Pracuj.pl Hybrydowo Mid

Risk Analyst

Mindbox Sp. z o.o.

⚲ Warszawa

11 400–13 400 zł netto (+ VAT) / mies.

Opis stanowiska

Nasze wymagania:
3–5 years’ experience in risk management, cybersecurity risk, or IT risk
Expertise in conducting vendor cybersecurity assessments and due diligence reviews
Knowledge of frameworks: NIST, ISO 27001, SOC 2
Strong analytical and problem-solving skills
Ability to assess risk under uncertainty and propose actionable solutions
Excellent written and verbal communication skills

Mile widziane:
Experience in tech, financial services, or regulated environments
Familiarity with regulatory standards: DORA, GDPR, SOX

O projekcie:
As a Third-Party Risk Analyst, you will play a critical part in protecting Equinix from third-party cybersecurity and operational risks. This role involves executing risk-based due diligence, monitoring supplier security posture, and supporting Equinix’s Third-Party Risk Management (TPRM) program in line with industry and regulatory standards.
Sounds like your kind of challenge?

Zakres obowiązków:
1. Risk Assessment & Due Diligence
• Perform cybersecurity and risk assessments on third parties using standardized industry frameworks
• Evaluate supplier security posture, controls, and compliance with Equinix standards
• Analyze risk across multiple domains: information security, data privacy, and business continuity
• Assign risk ratings and document findings according to TPRM standards
2. Risk Identification & Issue Management
• Detect control gaps and vulnerabilities; recommend remediation plans
• Track and document remediation progress with vendors and internal teams
• Escalate high-risk findings based on defined governance thresholds
3. Ongoing Monitoring
• Support continuous monitoring: threat intelligence reviews, security ratings, vendor performance updates
• Track changes in risk posture and support periodic reassessments
4. Stakeholder Engagement
• Partner with Procurement, Security, Legal, and Business Units to enable risk-based decisions
• Communicate risk findings effectively to technical and non-technical stakeholders
5. Program Support & Documentation
• Maintain accurate and auditable records of assessments and decisions
• Ensure compliance with TPRM policies, industry standards, and regulations (e.g., DORA, NIST, ISO)
• Support audits and regulatory reviews with necessary documentation
Note: Detailed project information will be shared during the recruitment process.

Oferujemy:
We are open to the employment form according to your preferences
Work with experienced and engaged team, willing to learn, share knowledge and open for growth and new ideas
Hybrid work setup – remote days available depending on the client’s arrangements - 2 days a week from the office in Warszawa
Mindbox is a dynamically growing IT company, but still not a large one – everybody can have a real impact on where we are going next
We invest in developing skills and abilities of our employees
We have attractive benefits and provide all the tools required for work f.e. computer
Interpolska Health Care, Multisport, Warta Insurance, training platform (Sages)

🔍 Dekoder Ogłoszenia

🔴
Ability to assess risk under uncertainty and propose actionable solutions
Oczekuje się, że będziesz podejmować decyzje i proponować rozwiązania nawet przy braku pełnych informacji.
🟡
supporting Equinix’s Third-Party Risk Management (TPRM) program
Będziesz pracować w ramach istniejącego, prawdopodobnie rozbudowanego i formalnego programu zarządzania ryzykiem związanym z dostawcami.
🟡
Detect control gaps and vulnerabilities; recommend remediation plans
Twoim zadaniem będzie znajdowanie problemów i sugerowanie, jak je naprawić, ale niekoniecznie wdrażanie tych napraw.
🟡
Track and document remediation progress with ven
Będziesz odpowiedzialny za monitorowanie postępów w naprawianiu problemów, co może oznaczać dużo pracy administracyjnej i raportowania.