Information Security Officer

Brak informacji o wynagrodzeniu
SeniorFull-time·B2B
#449946·Dodano 4 dni temu·1
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

Information SecurityIT Security

Firma i stanowisko

Tradevest Polska SP. Z O. O. operates within the Tradevest Group and addresses information security across multiple regulatory jurisdictions including Germany and Poland.

Wymagania

  • At least three years of practical experience as an information security officer or in a comparable information security role in a fast-growing company.
  • Preferred certifications include CISA, CISM, or ISO 27001 Lead Auditor.
  • Strong knowledge of legal and regulatory requirements such as DORA (Digital Operational Resilience Act) and NIS2.
  • Strong business acumen and proactive collaboration skills with stakeholders across the company and group.
  • Experience implementing security strategies, policies, procedures, and standards.
  • Extensive knowledge of current and emerging cybersecurity technologies, document management, and security operations.

Obowiązki

  • Continuous coordination of information security objectives with the strategic objectives of the Tradevest Group.
  • Advising management on information security issues and providing regular reports on security status.
  • Establishing, operating, and developing the information management system (ISMS) based on GRC software.
  • Creating and updating security guidelines and procedures in line with standards and legal requirements like MaRisk and DORA.
  • Creating, coordinating, and implementing audit procedures following a multi-year audit plan.
  • Coordinating and following up on measures to address risks and prevent security incidents.
  • Recording and coordinating the handling, analysis, and follow-up of information security incidents.
  • Coordinating ongoing and on-demand information risk analyses with relevant owners.
  • Supporting implementation and documentation of emergency tests and updating emergency manuals.
  • Coordinating awareness-raising and training measures tailored to target groups on information security.
  • Assessing technical security posture of critical ICT third-party service providers and reviewing certifications such as ISO 27001 and SOC 2.
  • Planning, coordinating, and evaluating penetration testing and digital operational resilience testing pursuant to Art. 24–27 DORA.

Inne informacje

Please be informed that the data controller is Tradevest GmbH (hereinafter "controller"). You have the right to request access to your personal data, their rectification, erasure or restriction of processing, the right to object to processing, as well as the right to data portability and to lodge a complaint to the supervisory authority. Personal data will be processed for the purpose of the recruitment process. Provision of data to the extent resulting from the Act of 26 June 1974 Labour Code is mandatory. In the remaining scope, providing data is voluntary. Refusal to provide mandatory data may result in the impossibility to carry out the recruitment process. The Administrator processes mandatory data on the basis of a legal obligation incumbent upon him/her, while with regard to additional data, the basis for processing is consent. Personal data will be processed until the recruitment procedure is completed and for the period of the possibility of asserting potential claims, and in the case of consent to participate in future recruitment procedures - until the withdrawal of such consent. Consent to the processing of personal data can be withdrawn at any time. The recipient of the data is the Just Join IT service and other entities to whom we have entrusted the processing of data in connection with recruitment.

Tradevest Polska

Tradevest Polska

Pracodawca

Aplikuj teraz