Information Security Assessment Lead @

21 hours ago


Warszawa, Mazovia, Czech Republic PepsiCo Full time

What will you bring to the team?

  • You have proven expertise in applying security frameworks such as NIST 800-53, ISO 27002, CIS, and OWASP.
  • You have strong analytical skills to interpret security scan and penetration test results, influencing the drive for remediation.
  • You're experienced automating risk assessments using ServiceNow and reporting, with familiarity using Power BI.
  • You're experienced in threat modeling and cloud platforms such us: Azure, AWS, Alibaba, ensuring robust defenses across diverse environments.
  • You have excellent communication and influencing skills, capable of educating stakeholders and building a strong security culture.
  • You have a track record of integrating security into the project lifecycle, utilizing Agile and DevSecOps practices.
  • You have proactive, problem-solving mindset, dedicated to continuous improvement and staying ahead of emerging threats.

Due to our expanding global business and the increasing scope of our information security assessors, we're seeking an exceptional individual to join our Information Security Assessment (ISA) Lead Team, managed by Mohammed. This role is within the Risk Management Leadership Tower, part of the Governance, Risk, and Compliance (GRC) organization of InfoSec.

Your primary responsibility will be to conduct security risk assessments, identify cyber risks, and ensure our business solutions are secure and compliant before deployment. You will align business solutions with our Information Security Policy and Standards, aiding in the effective management and mitigation of risks.

Why should you join this team?

  • You will collaborate with a highly skilled global team and gain exposure to cutting-edge security technologies, products, and frameworks.
  • You will play a pivotal role in evaluating and enabling key businesses to securely lead in the market within a multinational environment.

What kind of manager is Mohammed?

Working with Mo and the ISA Lead Team means joining a team that values innovation, creativity, and collaboration. Our leadership promotes open communication, supports professional growth, encourages calculated risks, and fosters a culture of continuous learning to solve complex security challenges.

How do we work and what do we offer?

  • We work in a hybrid model (2 days from the office in Warsaw, Plac Konesera, 3 days from home)
  • The most important benefits of this position: annual bonus, private healthcare, life insurance, Multisport, private pension plan, employee assistance program, company car or equivalent
,[You're reviewing, assessing, and evaluating technology solutions to ensure compliance with our security policy, standards, and industry standards., You're managing the end-to-end process of security assessments, your queue, meetings, while meeting SLAs and ensuring cyber risks are evaluated and communicated to customers., You're translating identified security risks in ISA reviews for both technical and non-technical stakeholders, including security scan and penetration test results, and privacy concerns., You're proactively identifying and prioritizing potential security risks in customer solutions., You're collaborating across InfoSec, IT, and Business teams to resolve security challenges and educate stakeholders on minimizing cyber risks., You're levaraging ServiceNow, Power BI, and other tools to automate processes, tracking metrics, and using data to drive security decisions., You're continuously monitoring and improving processes, integrating Agile and DevSecOps methodologies, and staying up-to-date with emerging threats.] Requirements: Security, NIST, ISO, CIS, OWASP, Cloud platform, AWS, Azure, Analytical skills, ServiceNow, Alibaba Additionally: International projects, Private healthcare, Company car, Multisport, Modern office, No dress code, Free snacks, Free coffee.

  • Warszawa, Mazovia, Czech Republic DENTONS BUSINESS SERVICES EMEA Full time

    3+ years in Microsoft Infrastructure or Security Engineering roles.Strong interest in cybersecurity with a solid engineering background.Automation experience (e.g., PowerShell).Securing Windows platforms, Microsoft 365, and Azure.Knowledge of OS/cloud attack vectors, system hardening, and secure privilege escalation.Project delivery from initiation to...


  • Warszawa, Mazovia, Czech Republic PepsiCo Full time

    At PepsiCo, we're seeking a highly skilled Cyber Security Risk Management Specialist to join our Information Security Assessment (ISA) Lead Team. This role is part of the Governance, Risk, and Compliance (GRC) organization within InfoSec.Main Responsibilities:Conduct security risk assessments to identify cyber risks and ensure business solutions are secure...


  • Warszawa, Mazovia, Czech Republic ITDS Full time

    As a key member of ITDS's team, you will contribute to strengthening the organization's IT risk posture and ensuring that information systems meet security standards.About ITDSWe are an innovative company involved in various professional IT projects for international companies in the financial industry in Europe. We offer a dynamic environment for ambitious...


  • Warszawa, Mazovia, Czech Republic PepsiCo Full time

    What will you bring to the team?  Bachelor's degree in computer science, engineering, or a related field,6-7 years of recent and relevant experience, along with 2+ years of directly related software  engineering or development experience.Extensive expertise in application security and vulnerability management, encompassing exploit  development, security...


  • Warszawa, Mazovia, Czech Republic PepsiCo Full time

    Job DescriptionWe are seeking a highly skilled Chief Application Security Architect to join our team at PepsiCo. In this role, you will be responsible for optimizing security tools, improving signal-to-noise ratios, and ensuring that findings are prioritized and actionable without impeding development speed.About the TeamPepsiCo's Global Application Security...


  • Warszawa, Mazovia, Czech Republic DENTONS BUSINESS SERVICES EMEA Full time

    About the RoleDentons Business Services EMEA is seeking a skilled Cloud Security Specialist to join our team. This role will be responsible for designing, configuring, and maintaining security controls for cloud and hybrid infrastructure.Key ResponsibilitiesSelect and deploy technical and procedural controls to meet specific security requirementsCo-define...


