location.
Inne informacje
This is a hybrid position based in Krakow, Poland, requiring presence in the office three days per week at Unity Tower.
Aristocrat
25 aktywnych ofert