Unlock Full Resume Report

New offer - be the first one to apply!

September 7, 2026

Senior Information Security Engineer

Senior • Remote

13,300 - 22,000 PLN/yr

Warsaw, MZ, Poland

Description

Join the Governance, Risk & Compliance (GRC) team as a Senior Information Security Engineer. The role ensures that applications, systems, and processes comply with industry standards and regulatory requirements, including ISO 27001, ISO 22301, ISO 42001, SOC 2 Type II, Cyber Essentials, GDPR, and the EU AI Act.

This position combines GRC expertise with a technical engineering mindset. It is not purely audit-focused: responsibilities include assessing security architectures, supporting forensic investigations, building automation to replace manual processes, and providing hands-on guidance to engineering and security teams. A core focus is creating scalable, repeatable solutions for compliance evidence collection and policy enforcement.

Responsibilities

Governance, Risk & Compliance

  • Identify manual, repetitive GRC processes and design automation blueprints for evidence collection, control monitoring, access reviews, policy-enforcement checks, and compliance reporting.
  • Build and maintain automated workflows using compliance platforms, scripting, or integration tools to reduce manual effort and improve audit readiness.
  • Develop reusable templates, playbooks, and standardised blueprints for recurring GRC activities, including vendor assessments, internal audits, and risk reviews.
  • Collaborate with engineering and IT teams to integrate security and compliance checks into existing toolchains and CI/CD pipelines where applicable.
  • Continuously evaluate and improve GRC tooling, data flows, and reporting to improve operational efficiency.
  • Manage stakeholder expectations and partner with internal teams on IT risks and compliance obligations.
  • Maintain regional and local stakeholder relationships, meeting schedules, minutes, and reports.
  • Support the SOC 2 Type II framework through evidence collection, control-testing coordination, and audit support.
  • Manage ISO 27001 and ISO 22301 audit lifecycles and coordinate ISMS and BCMS improvements.
  • Support maintenance and continuous improvement of the ISO 42001 AI Management System in alignment with the EU AI Act.
  • Support vendor risk management, including third-party security assessments and due-diligence reviews.

Business Continuity & ISO 22301

  • Serve as a subject-matter expert or key contributor for the Business Continuity Management System (BCMS), supporting its strategy, framework, and ISO 22301 audit programme.
  • Support Business Impact Analysis (BIA), BCP/DRP development, recovery exercises, and continuity-metrics management.

AI Security & Compliance

  • Support AI security and compliance activities, including AI-risk assessments, alignment with ISO 42001 controls, and EU AI Act regulatory readiness.
  • Collaborate with product and engineering teams to evaluate security controls for AI/ML features and services.

Qualifications

  • 5+ years of experience in information security, governance, risk, and/or compliance roles with a technical orientation.
  • Demonstrated compliance or auditing experience with at least one major framework.
  • Solid understanding of controls-auditing principles and evidence management.
  • Knowledge of risk-management methodologies and experience conducting or supporting risk assessments.
  • Ability to manage and deliver multiple complex projects simultaneously with minimal supervision.
  • Ability to investigate, question, and interpret internal and external IT security and compliance issues at governance and technical levels.
  • Strong understanding of technology, cloud-based products, and SaaS environments.
  • Experience working across business units and geographical boundaries with engineering, business, and operational teams.
  • Experience with ISO 27001.
  • Excellent written and verbal English communication skills.

Nice to Have

  • CISA, CRISC, CISM, CISSP, CCSK, CCSP, or equivalent certification.
  • Experience with ISO 9001, ISO 27017, and ISO 27018.
  • Experience with ISO 22301, including BIA, BCP/DRP, and recovery testing.
  • Experience with BSI C5 or similar cloud-specific compliance frameworks.
  • Knowledge of AI security principles, ISO 42001 experience, or familiarity with the EU AI Act and its technical requirements.
  • Technical understanding of cloud infrastructure, preferably AWS, networking fundamentals, identity management, and SaaS security architectures.
  • Experience with enterprise risk-management frameworks and tools.
  • Understanding of threat-modelling methodologies and secure development lifecycle (SDLC) principles.
  • Hands-on incident-response experience, including security incident investigation, containment, and post-mortem processes.

Benefits

  • 100% remote work, Wi-Fi reimbursement, and an equipment stipend; MacBook laptop provided.
  • Unlimited vacation days.
  • Private medical care for employees and dependents.
  • Wellness programme, including a Multisport Card.
  • Company-wide shutdowns in August and around Christmas.

Similar jobs you might like