Unlock Full Resume Report
ATS Pass
Missing keywords
Tailored AI suggestions
Job match analysis
Interview-focused insights
New offer - be the first one to apply!
September 4, 2026
GRC Consultant
Senior • On-site
Warsaw, Poland
Apply now
About the position
We are looking for a GRC Consultant to join the Cybersecurity team and support the implementation of cybersecurity governance and regulatory compliance initiatives for an international client operating in the energy sector.
In this role, you will support the implementation of an Information Security Management System (ISMS) aligned with an international cybersecurity governance framework while ensuring compliance with applicable Polish cybersecurity regulations. You will help establish a unified control framework that satisfies both corporate security requirements and local regulatory obligations.
Working closely with client stakeholders, you will drive Governance, Risk & Compliance (GRC) activities, facilitate workshops, coordinate risk management processes, and prepare the organization for internal and external audits. This is an opportunity for someone who enjoys combining cybersecurity, governance, compliance, and stakeholder management in an international environment.
Key responsibilities
- Support the implementation and continuous improvement of an ISO/IEC 27001:2022-compliant Information Security Management System (ISMS).
- Develop and maintain information security policies, standards, procedures, and governance documentation.
- Build and maintain cybersecurity risk registers, including risk identification, assessment, treatment plans, ownership, and follow-up.
- Conduct cybersecurity risk assessments, Business Impact Analyses (BIA), and facilitate workshops with business stakeholders.
- Map security controls against ISO/IEC 27001:2022, NIS2, and other applicable regulatory and organizational requirements.
- Coordinate Third-Party Risk Management (TPRM) activities, including vendor security assessments and supplier risk classification.
- Collaborate with internal stakeholders to define and review information security requirements in supplier contracts.
- Build and maintain IT asset inventories and support the documentation of business processes and data flows.
- Contribute to vulnerability management planning and compliance evidence collection.
- Develop and maintain incident response and business recovery documentation.
- Prepare documentation and evidence required for internal and external compliance audits.
- Work closely with client stakeholders to ensure the successful delivery of cybersecurity governance and compliance initiatives.
Required Experience & Skills
- 7+ years of experience in Governance, Risk & Compliance (GRC), Information Security, or Cybersecurity Governance.
- Hands-on experience implementing or maintaining an Information Security Management System (ISMS) based on ISO/IEC 27001:2022 or a similar information security framework.
- Current working knowledge of NIS2 and the Polish Cybersecurity Act (uKSC), with experience applying their requirements in cybersecurity governance, compliance, or ISMS initiatives.
- Experience supporting cybersecurity compliance or regulatory governance initiatives.
- Practical experience managing cybersecurity risk registers and risk treatment processes.
- Experience facilitating workshops and working directly with business stakeholders and senior management.
- Good understanding of cybersecurity governance, compliance frameworks, and risk management best practices.
- Native or fluent Polish (required).
- Professional proficiency in English.
Nice to have
- Experience working in Energy, Utilities, Manufacturing, or other industrial environments.
- Basic understanding of Operational Technology (OT) / Industrial Control Systems (ICS) environments.
- Experience with GRC platforms, such as Eramba, ServiceNow IRM, OneTrust, Archer, or Lansweeper.
- Experience in Third-Party Risk Management (TPRM), including vendor security assessments and supplier risk management.
- Professional certifications, such as ISO/IEC 27001:2022 Lead Implementer, ISO/IEC 27001:2022 Lead Auditor, CISM, CRISC, or CISA.
What we offer
- Contract under Polish law: B2B or Umowa o Pracę.
- Benefits such as private medical care, group insurance, and Multisport card.
- English language classes.
- Hybrid work model with occasional on-site presence.
- Opportunity to work with experienced cybersecurity professionals on international projects.
- Exposure to complex cybersecurity governance and compliance programmes in a regulated environment.
- Continuous learning and professional development.
- International, collaborative working environment with opportunities for long-term growth.
Similar jobs you might like

ICT Risk & Compliance Expert
Connectis
Senior
Technology
Warsaw, Poland · On-site
0K zł - 0K zł/yr
2 days ago

Cybersecurity Governance Risk and Compliance Consultant
Team Connect
Senior
Technology
Warsaw, Poland · On-site
N/A
1 days ago

GRC Analyst/Consultant
Link Group
Senior
Technology
Bialystok, PD, Poland · Remote
0K zł - 0K zł/yr
2 days ago
Security Risk & Compliance Expert
ITLT
Senior
Technology
Warsaw, Poland · Remote
N/A
1 days ago
Senior Information Security Engineer
SmartRecruiters Inc.
Senior
Technology
Warsaw, MZ, Poland · Remote
13K zł - 22K zł/yr
2 days ago
Senior Information Security Engineer
SmartRecruiters Inc.
Senior
Technology
Warsaw, MZ, Poland · Remote
13K zł - 22K zł/yr
2 days ago

Cybersecurity GRC Consultant
TechTree
Senior
Technology
Warsaw, Poland · On-site
424K zł - 439K zł/yr
1 days ago
Fullstack Engineer (Java, Python, Vue.js)
Webellian Sp.z o o
Senior
Technology
Warsaw, MZ, Poland · Hybrid
N/A
27 days ago
DevOps Engineer
Webellian Sp.z o o
Mid
Technology
Warsaw, MZ, Poland · On-site
N/A
2 days ago
FinOps Engineer
Webellian Sp.z o o
Senior
Technology
Warsaw, MZ, Poland · On-site
N/A
1 days ago