GRC Consultant
⚲ Warszawa
Do uzgodnienia
Wymagania
- Governance, Risk & Compliance (GRC)
- ISO/IEC 27001:2022 implementation (ISMS)
- NIS2 & Polish Cybersecurity Act (uKSC)
- Cybersecurity Risk Management
- Third-Party Risk Management (TPRM)
- Security Policies & Governance
- Compliance & Audit Readiness
Opis stanowiska
About Webellian
Webellian is a well-established Digital Transformation and IT consulting company committed to creating a positive impact for our clients. We strive to make a meaningful difference in diverse sectors such as insurance, banking, healthcare, retail, and manufacturing. Our passion for cutting-edge and disruptive technologies, as well as our shared values and strong principles, are what motivate us. We are a community of engineers and senior advisors who work with our clients across industries, playing a deep and meaningful role in accelerating and realizing their vision and strategy.
About the position
We are looking for a GRC Consultant to join our Cybersecurity team and support the implementation of cybersecurity governance and regulatory compliance initiatives for one of our international clients operating in the energy sector.
In this role, you will support the implementation of an Information Security Management System (ISMS) aligned with an international cybersecurity governance framework while ensuring compliance with applicable Polish cybersecurity regulations. You will help establish a unified control framework that satisfies both corporate security requirements and local regulatory obligations.
Working closely with client stakeholders, you will drive Governance, Risk & Compliance (GRC) activities, facilitate workshops, coordinate risk management processes, and prepare the organization for internal and external audits. This is an excellent opportunity for someone who enjoys combining cybersecurity, governance, compliance, and stakeholder management in an international environment.
Key responsibilities:
• Support the implementation and continuous improvement of an ISO/IEC 27001:2022-compliant Information Security Management System (ISMS).
• Develop and maintain information security policies, standards, procedures, and governance documentation.
• Build and maintain cybersecurity risk registers, including risk identification, assessment, treatment plans, ownership, and follow-up.
• Conduct cybersecurity risk assessments, Business Impact Analyses (BIA), and facilitate workshops with business stakeholders.
• Map security controls against ISO/IEC 27001:2022, NIS2, and other applicable regulatory and organizational requirements.
• Coordinate Third-Party Risk Management (TPRM) activities, including vendor security assessments and supplier risk classification.
• Collaborate with internal stakeholders to define and review information security requirements in supplier contracts.
• Build and maintain IT asset inventories and support the documentation of business processes and data flows.
• Contribute to vulnerability management planning and compliance evidence collection.
• Develop and maintain incident response and business recovery documentation.
• Prepare documentation and evidence required for internal and external compliance audits.
• Work closely with client stakeholders to ensure the successful delivery of cybersecurity governance and compliance initiatives.
Required Experience & Skills
•
7+ years of experience in Governance, Risk & Compliance (GRC), Information Security, or Cybersecurity Governance.
• Hands-on experience implementing or maintaining an Information Security Management System (ISMS) based on ISO/IEC 27001:2022 or a similar information security framework.
• Current working knowledge of NIS2 and the Polish Cybersecurity Act (uKSC), with experience applying their requirements in cybersecurity governance, compliance, or ISMS initiatives.
• Experience supporting cybersecurity compliance or regulatory governance initiatives.
• Practical experience managing cybersecurity risk registers and risk treatment processes.
• Experience facilitating workshops and working directly with business stakeholders and senior management.
• Good understanding of cybersecurity governance, compliance frameworks, and risk management best practices.
• Native or fluent Polish (required).
• Professional proficiency in English.
Nice to have
• Experience working in Energy, Utilities, Manufacturing, or other industrial environments.
• Basic understanding of Operational Technology (OT) / Industrial Control Systems (ICS) environments.
• Experience with GRC platforms, such as Eramba, ServiceNow IRM, OneTrust, Archer, or Lansweeper.
• Experience in Third-Party Risk Management (TPRM), including vendor security assessments and supplier risk management.
• Professional certifications, such as:• ISO/IEC 27001:2022 Lead Implementer
• ISO/IEC 27001:2022 Lead Auditor
• CISM
• CRISC
• CISA
What we offer
• Contract under Polish law: B2B or Umowa o Pracę.
• Benefits such as private medical care, group insurance, and Multisport card.
• English language classes.
• Hybrid work model with occasional on-site presence.
• Opportunity to work with experienced cybersecurity professionals on international projects.
• Exposure to complex cybersecurity governance and compliance programmes in a regulated environment.
• Continuous learning and professional development.
• International, collaborative working environment with opportunities for long-term growth.
Join a growing team of dedicated professionals! We love to pass on the knowledge to grow excellence, speak our minds without playing politics, and just enjoy hanging around together. If you share our passions - we want to meet you! So go ahead and apply ➡️
Webellian is a well-established Digital Transformation and IT consulting company committed to creating a positive impact for our clients. We strive to make a meaningful difference in diverse sectors such as insurance, banking, healthcare, retail, and manufacturing. Our passion for cutting-edge and disruptive technologies, as well as our shared values and strong principles, are what motivate us. We are a community of engineers and senior advisors who work with our clients across industries, playing a deep and meaningful role in accelerating and realizing their vision and strategy.
