Lead Cyber Security GRC Specialist

3 tygodni temu


Warsaw, Polska Bayer Sp. z o.o. Pełny etat

For Digital Hub Warsaw, we are looking for: Lead Cyber Security GRC Specialist Responsible for developing, implementing, and managing cyber security Governance, Risk, and Compliance (GRC) initiatives within Bayer, measuring adherence to Bayer policies and procedures which are based on industry standards. Assessing compliance of Bayer processes, monitoring critical IT security deliverables, and providing audit support for cybersecurity teams. Also, managing IT security exceptions and recommending controls to address gaps through data and security risk assessments. Support preparation of alignment meetings with German workers councils to ensure that cybersecurity tools and processes are implemented in accordance with co-determination laws. Key Tasks & Responsibilities: Perform risk management activities to identify, assess, and mitigate cyber security risks for Bayer. These include owning and management of the cybersecurity framework (in particular based on ISO/IEC 27001), measuring the effectiveness of this framework and driving for the maturity and to support business needs Develop and maintain key performance indicators (KPIs) and metrics to measure the effectiveness of GRC initiatives. Prepare regular reports for senior management on the status of GRC activities. Collaborate with cross-functional teams to integrate GRC principles into business processes and systems Provide consulting across the organization on matters of cybersecurity GRC Monitor regulatory changes and industry trends to ensure the organization remains compliant and proactive in addressing emerging risks Act as a liaison with external auditors, and stakeholders on GRC-related matters Work closely together with other cybersecurity teams to ensure that in case of process changes data privacy and workers council requirements are met and new approvals are obtained, if necessary Focus on Governance topics: Develop and implement GRC strategies, policies, and procedures to ensure compliance with regulatory standards and industry best practices Ensure that the board and senior management receive accurate and timely information for decision-making. Establish and maintain policies and procedures to promote ethical behavior and accountability Develop and enforce GRC policies and strategies for IT Security compliance Report GRC status to management and liaise with stakeholders Qualifications & Competencies (education, skills, experience): Educational Background: A Bachelor's or Master's degree in law, information technology, cybersecurity, computer science, or a related field is essential, though relevant working experience may be considered an equivalent. [3] years of experience in cyber security, previous experience in a GRC role highly desired Proficiency in various cybersecurity tools and software, understanding of network infrastructure and security protocols, and knowledge of threat modeling and risk assessment techniques are helpful Profound knowledge of EU and German cybersecurity and data privacy legislation, such as NIS-2, KRITIS, DORA, GDPR, etc. Experience with policy writing Practical experience information security in a corporate or government setting is valuable, along with familiarity with information security standards and frameworks such as ISO/IEC 27001 and NIST Experience with risk management frameworks such as NIST Cybersecurity Framework or ISO 27001 Certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC) are desirable Dealing with high complexity and ability to think and act in a goal- and result-oriented manner English, fluent in written and spoken. German language skills would be a plus What do We offer: A flexible, hybrid work model Great workplace in a new modern office in Warsaw Career development, 360° Feedback & Mentoring programme Wide access to professional development tools, trainings, & conferences Company Bonus & Reward Structure VIP Medical Care Package (including Dental & Mental health) Holiday allowance ("Wczasy pod gruszą") Life & Travel Insurance Pension plan Co-financed sport card - FitProfit Meals Subsidy in Office Additional days off Budget for Home Office Setup & Maintenance Dedicated working Zone with state-of-the art Lab available only for Cyber Security Team Access to Company Game Room equipped with table tennis, soccer table, Sony PlayStation 5 and Xbox Series X consoles setup with premium game passes, and massage chairs Tailored-made support in relocation to Warsaw when needed Please send your CV in English You feel you do not meet all criteria we are looking for? That doesn't mean you aren't the right fit for the role. Apply with confidence, we value potential over perfection. WORK LOCATION: WARSAW AL.JEROZOLIMSKIE 158



  • warsaw, mazowieckie, Polska Bayer Sp. z o.o. Pełny etat 23 zł - 500 zł

    For Digital Hub Warsaw, we are looking for: Lead Cyber Security Architect This role contributes technically in defining and assessing Bayer’s security strategy, technical architecture and practices. They translate business objectives and risk management strategies into specific security controls enabled by security technologies and services. Provide...


