(Cybersecurity) Head of Cybersecurity Risk

4 tygodni temu


Krakow, Polska HSBC Service Delivery (Polska) Sp. z o.o. Pełny etat

technologies-expected :
ServiceNow
Archer

about-project :
The Cybersecurity function is responsible for enabling businesses and functions to manage their Information and Cybersecurity risks as well as ensuring risks and controls are assessed and implemented appropriately, objectively and independently through professional and specialized subject matter experts, whilst ensuring regulatory compliance.

responsibilities :
The Global Head of Cybersecurity Risk & Controls will play a key role in coordinating activities required to implement the Cybersecurity Risk and Controls Strategy across globally in partnership with Control Owners and SMEs. This role will report into the Global Head of Business Engagement, whilst closely partnering with Regional and Business Information Security Officers. The key part of the role will be leading on design, oversight and reporting on Cybersecurity controls.
The ideal candidate will possess strong leadership and communication skills, a wide knowledge in risk and controls space, as well as across all cybersecurity domains and strong experience in managing international teams and stakeholders. The role holder will be required to manage a global team, stakeholders including the Control Owners, regional and business CIOs and COOs; Cybersecurity Leadership and staff; Chief Controls Office (CCO) Technology, 2LoD Resilience Risk and 3LoD Internal Audit teams.
Building out, leading and managing a new Global merged team combining Cybersecurity Risk & Controls capabilities.
Working with the Control Owners, wider CBE team, 2LoD, 3LoD and CCO Technology to ensure that the Cybersecurity owned controls in the Risk and Controls Library and federated controls owned by the business, are designed according to the Bank’s requirements and industry standards and best practises (e.g. NIST FSS) and embedded across the business and regions.
Lead on reporting capabilities to enable oversight of control effectiveness through Key Control Indicators, as well as to ensure these are tailored and consumed by the business and regions.
Conduct periodic maturity assessment of Cybersecurity controls against industry best practices frameworks (e.g. NIST) in partnership with independent/external suppliers
Drive continuous improvement and embedding of the Cybersecurity Risk Quantification (CRQ) model to enable a data driven risk assessment and oversight

requirements-expected :
Experience with Technology risks and controls. Knowledge of Cybersecurity is a must.
Significant, subject matter expertise in risk and control management. This includes but is not limited to controls design and implementation and control assessment, as well as MI and executive reporting.
Wide general cybersecurity knowledge; Understanding of Cybersecurity concepts such as threats, vulnerabilities, attack vectors, inherent/residual risk.
Understanding metrics and measures in managing risks and controls (KPIs, KCIs, KRIs) is a must.
Familiarity with the NIST Cyber Security Framework (CSF) would be beneficial.
Knowledge of Centre for Internet Security (CIS) Measures and Metrics is a plus.
Experience with GRC Tools (such as HELIOS, ServiceNow, Archer) is a plus.
Experience in dealing with Senior Management, internal and external audit.
Strong understanding of regulatory landscape, and key process to ensure robust response to regulatory assessments/exams, as well as customer and third party requests on Cybersecurity maturity posture.

benefits :
sharing the costs of sports activities
private medical care
sharing the costs of professional training & courses
life insurance
flexible working time
integration events
corporate sports team
doctor’s duty hours in the office
retirement pension plan
corporate library
no dress code
video games at work
coffee / tea
parking space for employees
leisure zone
extra social benefits
employee referral program
opportunity to obtain permits and licenses
charity initiatives
family picnics
extra leave



  • Krakow, Polska Mindbox S.A. Pełny etat

    about-project : Cybersecurity Control Design Analyst will support continuous maintenance and development of the Cybersecurity control environment. The role holder will be tasked with support of defining and maintaining operational controls instances and their attributes, control measurements as well as control requirements for Group...


  • Krakow, Polska Michael Page Pełny etat

    responsibilities : The Controls Design Manager will be deployed onsite to one of our Investment Banking clients to support a key global project in the Cybersecurity regulatory space. This person will define and design controls and their measurements following the bank's Standards and new Regulations. Your duties will include: Working with Control Owners to...


  • Krakow, Polska Groupe SII Pełny etat

    Join one of the largest financial institutions in the world as a Cybersecurity Fullstack Engineer. You will work on a cybersecurity team that works on data loss prevention, security infrastructure, and vulnerability management. The team delivers critical functions and transactions worth billions of pounds across the organization. Your primary responsibility...


  • Krakow, Polska Mindbox S.A. Pełny etat

    about-project : The Cybersecurity Pen Test Senior Consultant job is responsible for operating as part of a global/regional team within Cybersecurity to define and implement an industry leading Cybersecurity Service that supersedes our constantly changing information security threats. This role is accountable for direct management of a team and/or managing...


  • Krakow, Polska Algoteque Pełny etat

    ALGOTEQUE is an IT consultancy firm that helps startups, mid-sized and large corporations to create and deliver innovative technologies.Our team has a successful track record in designing, developing, implementing, and integrating software solutions (AI, ML, BI, Web, Automation) for Telecom, Energy, Bank, Insurance, Pharma, Automotive, Industry, e-commerce....


  • Krakow, Polska Mindbox S.A. Pełny etat

    (Cybersecurity) Senior Software Engineer Miejsce pracy: Kraków Technologies we use Expected C# Microsoft SQL Server .NET Optional Azure DevOps Operating system Windows About the project The team focuses on the delivery of middle sized applications to support processes and communications with various business partners inside our organisation. The...


