Information Security Manager

We are looking for talented people for the role of
Information Security Manager
Gdańsk
Summary

The Information Security & Assurance (IS&A) is a global team that is responsible for ensuring all security risks pertaining to business delivery and Client engagements are managed end to end. The team engages on a frequent basis with business leaders to identify, analyze and mitigate security risks. The team is also the primary touch point between the Corporate Security Group and Business teams, while supporting the business on Client security requirements and compliance.

As a Manager in IS&A, you will be part of Corporate Security Group and facilitate security requirements for Cognizant GGM (Global Growth Markets) Business and its clients.

Responsibilities
  • Manage security and compliance risks in service delivery for key verticals
  • Communicate with Business teams to understand all critical security requirements and risk scenarios
  • Engage in IS&A program for the key accounts: define control framework; identify and evaluate risks; understand business context and prepare reports and recommendations
  • Coordinate with Incident management team during incidents and support investigation of security breaches
  • Perform annual Security Risk assessments and conduct related ongoing compliance monitoring activities in coordination with Privacy Officer and Legal Team members
  • Manage External ISO 27001 audit and coordination with auditors: plan out audit schedule and charter for corporate functions and coordinate with all internal stakeholders towards preparation
  • Assess, prepare and ensure all IT systems, policies and procedures fully comply with Cognizant ISO 27001 SoA, local laws and cross-borders regulations
  • Engage with different stakeholders: external auditors, customer visitor, business leaders and corporate teams, such as HR, legal, IT, etc.
  • Conduct reviews to assess the service delivery control environment and evaluate adherence to client identified contractual requirements, Cognizant policies and standards

 

You have
  • Already have or in process to obtain relevant Security Certifications e.g. CISA, CISSP, CISM, etc.
  • Experience on ISO 27001 Information Security Management system, Risk Assessments, Evaluation of results / findings, IT GRC Governance Risk Compliance Tools
  • Knowledge on GDPR and EU Data Protection directive is beneficial
  • Participation in information security and risk management field, especially with Technology Risk Management / IT Audit in Enterprise organizations
  • Knowledge in understanding and deploying risk management and security frameworks such as NIST, ISF and ISO
  • Knowledge of SSAE/ISAE3402, SOC 1 and SOC 2 and PCI-DSS, assessment and control implementation
  • Basic Understanding of network and system security technology and practices across all major-computing areas with a special emphasis on Internet related technology
Personal characteristics:
  • Ability to think strategically; work with a sense of urgency and pay attention to detail
  • Ability to present complex solutions and methods to a general community
  • Independent thinking, willingness to "step outside the box" and take reasonable, calculated risks
  • Excellent written and verbal communication and organizational skills in English
  • Strong collaboration skills and willingness to be a team player to solve problems and incorporate input from various sources
  • Willing to travel (10%)
We offer
  • Opportunity to be part of a rapidly expanding global organization with irreproachable reputation.
  • Pleasant and inspiring working atmosphere.
  • Professional development and clear career path.
  • Training & development opportunities.
  • Competitive salary with cafeteria benefits.
Prosimy o dopisanie klauzuli: Wyrażam zgodę na przetwarzanie moich danych osobowych zawartych w mojej ofercie pracy dla potrzeb niezbędnych do realizacji procesu rekrutacji (zgodnie z Ustawą z dnia 29.08.1997 r. o Ochronie Danych Osobowych; tekst jednolity Dz. U. z 2016 r. poz. 922 z późn. zm. ). Jednocześnie oświadczam, że zostałem/am poinformowany/a o dobrowolności podania danych osobowych oraz prawie dostępu do treści swoich danych i ich poprawiania.

    Luxoft

    mazowieckie / Warsaw

    31-12-2020

    QA Engineer

    Perform manual exploratory testing and execute scripted test cases Evaluate, modify, and flesh-out test case suites Create new test cases, create scripts and automate testing environment Participate in all aspects of logging and tracking defects 3+ years...

    Luxoft

    dolnośląskie / Wroclaw

    31-12-2020

    Lead Architect (DevOps)

    Experience of technology and digital transformation programs within Investment Banking (Agile, DevOps, Waterfall) Team leading and confident stakeholder management skills Financial Services experience Good technical background and understanding of Cloud,...

    Luxoft

    małopolskie / Krakow

    31-12-2020

    Senior Business Analyst

    You and your teammates are responsible for all aspects of delivering software to your users: o Application full stack ownership for FIS Global FrontArena o Application Development and Maintenance for XML and python based integrations to the FrontArena...

Więcej ofert pracy

Podobne oferty pracy

  • ING Tech Polandt

    śląskie / Katowice

    30-12-2020

    Inżynier sieciowy wsparcia zarządzania ryzykiem [rekrutacja online]

    umowa o pracę taki rodzaj umowy oferujemy Start 7:00 - 9:00 Koniec 15:00 - 17:00 w tych godzinach pracujemy ul. Konduktorska 35, Katowice tutaj mieści się nasze biuro Zakres obowiązków 50% - Monitorowanie i raportowanie stanu zabezpieczeń...

  • TeamQuestt

    mazowieckie / Warszawa

    30-12-2020

    Pentester - IT Security Specialist

    Doradztwo w zakresie bezpieczeństwa informacji Wykonywanie testów penetracyjnych aplikacji (głównie webowych) i infrastruktury IT Przygotowanie raportów z wykonanych testów penetracyjnych 1,5+ doświadczenie w testach penetracyjnych aplikacji...

  • Miejskie Przedsiębiorstwo Wodociągów i Kanalizacji w m.st. Warszawie S.A.t

    mazowieckie / Warszawa ul. Zaruskiego 4

    29-12-2020

    Starszy Specjalista / Główny Specjalista w Wydziale Operacyjnego Centrum Cyberbezpieczeństwa

    (Biuro Informatyki i Telekomunikacji- Wydział Operacyjnego Centrum Cyberbezpieczeństwa) Naszym Pracownikom oferujemy: zatrudnienie w oparciu o umowę o pracę pracę w oparciu o wartości wynikające z ponad 130-letniej tradycji atrakcyjne premie...