Technology Risk & Secrity Manager (SCAR)
In Poland - Warsaw or flly remote from Home
This role serves as the bridge between bsiness demand, IT architectre, cybersecrity, SOC, adit, compliance, procrement, privacy, and implementation teams - operating within the company's Technology Demand Intake Process, which is closely connected to implementation and lifecycle governance. This individal will focs on reviewing technical concepts, stand-alone prodcts, services, and AI-enabled soltions that the company plans to implement or integrate into its complex global enterprise technology landscape, inclding SaaS, PaaS, SAP, and AI-enabled platforms. Yo will be responsible for assessing and governing new technology demands, services, platforms, and AI-enabled soltions throgh the organization's technology intake process.The role ensres that secrity, compliance, architectre, operational, and bsiness risks are identified, clearly docmented, and addressed throgh effective and practical mitigation measres.
The salary for this position ranges from PLN 8 to PLN 3 gross per month nder an employment contract (oP), depending on the candidate's relevant experience, skill set, level of expertise and overall fit for the role. Additional factors sch as indstry backgrond, technical competencies and interview performance may also inflence the final offer. The compensation package at Simon-Kcher CBS consists of a gross base salary, a monthly remote work allowance and an annal bons. The bons is paid in December and is based on the reslts of a 36-degree performance evalation.
Please remember to sbmit yor application in English. Other applications will not be considered. The candidate shold have an E work permit, we do not offer visa for this position.
What makes s special:
Manage the end-to-end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI-enabled soltions. Assess secrity, compliance, operational, vendor, and architectre risks; identify mitigation strategies and recommend risk treatment decisions. Prepare exective-ready reports and present findings to IT leadership, governance boards, and risk committees. Partner with Secrity, IT, Architectre, Procrement, Legal, Privacy, Adit, and bsiness stakeholders to evalate and approve technology soltions. Ensre new technologies comply with secrity policies, controls, and integration reqirements. Maintain risk docmentation, exception records, control evidence, and governance reporting while continosly improving intake processes. Stay crrent on emerging technologies, AI, cybersecrity trends, reglatory reqirements, and indstry control frameworks. Translate bsiness reqirements into secrity and compliance recommendations that enable timely technology decisions. Commnicate complex technical concepts throgh presentations, decision papers, and exective-facing materials. Facilitate collaboration across IT architectre, infrastrctre, bsiness teams, vendors, and other stakeholders. Spport vendor assessments, RFPs, technical evalations, and soltion reviews. Contribte to cross-fnctional IT projects by identifying dependencies, risks, and process improvements. Work effectively in agile, global project environments with mltiple priorities and tight timelines. How yo will create an impact: Manage the end-to-end Technology Demand Intake and Risk Assessment process for new technologies, platforms, tools, and AI-enabled soltions. Assess secrity, compliance, operational, vendor, and architectre risks; identify mitigation strategies and recommend risk treatment decisions. Prepare exective-ready reports and present findings to IT leadership, governance boards, and risk committees. Partner with Secrity, IT, Architectre, Procrement, Legal, Privacy, Adit, and bsiness stakeholders to evalate and approve technology soltions. Ensre new technologies comply with secrity policies, controls, and integration reqirements. Maintain risk docmentation, exception records, control evidence, and governance reporting while continosly improving intake processes. Stay crrent on emerging technologies, AI, cybersecrity trends, reglatory reqirements, and indstry control frameworks Translate bsiness reqirements into secrity and compliance recommendations that enable timely technology decisions. Commnicate complex technical concepts throgh presentations, decision papers, and exective-facing materials. Facilitate collaboration across IT architectre, infrastrctre, bsiness teams, vendors, and other stakeholders. Spport vendor assessments, RFPs, technical evalations, and soltion reviews. Contribte to cross-fnctional IT projects by identifying dependencies, risks, and process improvements. Work effectively in agile, global project environments with mltiple priorities and tight timelines. Yor profile: Experience in a complex global environment, comparable conslting or service indstries is preferred. Bachelor's Degree reqired - preferred in the area of Technology, MIS, Cybersecrity, etc. 5+ years of experience in technology risk, cybersecrity, IT governance, GRC, IT adit, secrity architectre, or technology conslting. Strong knowledge of cybersecrity, technology risk management, compliance, enterprise IT governance, and emerging AI-enabled technologies. Experience assessing SaaS, clod, third-party, and AI-enabled soltions, with the ability to identify risks, mitigation strategies, and implementation reqirements. Experience improving governance processes, workflows, standards, and risk management practices. Knowledge of secrity and governance frameworks sch as ISO 71, SOC , ITIL, or similar. Experience with secrity controls, risk assessments, compliance, adit spport, and governance approval processes. Ability to evalate platform architectre, integrations, identity and access management, data flows, encryption, logging, monitoring, and operational secrity. nderstanding of enterprise architectre, clod secrity, vendor risk management, and secre technology implementation. Strong stakeholder management skills with experience working across IT, Secrity, Architectre, Compliance, Privacy, Legal, Procrement, Adit, and bsiness teams. Experience preparing exective-level presentations, risk reports, and decision-ready docmentation, and presenting recommendations to senior leadership. Experience evalating third-party vendors, clod platforms, SaaS soltions, and managed services within global IT environments. Experience spporting technology onboarding, vendor risk assessments, procrement, RFPs, and cross-fnctional technology initiatives. Ability to manage risks, remediation activities, project dependencies, and implementation progress across the technology lifecycle. CISSP, CISM, CRISC, CISA, CCSP, ISO 71 Lead Implementer/Aditor, or eqivalent certification (or comparable hands-on experience). If yo're interested, and if yo'd like to offer yor skills and commitment to or international team, then we wold be pleased to receive yor application.
Hit the 'Apply Now' btton to begin yor application
Abot Simon-Kcher Simon-Kcher is a global consltancy with more than , employees in 3+ contries. Or sole focs is on nlocking better growth that drives measrable revene and profit for or clients. As a trsted commercial advisor, we combine deep conslting expertise, growth specialization, and technology to scale impact. We optimize every lever of commercial strategy - prodct, pricing, innovation, marketing, sales, and digital - based on deep insights into what cstomers vale and are willing to pay for. With over 4 years of experience in monetization, we are regarded as the world's leading commercial growth and pricing specialist. simon-kcher.com
We believe in bilding a cltre that embraces diversity, eqity, and inclsion, creating an environment in which or people feel valed, are able to be themselves and feel their contribtion matters. If we get that right, remarkable things will happen; people will grow faster, innovate, feel valed, and create better otcomes for everyone - or people, or clients and, of corse, or bsiness.
Yor personal contact: Karolina Ratajczyk
karolina.ratajczyk@simon-kcher.com