IT Security Officer (m/f/d)

Job ID: 38216086

Budget: €36 – €0 EUR

General information
Reference: 168508
Location: Poland
Start: 03.06.2024
Volume: full-time
Duration: Until end of the year

Your Skills
- Technical degree (preferably in IT) or senior IT Security experience and knowledge of IT security and infrastructure concepts, foundations, frameworks, and processes
- A solid understanding of security best practices and relevant standards such as ISO2700, NIST CSF/RMF, PCI DSS
- Risk and Security governance knowledge and experience
- Basic knowledge of applicable laws/regulations pertaining to areas of responsibility
- Advanced knowledge of organization, technology controls, security, and risk issues
- Demonstrated ability to participate in complex, comprehensive, large projects, and initiatives.
- One or more industry recognized Information Security Certifications (CISSP, CISM, CCSP, CRISC, CISA, CDPSE)

Your Tasks
- Assess/review IT Risk and Security controls for company applications
- Perform IT application security risk assessments.
- Review and understand security architecture, data flow, network diagrams, etc.
- Review relevant documentation pertaining to in-scope applications.
- Engage with ITRS consulting team to obtain risk levels for gaps.
- Work with IT PMs to prepare gap presentations for Primary Asset Owner(s)
- Work with Risk Assessment and Control Evaluation (RACE) process and RSA Archer GRC application
- Engage and conduct (project specific meetings) with application teams (IT Product Owners, CART Owners, CART contributors, IT Project Managers, Data Protection Experts, Information Security Officers, etc.) to complete activities associated with the Risk Assessment and Control Evaluation (RACE) process, including reviewing Control Assessments (CA) and Risk Treatment Plans (RTP) using the RSA Archer Governance Risk and Compliance (GRC) application
- Become proficient with the use of the GRC RSA Archer application (training, data entry, processing, reporting)
- Adapt RSA Archer Control Assessment and Risk Treatment (CART) deliverables to IRM control framework based on National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) v2.0
- Participate in various project related meetings with the project team, RACE team, RACE Task Force, and IT Project Managers and IT Security Officers as required.

Your Contact:
Martyna Sobotovic
Westhouse Consulting GmbH
Related categories: Computer Security Internet Security