SonicJobs Logo
Left arrow iconBack to search

Cybersecurity Risk Manager (Warsaw, on-site) – Frontex

The White Team
Posted 14 days ago, valid for 6 hours
Location

Capon Bridge, WV, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • Frontex is seeking a Cybersecurity Risk Manager for their Warsaw headquarters, requiring 9 years of IT experience, with at least 6 years in relevant roles.
  • The position demands advanced knowledge in cybersecurity and risk management, along with a minimum Level 7 education and C1 English proficiency.
  • Candidates must possess at least 4 relevant certifications, such as CISSP or CISA, and are expected to implement risk management frameworks and ensure compliance with regulations.
  • The role is on-site for a duration of 48 months, with a flexible salary based on the European public grading system.
  • Security clearance is required after 45 days, and travel expenses are not covered.

Cybersecurity Risk Manager (Warsaw, on-site) – Frontex

Profile: Cybersecurity Risk Manager (Cybersecurity, risk management, risk assessment) - Level Advanced.

Place of performance: Frontex Headquarters – 100% on-site.

Duration of the mission: 48 months.

Security Clearance: Is required (required from day 45 of assignment) - RESTREINT UE/EU RESTRICTED.

Minimum level of education: Level 7.

Minimum English language skills: C1.

Minimum IT relevant experience: 9 years (6 years in relevant roles).

Award Criteria: 35% Price / 65% Quality.

Minimum required scoring for interview: 60%.

Travel expenses: Not foreseen.

Rate: Flexible. The rate offered depends on the candidate’s level, in accordance with the European public grading system. Further details are available upon discussion.

· NWH: 230days x4 years.

· EWH: 30days x4 years.

Required technical certificates:

At least 4 certifications are required among:

· CISSP (Certified Information Systems Security Professional).

· CISA (Certified Information Systems Auditor).

· CISM (Certified Information Security Manager).

· GSNA (GIAC Certified Systems and Network Auditor).

· GCCC (GIAC Certified Critical Controls).

· ISO 27001 Lead implementer.

· ISO 27001 Lead Auditor.

· ISO 27005 Risk Manager.

· CAP ((ISC)2 Certified Authorization Professional).

· CRISC (ISACA Certified in Risk and Information Systems Control).

· CISSP-ISSMP ((ISC)2 Certified Information Systems Security Management Professional).

· GIAC Certified ISO-27000 Specialist.

or equivalent certification recognized internationally (subject to acceptance as a valid credential by the Contracting EU-I).

Knowledge and Skills

· Perform risks assessments and analysis to identify threats, categorise assets, and rate system vulnerabilities so that they can implement effective controls.

· Implement cybersecurity risk management frameworks, methodologies and guidelines and ensure compliance with regulations and standards.

· Enable business assets owners, executives, and other stakeholders to make risk informed decisions to manage and mitigate risks.

· Enable employees to understand, embrace and follow the controls.

· Build a cybersecurity risk-aware environment.

· Advanced knowledge of risk management frameworks, standards, methodologies, tools, guidelines and best practices.

· Knowledge of cyber threats, threats taxonomies and vulnerabilities repositories.

· Knowledge of risk sharing options and best practices.

· Knowledge of state of the art technical and organisational controls that appropriately mitigate cybersecurity risks.

· Knowledge of monitoring, implementing and testing the effectiveness of the controls.

· Analyse and consolidate organisation’s quality and risk management practices.

· Communicate, present and report to relevant stakeholders.

· Propose and manage risk sharing options.

Specific requirements

· Experience in making Business Impact Assessments.

· Knowledge on risk assessment implementation in GRC Service Now.

· Experience in preparing personal data protection documentation.

· Experience in tools for graphical and programmatic threat modelling.

· Experience in threat modelling for DevOps.

· Experience in designing Zero Trust Architecture.

· Experience in Securing Software Development Lifecycle.

· Experience in designing controls for defending Directory Services.

Typical tasks and responsibilities

· Develop an organisation’s cybersecurity risk management strategy.

· Manage an inventory of organisation’s assets.

· Identify and assess cybersecurity-related threats and vulnerabilities of ICT systems.

· Identification of threat landscape including attackers’ profiles and estimation of attacks’ potential.

· Assess cybersecurity risks, and propose most appropriate risk treatment options, including security controls, and risk mitigation and avoidance that best address organisation’s strategy.

· Monitor effectiveness of cybersecurity controls and risk levels.

· Ensure that all cybersecurity risks remain at an acceptable level for the organisation’s assets.

· Develop, maintain, report and communicate complete risk management cycle.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.