IT Risk and Compliance Specialist

  • Katowice
  • Innergo Systems Spółka Z O.o.
Optional, Microsoft Active Directory, PowerShell, PythonYour responsibilities, Monitor user access to IT systems by performing the following: Semiannual access reviews, Termination validation procedures, IT Privilege access reviews;, Validate that access to critical functions within key applications is appropriately segregated (Segregation of Duties – SOD);, Work with system administrators to ensure that plans exist to recover applications and systems in the case of a disaster;, Assessing applications, vendors, and processes from Cybersecurity and Privacy perspective;, Work with the IT and Legal teams to ensure compliance with regulations (SoX, GDPR, DOL, etc);, Work with the IT organization to create policies, procedures, and standards;, Support the execution of the IT Risk Management process;, Maintain the global framework of IT Controls;, Establish effective communication processes with the business and regional IT teams to coordinate the global assessment of IT controls;, Integrally engage in projects making sure that they comply with O-I policies and security requirements;, Assist with independent vulnerability assessment and SoX audit processes;, Follow documented procedures and retain necessary audit documentation;, Participate in the incident response activities in accordance with established procedures.Bachelor’s degree or equivalent years of experience in information technology or related discipline;, Understanding of security protocols and standards;, Solid knowledge of information security principles and practices;, Organized, responsive, and highly thorough problem solver;, Detail oriented;, Demonstrated analytical capabilities;, Self-starter and strong collaboration skills;, Experience in effective communication with customers, employees, and management;, Have high integrity and be able to maintain the confidentiality of work performer;, Must be able to communicate in English – both written and verbal.Optional, 3 years of experience working in Information Technology/IT Risk and Compliance/IT GRC;, 3 years of experience working with IT general computer control evaluations, remediation, and with external auditors;, Intermediate knowledge of Microsoft Active Directory and Windows services;, Intermediate operational knowledge of SAP GRC;, Intermediate knowledge related to privacy assessment (GDPR) ;, Understanding of the industry’s control frameworks and leading practices;, Experience evaluating system security requirements;, Knowledge of system functions, security policies, technical security safeguards, and operational security measures;, Experience in communicating and presenting to a management-level audience;, Knowledge of industry-leading practices, security frameworks, policies, and standards;, Ability to determine priorities, makes discretionary decisions and determines when to notify management;, Ability to work well with people from many different disciplines with varying degrees of technical experience;, Scripting in PowerShell and/or Python,, Security Certifications (CISSP, CISM, CISA, CRISP, ITIL);, Ability to communicate in English – both written and verbal;, Attention to details.What we offer, Private medical care;, Life insurance;, Remote work opportunities;, Flexible working time;, Integration events.Benefits, private medical care, life insurance, remote work opportunities, corporate products and services at discounted prices, integration eventsWe are looking for a person who will be responsible for monitoring the IT controls environment at O-I. This includes evaluating log information, performing user access reviews, participating in the incident response process documenting, testing, and auditing processes for compliance with established policies and procedures in various locations around the world or at 3rd parties. The IT Risk and Compliance Specialist will also work with technical resources and other team leads to produce technical documentation and recovery plans for critical systems. The IT Risk and Compliance Specialist will also be involved in the implementation and cybersecurity assessment of new security solutions, participation in the creation and or maintenance of policies, standards, baselines, guidelines, and procedures as well as participating in vulnerability audits or independent assessments.The scope of implementations carried out by INNERGO:, LAN and WLAN networks, MPLS, SD WAN, Wi-Fi;, Video and teleconference systems;, Server and matrix platforms;, Data Center;, Delivery and service of Apple devices,, Implementation of cybersecurity systems., Outsourcing services of IT systems maintenance departments,, 5G and LTE private networks;, Connected City solutions;, Applications in no-code technology;, Electroo electric vehicle charging systems.INNERGO Systems Spółka z o.o., INNERGO is a company built on 100% Polish capital. We have been operating in the IT integrator market since 2009 and currently employ over 100 people., , Since the beginning of the company's operations, we have set ourselves the goal of implementing technologically advanced ICT integration projects, combining the offer of world-class manufacturers with a wide portfolio of our own services. We have played a key role in the digital transformation of many companies, implementing more than 2,000 projects, for clients from various industries.This is how we work,