Unlock Full Resume Report

New offer - be the first one to apply!

September 2, 2026

Senior Information Security Engineer

Senior • Remote

13,300 - 22,000 PLN/yr

Warsaw, MZ, Poland

Job Description

The Senior Information Security Engineer will join the Governance, Risk & Compliance (GRC) team and help ensure that applications, systems, and processes comply with industry standards and regulatory requirements, including ISO 27001, ISO 22301, ISO 42001, SOC 2 Type II, Cyber Essentials, GDPR, and the EU AI Act.

This role combines GRC expertise with a technical engineering mindset. It is not purely audit-focused: the role involves assessing security architectures, supporting forensic investigations, automating manual processes, and providing hands-on guidance to engineering and security teams. A core focus is engineering scalable, repeatable solutions for activities such as compliance evidence collection and policy enforcement.

Responsibilities

Governance, Risk & Compliance

  • Identify manual, repetitive GRC processes and design automation blueprints for evidence collection, control monitoring, access reviews, policy-enforcement checks, and compliance reporting.
  • Build and maintain automated workflows using compliance platforms, scripting, or integration tools to reduce manual effort and improve audit readiness.
  • Develop reusable templates, playbooks, and standardised blueprints for recurring GRC activities, including vendor assessments, internal audits, and risk reviews.
  • Collaborate with engineering and IT teams to integrate security and compliance checks into existing toolchains and CI/CD pipelines where applicable.
  • Continuously evaluate and improve GRC tooling, data flows, and reporting to increase operational efficiency.
  • Manage stakeholder expectations and partner with internal teams to manage IT risks and compliance obligations effectively.
  • Maintain regional and local stakeholder relationships, meeting schedules, minutes, and reports.
  • Support maintenance of the SOC 2 Type II framework, including evidence collection, control-testing coordination, and audit support.
  • Manage ISO 27001 and ISO 22301 audit lifecycles and coordinate ISMS and BCMS improvements with stakeholders.
  • Support maintenance and continuous improvement of the ISO 42001 AI Management System framework in alignment with the EU AI Act.
  • Support vendor risk management, including third-party security assessments and due-diligence reviews.

Business Continuity & ISO 22301

  • Serve as a subject-matter expert or key contributor for the Business Continuity Management System (BCMS), supporting its strategy, framework, and audit programme under ISO 22301.
  • Support Business Impact Analysis (BIA), BCP/DRP development, recovery exercises, and continuity metrics management.

AI Security & Compliance

  • Support AI security and compliance activities, including AI risk assessments, alignment with ISO 42001 controls, and EU AI Act regulatory readiness.
  • Collaborate with product and engineering teams to evaluate security controls for AI/ML features and services.

Qualifications

  • 5+ years of experience in information security, governance, risk, and/or compliance roles with a technical orientation.
  • Demonstrated compliance or auditing experience with at least one major framework.
  • Solid understanding of controls auditing principles and evidence management.
  • Knowledge of risk management methodologies and experience conducting or supporting risk assessments.
  • Ability to manage and deliver multiple complex projects simultaneously with minimal supervision.
  • Ability to investigate, question, and interpret internal and external IT security and compliance issues at governance and technical levels.
  • Strong understanding of technology, cloud-based products, and SaaS environments.
  • Experience working across business units and geographical boundaries with engineering, business, and operational teams.
  • Experience with ISO 27001.
  • Excellent written and verbal English communication skills.

Nice to Have

  • CISA, CRISC, CISM, CISSP, CCSK, CCSP, or equivalent professional certifications.
  • Experience with ISO 9001, ISO 27017, and ISO 27018.
  • Experience with ISO 22301, including BIA, BCP/DRP, and recovery testing.
  • Experience with BSI C5 or similar cloud-specific compliance frameworks.
  • Knowledge of AI security principles, ISO 42001, or the EU AI Act and its technical requirements.
  • Technical understanding of cloud infrastructure, preferably AWS, networking fundamentals, identity management, and SaaS security architectures.
  • Experience with enterprise risk management frameworks and tools.
  • Understanding of threat modelling methodologies and secure development lifecycle (SDLC) principles.
  • Hands-on incident-response experience, including security incident investigation, containment, and post-mortem processes.

Benefits

  • 100% remote work, Wi-Fi reimbursement, equipment stipend, and a provided MacBook laptop.
  • Unlimited vacation days.
  • Private medical care for employees and dependents.
  • Wellness programme, including a Multisport Card.
  • Company-wide shutdowns in August and around Christmas.

Similar jobs you might like