Unlock Full Resume Report

New offer - be the first one to apply!

September 23, 2026

Security Governance Compliance Specialist

Senior • On-site

Warsaw, Poland

Quick Facts

  • Role: Security Governance Compliance Specialist
  • Collaboration: Employment contract; hybrid (minimum 50% office presence)
  • Location: Warsaw

Description

The Security Governance team ensures the organization complies with security requirements, covering both regulatory (e.g., law, ISO standards) and internal standards. You will support the development and maintenance of security governance frameworks, working with IT and business teams to keep systems and processes aligned with applicable regulations. The role includes contributing to audits, identifying gaps, and recommending improvements to strengthen organizational security.

Role description & responsibilities

  • Develop and maintain security governance for risk management and internal control systems (information security, cybersecurity, and business continuity)
  • Lead and coordinate risk identification, assessment, and monitoring for business processes, IT systems, and transformation initiatives
  • Design, evaluate, and improve control mechanisms to ensure compliance with regulatory requirements, industry standards, and ISO standards
  • Monitor regulatory changes and assess their impact, including implementing requirements from NIS2, DORA, UKSC, and other sector regulations
  • Work with process and risk owners to define risk treatment plans and monitor mitigation actions
  • Maintain and develop documentation for risk management, internal controls, and information security management systems
  • Plan and execute internal audits and compliance assessments against ISO 27001 and ISO 22301, plus regulatory requirements; track corrective actions
  • Prepare management reports, analyses, and materials supporting risk and security decision-making
  • Support business and technology projects by assessing risk, regulatory requirements, and adequacy of safeguards (including for cloud solutions and AI)
  • Represent the organization during audits, regulator inspections, and collaboration with external auditors and international working groups

Requirements

  • Relevant higher education (IT, cybersecurity, risk management, finance, audit, information security, or related field)
  • Minimum 5 years of experience in security risk management, internal controls, compliance, information security, or cybersecurity
  • Practical knowledge of risk management and internal control systems, particularly ISO 27001, ISO 31000, COSO (or equivalent)
  • Experience in a regulated environment and with audit/control requirements (e.g., SOX, NIS2, DORA, telecom or financial sector regulations)
  • Experience conducting risk analysis, evaluating control effectiveness, and providing recommendations to business and senior management
  • Practical knowledge of audit processes and working with internal and external audit
  • Ability to interpret regulatory requirements and translate them into processes and control mechanisms
  • Experience managing stakeholders and working in project environments
  • Very good analytical and communication skills; ability to present risk and control topics to leadership
  • English proficiency of at least B2

Benefits

Not specified in the provided posting.

Similar jobs you might like