Wybierz usługę po lewej lub skontaktuj się z nami mailowo!
What you'll be responsible for:
Role Description:
-
The Audit Manager, Information Security position will be an integral member of the Information Security and Risk Management team. This role will be responsible for organizing and managing internal and external audits. Work in Chief Information Security Officer (CISO) office under Director, Information Security Governance, Risk and Compliance, this role serves as an information security technology professional for Grant Thornton to support the design, implementation, and maintenance of a cohesive information security governance, risk and compliance program. The successful candidate will have a good mix of deep technical knowledge, understanding of industry best practice, frameworks and regulations, and a demonstrated background in information security risk management program.
-
An experienced and motivated risk and compliance individual contributor is needed to work across a matrixed team in place today and growing in the future. The successful candidate has a track record of developing strong relationships, collaborating across teams, coordinating multiple timelines, and managing complex, cross discipline projects.
Responsibilities:
-
Develop audit program and plans, determine scope of audit coverage, and organize and manage internal and external audit engagements.
-
Oversee the process of audits, making recommendations on policies, and ensuring that the organization fulfills compliance obligations.
-
Coordinates and/or performs audit work, reviews audit reports prior to formal release, reviews management responses and reviews supporting workpapers to ensure reports are properly supported.
-
Identifies factors causing deficient conditions and provides constructive, economical, and practical recommendations for audit findings. Drafts recommendations for management responses and corrective action plans.
-
Support iterative review of assessment results, working with appropriate stakeholders across the lines of defense.
-
Follows-up to determine adequacy and implementation of corrective actions.
-
Identify and manage implementation of new compliance requirements/controls that are introduced by changes to regulations/standards/frameworks (new compliance requirements introduced per changes to ISO 27001, SOC 2, NIST 800-53, NIST CSF, GDPR)
-
Participate and provide input during policy annual reviews.
-
Educate control owners to submit risks/exceptions and support risk assessments.
-
Design automated and manual control testing methods.
-
Conduct compliance assessments and internal control testing of critical business processes, critical information systems/assets (technology/application) and processes to evaluate design and operating effectiveness of controls, and proactively prepare stakeholders for external audits.
-
Participate in policy reviews and provide meaningful feedback; facilitate policy operationalization
-
Establishes and maintains effective working relationships with Control Owners and Control Operators.
-
Support and advise Control Owners and Control Operators to:
-
-
build programs based on principles: compliance-by-design and security-by-design,
-
-
-
proactive evidence collection for audits using GRC Tool,
-
-
-
validate evidence for sufficiency per control requirements,
-
-
-
remediate findings.
-
-
Create collateral to promote culture of compliance aligned to firm’s risk tolerance.
-
Contribute to the development of scalable models and tools that speed up both decision making and accuracy for the organization.
-
Assimilate risk and compliance assessment/audit data into concise and meaningful reports/dashboards for leadership.
Our expectations:
The ideal candidate:
-
is a self-starter, with the ability to drive tasks to completion independently and learn new skills on the job as program requirements evolve.
-
possesses strong business judgment, deep analytical thinking, is comfortable managing multiple responsibilities within a fast-paced environment, and has worked collaboratively with others to develop, implement, and communicate business improvement and innovative strategies.
-
possesses strong verbal and written communication skills, a solution-oriented approach, and relationship-building skills are important attributes to succeed in this role. Successful candidate will develop strong relationships, collaborate across teams, coordinate multiple timelines, and manage complex, cross discipline projects.
-
global view of their business and think in terms of immediate problem solving but also automating, expanding, and scaling solutions broadly.
-
thinks strategically at a global level and effectively develop key processes, procedures and communications that facilitate cross-functional implementation of compliance management processes and compliance reporting.
Experience:
-
Experience with information security frameworks, industry standards (i.e., NIST 800-53; ISO 27001, ISO 27017, COSO, HITRUST)
-
Experience with regulatory requirements (i.e., GDPR etc.)
-
Experience performing IT audits and control testing
-
Experience using GRC tools and technologies in support of the assessment/audit process
-
Experience gathering information from a range of different sources to help identify weaknesses in security controls
-
Expert with security control design, development, implementation, and monitoring
-
Demonstrated experience across multiple information security domains preferred
Qualifications:
-
Bachelor's degree in Computer Science, Engineering or related field or equivalent work experience
-
CISA, CRISC, CISM, or CISSP certifications (one or more) preferred
-
Demonstrated advanced verbal and written communication skills
-
Excellent organization skills and be a self-motivated learner
What we offer:
- Hybrid working model (2 days in the office and 3 days working remotely).
- Stable employment with an employment contract, private medical care, and a benefits package including MultiSport and a benefits platform.
- Opportunity to work in an international environment and collaborate with experienced Grant Thornton experts and professionals from around the world.
- A culture based on teamwork, trust, and knowledge sharing.
- A well-structured onboarding program to support a smooth start and successful integration into your new role.
- Clear career development paths and access to learning and certification programs.
- Access to training platforms and tools that support professional growth.
- An inclusive workplace that welcomes people with disabilities.
- A modern office in Poznań, located in Malta Office Park.
- Fluency in Polish and English.
Jak przebiega rekrutacja?
-
Wybierz interesującą Cię ofertęZnajdź stanowisko, które Cię interesuje, na liście poszukiwanych przez nas profili:
-
ZaaplikujWyślij swoje CV w języku polskim w odpowiedzi na interesującą Cię ofertę.
-
Daj się poznać!Jeżeli pasujesz do profilu osoby, której poszukujemy, zaprosimy Cię na spotkanie online. W rozmowie weźmie udział rekruter oraz Twój przyszły menedżer. Porozmawiamy o Twoich dotyczasowych doświadczeniach i obecnej sytuacji zawodowej, a także o aspiracjach na przyszłość. Spodziewaj się pytań z obszarów merytorycznych, a jeśli stanowisko tego wymaga – to również krótkiej rozmowy po angielsku.
-
Wypatruj odpowiedziJeśli wszystko poszło dobrze, otrzymasz od nas ofertę współpracy. Jeśli nie – powiemy, co miało wpływ na naszą decyzję.
-
Witamy na pokładzie!Ustalimy dogodny dla obu stron termin i formę rozpoczęcia współpracy.
-
Is it possible to work remotely?We work in a hybrid model that combines the flexibility of remote work with the benefits of in-person collaboration. Regular presence in our Poznań office is important to us, typically 2-3 days per week. For more details about the working model, feel free to ask during the recruitment process.
-
What is the dress code at Grant Thornton?We ask that you follow specific guidelines depending on the business situation. When working independently—and provided there are no scheduled meetings with clients or business partners—a casual dress code applies; you can wear whatever is comfortable, such as a T-shirt, jeans, or a casual shirt. After all, hardly anyone sits at home in a suit and tie or a formal business suit unless they have to. However, if meetings are scheduled, your attire should be more formal and appropriate for the client. You will certainly receive detailed information about these guidelines before you start at GT, so you know what to expect.
-
Will I always receive feedback after a job interview?We always get back to candidates with feedback—regardless of the recruitment outcome—within a maximum of two weeks following the interview. This contact may be via phone or email. We also inform candidates if the recruitment process takes longer than expected. We strive to ensure our candidates always know the current status of their application.
-
What are the possible forms of cooperation?We offer employment based on a contract of employment (Umowa o Pracę). Details regarding the employment terms are discussed during the recruitment process.