CYBERSECURITY: GOVERNANCE, RISK AND COMPLIANCE SPECIALIST
Innergo
mid
Sign in to applyFree account, takes a minute.
Job description
INNERGO to firma zbudowana w 100% w oparciu o polski kapitał. Działamy na rynku integratorów IT od 2009 roku i zatrudniamy obecnie ponad 150 osób.
Od początku działania firmy postawiliśmy sobie za cel realizacje zaawansowanych technologicznie projektów integracji teleinformatycznej, łącząc ofertę światowej klasy producentów z szerokim portfolio własnych usług. Odegraliśmy kluczową rolę w transformacji cyfrowej wielu firm, realizując ponad 2000 projektów, dla klientów z różnych branż.
Zakres wdrożeń realizowanych przez INNERGO :
• sieci LAN i WLAN, MPLS, SD WAN, Wi-Fi
• systemy telekomunikacyjne klasy Enterprise
• platformy serwerowe i macierzowe
• infrastruktura pasywna serwerowni
• wdrożenia systemów z zakresu cyberbezpieczeństwa
• dostawy i serwis urządzeń Apple
• serwis gwarancyjny i pogwarancyjny
• prywatne sieci 5G i LTE
• rozwiązania klasy Connected City
• aplikacje z wykorzystaniem platform „no-code“
JOIN INNERGO AS:
Cybersecurity: Governance, Risk and Compliance Specialist
Poznań / Warszawa / Kraków / Wrocław / Rzeszów / Krosno / Gdynia / Remote
JOB FUNCTIONS:
• M onitor user access to IT systems by performing the following: Semiannual access reviews, Termination validation procedures, IT Privilege access reviews
• Validate that access to critical functions within key applications is appropriately segregated (Segregation of Duties – SOD)
• Establish effective communication processes with the business and regional IT teams to coordinate the global assessment of IT controls
• Integrally engage in projects making sure that they comply with O-I policies and security requirements
• Assist with independent vulnerability assessment and SoX audit processes
• Follow documented procedures and retain necessary audit documentation
• Participate in the incident response activities in accordance with established procedures
• Develop and support IT Governance processes
• Develop and support IT Risk Management processes
• Develop and support IT Compliance processes
• Assessing applications, vendors, and processes from a Cybersecurity and Privacy perspective
• Work with the IT and Legal teams to ensure compliance with regulations (SoX, GDPR, DOL, etc).
POSITION REQUIREMENTS:
• Bachelor’s degree in information technology or legal or equivalent years of experience
• Understanding of security frameworks (NIST), and regulatory requirements – governance, risk management, privacy, and data security
• Understanding of security protocols and standards
• Solid knowledge of information security principles, practices
• Minimum 3 years of experience working in Information Technology/IT and Data Governance, IT Risk Management, IT Compliance
• Minimum 3 years of experience working with IT general computer control evaluations, remediation, and with external auditors
• Intermediate knowledge related to privacy assessment (GDPR)
• Understanding of the industry’s control frameworks and leading practices
• Experience in evaluating system security requirements
• Knowledge of system functions, security policies, technical security safeguards, and operational security measures
• Knowledge of industry-leading practices, security frameworks, policies, and standards
• Intermediate operational knowledge of ServiceNow
• Intermediate operational knowledge of SAP GRC
• Ability to determine priorities, makes discretionary decisions and determines when to notify management
• Ability to work well with people from many different disciplines with varying degrees of technical experience
• Experience in communicating and presenting to a management-level audience
• Organized, responsive, and highly thorough problem solver
• Detail oriented
• Demonstrated analytical capabilities
• Self-starter and strong collaboration skills
• Experience in effective communication with customers, employees, and management
• Have high integrity and be able to maintain the confidentiality of work performed
• Must be able to communicate in English – both written and verbal.
ADDITIONAL QUALIFICATIONS:
• ISACA Certified Information Security Manager (CISM)
• ISACA Certified in Risk & Information System Controls (CRISC)
• ISACA Certified in the Governance of Enterprise IT (CGEIT)
• (ISC)2 Certified Information Systems Security Professional (CISSP).
WE OFFER:
• Necessary for work tools
• Co-financing for private medical care, life insurance, sports card
• Integration meetings and trips
• Additional days off.
Skills
NISTSoXGDPRDOLServiceNowSAP GRCCISMCRISCCGEITCISSP