Information Security Officer

Summary

The Information Security Officer will lead the company's information security strategy, managing the ISMS and ensuring compliance with regulatory standards like DORA and NIS2. The role involves advising management, conducting risk assessments, and coordinating security audits and incident response across the group.

Take ownership of our information security strategy and help protect what matters most: our data, our systems, and the trust our clients place in us. In this role, you'll ensure all Group companies meet the highest security standards and stay resilient against emerging threats.
  • Continuous coordination of information security objectives with the strategic objectives of the Tradevest Group.
  • Work directly with the management advising them on information security issues and provide regular reports on the status of information security.
  • Establishment, operation and further development of our information management system (ISMS) based on the GRC software we use.
  • Creating and updating security guidelines and procedures in accordance with current standards and legal requirements (MaRisk, DORA etc.) arising from the different regulatory jurisdictions we operate in, such as Germany and Poland.
  • Creation, coordination and implementation of audit procedures based on a multi-year audit plan.
  • Coordination and follow-up of measures to address risks and prevent information security incidents..
  • Recording and coordinating the handling of information security incidents as well as the corresponding analysis and follow-up of incidents.
  • Coordinating the ongoing and on-demand performance of information risk analyses and related activities in close cooperation with process, information and risk owners.
  • Supporting the implementation and documentation of emergency tests and updating the emergency manual in close cooperation with the process, information and risk owners.
  • Coordination of target group-oriented awareness-raising and training measures on the topic of information security.
  • At least three years of practical experience in the role of information security officer or in a comparable position in the field of information security in a fast-growing company.
  • Certifications such as CISA, CISM, or ISO 27001 Lead Auditor are highly preferred.
  • Very good knowledge of legal and regulatory requirements such as DORA (Digital Operational Resilience Act), NIS2 etc.
  • Strong business acumen combined with an intuition for proactive collaboration with stakeholders across the company and group entities.
  • Experience in implementing security strategies, policies, procedures, and standards.
  • Extensive knowledge of current and emerging cyber security technologies, document management and security operations.
B2B Warsaw

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available