Unlock Full Resume Report

New offer - be the first one to apply!

September 3, 2026

Cybersecurity Governance Risk and Compliance Consultant

Senior • On-site

Warsaw, Poland

For one of our clients, we are looking for a Cybersecurity Governance Risk and Compliance Consultant.

Delivery Mode

  • Hybrid: 30% onsite / 70% remote

Experience Required

  • At least 9 years of post-education experience, including 8+ years in a similar role

Required Certifications

At least 4 certifications from the following list, or an internationally recognized equivalent accepted by the Contracting Authority:

  • CISA (ISACA Certified Information Systems Auditor)
  • CISM (ISACA Certified Information Security Manager)
  • CRISC (ISACA Certified in Risk and Information Systems Control)
  • CISSP (ISC2 Certified Information Systems Security Professional)
  • CGRC (ISC2 Certified in Governance, Risk and Compliance)
  • CSSLP (ISC2 Certified Secure Software Lifecycle Professional)
  • CCSP (ISC2 Certified Cloud Security Professional)
  • CISSP-ISSMP (ISC2 Certified Information Systems Security Management Professional)
  • GSNA (GIAC Certified Systems and Network Auditor)
  • GCCC (GIAC Certified Critical Controls)
  • GIAC Certified ISO-27000 Specialist
  • ISO 27001 Lead Implementer or equivalent
  • ISO 27001 Lead Auditor or equivalent
  • ISO 27005 Risk Manager or equivalent

Knowledge and Skills

  • Knowledge of cybersecurity-related laws, regulations, and legislation
  • Knowledge of cybersecurity standards, methodologies, and frameworks
  • Knowledge of cybersecurity policies
  • Knowledge of legal, regulatory, and legislative compliance requirements, recommendations, and best practices
  • Knowledge of privacy impact assessment standards, methodologies, and frameworks
  • Comprehensive understanding of business strategy, models, and products, and ability to factor these into legal, regulatory, and standards requirements
  • Ability to apply data protection and privacy practices to organisational processes, finance, and business strategy
  • Ability to lead development, acceptance, implementation, and communication of cybersecurity and privacy policies and procedures
  • Ability to conduct, monitor, and review privacy impact assessments using standards, frameworks, methodologies, and tools
  • Ability to explain data protection and privacy topics to stakeholders and users
  • Understanding of and adherence to ethical requirements and standards
  • Ability to assess the implications of legal framework changes for cybersecurity and data protection strategy and policies
  • Ability to collaborate with team members and colleagues

Specific Requirements

  • Minimum 5+ years of cybersecurity GRC experience, with a clear focus on cybersecurity risk management
  • Proven experience designing or operationalising a cyber risk management framework
  • Hands-on experience using ServiceNow GRC, including IRM, Risk, and Policy and Compliance modules
  • Demonstrated experience maintaining and managing a cybersecurity risk register
  • Experience integrating risk management with vulnerability management, incident management, cloud risk, and third-party risk
  • Experience contributing to cybersecurity maturity improvement programmes

Typical Tasks and Responsibilities

  • Ensure compliance with, and provide legal advice and guidance on, data privacy and data protection standards, laws, and regulations
  • Identify and document compliance gaps
  • Conduct privacy impact assessments and develop, maintain, communicate, and provide training on privacy policies and procedures
  • Enforce and advocate the organisation’s data privacy and protection programme
  • Ensure data owners, holders, controllers, processors, subjects, and internal or external partners and entities understand their data protection rights, obligations, and responsibilities
  • Act as a key contact point for queries and complaints regarding data processing
  • Assist with designing, implementing, auditing, and compliance testing activities to ensure cybersecurity and privacy compliance
  • Monitor audits and data protection-related training activities
  • Cooperate and share information with authorities and professional groups
  • Contribute to development of the organisation’s cybersecurity strategy, policies, and procedures
  • Develop and propose staff awareness training to achieve compliance and foster a data-protection culture
  • Manage legal aspects of information security responsibilities and third-party relations

Similar jobs you might like