Cyber Specialist
Tech Stack / Keywords
Firma i stanowisko
Aristocrat is a global team combining passion for gaming and innovation, focused on delivering joy through play. The role is located in Kraków at the Unity Tower office with a hybrid work model (three days in office, two remote).
Wymagania
- Higher education in cybersecurity, information security, information systems, risk management, auditing, computer science, or related field, or equivalent experience
- Minimum 5 years experience in cybersecurity, IT risk management, IT audit, compliance, vendor risk management, security assessments, or related area
- Proven experience independently performing security assessments and formulating detailed findings and risk-based recommendations
- Experience evaluating security of architecture and infrastructure and reviewing supplier documentation, SOC reports, audit documentation, remediation plans, and compliance evidence
- Experience working in corporate technology environments with cloud platforms and external service providers
- Possession of at least one certification: CISSP, CISA, CRISC, or GIAC; other certifications are a plus
- Experience conducting vendor risk assessments or third-party security reviews
- Experience supporting audits, controls, or activities related to client security assurance
- Knowledge of cloud security, application security, identity and access management, or data protection
- Experience using GRC platforms, workflow management tools, ticketing systems, and compliance documentation management tools
Obowiązki
- Conducting technical security assessments of web and mobile applications, APIs, cloud services, technology platforms, business processes, and third-party solutions
- Evaluating application security measures including authentication, authorization, session management, encryption, credentials, logging, and secure configurations to identify risks and vulnerabilities
- Developing practical recommendations based on risk analysis that consider security, operational requirements, and business goals
- Documenting findings, conclusions, and risk-related decisions clearly and professionally
- Reviewing evidence supporting security controls and assessing their effectiveness
- Preparing summaries of security assessments, threat analyses, and remediation recommendations for management
- Presenting results to both technical and non-technical audiences
- Supporting reporting on assessments, emerging threats, remediation actions, and security trends
- Reviewing security questionnaires from suppliers, SOC reports, certifications, penetration test reports, and related security documentation
- Assessing security levels of potential and current suppliers, SaaS vendors, cloud service providers, and technology partners
- Collaborating with Procurement, Legal, business teams, and suppliers to address security issues and determine residual risk levels
- Supporting internal and external audits, client security inquiries, and regulatory controls
- Maintaining up-to-date knowledge of standards and requirements such as ISO 27001, NIST CSF, NIST 800-53, CIS Controls, PCI DSS, NIS2, OWASP, and GLI
- Participating in continuous improvement of processes, templates, standards, and reporting practices related to security assessments
Benefity
- Competitive and comprehensive compensation package based on skills, experience, qualifications, and location
- Potential eligibility for annual bonuses and incentive benefits depending on position and location
- Health and wellness benefits
- Paid time off
- Retirement programs
- Insurance protection
- Additional local or statutory benefits
Inne informacje
Administratorem Twoich danych jest Aristocrat Poland (dalej: „Administrator”). Dane przetwarzamy w celu rekrutacji na stanowisko z ogłoszenia — na podstawie Kodeksu pracy (art. 6 ust. 1 lit. c RODO) w zakresie danych obowiązkowych, Twojej zgody (art. 6 ust. 1 lit. a RODO) w zakresie danych dodatkowych oraz naszego prawnie uzasadnionego interesu (art. 6 ust. 1 lit. f RODO) w zakresie obrony przed roszczeniami. Podanie danych wymaganych Kodeksem pracy jest obowiązkowe, pozostałych — dobrowolne. Dane przechowujemy do zakończenia rekrutacji i przez okres przedawnienia roszczeń, a przy zgodzie na przyszłe rekrutacje — do jej wycofania, nie dłużej niż 24 miesiące. Odbiorcami mogą być nasi dostawcy usług rekrutacyjnych, w tym JUST JOIN IT Sp. z o.o., operator serwisów rocketjobs.pl, justjoin.it, rocketjobs.com. Masz prawo dostępu do danych, ich sprostowania, usunięcia, ograniczenia i przenoszenia, wniesienia sprzeciwu oraz skargi do Prezesa UODO. Zgodę możesz wycofać w każdej chwili — bez wpływu na przetwarzanie sprzed wycofania. Dane nie podlegają profilowaniu.
Aristocrat
25 aktywnych ofert