Threat and Control Assessment Consultant
Workplace: Kraków / remote
Why us?
Your challenges
- Perform effective threat and control assessments of services within our internal, external and cloud estate
- Liaise with Developers, Architects and other Technical Leads to understand the end to end service and identify where there are any control gaps
- Understand the Business requirements, evaluate potential products / solutions and provide technical recommendations
- Be „hands on” with technology and contribute to the design, development and the support of projects with security recommendations
- Identify threats across the IT estate; including applications, databases, network and other infrastructure components
- Engage with other Cybersecurity teams, senior management and members of the Business when confronted with potential security issues
- Contribute to process, procedures and tool identification / development
- Stay up to date with industry new trends and best practices
Requirements
Mindset
- An inquisitive approach, always asking how to achieve goals in a smarter and more effective way
- Positive and professional attitude, team player, flexible and adaptable, embraces change
Good Risk and Controls understanding
- Knowledge and exposure of Risk and Control Management
- Ability to understand and assess both threats, controls and vulnerabilities, articulating these to both technical and business stakeholders
- Desirable to have one or more industry-recognised cybersecurity-related certifications including CISSP, CRISC, CISM or Cloud Security Certifications
Strong Technical background
- Proven experience in general security concepts and principles
- Hands on experience with threat modelling and strong technical understanding and experience of assessing vulnerabilities and identifying weaknesses in diverse
enterprise IT assets - Strong understanding of applications design and architecture
- Knowledge and experience with network, host and application security practices
- Good working knowledge of one or more of the Cloud Service Providers – AWS, GCP or Azure
- Strong understanding of Software Development Life Cycle (SDLC) with a focus on security
- Experience in continuous improvement and process optimisation
- Understanding of emerging technologies and corresponding security threats
Strong stakeholder management and communications skills
- Experience of working in international and diverse environments
- Experience in engaging with business, technology, regional and regulatory stakeholders
- Ability to communicate to key stakeholders – effectively translating technical gaps into
business risk
Ability to complete tasks independently to a high quality standard
- Self-motivated individual with strong analytical and problem solving skills
- Experience within fast-moving, complex and demanding corporate environments and able to provide appropriate direction to the team whilst dealing with ambiguity and
change
We offer
- A full-time contract (B2B also possible)
- Stable and long-term cooperation
- Well-defined career path at the European leader in engineering & IT consulting
- Participation in company conferences, trainings, workshops, integration meetings, etc.
- Certification and training opportunities
- Opportunity to relocate and work in different ALTEN Polska branches
- After completion of the project, opportunity to engage in a subsequent one within the company.
- Introduction and cooperation with dedicated Business Development Manager
- Work in company with #GreatPlaceToWork Certificate
Benefits
- Medicover medical care
- Medicover dental care
- Medicover Benefits platform / Medicover Sport card
- Employee referral program
- Layette for a newborn employee’s child
- Group life insurance
- Pension scheme
Do not hesitate and join our team!
Apply now!
Additional information
Please, include following in your CV:
„I agree to the processing of personal data provided in this document for executing this and future recruitment processes by ALTEN Polska Spółka z o.o., ul. Grzybowska 87, 00-844 Warszawa, pursuant to the Personal Data Protection Act of 10 May 2018 (Journal of Laws 2018, item 1000) and in agreement with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)”.
Employment or B2B contract