JustJoin.IT Hybrydowo Senior

Business Information Security Officer

Lufthansa Systems

⚲ Gdańsk

10 000 - 21 000 PLN brutto (UoP)

Wymagania

  • ISO 27001
  • CISSP, CISM, CISA, or CRISC
  • SSDLC

Opis stanowiska

We are seeking a highly skilled and motivated individual to join our Lufthansa Systems as a Business Information Security Officer (BISO). In this role you will be responsible for ensuring the confidentiality, integrity, and availability of our organization's information assets for the Flight Planning product line.

You will play a critical role in establishing and maintaining our information security strategy, policies, and controls. This is an excellent opportunity to contribute to the protection of sensitive information and help shape the security posture of our organization.
Join our team and help us protect our valuable information assets. Apply now and be a part of our commitment to maintaining a secure and resilient business environment.
 

Who are we?

Lufthansa Systems Poland is acclaimed and widely recognized provider of superior services and IT solutions for the aeronautical, logistic and financial industries. As a part of the Lufthansa Group we implement technological solutions and dedicated services.

Why do we need you?
In this role, you will:
• Implement and operationalize information security policies and standards within the product line, ensuring alignment with the company’s overall security strategy.
• Serve as the primary contact between the product line and the central information security organization.
• Manage and maintain the Information Security Management System (ISMS) within an ISO 27001-certified environment, ensuring product-specific compliance.
• Conduct and oversee information security risk assessments, and ensure effective risk mitigation and treatment.
• Identify, assess, and coordinate remediation of technical vulnerabilities, evaluating both technical and business impact.
• Monitor and enforce technical and organizational security controls to safeguard systems and data.
• Investigate and manage security incidents, supporting incident response, mitigation, and reporting.
• Coordinate and support internal and external security audits, ensuring timely closure of findings and compliance with standards.
• Prepare and deliver regular security reports to management, highlighting risks, incidents, and mitigation actions.
• Contribute to projects and product changes from a security governance perspective, ensuring compliance and risk-awareness.
• Promote security awareness and coordinate training activities for employees within the product area.

Who are you?
⁠Your profile:
• Bachelor’s degree in Computer Science, Information Technology, or a related field.
• Professional certifications such as CISSP, CISM, CISA, or CRISC are an advantage.
• Several years of experience in information security management, preferably in a GRC-focused role.
• Strong knowledge of information security frameworks and standards (e.g., ISO 27001, NIST CSF).
• Experience in risk management, vulnerability management, and incident handling.
• Solid understanding of security technologies and best practices.
• Strong project management and organizational skills.
• Excellent communication and stakeholder management abilities.
• Analytical mindset and strong problem-solving skills.
• Fluent English (written and spoken).
• Readiness to work from the office in Gdańsk min. 2 days a week

​​​

What do we offer?
• An international working environment, atmosphere that stimulates development.
• Individual career path.
• Employment contract, salary in the range of 10 000 - 21 000 zł gross for senior level​​
• Lufthansa Group membership benefits.
• Flexible working time and place adjusted to employee’s needs. Possibility of starting your workday between 07:00 and 11:00.
• Support for your passion for sports within the local activity group and co-financing Multisport cards.
• Private medical care for employees and their family members.
• Life insurance.
• Training opportunities and real growth paths.
• Modern office in Oliwa – great location and comfortable workspace.

🔍 Dekoder Ogłoszenia

🟡
excellent opportunity to contribute to the protection of sensitive information and help shape the security posture of our organization.
Może oznaczać, że będziesz miał realny wpływ na bezpieczeństwo, ale równie dobrze może być to standardowy zwrot motywacyjny bez konkretnych gwarancji wpływu.
🟡
Serve as the primary contact between the product line and the central information security organization.
Może oznaczać, że będziesz kluczowym łącznikiem, ale też że będziesz musiał przekazywać wiele informacji i być "pośrednikiem" bez dużej decyzyjności.
🟡
Manage and maintain the Information Security Management System (ISMS) within an ISO 27001-certified environment, ensuring product-specific compliance.
Wskazuje na pracę w ramach istniejących procesów i certyfikacji, co może oznaczać mniejszą swobodę w tworzeniu nowych rozwiązań, a większy nacisk na utrzymanie zgodności.