New offer - be the first one to apply!

October 5, 2026

Information Security Officer

Senior • On-site

Warsaw, Poland

Quick Facts

  • Role: Information Security Officer

  • Focus: Own the information security strategy and ensure group-wide security compliance and resilience.

Description

Own and advance the organization’s information security strategy to protect data, systems, and client trust. Ensure all group companies meet high security standards and stay resilient against emerging threats. Lead security governance activities including ISMS operations, security policies and procedures, audits, risk analyses, incident handling, third-party assessments, and testing aligned with regulatory requirements.

Responsibilities

  • Continuously coordinate information security objectives with strategic objectives.

  • Advise management on information security topics and provide regular status reports.

  • Establish, operate, and further develop an ISMS based on the organization’s GRC software.

  • Create and update security guidelines and procedures aligned with current standards and legal requirements (e.g., MaRisk, DORA) across operating jurisdictions.

  • Create, coordinate, and implement audit procedures using a multi-year audit plan.

  • Coordinate and follow up measures to address risks and prevent information security incidents.

  • Record, coordinate, analyze, and follow up on information security incidents.

  • Perform ongoing and on-demand information risk analyses in close cooperation with process, information, and risk owners.

  • Support emergency tests and update the emergency manual with relevant owners.

  • Coordinate awareness and training activities tailored to target audiences.

  • Assess technical security posture of critical ICT third-party service providers in coordination with outsourcing management, including review of certifications (e.g., ISO 27001, SOC 2).

  • Plan, coordinate, and evaluate penetration testing and digital operational resilience testing per Art. 24–27 DORA.

Requirements

  • At least 3 years of practical experience as an Information Security Officer or comparable role in information security in a fast-growing company.

  • Very good knowledge of legal and regulatory requirements such as DORA and NIS2.

  • Experience implementing security strategies, policies, procedures, and standards.

  • Strong business acumen and proactive collaboration with stakeholders across the company and group entities.

  • Extensive knowledge of current and emerging cybersecurity technologies, document management, and security operations.

  • Preferred: CISA, CISM, or ISO 27001 Lead Auditor certifications.

Benefits

Own enterprise-wide information security strategy, governance, and resilience activities end-to-end.

Similar jobs you might like

Unlock Full Resume Report