CyberSecurity Risk Manager

Posted 4 Days Ago
Be an Early Applicant
Warsaw, Warszawa, Masovian, POL
In-Office
Expert/Leader
Information Technology
The Role
Lead development and maintenance of the organisation's cybersecurity risk management strategy. Conduct risk assessments, BIAs, threat modelling, and controls design; implement risk frameworks, monitor controls, support compliance (including ServiceNow GRC), and enable risk-informed decisions across stakeholders. Contribute to Zero Trust Architecture, data protection governance, and produce risk registers, metrics, and reports for executives.
Summary Generated by Built In
Company Description

Arηs Group, Part of Accenture, specializes in the management of complex public sector IT projects, including systems integration, informatics and analytics, solution implementation and program management. Our team helps lead clients through digital and information systems design, bringing expertise in a variety of areas ranging from software development, data science and security management to machine learning, cloud, and mobile development.
Arηs Group was acquired by Accenture in July 2024.

Job Description

  • Develop and maintain the organisation’s cybersecurity risk management strategy
  • Conduct cybersecurity risk assessments and analyses to identify threats, categorise assets, assess vulnerabilities, and recommend risk treatment options
  • Identify and assess cybersecurity-related threats and vulnerabilities of ICT systems and maintain awareness of the evolving threat landscape
  • Perform Business Impact Assessments and support cybersecurity risk-based decision making
  • Design, implement, monitor, and evaluate cybersecurity controls to ensure risks remain at acceptable levels
  • Implement and maintain cybersecurity risk management frameworks, methodologies, standards, and best practices
  • Support compliance with security, risk, governance, and regulatory requirements
  • Enable business stakeholders, asset owners, and executives to make risk-informed decisions
  • Promote a cybersecurity risk-aware culture across the organisation
  • Develop and maintain cybersecurity risk registers, reports, metrics, and documentation
  • Support threat modelling activities for systems, applications, and DevOps environments
  • Contribute to the design of Zero Trust Architecture and security controls for critical enterprise services, including Directory Services
  • Support personal data protection and information security governance initiatives
  • Communicate risk management activities, findings, and recommendations to relevant stakeholders

Qualifications

  • Minimum 9 years of relevant IT professional experience, with at least 6 years in a cybersecurity risk management, information security governance, cybersecurity architecture, or similar role.
  • Minimum education level: Level 7 (Master's degree or equivalent) in an ICT-relevant field.
  • At least 4 of the following certifications:
    • CISA (Certified Information Systems Auditor)
    • CISM (Certified Information Security Manager)
    • CRISC (Certified in Risk and Information Systems Control)
    • CISSP (Certified Information Systems Security Professional)
    • CGRC (Certified in Governance, Risk and Compliance)
    • CSSLP (Certified Secure Software Lifecycle Professional)
    • CCSP (Certified Cloud Security Professional)
    • CISSP-ISSMP (Certified Information Systems Security Management Professional)
    • GSNA (GIAC Certified Systems and Network Auditor)
    • GCCC (GIAC Certified Critical Controls)
    • GIAC Certified ISO-27000 Specialist
    • ISO 27001 Lead Implementer
    • ISO 27001 Lead Auditor
    • ISO 27005 Risk Manager
    • or equivalent, internationally recognized certification
  • Excellent verbal and written communication in English, C1+ certificate desirable
  • Advanced knowledge of cybersecurity risk management frameworks, methodologies, standards, regulatory requirements, tools, best practices, cyber threats, threat taxonomies, vulnerabilities, risk assessment methodologies, risk treatment strategies, and security controls.
  • Experience performing cybersecurity risk assessments, cyber risk analysis, Business Impact Assessments, threat modelling activities, and monitoring the effectiveness of security controls within enterprise environments.
  • Experience implementing cybersecurity governance, risk and compliance processes, including ServiceNow GRC, personal data protection documentation, and organisational risk management practices.
  • Experience designing and assessing security architectures and controls, including Zero Trust Architecture, Secure Software Development Lifecycle (Secure SDLC), threat modelling for DevOps environments, and security controls for Directory Services.
  • Ability to analyse and consolidate organisational risk management and quality management practices, propose and manage risk treatment, risk mitigation and risk-sharing strategies, and communicate recommendations to technical and non-technical stakeholders, including senior management.
  • Excellent communication, documentation, analytical, problem-solving, and stakeholder management skills, with the ability to work independently and provide expert guidance on cybersecurity risk management matters.

Skills Required

  • Minimum 9 years relevant IT professional experience, with at least 6 years in cybersecurity risk management, information security governance, cybersecurity architecture, or similar role
  • Master's degree or equivalent (Level 7) in an ICT-relevant field
  • At least 4 internationally recognized cybersecurity certifications from the provided list (e.g., CISA, CISM, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor, etc.)
  • Excellent verbal and written communication in English
  • C1+ English certificate
  • Advanced knowledge of cybersecurity risk management frameworks, methodologies, standards, regulatory requirements, and risk assessment methodologies
  • Experience performing cybersecurity risk assessments, cyber risk analysis, Business Impact Assessments, threat modelling, and monitoring security controls in enterprise environments
  • Experience implementing cybersecurity governance, risk and compliance processes, including ServiceNow GRC and personal data protection documentation
  • Experience designing and assessing security architectures and controls, including Zero Trust Architecture, Secure SDLC, threat modelling for DevOps, and Directory Services controls
  • Ability to analyse and consolidate organisational risk and quality management practices and propose/manage risk treatment strategies
  • Ability to communicate risk findings and recommendations to technical and non-technical stakeholders, including senior management
  • Strong documentation, analytical, problem-solving, and stakeholder management skills; ability to work independently and provide expert guidance
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Luxembourg
1,493 Employees
Year Founded: 2003

What We Do

Arηs Group is a market leader in the management of complex IT projects and systems. Founded in Luxembourg in 2003, we’ve grown organically to encompass 16 entities worldwide with over 2,500 employees in Luxembourg, Belgium, France, Greece, Italy, Portugal, Bulgaria and Jordan. With our focus on getting things done, we help our clients achieve their goals with best-of-breed solutions, superior execution and exceptional services. We offer bespoke software development, data science, infrastructure, digital trust and mobile development to government institutions at national and European level, telecom providers, and financial institutions, among others. Our bold company culture is built around working hard and playing hard, with a flat and agile structure that lends itself to efficiency and employee empowerment. We value our diverse workplace of close-knit teams and provide a place where everyone can be supported to learn and evolve.

Similar Jobs

Capco Logo Capco

IT Security Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Pfizer Logo Pfizer

Senior Director, Applied AI - US Commercial

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
28 Locations
121990 Employees
215K-358K Annually

Akamai Technologies Logo Akamai Technologies

Manager Engineering

Cloud • Security • Software • Cybersecurity
In-Office or Remote
2 Locations
10285 Employees
50K-150K Annually

Capco Logo Capco

Product Manager

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account