JustJoin.IT Hybrydowo Mid

Mid-Level Third-Party Cybersecurity Risk Assessor – Security & Compliance

ITDS

⚲ Krakow

23 100 - 27 930 PLN netto (B2B)

Wymagania

  • Third-Party Security Assessment
  • Cybersecurity Risk Assessment
  • English communication
  • German Communication
  • IT Systems & Infrastructure Security
  • Compliance & Regulatory Frameworks
  • Stakeholder Management
  • Control Testing & Audit
  • SLA Management
  • CISSP / CISM / Security+ Certification

Opis stanowiska

Unleash the power of cybersecurity — shape resilient digital ecosystems for tomorrow!
Krakow-based opportunity with hybrid work model (up to 4 remote days per week).
As a Mid-Level Third-Party Cybersecurity Risk Assessor, you will be working for our client, a leading global financial institution, in their dynamic Cybersecurity team. You will play a pivotal role in safeguarding organizational assets by assessing third-party security risks, ensuring compliance, and enhancing operational resilience. Join a forward-thinking environment where innovation drives career growth and security excellence.

Your main responsibilities:
• Complete cybersecurity control assurance, security, and risk assessments for third-party engagements.
• Deliver all aspects of Third-Party Security Assessment (TPSA) service and operations, ensuring efficiency and continuous improvement.
• Collaborate effectively with HSBC Business, third-party stakeholders, TPSA region leads, and team members to meet SLAs.
• Ensure assessments adhere to relevant regulations, standards, and internal controls.
• Communicate requirements clearly and manage stakeholder expectations to achieve cyber security outcomes.
• Contribute to team efforts to meet monthly service management targets, including SLAs.
• Collaborate with team members to develop optimal solutions that meet technical and security requirements.

You're ideal for this role if you have:
• At least 2 years of experience in cybersecurity or related technical roles.
• Strong knowledge of IT systems, infrastructure, and data security principles.
• Practical experience in third-party security assessment processes, control testing, or audit disciplines.
• Excellent communication skills in business English (fluent) and German (fluent), both verbal and written.
• Proven ability to deliver high-quality results under pressure and pace.
• Skilled in managing and influencing stakeholders from diverse backgrounds and cultures.

It is a strong plus if you have: (optional)• Relevant cybersecurity certifications such as CISSP, CISM, or CompTIA Security+.
• A genuine enthusiasm for cybersecurity and knowledge-sharing.
Language Required for the role:
• Fluent in English and German (verbal and written).

Eligibility for the role:
• Only candidates with an existing legal right to work in the European Union will be considered for this role.

#MAKEYourCareerBETTER
Interested? Apply now and include your CV (preferably in English) along with a statement confirming your consent to the processing and storage of your personal data.

🔍 Dekoder Ogłoszenia

🟡
Unleash the power of cybersecurity — shape resilient digital ecosystems for tomorrow!
Jest to typowy, marketingowy slogan wprowadzający, który nie zawiera konkretnych informacji o stanowisku.
🔴
Join a forward-thinking environment where innovation drives career growth and security excellence.
Może oznaczać, że firma faktycznie inwestuje w rozwój pracowników i innowacje, ale równie dobrze może być pustym hasłem marketingowym.
🔴
You will play a pivotal role in safeguarding organizational assets by assessing third-party security risks, ensuring compliance, and enhancing operational resilience.
Choć brzmi to jak kluczowa rola, w praktyce może oznaczać wykonywanie standardowych procedur oceny ryzyka bez dużej autonomii decyzyjnej.
🔴
Deliver all aspects of Third-Party Security Assessment (TPSA) service and operations, ensuring efficiency and continuous improvement.
Może sugerować szeroki zakres obowiązków, ale w rzeczywistości może oznaczać powtarzalne zadania związane z procesem oceny.
🔴
Contribute to team efforts to meet monthly service management targets, including SLAs.
Podkreśla pracę zespołową i cele, ale może oznaczać presję na osiąganie wyników i potencjalne nadgodziny w celu dotrzymania terminów.