Utwórz profil, aby pracodawcy mogli Cię znaleźć, otrzymywać lepiej dopasowane oferty pracy i szybciej aplikować.
  • Wyszukiwanie ofert pracy
  • Zapisane
  • Stwórz CV
    Nowe
  • Wynagrodzenia
  • Subskrypcje

Security Engineer (ISO 27001)

20000 - 27000 zł

Creativestyle Polska Sp. z o.o.

Operating system, macOS, Linux

About the project, We're looking for a Security Engineer who likes having an impact and enjoys taking responsibility ‍♂️ ‍♀️, , If implementing ISMS/GRC, building security processes and taking care of technical security is your thing, you'll have the chance to own this area, shape its future and leave your mark on it. We're counting on your expertise, hands-on mindset and best practices to help us build a strong and mature security function together., , Because this role also covers physical security and on-site work, we'd love to work with someone based in Kraków in a hybrid model. Working remotely from anywhere in Poland is also possible, as long as you're happy to visit the office regularly., , We believe great teams are built on diversity and inclusion. That's why we're creating a workplace where everyone feels welcome and can be their authentic selves. We encourage applications from all people, regardless of gender, age, background, sexual orientation, religion, or disability.

Your responsibilities, ISMS OPERATIONS (~60%), Own and operate the risk management process: risk workshops, Risk Register and Risk Treatment Plan maintenance, Statement of Applicability (SoA) preparation, Write, maintain and review security policies and procedures in collaboration with process owners across the organisation, Collect and organise audit evidence; execute recurring activities from the ISMS Operational Calendar, Lead preparation for the certification audit; support internal, external and customer audits, Own customer security questionnaires and supplier security reviews, Run the security awareness programme in collaboration with HR, Own the security roadmap; shape the security function over time (priorities, budget input, future hires), TECHNICAL IMPLEMENTATION (~40%), MDM/EDR rollout and administration (macOS ABM, configuration baselines, full-disk encryption), in collaboration with the Internal IT team, Hardening and monitoring of self-hosted GitLab; centralised logging and monitoring; vulnerability management, Incident response: build the procedure, coordinate incident handling, conduct post-mortems, Support secure SDLC (SAST/SCA in CI/CD, secrets management), working alongside our technology teams, Physical security of the offices (access control, monitoring), in collaboration with Office Crew

YOU'RE OUR KIND OF PERSON IF YOU..., have 5+ years of experience in IT security, including hands-on experience with ISO 27001 ISMS (whether implementing it from scratch or helping maintain a certified security management system), are comfortable owning risk management end-to-end: analysing risks, maintaining the Risk Register and planning effective mitigation actions, have hands-on experience in areas such as MDM, EDR, Linux hardening, GitLab/CI-CD security, AWS security fundamentals, and centralised logging, are familiar with GDPR in the context of information security (including Art. 28, 32, 33 and DPIA from an operational, not legal, perspective), understand web application security (OWASP Top 10, secure SDLC practices) well enough to collaborate with technology teams and help shape secure development standards, thrive in an autonomous role, feel comfortable making security decisions and take full ownership of the results, are fluent in Polish and English and feel comfortable

Optional, BONUS POINTS IF YOU:, hold certifications such as ISO 27001 Lead Implementer / Lead Auditor (highly preferred), CISSP, CISM or CRISC, have experience working in a software house or agency environment, supporting multiple clients in a contract-based model and sharing ownership of successful outcomes, are familiar with the e-commerce world (Magento / Shopware) and have a basic understanding of PCI-DSS from a service provider perspective, have knowledge of NIS2, DORA or the AI Act, speak German, or have experience with customer security audits, have completed at least one full ISO 27001 implementation cycle, from initial setup to certification

Division of working time, ISMS OPERATIONS - 60%, TECHNICAL IMPLEMENTATION - 40%

This is how we work, in house, agile, scrum, kanban

This is how we work on a project, documentation, issue tracking tools, testing environments

Development opportunities we offer, conferences in Poland, development budget, intracompany training, mentoring, soft skills training, space for experimenting, substantive support from technological leaders, support of IT events, technical knowledge exchange within the company, the company supports open source projects, time for development of your ideas