About the position
We are looking for a GRC Consultant to join our Cybersecurity team and support the implementation of cybersecurity governance and regulatory compliance initiatives for one of our international clients operating in the energy sector.
In this role, you will support the implementation of an Information Security Management System (ISMS) aligned with an international cybersecurity governance framework while ensuring compliance with applicable Polish cybersecurity regulations. You will help establish a unified control framework that satisfies both corporate security requirements and local regulatory obligations.
Working closely with client stakeholders, you will drive Governance, Risk & Compliance (GRC) activities, facilitate workshops, coordinate risk management processes, and prepare the organization for internal and external audits. This is an excellent opportunity for someone who enjoys combining cybersecurity, governance, compliance, and stakeholder management in an international environment.
Key responsibilities:
• Support the implementation and continuous improvement of an ISO/IEC 27001:2022-compliant Information Security Management System (ISMS).
• Develop and maintain information security policies, standards, procedures, and governance documentation.
• Build and maintain cybersecurity risk registers, including risk identification, assessment, treatment plans, ownership, and follow-up.
• Conduct cybersecurity risk assessments, Business Impact Analyses (BIA), and facilitate workshops with business stakeholders.
• Map security controls against ISO/IEC 27001:2022, NIS2, and other applicable regulatory and organizational requirements.
• Coordinate Third-Party Risk Management (TPRM) activities, including vendor security assessments and supplier risk classification.
• Collaborate with internal stakeholders to define and review information security requirements in supplier contracts.
• Build and maintain IT asset inventories and support the documentation of business processes and data flows.
• Contribute to vulnerability management planning and compliance evidence collection.
• Develop and maintain incident response and business recovery documentation.
• Prepare documentation and evidence required for internal and external compliance audits.
• Work closely with client stakeholders to ensure the successful delivery of cybersecurity governance and compliance initiatives.
Required Experience & Skills
•
7+ years of experience in Governance, Risk & Compliance (GRC), Information Security, or Cybersecurity Governance.
• Hands-on experience implementing or maintaining an Information Security Management System (ISMS) based on ISO/IEC 27001:2022 or a similar information security framework.
• Current working knowledge of NIS2 and the Polish Cybersecurity Act (uKSC), with experience applying their requirements in cybersecurity governance, compliance, or ISMS initiatives.
• Experience supporting cybersecurity compliance or regulatory governance initiatives.
• Practical experience managing cybersecurity risk registers and risk treatment processes.
• Experience facilitating workshops and working directly with business stakeholders and senior management.
• Good understanding of cybersecurity governance, compliance frameworks, and risk management best practices.
• Native or fluent Polish (required).
• Professional proficiency in English.
Nice to have
• Experience working in Energy, Utilities, Manufacturing, or other industrial environments.
• Basic understanding of Operational Technology (OT) / Industrial Control Systems (ICS) environments.
• Experience with GRC platforms, such as Eramba, ServiceNow IRM, OneTrust, Archer, or Lansweeper.
• Experience in Third-Party Risk Management (TPRM), including vendor security assessments and supplier risk management.
• Professional certifications, such as:• ISO/IEC 27001:2022 Lead Implementer
• ISO/IEC 27001:2022 Lead Auditor
• CISM
• CRISC
• CISA
What we offer
• Contract under Polish law: B2B or Umowa o Pracę.
• Benefits such as private medical care, group insurance, and Multisport card.
• English language classes.
• Hybrid work model with occasional on-site presence.
• Opportunity to work with experienced cybersecurity professionals on international projects.
• Exposure to complex cybersecurity governance and compliance programmes in a regulated environment.
• Continuous learning and professional development.
• International, collaborative working environment with opportunities for long-term growth.
Join a growing team of dedicated professionals! We love to pass on the knowledge to grow excellence, speak our minds without playing politics, and just enjoy hanging around together. If you share our passions - we want to meet you! So go ahead and apply ➡️
🔍 Dekoder Ogłoszenia
🟡
We strive to make a meaningful difference in diverse sectors
Firma pracuje z klientami w różnych branżach, co może oznaczać różnorodność projektów, ale też potencjalnie brak głębokiej specjalizacji w jednej dziedzinie.
🟡
Our passion for cutting-edge and disruptive technologies
Firma interesuje się nowymi technologiami, ale niekoniecznie oznacza to, że będzie się ich używać w codziennej pracy lub że projekt będzie innowacyjny.
🟡
We are a community of engineers and senior advisors
Sugestia współpracy i wsparcia, ale może też oznaczać, że oczekuje się samodzielności i podejmowania inicjatywy.
🟡
playing a deep and meaningful role in accelerating and realizing their vision and strategy
Obietnica wpływu na strategię klienta, co może oznaczać dużą odpowiedzialność i potrzebę proaktywnego podejścia.
🔴
This is an excellent opportunity fo
Niedokończone zdanie sugeruje, że opis pozycji mógł zostać przycięty, co może oznaczać brak kluczowych informacji o dalszych benefitach lub obowiązkach.