The Information Security Manager will lead the information security strategy, promote a security-first culture, and ensure adherence to security policies and controls. They will also manage security incidents, conduct risk assessments, and collaborate with stakeholders to protect critical assets and data.
Ciklum is looking for an Information Security Manager to join our team full-time in Poland.
We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges. With a global team of over 4,000 highly skilled developers, consultants, analysts and product owners, we engineer technology that redefines industries and shapes the way people live.
About the role:
As an Information Security Manager, become a part of a cross-functional development team engineering experiences of tomorrow.
Responsibilities:
- As an Information Security Manager (ISM) you will promote a security first culture at the project
- You will contribute to the delivery of an information security strategy to address the evolving business risk and empower the Domain to deliver the prioritised roadmap
- You will lead the collaboration with stakeholders to communicate and embed secure ways of working with regular cadence and engagement
- This will include protecting the client's brand and its customers, detecting and responding to incidents, strengthening our defences, reducing the attack surface, proactively highlighting risks to the business and promoting security awareness as second nature
- You will drive adoption of and adherence to security policies, standards, and controls through the provision of expert advice and guidance
- Protect our most critical assets and ensure appropriate assurance and rigorous testing is in place. You will ensure local security incidents are managed effectively, and that lessons learned, and audit findings are remediated
- You will have come from a technical background and having good knowledge of security in AWS Cloud environments having held a technical role
- Ensure effective security operations (e.g. vulnerability scanning, patching)
- Protect the integrity, availability, authenticity, non-repudiation and confidentiality of information and data in storage and in transit. Manage risk in a pragmatic and cost-effective manner to ensure stakeholder confidence
- You will report on the overall effectiveness of the security programme on the Domain against defined key performance indicators and drive continuous improvement
- Our information security team works in collaboration with business and IT teams across our many businesses
- You will build strong working relationships influence others to do the right thing to Protect our Smile
- Security is part of everyone’s job. We practise secure behaviours first in everything we do
Requirements:
- Demonstrable experience of leading and information security capability for a large business unit
- Good understanding of security within agile development processes, and in Amazon Web Services
- Adept understanding of security operations and security incident management in Cloud and OnPrem environments
- Good experience in implementing ISMS in a large organisation
- AWS Cloud Fundamental or Practitioner certification preferable
- ISO27001 Lead Implementer, COMPTIA Security+, CISMP/CISSP/CISM/CISA certified preferred
- Good understanding of the international regulatory context, particularly data privacy
- Good understanding of standards and frameworks such as ISO, NIST, PCIDSS, OWASP and ITIL
- Excellent planning and organisation skills to determine effective course of action
- Strong communication skills. Experienced at gaining commitment from stakeholders to reach broader goal to reduce information security risks
- Excellent interpersonal and relationship skills to work with technical and non-technical colleagues around the world
- Goal orientated to maintain focus on agreed Information Security objectives and deliverables
- Problem solving skills to identify creative and elegant solutions to support Information Security GRC activities and overall objectives
- A logical thinker, and a team player with ability to think positively in a problem situation
- Strong commercial acumen when making proposals, taking actions or help support decision making
- Good organisational structure awareness. Able to identify the decision makers and influencers
- Ability to understand the needs, objectives, and constraints of those in other teams
What’s in it for you?
- Strong community: Work alongside top professionals in a friendly, open-door environment
- Growth focus: Take on large-scale projects with a global impact and expand your expertise
- Tailored learning: Boost your skills with internal events (meetups, conferences, workshops), Udemy access, language courses, and company-paid certifications
- Endless opportunities: Explore diverse domains through internal mobility, finding the best fit to gain hands-on experience with cutting-edge technologies
- Flexibility: Enjoy flexibility – full remote working possibilities
- Care: We've got you covered with company-paid premium medical package through Luxmed
- Benefits: Access the MyBenefit cafeteria platform, allowing you to choose perks that best suit your lifestyle and needs
About us:
At Ciklum, we are always exploring innovations, empowering each other to achieve more, and engineering solutions that matter. With us, you’ll work with cutting-edge technologies, contribute to impactful projects, and be part of a One Team culture that values collaboration and progress.
With delivery centers in Wrocław and Gdańsk, our 300+ professionals in Poland drive forward-thinking solutions for global clients. Join a community where collaboration sparks innovation—and your impact reaches millions.
Explore, empower, engineer with Ciklum!
Interested already? We would love to get to know you! Submit your application. We can’t wait to see you at Ciklum.
#LI-KZ1