What we offer, If this job makes you excited and you see yourself and your skillset in it, we should definitely meet and talk (including salary ranges ). For an employment contract (UoP), the salary range is PLN 20 000 - 27 000 gross. Your final salary will be shaped by your skills, experience, engagement and collaboration quality. The role comes with wide privileged access, security decision-making responsibilities and close collaboration across the organization - meaning that UoP contract provides the most transparent and stable framework for both sides., If you prefer B2B cooperation model, we’re happy to discuss it together. Due to the nature of the role, terms are agreed individually. Please indicate this in the application form and we’ll get back to you in the next step to align on the details., People & atmosphere. Technically not a benefit, but always the first answer when someone talks about creativestyle - so we keep it, Home office. No stress! The world keeps spinning even if you stay home sometimes, PLN 3 000 annual training budget (for whatever boosts your skills) + language courses. Your growth = our growth, MacBook Pro, all the tools you need and a big monitor on top, Medicover + Multisport Plus. Rybnik office: gym in K1 building (no excuses, just the elevator!), Kraków: 4' away... on foot, Office life: game consoles, a billiards/ping-pong league, and a themed lunch every month, An old mill in Zabłocie turned loft office. Spacious, comfortable, stylish and a rooftop as a bonus, Great access. By bike, horse, fast tram or train (Kraków Zabłocie station). HR crew might just show up on a broomstick, CS gear corner. Need speakers or a podcast studio? Just take it. “Company” doesn’t mean “not for you”, Even more good stuff

Benefits, sharing the costs of sports activities, private medical care, sharing the costs of foreign language classes, sharing the costs of professional training & courses, flexible working time, fruits, integration events, corporate sports team, corporate library, no dress code, video games at work, coffee / tea, drinks, leisure zone, pre-paid cards, sharing the costs of tickets to the movies, theater, extra leave, dofinansowanie do lunchu w biurze, parking dla rowerów, trening umiejętności miękkich, firmowa wypożyczalnia sprzętów, badanie FRIS®

Recruitment stages, A short call, An online or face-to-face meeting , A moment to decide together

WHAT'S NEXT?, You’re just 3 steps away from signing a contract with us! We’ll do our best to make the process smooth and painless... smoother than a pirate finding treasure with the map already in hand., , 1.A short call- to get to know each other, check your English, and answer your questions, 2.An online or face-to-face meeting- to dive into the technical side and see if we’re a good match, 3.A moment to decide together- and we’ll always come back to you with feedback, , Just like in a video game, you unlock the next level by successfully completing the previous one., , We’ll be in touch with selected candidates and invite them to the next stages of the process.

Creativestyle Polska Sp. z o.o., •25+ years in the game, Polish-German at heart and still crafting e-commerce solutions that help businesses grow and stand out, •100+ people with passion for tech and a taste for ambitious projects, •Everyone here, from the project team to the top, has a tech background and speaks “internet” fluently , •We’re mostly based in Poland (Kraków and Rybnik), with Germany just around the corner (Munich and Hamburg - Oktoberfest included, of course), •We only pick projects worth doing - no fixing other people's mess, •We believe in doing things properly, not quickly. That’s how we became a leader and collected several awards along the way (e.g. Shop Usability Award). This year, we truly smashed it! We earned the title Agency of the Year + 2 victories we achieved together with our clients: #BestCustomerExperience (benuta) and #BestMobileExperience (Bergzeit), •Slack, Jira, Confluence - these are part of our daily toolkit, •We communicate in English, German and Polish. And since we also have people from Silesia, we can switch to a more local vibe when needed , •Mainly DACH clients - daily contact, with Project Managers handling complex topics, •At creativestyle, freedom and responsibility come in equal parts, •Mistakes are part of the journey, not something to point fingers at. We leave room for trial and error, but try not to repeat it , •2 HappyAtWork Index mentions for us - proof the project crew is in good shape and "the rum barrel never dries out", •Our guiding values (reliability, empathy, and curiosity) navigate us better than Google Maps, always bringing us back to port, •Our tech edge - where we really shine, •We grow when you grow! Our “Cyber Sailors set sail” project made the podium and won 1st place in the "Talent Development in an Organization" category at the HR Dream Team 2024 awards

This is how we work,
Oferta pracy dodana 22 dni temu