招聘
Cybersecurity Risk and Resiliency Manager
Location: Katowice - 2 days office / 3 days remote
Let us introduce you the job offer by EY GDS Poland – a member of the global integrated service delivery center network by EY.
The opportunity
As a Manager within our Cybersecurity Risk, Compliance & Resilience (CRCR) competency, you will play a pivotal role in assisting EY clients in evaluating the effectiveness and efficiency of their cybersecurity and resiliency programs. Your focus will be on aligning these programs with business growth and operational strategies. In addition to conducting compliance and control evaluations, you will be instrumental in developing and implementing risk management strategies and business continuity plans, ensuring organizations are well-prepared to respond effectively to incidents and disruptions. You will identify deficiencies and provide actionable recommendations and guidelines to enhance cyber resilience. This role is not solely about overseeing others, you will be expected to bring your hands-on experience to the forefront, directly contributing to project delivery and execution, while also managing and coordinating efforts as needed.
Your key responsibilities
-
Evaluate and assess the effectiveness of clients' cybersecurity and resiliency programs.
-
Develop and implement risk management strategies and business continuity plans.
-
Conduct compliance and control evaluations, ensuring adherence to regulations and standards such as ISO 27001 and NIST.
-
Perform audits or reviews of Information Security Management Systems (ISMS) and IT general controls.
-
Manage Third Party Risk Management (TPRM) processes.
-
Provide domain knowledge in cybersecurity, including governance, IT infrastructure security, and risk management.
-
Actively participate in hands-on project delivery, ensuring technical and operational tasks are completed with high quality and aligned to client expectations.
-
Collaborate with engagement team members, fostering teamwork and responsibility.
-
Set up governance frameworks for cybersecurity services, ensuring alignment with organizational objectives.
-
Develop and monitor Key Performance Indicators (KPIs) to measure the effectiveness of cybersecurity services.
-
Oversee service delivery processes, ensuring high-quality service and client satisfaction.
-
Work on offer preparation, acting as a Service Delivery Manager (SDM) for key cyber project portfolios, discussing client needs, preparing proposals, and actively pursuing and securing project engagements.
-
Balance direct hands-on involvement with team coordination, ensuring seamless execution of both technical tasks and broader project objectives.
Skills and attributes for success
Minimum 5 years of experience in the field of Information Security and/or Information Technology with minimum two years of them focusing on Information security field with expertise including –but not limited to-below areas:
-
Assuring the conformity to regulations, norms and standards such as ISO27001, NIST or any other ISMS governance systems
-
IT Controls such as IT General Controls (ITGC), IT Application Controls (ITAC) or any other
-
Implementation of the risk management plans and business continuity program assessments
-
Performing audits or reviews of ISMS systems and/or IT general controls
-
Experience in Third Party Risk Management (TPRM)
-
Domain knowledge in Cybersecurity, including governance, IT infrastructure security and risk management, cyber program assessments including cyber transformation and enterprise resilience.
-
Demonstrated hands-on experience in cybersecurity, with a proven track record of executing technical work, not just overseeing teams.
-
Demonstrate excellent interpersonal skills, inspire teamwork and responsibility with engagement team members
-
Strong analytical and problem-solving abilities, with a keen eye for detail.
-
Excellent interpersonal skills, with the ability to inspire teamwork and collaboration.
Strong project management skills, including:
-
Project planning and resource management, ensuring alignment with client and organizational objectives
-
Budgeting and work estimation (e.g., man-days estimation, resource allocation)
-
Effective stakeholder communication, ensuring alignment of expectations and facilitating decision-making
-
Experience in establishing governance frameworks and developing KPIs for service delivery.
To qualify for the role, you must have
-
Excellent command of the English language; other languages would be an asset.
-
Analytical and problem-solving abilities, observant with an eye for detail.
-
Ability to liaise with stakeholders and manage multiple priorities effectively.
-
Proven experience in both hands-on technical work and project leadership/coordinating responsibilities.
Ideally, you’ll also have
-
Knowledge about Digital Operational Resilience Act (DORA), NIS2 directive, EU Cybersecurity Act, EU AI Act, and/or other relevant EU regulations.
-
Practical knowledge of GRC system such RSA Archer, SAP GRC, One Trust, Service Now GRC
What we look for
What we look for in a Junior Cyber Ark Developer is a technically minded individual with a strong foundation in Cyber Ark PAM solutions or similar Identity and Access Management tools, complemented by scripting skills in languages like PowerShell or Python. We value candidates who possess analytical problem-solving abilities, effective communication skills, and a willingness to learn and collaborate within a diverse team environment. A basic understanding of relevant technologies and a readiness to travel are also essential attributes for success in this role.
What we offer
EY Global Delivery Services (GDS) is a dynamic and truly global delivery network. We work across nine locations – Argentina, Hungary, India, the Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom – and with teams from all EY service lines, geographies and sectors, playing a vital role in the delivery of the EY growth strategy. From accountants to coders to advisory consultants, we offer a wide variety of fulfilling career opportunities that span all business disciplines. In GDS, you will collaborate with EY teams on exciting projects and work with well-known brands from across the globe. We’ll introduce you to an ever-expanding ecosystem of people, learning, skills and insights that will stay with you throughout your career.
-
Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
-
Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
-
Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
-
Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
About EY
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.
If you can demonstrate that you meet the criteria above, please contact us as soon as possible.
The exceptional EY experience. It’s yours to build.
In compliance with the requirements of the Whistleblower Protection Act, our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions. Any misconduct should be reported through the EY Ethics Hotline.
总浏览量
0
申请点击数
0
模拟申请者数
0
收藏
0
相似职位

