For our client – European Agency in Warsaw, Poland – On Site
We are looking for Senior Cybersecurity Risk Manager (CSRM)
Position Overview
The Cybersecurity Risk Manager (CSRM) is a senior-level role responsible for defining, implementing, and maintaining cybersecurity risk management practices across the organisation. The role focuses on identifying, assessing, and mitigating risks related to ICT systems, ensuring compliance with relevant standards, and enabling informed decision-making by stakeholders.
This position requires strong expertise in cybersecurity frameworks, threat analysis, and risk governance in complex environments.
Key Responsibilities
- Develop and implement the organisation’s cybersecurity risk management strategy
- Maintain and manage a comprehensive inventory of organisational assets
- Identify, analyse, and assess cybersecurity threats and vulnerabilities affecting ICT systems
- Define and analyse threat landscapes, including attacker profiles and potential attack scenarios
- Conduct risk assessments and recommend risk treatment strategies, including mitigation, avoidance, and risk-sharing options
- Design and evaluate security controls to reduce cybersecurity risks to acceptable levels
- Monitor and test the effectiveness of implemented controls and risk mitigation measures
- Ensure risks remain within acceptable tolerance levels aligned with organisational objectives
- Lead and maintain the full cybersecurity risk management lifecycle (assessment, treatment, monitoring, reporting)
- Communicate risk insights, reports, and recommendations to executives and stakeholders
Required Profile & Qualifications
Education & Experience
-
- Minimum education level: EQF Level 7 (Master’s degree or equivalent)
- Minimum 9 years of relevant IT experience
- Minimum 6 years of experience in a similar cybersecurity risk management role
-
Certifications
Candidates must hold at least 4 of the following certifications (or equivalent):- [1] CISSP (Certified Information Systems Security Professional)
- [2] CISA (Certified Information Systems Auditor)
- [3] CISM (Certified Information Security Manager)
- [4] GSNA (GIAC Certified Systems and Network Auditor)
- [5] GCCC (GIAC Certified Critical Controls)
- [6] ISO 27001 Lead implementer
- [7] ISO 27001 Lead Auditor
- [8] ISO 27005 Risk Manager
- [9] CAP ((ISC)2 Certified Authorization Professional)
- [10] CRISC (ISACA Certified in Risk and Information Systems Control)
- [11] CISSP-ISSMP ((ISC)2 Certified Information Systems Security Management Professional)
- [12] GIAC Certified ISO-27000 Specialist
Core Knowledge & Expertise
- Advanced knowledge of cybersecurity risk management frameworks, standards, and methodologies (e.g., ISO 27001, ISO 27005)
- Strong understanding of cyber threats, vulnerabilities, and threat taxonomies
- Experience in performing risk assessments, asset classification, and vulnerability analysis
- Knowledge of security controls, compliance requirements, and regulatory frameworks
- Understanding of risk treatment strategies and risk-sharing mechanisms
- Familiarity with monitoring and evaluating control effectiveness
- Ability to promote and build a risk-aware culture across the organisation
Key Skills
- Strong analytical and risk assessment capabilities
- Ability to consolidate and improve organisational risk and quality practices
- Excellent communication, reporting, and stakeholder management skills
- Ability to present complex risk scenarios to both technical and non-technical audiences
- Capability to design and manage risk mitigation and risk-sharing strategies
Specific Technical Requirements
- Experience conducting Business Impact Assessments (BIA)
- Experience with GRC tools (ServiceNow preferred)
- Knowledge of data protection and compliance documentation
- Experience with threat modelling tools and techniques
- Experience in DevSecOps / threat modelling for DevOps environments
- Knowledge of Zero Trust Architecture design principles
- Experience securing Software Development Lifecycle (SDLC)
- Expertise in Directory Services security controls
Work Environment & Contract Details
- Location: Warsaw, (on-site, 100%)
- Contract Duration: Initial 12 months (extendable up to 48 months total)
- Start Date: From 01/08/2026 (latest within 3 months of award)
-
Language Requirements
English proficiency at CEFR Level C1 or higher
Ideal Candidate Profile
The ideal candidate is a highly experienced cybersecurity professional with a strong background in risk management, capable of operating in a regulated, high-security environment. The candidate should demonstrate a combination of technical expertise, strategic thinking, and strong communication skills to support decision-makers and ensure robust cybersecurity governance.
Service delivery: On-Site