  • Warszawa, Mazovia, Czech Republic Devire Full time

    We are looking for a seasoned Chief Security Architect to join our client's team and contribute to strengthening the software supply chain.This role focuses on ensuring that deployed code meets the highest security standards by combining third-party security tools with internally developed systems. We enhance the security of various codebases, including...


  • Warszawa, Mazovia, Czech Republic Devire Full time

    At Devire, we are committed to excellence in recruitment, outsourcing, and employer branding services. As a leading international company, we have been representing top employers on the European market for over 30 years, conducting comprehensive projects to find senior talent and implementing innovative IT solutions.We are seeking an experienced Senior...


  • Warszawa, Mazovia, Czech Republic T-Mobile Polska Full time

    About UsT-Mobile Polska is a leading telecommunications company in Poland, providing innovative solutions to customers across the country.Job DescriptionWe are seeking an experienced Data Platforms Technical Lead - Cloud Architect to join our team. As a key member of our data platforms infrastructure team, you will be responsible for designing, developing,...


  • Warszawa, Mazovia, Czech Republic T-Mobile Polska Full time

    Extensive experience (4+ years) in designing and delivering cloud or hybrid data platformsStrong background in data engineering and analyticsProficiency in cloud technologies (AWS, GCP)Experience with Data Warehousing, Big Data technologies and NoSQL databasesStrong leadership and communication skillsAbility to translate complex technical concepts for...

  • Engineering ​Lead

    5 days ago


    Warszawa, Mazovia, Czech Republic T-Mobile Polska Full time

    Ideally, you have over 2+ years of experience as a software engineering manager, leading teams responsible for high-scale production services.You possess at least 7+ years of professional software development experience, contributing to the development of full-stack  distributed systems.You excel at aligning and executing new technical ideas,...


  • Warszawa, Mazovia, Czech Republic Devire Full time

    Company OverviewDevire is a renowned international company specializing in recruitment, outsourcing, and employer branding services. With over 30 years of experience, we represent leading employers on the European market, conducting comprehensive projects of searching for managers and specialized staff, implementing the latest solutions in the area of IT...


  • Warszawa, Mazovia, Czech Republic AVENGA Full time

    **Company Overview**AvenGA is a dynamic and innovative company seeking an experienced Lead Developer to join our team.**Job Description**We are looking for a highly skilled and motivated developer who can lead the development of complex frontend applications using Angular. The ideal candidate will have extensive experience in frontend development, micro...


  • Warszawa, Mazovia, Czech Republic Devire Full time

    Devire is an international company with a strong presence in the European market, specializing in recruitment, outsourcing, and employer branding services. For over 30 years, we have been representing leading employers and implementing innovative solutions in the IT sector.We are seeking a skilled Java Developer to join our dynamic technology team within the...

  • Customer Trust Expert

    5 hours ago


    Warszawa, Mazovia, Czech Republic Asana Full time

    6+ years of experience working with security compliance frameworks and audits (e.g., SOC 2, ISO 27001, FedRAMP, etc.).Strong knowledge of customer security expectations for B2B SaaS organizations.Proven ability to drive operational process improvements and develop metrics for tracking success.Excellent communicator and influencer, with the ability to...


  • Warszawa, Mazovia, Czech Republic monday Full time

    Strong proven technical skills and a passion for developing products that people love and use everyday.Technical leadership experience (Architect/ tech lead or similar roles)Experience building user facing products on the web or distributed infrastructure in large scaleExperience in Full-stack development.Understanding of product and a passion for building...


  • Warszawa, Mazovia, Czech Republic AVENGA Full time

    Highly competent with SIEM Engineering and Detection EngineeringGood understanding and knowledge of common industry cyber securityframeworks, standards and methodologies, including; OWASP, MITRE ATT&CK and NIST is essentialAble to work in fast paced environmentsGreat written and oral communication skillsPassion for security and love to learn and grow...

  • IT&D Controls Manager

    5 hours ago


    Warszawa, Mazovia, Czech Republic Reckitt Full time

    At least 5 years of experience in IT controls, IT audit, or a related field within the 1LOD.Strong understanding of IT General Controls (ITGC) and IT control frameworks such as COBIT/NIST/ISO 27001/SOX.Proven experience in hands-on remediation of IT control deficiencies and managing risk acceptance.SAP systems experience is essential, with knowledge of...


  • Warszawa, Mazovia, Czech Republic Reckitt Full time

    Bachelor's degree in Computer Science, Information Technology, or a related field. Master's degree is a plus.Proven experience (7+ years) in a platform or cloud engineer role overseeing Azure-based solutions, including platform engineering on MS Azure cloud platform.In-depth knowledge of Azure services and infrastructure components.Experience with CI/CD...


  • Warszawa, Mazovia, Czech Republic Devire Full time

    10+ years of experience in software engineering, development, or similar roles.Broad knowledge of multiple programming languages, with deep expertise in at least one of Golang, Java, or Python.Familiarity with Linux, Docker, Kubernetes, Terraform, and AWS.Understanding of networking protocols (TCP, UDP, ICMP, ARP, DNS, TLS, HTTP, SSH, etc.).Experience with...