Skip to content
Team Connect

Cybersecurity Governance Risk and Compliance Consultant

Team Connect Show all offers
Warszawa
Expires Oct 8, 2026
22 days ago

In short

Cybersecurity GRC Consultant needed in Warsaw (hybrid). Requires 8+ years experience and at least 4 specific certifications (CISA, CISM, CRISC, CISSP, etc.). Knowledge of laws, standards, policies, and frameworks is essential.

AI-written summary based on the listing content.

About Company: Team Connect is Poland’s leading nearshore and offshore IT provider. Since 2008 we successfully create and develop software for our clients. We specialize in Agile and DevOps-based software development. From the analysis stage through implementation. We develop backend, frontend, and mobile applications. For one of our clients, we are looking for a Cybersecurity Governance Risk and Compliance Consultant. Location & Delivery Mode: Warsaw, hybrid – 30% onsite / 70% remote. Experience Required: At least 9 years post-education, incl. 8+ years in a similar role. Required Certificates: At least 4 certifications among (must have):[1] CISA (ISACA Certified Information Systems Auditor)[2] CISM (ISACA Certified Information Security Manager)[3] CRISC (ISACA Certified in Risk and Information Systems Control)[4] CISSP (ISC2 Certified Information Systems Security Professional)[5] CGRC (ISC2 Certified in Governance, Risk and Compliance)[6] CSSLP (ISC2 Certified Secure Software Lifecycle Professional)[7] CCSP (ISC2 Certified Cloud Security Professional)[8] CISSP-ISSMP (ISC2 Certified Information Systems Security Management Professional)[9] GSNA (GIAC Certified Systems and Network Auditor)[10] GCCC (GIAC Certified Critical Controls)[11] GIAC Certified ISO-27000 Specialist[12] ISO 27001 Lead implementer or equivalent.[13] ISO 27001 Lead Auditor or equivalent.[14] ISO 27005 Risk Manager or equivalent.or for any listed above, an equivalent alternative certification recognized internationally (subject to acceptance as a valid credential by the Contracting Authority)

Knowledge & Skills: Knowledge:[01] Cybersecurity related laws, regulations and legislations[02] Cybersecurity standards, methodologies and frameworks[03] Cybersecurity policies[04] Legal, regulatory and legislative compliance requirements, recommendations and best practices[05] Privacy impact assessment standards, methodologies and frameworks

Skills: [06] Comprehensive understanding of the business strategy, models and products and ability to factor into legal, regulatory and standards’ requirements[07] Carry out working-life practices of the data protection and privacy issues involved in the implementation of the organisational processes, finance and business strategy[08] Lead the development of appropriate cybersecurity and privacy policies and procedures that complement the business needs and legal requirements; further ensure its acceptance, comprehension and implementation and communicate it between the involved parties[09] Conduct, monitor and review privacy impact assessments using standards, frameworks, acknowledged methodologies and tools[10] Explain and communicate data protection and privacy topics to stakeholders and users[11] Understand, practice and adhere to ethical requirements and standards[12] Understand legal framework modifications implications to the organisation’s cybersecurity and data protection strategy and policies[13] Collaborate with other team members and colleagues

Specific Requirements: [01] minimum 5+ years of experience in cybersecurity GRC, with clear focus on cybersecurity risk management[02] Proven experience in designing or operatiationalising a cyber risk management framework[03] Hands-on experience in using ServiceNow GRC (IRM / Risk / Policy and Compliance modules)[04] Demonstrated experience maintaining and managing a cybersecurity risk register.[05] Experience integrating risk management with: Vulnerability management, Incident management, Cloud risk, Third-party risk[05] Experience contributing to cybersecurity maturity improvement programmes.11. Typical Tasks & Responsibilities: - Ensure compliance with and provide legal advice and guidance on data privacy and data protection standards, laws and regulations- Identify and document compliance gaps- Conduct privacy impact assessments and develop, maintain, communicate and train upon the privacy policies, procedures- Enforce and advocate organisation’s data privacy and protection program- Ensure that data owners, holders, controllers, processors, subjects, internal or external partners and entities are informed about their data protection rights, obligations and responsibilities- Act as a key contact point to handle queries and complaints regarding data processing- Assist in designing, implementing, auditing and compliance testing activities in order to ensure cybersecurity and privacy compliance- Monitor audits and data protection related training activities- Cooperate and share information with authorities and professional groups- Contribute to the development of the organisation’s cybersecurity strategy, policy and procedures- Develop and propose staff awareness training to achieve compliance and foster a culture of data protection within the organization- Manage legal aspects of information security responsibilities and third-party relations'

Published 2026-08-27
Source