Director, Security Architect
Fidelity · Merrimack, New Hampshire, USA

Python Gen AI developer - Director- Cyber Security Engineering
Morgan Stanley · Bengaluru, Karnataka, India

Head of Security (JetBrains Cloud Platform)
JetBrains · Amsterdam, Netherlands; Belgrade, Serbia; Berlin, Germany; Limassol, Cyprus; London, United Kingdom; Munich, Germany; Paphos, Cyprus; Prague, Czech Republic; Warsaw, Poland; Yerevan, Armenia

Senior Network Security Services Architect CTO Office
Bloomberg ·

Cloud Network Security Architecture Manager (TIC 3.0)
General Dynamics · USA DC Washington
关于EY

EY
PublicEY, previously known as Ernst & Young, is a British multinational professional services network based in London, United Kingdom. Along with Deloitte, KPMG and PwC, it is one of the Big Four professional services firms.
10,001+
员工数
London
总部位置
评价
3.4
10条评价
工作生活平衡
2.3
薪酬
3.7
企业文化
4.1
职业发展
3.8
管理层
3.2
65%
推荐给朋友
优点
Good learning opportunities and career advancement
Supportive culture and kind people
Professional environment and good benefits
缺点
Long working hours and poor work-life balance
Hectic and taxing work environment
Limited support for interns and technical growth
薪资范围
31,254个数据点
Mid/L4
Mid/L4 · Operations Research Analyst
1,738份报告
$142,571
年薪总额
基本工资
$136,899
股票
-
奖金
$5,673
$100,128
$203,912
面试经验
7次面试
难度
3.0
/ 5
时长
14-28周
录用率
57%
面试流程
1
Application Review
2
HR Screen
3
Hiring Manager Interview
4
Technical/Case Interview
5
Partner/Director Interview
6
Offer
常见问题
Behavioral/STAR
Case Study
Technical Knowledge
Past Experience
Culture Fit
新闻动态
Five questions banks must ask to unlock tech value - EY
EY
News
·
3d ago
Five hallmarks of effective AI strategies in banking - EY
EY
News
·
3d ago
How a healthcare company tackles third-party risk with tech and data - EY
EY
News
·
3d ago
Alum sues GW, former employer alleging discrimination, defamation after graduation speech - The GW Hatchet
The GW Hatchet
News
·
4d ago