  • Warsaw, Polska Intertek Pełny etat

    Our purpose Bringing quality and safety to life. Intertek, a leading international provider of ATIC (Assurance, Testing, Inspection, and Certification) services, is looking for a Cyber Security Manager to join Intertek IT Security team. Cyber Security Manager will report to the Head of IT Security Operations and manage a team of experienced Analysts that...

  • Cyber Security Engineer

    4 tygodni temu


    Warsaw, mazowieckie, Polska Square One Pełny etat 30 zł

    Wymagania : Minimum 4-5 lat doświadczenia na stanowisku odpowiedzialnym za Cyber Security Bardzo dobra znajomość AWS oraz podstawowa wiedza z zakresu Javy lub Pythona Bardzo dobre doświadczenie w zakresie ICS, Incident Response, Threat Hunting, Security Operations & Monitoring, Risk ManagementDoświadczenie w branży finansowej i bankowej Mile widziane...


  • Warsaw, Polska Intertek Pełny etat

    Our purpose Bringing quality and safety to life. Intertek, a leading international provider of ATIC (Assurance, Testing, Inspection, and Certification) services, is looking for a Senior Cyber Security Analyst to join Intertek IT Security team. This is an interesting and varied role, and a great opportunity to become a subject matter expert in the endpoint...


  • Warsaw, Polska Jit Team Pełny etat

    Salary: 1000 - 1200 PLN/day on B2B Work model: elastic hybrid from Gdynia / Gdańsk / Warszawa (at least 2-3 days per week from the office) Why choose this offer? You can expect a flexible work organization The international work environment will give you the opportunity to interact with the English language on a daily basis Scandinavian organizational...


  • Warsaw, Polska WTW Pełny etat

    Cyber Defence · Global Security Operations Centre (GSOC) Level 2 Analyst Warszawa / hybrid Contract of employment (Full-time) PL256601 As part of the Cyber Defence team in the Global Security Operations Centre, you will provide security monitoring, triage, and investigation of potential incidents, and help to constantly improve the ways that the team works...


  • Warsaw, Polska WTW Consulting Sp. z o.o. Pełny etat

    Cyber Defence · Global Security Operations Centre (GSOC) Level 3 Analyst Warszawa / hybrid Contract of employment (Full-time) PL256602 As part of the Cyber Defence team in the Global Security Operations Centre, you will provide oversight of triage, investigation of security alerts and potential security incidents. After a threat or incident is identified,...

  • IT Security Specialist

    3 tygodni temu


    Warsaw, Polska Bausch Health Poland Sp z.o.o. Pełny etat

    IT Security Specialist Miejsce pracy: Warszawa Technologies we use Expected Azure Active Directory Microsoft Defender Microsoft D365 F&O Microsoft Purview Optional Power Platform About the project Join our global diversified pharmaceutical company enriching lives through our relentless drive to deliver better health outcomes to our patients. We are all in it...


  • Warsaw, Polska WTW Pełny etat

    Cyber Defence · Global Security Operations Centre (GSOC) Level 1 Analyst Warszawa / Hybrid Contract of employment PL250802 As part of the Cyber Defence team in the Global Security Operations Centre, you will provide security monitoring, triage, and investigation of potential incidents, and help to constantly improve the ways that the team works so that we...

  • IT Security Specialist

    22 godzin temu


    Warsaw, Polska Experis Manpower Group Pełny etat

    Experis to światowy lider rekrutacji specjalistów i kadry zarządzającej w kluczowych obszarach IT. Z nami znajdziesz konkurencyjne oferty zatrudnienia oraz ciekawe projekty IT skierowane zarówno do ekspertów z wieloletnim doświadczeniem, jak i osób, które dopiero zaczynają swoją przygodę w branży IT. Start Date: ASAP / Within 1 Month / Flexible...