Cybersecurity Governance Risk and Compliance Consultant
About Company:
Team Connect is Poland’s leading nearshore and offshore IT provider. Since 2008 we successfully create and develop software for our clients. We specialize in Agile and DevOps-based software development. From the analysis stage through implementation. We develop backend, frontend, and mobile applications.
For one of our clients, we are looking for a Cybersecurity Governance Risk and Compliance Consultant.
Location & Delivery Mode: Warsaw, hybrid – 30% onsite / 70% remote.
Experience Required: At least 9 years post-education, incl. 8+ years in a similar role.
Required Certificates:
At least 4 certifications among (must have):
[1] CISA (ISACA Certified Information Systems Auditor)
[2] CISM (ISACA Certified Information Security Manager)
[3] CRISC (ISACA Certified in Risk and Information Systems Control)
[4] CISSP (ISC2 Certified Information Systems Security Professional)
[5] CGRC (ISC2 Certified in Governance, Risk and Compliance)
[6] CSSLP (ISC2 Certified Secure Software Lifecycle Professional)
[7] CCSP (ISC2 Certified Cloud Security Professional)
[8] CISSP-ISSMP (ISC2 Certified Information Systems Security Management Professional)
[9] GSNA (GIAC Certified Systems and Network Auditor)
[10] GCCC (GIAC Certified Critical Controls)
[11] GIAC Certified ISO-27000 Specialist
[12] ISO 27001 Lead implementer or equivalent.
[13] ISO 27001 Lead Auditor or equivalent.
[14] ISO 27005 Risk Manager or equivalent.
or for any listed above, an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority)
Knowledge & Skills:
Knowledge:
[01] Cybersecurity related laws, regulations and legislations
[02] Cybersecurity standards, methodologies and frameworks
[03] Cybersecurity policies
[04] Legal, regulatory and legislative compliance requirements, recommendations and best practices
[05] Privacy impact assessment standards, methodologies and frameworks
Skills:
[06] Comprehensive understanding of the business strategy, models and products and ability to factor into legal, regulatory and standards’ requirements
[07] Carry out working-life practices of the data protection and privacy issues involved in the implementation of the organisational processes, finance and business strategy
[08] Lead the development of appropriate cybersecurity and privacy policies and procedures that complement the business needs and legal requirements; further ensure its acceptance, comprehension and implementation and communicate it between the involved parties
[09] Conduct, monitor and review privacy impact assessments using standards, frameworks, acknowledged methodologies and tools
[10] Explain and communicate data protection and privacy topics to stakeholders and users
[11] Understand, practice and adhere to ethical requirements and standards
[12] Understand legal framework modifications implications to the organisation’s cybersecurity and data protection strategy and policies
[13] Collaborate with other team members and colleagues
Specific Requirements:
[01] minimum 5+ years of experience in cybersecurity GRC, with clear focus on cybersecurity risk management
[02] Proven experience in designing or operatiationalising a cyber risk management framework
[03] Hands-on experience in using ServiceNow GRC (IRM / Risk / Policy and Compliance modules)
[04] Demonstrated experience maintaining and managing a cybersecurity risk register.
[05] Experience integrating risk management with: Vulnerability management, Incident management, Cloud risk, Third-party risk
[05] Experience contributing to cybersecurity maturity improvement programmes.
11. Typical Tasks & Responsibilities:
- Ensure compliance with and provide legal advice and guidance on data privacy and data protection standards, laws and regulations
- Identify and document compliance gaps
- Conduct privacy impact assessments and develop, maintain, communicate and train upon the privacy policies, procedures
- Enforce and advocate organisation’s data privacy and protection program
- Ensure that data owners, holders, controllers, processors, subjects, internal or external partners and entities are informed about their data protection rights, obligations and responsibilities
- Act as a key contact point to handle queries and complaints regarding data processing
- Assist in designing, implementing, auditing and compliance testing activities in order to ensure cybersecurity and privacy compliance
- Monitor audits and data protection related training activities
- Cooperate and share information with authorities and professional groups
- Contribute to the development of the organisation’s cybersecurity strategy, policy and procedures
- Develop and propose staff awareness training to achieve compliance and foster a culture of data protection within the organization
- Manage legal aspects of information security responsibilities and third-party relations"