Cybersecurity Auditor
About the Role We are seeking a highly skilled Cybersecurity Auditor to evaluate client IT infrastructure, identify security gaps, and ensure robust protection against cyber threats.
Key Responsibilities
Plan and execute comprehensive technical and operational cybersecurity audits.
Assess the effectiveness of existing security controls, IT risk management processes, and incident response plans.
Ensure full organizational alignment with internal security policies and external EU regulatory mandates.
Generate detailed audit reports with actionable remediation strategies for stakeholders.
Regulatory & Framework Expertise (Strictly Required)
EU Legislation: In-depth knowledge of the new NIS2 Directive (Network and Information Security), DORA (Digital Operational Resilience Act), and ongoing GDPR compliance.
European Standards: Familiarity with the upcoming Cyber Resilience Act (CRA) requirements.
Global Frameworks: Proven expertise in auditing against ISO/IEC 27001:2022, NIST Cybersecurity Framework (CSF 2.0), and SOC 2 standards.
Required Certifications
Must hold at least one (preferably more) of the following active industry certifications:
CISA (Certified Information Systems Auditor)
ISO/IEC 27001 Lead Auditor
CISM (Certified Information Security Manager)
CISSP (Certified Information Systems Security Professional)
CRISC (Certified in Risk and Information Systems Control)
Qualifications
3+ years of proven experience in IT/Cybersecurity auditing, compliance, or risk management.
Experience in conducting IT/Cybersecurity audits in Poland
Strong technical understanding of cloud security, network architecture, and data encryption.
Experience participating in tenders.
Excellent analytical and problem-solving skills.
Fluent English (B2/C1 minimum); knowledge of Polish is a strong advantage.
Location: Poland (Hybrid / Remote)
Employment Type: Project base