freehire launches on Product Hunt on 26 August.

Follow →

Information Security Officer (ISO)

Open 28d

Summary

Oversee and improve an international company’s security governance, risk management, and compliance, conducting assessments and advising leadership on cybersecurity risks.

For our client, we are looking for an experienced Information Security Officer (ISO) to support a large international organization in strengthening its security governance framework and managing cyber security risks across the business.

This is a highly visible role that combines Security Governance, Risk & Compliance, Security Operations, and Security Assessments. You will act as a trusted security advisor, working closely with business and IT stakeholders to ensure security risks are identified, assessed, and managed effectively.

You will collaborate with an established security team and support management in making informed risk-based decisions while continuously improving the organization's security posture.

Your Responsibilities

  • Define and drive security strategy, priorities, and initiatives

  • Maintain security policies, standards, and procedures, ensuring adherence across the organization

  • Perform security and risk assessments, including:

    • Risk identification, evaluation, and treatment planning

    • Application and Information Classification (AIC) assessments

    • Supplier Risk Assessments (SRA)

    • Operational Risk Assessments (ORA)

  • Monitor and report on security vulnerabilities and risk exposure

  • Coordinate and support security testing and assessment activities

  • Detect, analyze, and support response to security incidents and threats

  • Advise management on information security risks and mitigation strategies

  • Promote security awareness and security best practices throughout the organization

  • Work closely with internal stakeholders to continuously improve security processes and controls

  • Stay current with emerging threats, industry trends, and regulatory requirements

What We're Looking For

Must Have

  • Proven experience in Information Security, Cyber Security, Information Risk Management, or a similar role

  • Hands-on experience conducting security and risk assessments

  • Strong understanding of risk management methodologies and risk treatment processes

  • Experience performing or coordinating:

    • Security Assessments

    • Supplier Risk Assessments (SRA)

    • Operational Risk Assessments (ORA)

  • Strong communication and stakeholder management skills

  • Ability to challenge the status quo and drive continuous improvement

  • A pragmatic, risk-based mindset with the ability to balance security and business needs

  • English - min. C1 level

Technical & Domain Knowledge

Good knowledge of security governance frameworks and regulations, including:

  • ISO 27001

  • NIST

  • NIS2

  • DORA

  • CIS Controls

  • SOC2

  • GDPR

You should be comfortable performing security assessments yourself while also acting as a subject matter expert and coordinating security-related activities across different teams.

Nice to Have

  • Experience in financial services or highly regulated environments

  • Experience with vulnerability management and security operations

  • Experience supporting incident response activities

  • Knowledge of offensive security testing practices

  • Relevant security certifications (e.g., CISSP, CISM, ISO 27001), although certifications are not required

Team & Environment

  • Work closely with Information Security Officers and senior IT leadership

  • Report into the Head of IT Europe

  • Operate as a key security advisor within an international environment

  • Collaborate with both business and technical stakeholders across multiple domains

Ideal Candidate

We're looking for someone who:

  • Thinks strategically but can also work hands-on when needed

  • Has strong analytical and risk assessment skills

  • Is confident communicating with both technical teams and senior management

  • Is proactive, curious, and eager to improve existing processes

  • Can influence stakeholders and drive security initiatives forward

If you are passionate about cyber security, governance, and risk management, and enjoy working in an environment where security is a business enabler, we'd love to hear from you.

Offer

  • Recruitment process: 1 call with recruiter and 1 technical interview

  • Remote work

  • B2B contract

  • Rate: 160 - 300 PLN / h - depends on experience and qualifications

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available