EY GDS
EY GDS
New

IT Risk Consultant with European languages

Brak informacji o wynagrodzeniu
MidFull-time
#442388·Dodano dziś·0
Źródło: nofluffjobs.com
Aplikuj teraz

Tech Stack / Keywords

DORACybersecurityIT RiskHITRUSTCOBITITIL certificate

Firma i stanowisko

As an IT Risk & Compliance Consultant in Digital Risk at EY GDS Poland, you will join a high-performing, international team delivering IT regulatory compliance, cybersecurity maturity, and IT control framework services to leading global clients.

Wymagania

  • 3–5 years of relevant experience in IT risk, cybersecurity, compliance or assurance
  • University degree in Information Technology, Computer Science, Cybersecurity or related field
  • English working proficiency (B2 and above)
  • Working proficiency (B2 and above) in at least one additional language: French, German, Spanish, Dutch or Italian
  • Working experience in at least one of the following areas: ISO 27001 implementation or audit, PCI DSS or payment security assessments, HIPAA/HITRUST or healthcare compliance, IT regulatory compliance or external assurance engagements
  • Understanding at least one of the following frameworks or domains: ISO 27001 / ISMS, NIST CSF or NIST 800-53, PCI DSS, GDPR, COBIT, ITIL, DORA, NIS2
  • Background in IT risk, cybersecurity, compliance, audit or advisory
  • Past experience in at least one of the following industries: banking, payments, financial services, healthcare, pharma, retail, e-commerce, energy, utilities, transport, telecom or critical infrastructure sectors
  • Experience with regulatory reviews, certifications or compliance programs is a strong advantage

Nice to have:

  • Experience in cyber maturity assessments or security benchmarking
  • Understanding of risk taxonomy, control libraries and remediation planning
  • Experience working in regulated industries or multi-jurisdiction environments
  • Experience with policy drafting, governance models and executive reporting
  • Certifications such as HITRUST, COBIT or ITIL

Obowiązki

  • Supporting design and review of IT regulatory and compliance frameworks across ISO 27001, NIST CSF, PCI DSS, HIPAA, HITRUST, GDPR, COBIT, ITIL
  • Performing cyber / IT maturity assessments, gap assessments, and control mapping, including development of remediation roadmaps
  • Assisting with ISO 27001 programs, including ISMS scoping, risk assessment, Statement of Applicability, control implementation, and audit readiness
  • Supporting PCI DSS assessments, including review of cardholder data environments, security controls, and evidence preparation
  • Contributing to HIPAA / HITRUST and regulated-data compliance projects in healthcare and life sciences environments
  • Drafting policies, standards, governance frameworks, RACI models, and senior management reports
  • Identifying control gaps and supporting remediation planning and execution
  • Collaborating with stakeholders across IT, security, compliance, and business teams to deliver high-quality, audit-ready documentation

Benefity

  • Sport subscription
  • Training budget
  • Private healthcare
  • International projects
Karta sportowa
Dofinansowanie szkoleń
Opieka zdrowotna
EY GDS

EY GDS

12 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz