IT Risk Consultant with European languages
Brak informacji o wynagrodzeniu
MidFull-time
#442388·Dodano dziś·0
Źródło: nofluffjobs.comTech Stack / Keywords
DORACybersecurityIT RiskHITRUSTCOBITITIL certificate
Firma i stanowisko
As an IT Risk & Compliance Consultant in Digital Risk at EY GDS Poland, you will join a high-performing, international team delivering IT regulatory compliance, cybersecurity maturity, and IT control framework services to leading global clients.
Wymagania
- 3–5 years of relevant experience in IT risk, cybersecurity, compliance or assurance
- University degree in Information Technology, Computer Science, Cybersecurity or related field
- English working proficiency (B2 and above)
- Working proficiency (B2 and above) in at least one additional language: French, German, Spanish, Dutch or Italian
- Working experience in at least one of the following areas: ISO 27001 implementation or audit, PCI DSS or payment security assessments, HIPAA/HITRUST or healthcare compliance, IT regulatory compliance or external assurance engagements
- Understanding at least one of the following frameworks or domains: ISO 27001 / ISMS, NIST CSF or NIST 800-53, PCI DSS, GDPR, COBIT, ITIL, DORA, NIS2
- Background in IT risk, cybersecurity, compliance, audit or advisory
- Past experience in at least one of the following industries: banking, payments, financial services, healthcare, pharma, retail, e-commerce, energy, utilities, transport, telecom or critical infrastructure sectors
- Experience with regulatory reviews, certifications or compliance programs is a strong advantage
Nice to have:
- Experience in cyber maturity assessments or security benchmarking
- Understanding of risk taxonomy, control libraries and remediation planning
- Experience working in regulated industries or multi-jurisdiction environments
- Experience with policy drafting, governance models and executive reporting
- Certifications such as HITRUST, COBIT or ITIL
Obowiązki
- Supporting design and review of IT regulatory and compliance frameworks across ISO 27001, NIST CSF, PCI DSS, HIPAA, HITRUST, GDPR, COBIT, ITIL
- Performing cyber / IT maturity assessments, gap assessments, and control mapping, including development of remediation roadmaps
- Assisting with ISO 27001 programs, including ISMS scoping, risk assessment, Statement of Applicability, control implementation, and audit readiness
- Supporting PCI DSS assessments, including review of cardholder data environments, security controls, and evidence preparation
- Contributing to HIPAA / HITRUST and regulated-data compliance projects in healthcare and life sciences environments
- Drafting policies, standards, governance frameworks, RACI models, and senior management reports
- Identifying control gaps and supporting remediation planning and execution
- Collaborating with stakeholders across IT, security, compliance, and business teams to deliver high-quality, audit-ready documentation
Benefity
- Sport subscription
- Training budget
- Private healthcare
- International projects
Karta sportowa
Dofinansowanie szkoleń
Opieka zdrowotna
EY GDS
12 aktywnych ofert