  • Krakow, Polska Mindbox S.A. Pełny etat

    technologies-optional : SharePoint Confluence Jira about-project : The CROS Governance and Delivery Lead supports the wider CROS function (Penetration Testing, Red Team, Security Research, and Crowd-sourced Security Testing) to ensure effective delivery of its services. The role holder will be responsible for maintaining governance and reporting...


  • Krakow, Polska Hitachi Careers Pełny etat

    Description Hitachi Energy is looking for Regional Head of Trade Management Europe (f/m/d)At Hitachi Energy our purpose is advancing a sustainable​ energy future for all. We bring power to our homes, schools, hospitals and factories. Join us and work with fantastic people, while learning and developing yourself on projects that have a real impact to our...


  • Krakow, Polska AVENGA Pełny etat

    Supporting the Client in a Third Party Risk Management process (TPRM), performing Vendor Risk Assessments. Estimated lenght: 2 years Required experience: conducting risk assessments (ideally of third-party vendors) against security standards, such as ISO 27001 and NIST Understanding of concepts of cyber security controls in IT areas (e.g. Access management,...


  • Krakow, Polska Mindbox S.A. Pełny etat

    technologies-expected : C# Microsoft SQL Server .NET technologies-optional : Azure DevOps about-project : The team focuses on the delivery of middle sized applications to support processes and communications with various business partners inside our organisation. The development has been based on .NET technology and we have implemented new trends in a...

  • Network Engineer

    4 tygodni temu


    Krakow, Polska CPL Jobs . Pełny etat

    technologies-expected : SSL/TLS DNS DHCP WINS NTP FTP HTTP SMTP CIFS LDAP Microsoft AD VPN IPSEC SSL VPN WebVPN AnyConnect DMVPN OSPF BGP VLAN STP technologies-optional : CCNA about-project : Network Engineers Wanted! Are you passionate about cybersecurity? Do you thrive in dynamic environments? Our client, a global leader in cybersecurity, is seeking...


  • Krakow, Polska Pterois Pełny etat

    technologies-expected : Leadership C Linux Kernel Embedded Automotive responsibilities : has at least 6 years experience in embedded systems development acted for at least 3 years as Software Project Leader is proficient in Linux Kernel development and modules integration knows different communication protocols (CAN, Ethernet, D-Bus) requirements-expected...

  • Network Engineer

    1 tydzień temu


    Krakow, Polska CPL Jobs . Pełny etat

    Expected, SSL/TLS, DNS, DHCP, WINS, NTP, FTP, SMTP, CIFS, LDAP, Microsoft AD, VPN, IPSEC, SSL VPN, WebVPN, AnyConnect, DMVPN, OSPF, BGP, VLAN, STP Optional, CCNA About the project, Network Engineers Wanted! Are you passionate about cybersecurity? Do you thrive in dynamic environments? Our client, a global leader in cybersecurity, is seeking enthusiastic and...


  • Krakow, Polska State Street Pełny etat

    Who we are looking for:An experienced professional to join the team as Assistant Vice President - Financial Risk Reporting based in the Poland. This role is part of the Global Risk Operations Group within Enterprise Risk Management’s Financial Risk Organization.The goal of ERM is to ensure that State Street’s risks are proactively identified,...

  • Technology Risk, Officer

    3 tygodni temu


    Krakow, Polska State Street Pełny etat

    Why this role is important to us:The Technology Risk Officer is a role within the Corporate Functions, Markets and Financing (CFMF) Business Risk Management Organization providing assistance to the supported Business teams, Business Risk Advisory (BRA) teams and other risk members on technology specific strategies and risks, including but not limited to...


  • Krakow, Polska Mindbox S.A. Pełny etat

    technologies-optional : JIRA Confluence GIT about-project : Join our team as an Agile Business Analyst/QA and take on a pivotal role in ensuring highquality solutions are delivered in a dynamic Agile and DevSecOps environment. Reporting directly to the Technical Delivery Lead or QA Manager, you will be a key link between the technical team and business...


  • Krakow, Polska Brown Brothers Harriman Pełny etat

    technologies-expected : Microsoft Excel technologies-optional : Active Directory about-project : At BBH we value diverse backgrounds, so if your experience looks a little different from what we've outlined and you think you can bring value to the role, we will still welcome your application! What You Can Expect At BBH: If you join BBH you will find a...


  • Krakow, Polska Orange Business Services Pełny etat

    about the role Budowanie, oferowanie i wdrażanie innowacyjnych oraz cyfrowych rozwiązań ICT dla Klientów Biznesowych Tworzenie i dobór rozwiązań dla Klientów w zakresie sprzętu IT (presales) Realizacja celów sprzedażowych, szacowanie opłacalności projektów i ich raportowanie Rozpoznawanie i kreowanie popytu na nowe innowacyjne...


  • Krakow, Polska HSBC Service Delivery (Polska) Sp. z o.o. Pełny etat

    technologies-expected : SAS Python R Matlab C++ VBA responsibilities : Contributing to model validation and testing activities. Preparing data sets in readiness for validation activities. Support the Model Validation team as required. Contribute to management, regulatory, and external confidence in all models used across the group. requirements-expected...


  • Krakow, Polska State Street Pełny etat

    Assistant Vice President – Krakow, Poland Information Technology Risk Coordinator Enterprise Technology Risk Management (ETRM) It is an exciting time to join State Street Corporation (SSC) as a member of the Risk organization. State Street is the industry leader in investment management, research & trading and servicing.The Enterprise Risk Management...