SonicJobs Logo
Left arrow iconBack to search

Cybersecurity Risk Manager (Warsaw, on-site) – Frontex

The White Team
Posted 14 days ago, valid for 17 hours
Location

Capon Bridge, WV, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • Frontex is seeking a Cybersecurity Risk Manager for their Warsaw headquarters, requiring 9 years of IT experience, with at least 6 years in relevant roles.
  • The position demands advanced knowledge in cybersecurity and risk management, along with a minimum Level 7 education and C1 English proficiency.
  • Candidates must possess at least 4 relevant certifications, such as CISSP or CISA, and are expected to implement risk management frameworks and ensure compliance with regulations.
  • The role is on-site for a duration of 48 months, with a flexible salary based on the European public grading system.
  • Security clearance is required after 45 days, and travel expenses are not covered.

Cybersecurity Risk Manager (Warsaw, on-site) – Frontex

Profile: Cybersecurity Risk Manager (Cybersecurity, risk management, risk assessment) - Level Advanced.

Place of performance: Frontex Headquarters – 100% on-site.

Duration of the mission: 48 months.

Security Clearance: Is required (required from day 45 of assignment) - RESTREINT UE/EU RESTRICTED.

Minimum level of education: Level 7.

Minimum English language skills: C1.

Minimum IT relevant experience: 9 years (6 years in relevant roles).

Award Criteria: 35% Price / 65% Quality.

Minimum required scoring for interview: 60%.

Travel expenses: Not foreseen.

Rate: Flexible. The rate offered depends on the candidate’s level, in accordance with the European public grading system. Further details are available upon discussion.

Ā· NWH: 230days x4 years.

Ā· EWH: 30days x4 years.

Required technical certificates:

At least 4 certifications are required among:

Ā· CISSP (Certified Information Systems Security Professional).

Ā· CISA (Certified Information Systems Auditor).

Ā· CISM (Certified Information Security Manager).

Ā· GSNA (GIAC Certified Systems and Network Auditor).

Ā· GCCC (GIAC Certified Critical Controls).

Ā· ISO 27001 Lead implementer.

Ā· ISO 27001 Lead Auditor.

Ā· ISO 27005 Risk Manager.

Ā· CAP ((ISC)2 Certified Authorization Professional).

Ā· CRISC (ISACA Certified in Risk and Information Systems Control).

Ā· CISSP-ISSMP ((ISC)2 Certified Information Systems Security Management Professional).

Ā· GIAC Certified ISO-27000 Specialist.

or equivalent certification recognized internationally (subject to acceptance as a valid credential by the Contracting EU-I).

Knowledge and Skills

Ā· Perform risks assessments and analysis to identify threats, categorise assets, and rate system vulnerabilities so that they can implement effective controls.

Ā· Implement cybersecurity risk management frameworks, methodologies and guidelines and ensure compliance with regulations and standards.

Ā· Enable business assets owners, executives, and other stakeholders to make risk informed decisions to manage and mitigate risks.

Ā· Enable employees to understand, embrace and follow the controls.

Ā· Build a cybersecurity risk-aware environment.

Ā· Advanced knowledge of risk management frameworks, standards, methodologies, tools, guidelines and best practices.

Ā· Knowledge of cyber threats, threats taxonomies and vulnerabilities repositories.

Ā· Knowledge of risk sharing options and best practices.

Ā· Knowledge of state of the art technical and organisational controls that appropriately mitigate cybersecurity risks.

Ā· Knowledge of monitoring, implementing and testing the effectiveness of the controls.

Ā· Analyse and consolidate organisation’s quality and risk management practices.

Ā· Communicate, present and report to relevant stakeholders.

Ā· Propose and manage risk sharing options.

Specific requirements

Ā· Experience in making Business Impact Assessments.

Ā· Knowledge on risk assessment implementation in GRC Service Now.

Ā· Experience in preparing personal data protection documentation.

Ā· Experience in tools for graphical and programmatic threat modelling.

Ā· Experience in threat modelling for DevOps.

Ā· Experience in designing Zero Trust Architecture.

Ā· Experience in Securing Software Development Lifecycle.

Ā· Experience in designing controls for defending Directory Services.

Typical tasks and responsibilities

Ā· Develop an organisation’s cybersecurity risk management strategy.

Ā· Manage an inventory of organisation’s assets.

Ā· Identify and assess cybersecurity-related threats and vulnerabilities of ICT systems.

Ā· Identification of threat landscape including attackers’ profiles and estimation of attacks’ potential.

Ā· Assess cybersecurity risks, and propose most appropriate risk treatment options, including security controls, and risk mitigation and avoidance that best address organisation’s strategy.

Ā· Monitor effectiveness of cybersecurity controls and risk levels.

Ā· Ensure that all cybersecurity risks remain at an acceptable level for the organisation’s assets.

Ā· Develop, maintain, report and communicate complete risk management cycle.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.