热门公司

EY
EY

EY, previously known as Ernst & Young, is a British multinational professional services network based in London, United Kingdom

Senior Cybersecurity Risk and Compliance Consultant

职能安全
级别资深
地点United States
方式现场办公
类型全职
发布2个月前
立即申请

Senior Cybersecurity Risk and Compliance Consultant

Location: Katowice - 2 days office / 3 days remote

Let us introduce you the job offer by EY GDS Poland – a member of the global integrated service delivery center network by EY.

The opportunity

As a Senior Consultant within our Cybersecurity, Risk, Compliance & Resilience (CRCR) competency, you will help EY Clients evaluate the effectiveness and maturity of their cybersecurity and resiliency programs in alignment with regulatory expectations, strategic priorities, and operational demands. In addition to governance, compliance, and control evaluations, you will lead the implementation of risk management strategies and threat modelling activities, ensuring that the organization maintains acceptable risk levels while enabling digital transformation. You will support the delivery of IT Security Plans and contribute to complex risk analysis and mitigation initiatives across hybrid IT environments.

Your key responsibilities

  • Help EY Clients evaluate the effectiveness and maturity of their cybersecurity and resiliency programs in alignment with regulatory expectations, strategic priorities, and operational demands.

  • Lead the implementation of risk management strategies and threat modeling activities, ensuring that the organization maintains acceptable risk levels while enabling digital transformation.

  • Support the delivery of IT Security Plans and contribute to complex risk analysis and mitigation initiatives across hybrid IT environments.

Skills and attributes for success

  • Minimum 5 years of experience in cybersecurity risk management, with proven expertise in executing complex risk assessments, threat modeling, and strategic mitigation planning.

  • Assuring conformity to regulations, norms, and standards such as ISO27001, NIST, or any other ISMS governance systems.

  • Implementation of risk treatment plans and running business continuity program assessments.

  • Practical knowledge of Third Party Risk Management (TPRM).

  • Deep understanding of cybersecurity risk trends, control frameworks, and legal/regulatory drivers.

  • Exceptional stakeholder management and leadership skills, including guiding junior risk analysts and engaging with senior client stakeholders.

  • Strong ability to evaluate emerging cybersecurity risks and recommend effective control solutions.

  • Excellent interpersonal skills, inspiring teamwork and responsibility among engagement team members.

  • Designing new functionalities and solutions.

  • Optimizing existing processes and system components.

  • Creating prototypes and proof-of-concept for new/improved modules.

  • Researching technological possibilities and analyzing trends.

To qualify for the role, you must have

  • Excellent command of the English language; other European languages would be an asset.

  • Analytical and problem-solving ability, with the capacity to work effectively as a team member or individual contributor, and an eye for detail.

  • Ability to critically develop and review Information Security SOPs to identify controls gaps and weaknesses.

  • Strong project management skills and the ability to liaise with stakeholders.

  • Effectively communicate complex cybersecurity risks and technical information to management, enabling informed decision-making and strategic guidance.

Ideally, you’ll also have

  • Excellent command of the English language; other European languages would be an asset.

  • Analytical and problem-solving ability, with the capacity to work effectively as a team member or individual contributor, and an eye for detail.

  • Ability to critically develop and review Information Security SOPs to identify controls gaps and weaknesses.

  • Strong project management skills and the ability to liaise with stakeholders.

  • Effectively communicate complex cybersecurity risks and technical information to management, enabling informed decision-making and strategic guidance.

What we look for

We are looking for individuals who are passionate about cybersecurity and possess a strong analytical mindset. You should be able to navigate complex regulatory environments and provide strategic insights that drive effective risk management. A collaborative spirit and the ability to communicate effectively with diverse stakeholders are essential for success in this role. If you are committed to enhancing organizational resilience and are eager to contribute to a dynamic team, we encourage you to apply. Your proactive approach and dedication to continuous improvement will be key in helping our clients achieve their cybersecurity goals.

What we offer

EY Global Delivery Services (GDS) is a dynamic and truly global delivery network. We work across nine locations – Argentina, Hungary, India, the Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom – and with teams from all EY service lines, geographies and sectors, playing a vital role in the delivery of the EY growth strategy. From accountants to coders to advisory consultants, we offer a wide variety of fulfilling career opportunities that span all business disciplines. In GDS, you will collaborate with EY teams on exciting projects and work with well-known brands from across the globe. We’ll introduce you to an ever-expanding ecosystem of people, learning, skills and insights that will stay with you throughout your career.

  • Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.

  • Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.

  • Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.

  • Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.

About EYEY | Building a better working world

EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

If you can demonstrate that you meet the criteria above, please contact us as soon as possible.The exceptional EY experience. It’s yours to build.

In compliance with the requirements of the Whistleblower Protection Act, our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions. Any misconduct should be reported through the EY Ethics Hotline.

浏览量

0

申请点击

0

Mock Apply

0

收藏

0

关于EY

EY

EY

Public

EY, previously known as Ernst & Young, is a British multinational professional services network based in London, United Kingdom. Along with Deloitte, KPMG and PwC, it is one of the Big Four professional services firms.

10,001+

员工数

London

总部位置

评价

2条评价

2.7

2条评价

工作生活平衡

2.0

薪酬

3.0

企业文化

2.2

职业发展

3.5

管理层

1.8

25%

推荐率

优点

Opportunity to become top performer

Handle large accounts

High responsibility roles

缺点

Long hours and intense work pressure

Poor management and leadership

Burnout issues

薪资范围

31,254个数据点

Mid/L4

Mid/L4 · Operations Research Analyst

1,738份报告

$142,571

年薪总额

基本工资

$136,899

股票

-

奖金

$5,673

$100,128

$203,912

面试评价

7条评价

难度

3.0

/ 5

时长

14-28周

录用率

57%

面试流程

1

Application Review

2

HR Screen

3

Hiring Manager Interview

4

Technical/Case Interview

5

Partner/Director Interview

6

Offer

常见问题

Behavioral/STAR

Case Study

Technical Knowledge

Past Experience

Culture Fit