- Develop and maintain global ISO/IEC 27001 and TISAX conformance/compliance requirements documentation in support of local UL Solutions Statements of Applicability (SoAs), information securiy policies, procedures, processes, and controls.
- Collaborate with ISMS Managers to ensure local conformance/compliance with ISO/IEC 27001 and TISAX requirements, including legal, regulatory, and contractual obligations.
- Partner with Global Technology, Global Cybersecurity, and other key functional teams (e.g., Legal, Business Continuity) to advise on applicable ISMS control requirements and potential solutions to address ISO/IEC 27001 and TISAX conformance/compliance issues.
- Support locations in conducting information security risk assessments and treatment, providing advice and guidance to ensure a consistent and aligned approach across the organization.
- Support the development of global processes that enable conformance/compliance with ISO/IEC 27001 and TISAX requirements.
- Support continuous improvement initiatives led by ISMS Managers.
- Assist in resolving corrective actions managed by ISMS Managers, leveraging prior experience in managing corrective actions to provide effective support.
- Stay current with changes in ISO/IEC 27001, TISAX, and other relevant best practice standards and regulatory frameworks.
- Bachelor’s or Master’s degree in Information Security, Computer Science, Cybersecurity, Risk Management, or a related field.
- Minimum 5 years of experience in information security, IT compliance, or risk management roles, preferably within a TIC (Testing, Inspection, Certification) organization.
- Proven experience in implementing and maintaining ISO/IEC 27001 and TISAX-conformant/compliant ISMS.
- Preferred certifications: ISO/IEC 27001 or TISAX Lead Implementer.
- Strong understanding of risk management methodologies, processes, and tools (e.g., risk registers, threat modeling).
- Familiarity with other compliance frameworks such as NIST, SOC 2, GDPR, and NIS2.
- Knowledge of ISO/IEC 17025 is a plus.
- Demonstrated experience supporting ISO/IEC 27001/TISAX implementations, including contributing to the resolution of corrective actions and supporting continuous improvement initiatives led by ISMS Managers.
- Excellent analytical, organizational, and project management skills.
- Strong interpersonal and communication skills, with the ability to influence stakeholders at all levels.
- Ability to work independently and manage multiple priorities in a fast-paced environment.
- Deep knowledge and expertise in ISO/IEC 27001, TISAX, and related standards.
- Experience in risk assessment and treatment (control implementation).
- Solid understanding of information security and cybersecurity regulatory compliance (e.g., GDPR, NIS2).
- Awareness of information security and cybersecurity principles and practices.
- Ability to clearly communicate complex concepts and influence others to adopt new perspectives.
- Proven ability to facilitate internal meetings, negotiate effectively, and engage with Certification Bodies.
- Advanced project management and collaboration skills, with experience working across multiple disciplines and organizational levels.
- Strong prioritization skills, demonstrated through effective scheduling and delivery of multiple projects while maintaining high quality and customer satisfaction.
- Ability to operate effectively within a matrix organization.
- Excellent communication, interpersonal, networking, and presentation skills.
- Fluent in English.
- Open mindedness and ability quickly grasp new concepts and ideas.
- Lead internal and external teams to solve unique and/or complex problems.
- Utilize sophisticated analytical thought process to exercise judgement and identify innovative solutions.
- Persuasiveness to influence the acceptance and implementation of the developed conclusions and recommendations.
- Management of multiple projects while maintaining high quality and excellent customer service.
- Willing and able to travel to meet position responsibilities.
- Second language advantageous but not necessary, except where required based on assigned geographic area
Podobne oferty
Data dodania: 2026-01-17
Kierownik / Kierowniczka Działu Zarządzania Infrastrukturą Cyberbezpieczeństwa
Firma:
Poczta Polska S.A.
Lokalizacja:
mazowieckie / Warszawa
Miejsce pracy: możliwość pracy z każdego miejsca w kraju Rodzaj zatrudnienia: umowa o pracę Twoje zadania: kierowanie i koordynacja zespołu odpowiedzialnego za infrastrukturę cyberbezpieczeństwa (24/7/365), w tym rozwój kompetencji i ścieżek...
Więcej informacjiData dodania: 2026-01-14
Główny specjalista/główna specjalistka
Firma:
Urząd Komunikacji Elektronicznej w Warszawie
Lokalizacja:
mazowieckie / Warszawa
Warunki pracy Praca biurowa przy monitorze ekranowym w wymiarze powyżej 4 godzin dziennie Narzędzia pracy: komputer i sprzęt biurowy Budynek przystosowany dla osób z niepełnosprawnościami Praca przy naturalnym i sztucznym oświetleniu Praca w pokoju, który...
Więcej informacjiData dodania: 2026-01-12
Kierownik / Kierowniczka Operacji Reagowania na Incydenty CERT
Firma:
Klient portalu Praca.pl
Lokalizacja:
mazowieckie / Warszawa
Pełne zarządzanie operacyjne zespołem CERT oraz nadzór nad jego ciągłością działania w trybie 24/7/365. Kierowanie kluczowymi działaniami podczas incydentów wysokiej krytyczności, w tym podejmowanie decyzji o eskalacji do kierownictwa, regulatorów lub...
Więcej informacji