Chief Information Security Officer
Tech Stack / Keywords
Firma i stanowisko
ING Bank Śląski operates in the financial sector and offers a Chief Information Security Officer role based in Katowice or Warszawa with a hybrid work model (2 days office, 3 days remote). The position reports to the CIO and involves collaboration within the IT division and other bank units.
Wymagania
- Higher education, preferably in IT, cybersecurity, engineering or related fields
- Minimum 8 years of experience in cybersecurity or IT risk, including significant managerial experience; financial sector is a plus
- Experience in highly regulated organizations and practical knowledge of digital resilience and cybersecurity requirements, especially DORA, NIS2, EBA guidelines, KNF requirements
- Experienced in communication with regulators, external auditors, and management
- In-depth knowledge of current threats, attack techniques, risk assessment models, and cybersecurity standards and best practices
- Ability to assess technology landscape in cybersecurity and dependencies across security classes
- Practical understanding of public cloud security, SaaS services, digital infrastructure, supplier security, and AI-related risks
- Experience in creating and executing medium- and long-term cybersecurity strategy including roadmap, priorities, and budget
- Experience managing expert teams, fostering engagement, and competency development
- Strong influencing skills, expectation management, and stakeholder relationship building
- Ability to make decisions under pressure, uncertainty, and conflicting priorities balancing security and business needs
- Fluent in English (B2) and Polish (C1)
Obowiązki
- Shape and update cybersecurity and IT risk management strategy, translating it into roadmap, investment priorities, and budget
- Monitor implementation of security policies and standards by business and technology units and initiate changes for new threats and regulatory requirements
- Continuously assess global threat landscape and prioritize remedial actions
- Supervise cybersecurity incident management including handling, escalation, reporting, and lessons learned
- Monitor the bank's cybersecurity status, control mechanisms effectiveness, and technological projects for security compliance
- Oversee implementation of audit and regulatory recommendations related to Cybersecurity and IT Risk
- Manage cybersecurity risks of suppliers, especially those supporting critical bank services
- Ensure adequate security of infrastructure and digital services including public cloud, SaaS, and centrally provided security services
- Develop approach to AI security covering safe AI use and threats from external actors
- Build security culture via education, communication, and promoting informed decisions
- Act as business and technology partner to co-create secure solutions and define non-negotiable requirements
- Represent the bank with regulators, external auditors, and in national and international financial sector cybersecurity initiatives
Benefity
- Work in a mature, business and technology advanced IT division with over 1000 employees
- Comprehensive competency development in software development, IT security, and DevOps through projects including cloud migration
- Access to educational platforms like Microsoft ESI, Udemy Business, eTutor and funding for technical training
- Collaboration in communities of programmers, analysts, testers, Women in Tech, including mentoring and internship opportunities
- Medical package, life insurance, Mindgram platform, Employee Pension Program, and Oncology Prevention Program
- Sports cards (Medicover Sport and Multisport) and benefit cafeteria
- Additional days off
- Employee Referral Program with financial rewards
- Company car or equivalent
- Annual bonus based on performance
- Attractive contests with prizes and discounts in selected stores
Inne informacje
Informujemy, że administratorem danych jest ING Bank Śląski S.A z siedzibą w Katowicach, ul. Sokolska 34 (dalej jako "administrator"). Masz prawo do żądania dostępu do swoich danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania, prawo do wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych oraz wniesienia skargi do organu nadzorczego. Dane osobowe przetwarzane będą w celu realizacji procesu rekrutacji. Podanie danych w zakresie wynikającym z ustawy z dnia 26 czerwca 1974 r. Kodeks pracy jest obowiązkowe. W pozostałym zakresie podanie danych jest dobrowolne. Odmowa podania danych obowiązkowych może skutkować brakiem możliwości przeprowadzenia procesu rekrutacji. Administrator przetwarza dane obowiązkowe na podstawie ciążącego na nim obowiązku prawnego, zaś w zakresie danych dodatkowych podstawą przetwarzania jest zgoda. Dane osobowe będą przetwarzane do czasu zakończenia postępowania rekrutacyjnego i przez okres możliwości dochodzenia ewentualnych roszczeń, a w przypadku wyrażenia zgody na udział w przyszłych postępowaniach rekrutacyjnych - do czasu wycofania tej zgody. Zgoda na przetwarzanie danych osobowych może zostać wycofana w dowolnym momencie. Odbiorcą danych jest serwis Just Join IT oraz inne podmioty, którym powierzyliśmy przetwarzanie danych w związku z rekrutacją.
ING Bank Śląski
9 aktywnych ofert