Unlock Full Resume Report

New offer - be the first one to apply!

September 2, 2026

Senior Information Security Engineer

Senior • Remote

13,300 - 22,000 PLN/yr

Warsaw, MZ, Poland

Job Description

This role ensures that applications, systems, and processes remain compliant with industry standards and regulatory requirements, including ISO 27001, ISO 22301, ISO 42001, SOC 2 Type II, Cyber Essentials, GDPR, and the EU AI Act.

The successful candidate combines GRC expertise with a technical, engineering mindset to drive compliance programmes across multiple frameworks and address business continuity, AI security, and cloud compliance. This is not a purely audit-focused role: it involves investigating technical details, assessing security architectures, supporting forensic investigations, building automation to replace manual processes, and providing hands-on guidance to engineering and security teams. A core part of the role is engineering scalable, repeatable solutions for compliance evidence collection and policy enforcement.

Responsibilities

Governance, Risk & Compliance

  • Identify manual, repetitive GRC processes and design automation blueprints for evidence collection, control monitoring, access reviews, policy enforcement checks, and compliance reporting.
  • Build and maintain automated workflows using compliance platforms, scripting, or integration tools to reduce manual effort and improve audit readiness.
  • Develop reusable templates, playbooks, and standardised blueprints for recurring GRC activities, including vendor assessments, internal audits, and risk reviews.
  • Collaborate with engineering and IT teams to integrate security and compliance checks into existing toolchains and CI/CD pipelines where applicable.
  • Continuously evaluate and improve GRC tooling, data flows, and reporting to drive operational efficiency.
  • Manage stakeholder expectations and partner with internal teams to manage IT risks and compliance obligations effectively.
  • Maintain regional and local stakeholder relationships, meeting schedules, minutes, and reports.
  • Support maintenance of the SOC 2 Type II framework, including evidence collection, control-testing coordination, and audit support.
  • Manage ISO 27001 and ISO 22301 audit lifecycles and coordinate ISMS and BCMS improvements with stakeholders.
  • Support maintenance and continuous improvement of the ISO 42001 AI Management System framework in alignment with the EU AI Act.
  • Support vendor risk management, including third-party security assessments and due-diligence reviews.

Business Continuity & ISO 22301

  • Serve as a subject matter expert or key contributor for the Business Continuity Management System (BCMS), supporting its strategy, framework, and audit programme under ISO 22301.
  • Support Business Impact Analysis (BIA), BCP/DRP development, recovery exercises, and continuity metrics management.

AI Security & Compliance

  • Support AI security and compliance activities, including AI-risk assessments, alignment with ISO 42001 controls, and regulatory readiness under the EU AI Act.
  • Collaborate with product and engineering teams to evaluate security controls for AI/ML features and services.

Qualifications

  • 5+ years of experience in information security, governance, risk, and/or compliance roles with a technical orientation.
  • Demonstrated compliance or auditing experience with at least one major framework.
  • Solid understanding of controls-auditing principles and evidence management.
  • Knowledge of risk-management methodologies and experience conducting or supporting risk assessments.
  • Ability to manage and deliver multiple complex projects simultaneously with minimal supervision.
  • Ability to investigate, question, and interpret internal and external IT security and compliance issues at governance and technical levels.
  • Strong understanding of technology, cloud-based products, and SaaS environments.
  • Experience working across business units and geographical boundaries with engineering, business, and operational teams.
  • Experience with ISO 27001.
  • Excellent written and verbal English communication skills.

Nice to Have

  • Professional certifications such as CISA, CRISC, CISM, CISSP, CCSK, CCSP, or equivalent.
  • Experience with ISO 9001, ISO 27017, and ISO 27018.
  • Experience with ISO 22301, including BIA, BCP/DRP, and recovery testing.
  • Experience with BSI C5 or similar cloud-specific compliance frameworks.
  • Knowledge of AI security principles, ISO 42001, or the EU AI Act and its technical requirements.
  • Technical understanding of cloud infrastructure, preferably AWS, networking fundamentals, identity management, and SaaS security architectures.
  • Experience with enterprise risk-management frameworks and tools.
  • Understanding of threat-modelling methodologies and secure development lifecycle (SDLC) principles.
  • Hands-on incident-response experience, including security incident investigations, containment, and post-mortem processes.

Benefits

  • 100% remote work, Wi-Fi reimbursement, equipment stipend, and a provided MacBook laptop.
  • Unlimited vacation days.
  • Private medical care for employees and dependents.
  • Wellness programme, including a Multisport Card.
  • Company-wide shutdowns in August and around Christmas.

Additional Information

Equal Employment Opportunity and Affirmative Action employer. Employment decisions are made without discrimination based on legally protected characteristics.

Similar jobs you might like