IT Risk Consultant with European languages
Katowice, Śląskie, Polska, 40-202Key offer highlights
Looking for experts - senior/expert
Remote work - no commuting
Full-time
Description
Digital Risk - IT Risk & Compliance Consultant Location: Katowice - 2 days in office / 3 days remote Let us introduce you the job offer by EY GDS Poland, part of EY’s global integrated service delivery network. At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help build a better working world. The opportunity As an IT Risk & Compliance Consultant in Digital Risk at EY GDS Poland you will join a high-performing, international team delivering IT regulatory compliance, cybersecurity maturity and IT control framework services to leading global clients. You will translate regulatory, sector and framework requirements into practical IT and security controls, supporting organizations in designing, assessing and enhancing their compliance and risk management capabilities across multiple frameworks and jurisdictions. What we look for We are looking for proactive and detail-oriented professionals who can translate complex regulatory requirements into practical controls, while supporting clients in building effective, scalable and evidence-driven compliance and risk management frameworks.
What we offer
EY Global Delivery Services (GDS) is a dynamic and truly global delivery network. We work across nine locations – Argentina, Hungary, India, the Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom – and with teams from all EY service lines, geographies and sectors, playing a vital role in the delivery of the EY growth strategy. From accountants to coders to advisory consultants, we offer a wide variety of fulfilling career opportunities that span all business disciplines. In GDS, you will collaborate with EY teams on exciting projects and work with well-known brands from across the globe. We’ll introduce you to an ever-expanding ecosystem of people, learning, skills and insights that will stay with you throughout your career.
Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
Ideally, you’ll also have
Experience in cyber maturity assessments or security benchmarking
Understanding of risk taxonomy, control libraries and remediation planning
Experience working in regulated industries or multi-jurisdiction environments
Experience with policy drafting, governance models and executive reporting
Experience profile:
Background in IT risk, cybersecurity, compliance, audit or advisory
Past experience in at least one of the following industries: banking, payments, financial services, healthcare, pharma, retail, e-commerce, energy, utilities, transport, telecom or critical infrastructure sectors
Experience with regulatory reviews, certifications or compliance programs is a strong advantage
Certifications:
At least one of the following certifications: ISO 27001, ISO 27005, ISO 31000
Additional certifications such as HITRUST, COBIT or ITIL are an advantage
Skills and attributes for success
Strong analytical and problem-solving skills with attention to detail
Your key responsibilities
As a Consultant, you will contribute to regulatory compliance, cyber maturity and framework implementation engagements. Your responsibilities will include:
Supporting design and review of IT regulatory and compliance frameworks across ISO 27001, NIST CSF, PCI DSS, HIPAA, HITRUST, GDPR, COBIT, ITIL
Performing cyber / IT maturity assessments, gap assessments and control mapping, including development of remediation roadmaps
Assisting with ISO 27001 programs, including ISMS scoping, risk assessment, Statement of Applicability, control implementation and audit readiness
Supporting PCI DSS assessments, including review of cardholder data environments, security controls and evidence preparation
Contributing to HIPAA / HITRUST and regulated-data compliance projects in healthcare and life sciences environments
Drafting policies, standards, governance frameworks, RACI models and senior management reports
Identifying control gaps and supporting remediation planning and execution
Collaborating with stakeholders across IT, security, compliance and business teams to deliver high-quality, audit-ready documentation
To qualify for the role, you must have
3–5 years of relevant experience in IT risk, cybersecurity, compliance or assurance
A university degree in Information Technology, Computer Science, Cybersecurity or a related field
English working proficiency (B2 and above)
Working proficiency (B2 and above) in at least one additional language: French, German, Spanish, Dutch or Italian
Working experience in at least one of the following areas:
ISO 27001 implementation or audit
PCI DSS or payment security assessments
HIPAA / HITRUST or healthcare compliance
IT regulatory compliance or external assurance engagements
Understanding at least one of the following frameworks or domains:
ISO 27001 / ISMS
NIST CSF or NIST 800-53
PCI DSS / payment security
GDPR / data protection
COBIT, ITIL
DORA, NIS2
Ability to interpret regulatory requirements and translate them into practical, risk-based controls
Strong communication skills with the ability to explain compliance and risk topics to business and technical stakeholders
Structured approach to documentation, policy design and reporting
Proactive mindset and willingness to work across multiple frameworks and regulatory environments
Confident to deal with senior level contacts, internally and externally
Able to effectively summarize and conclude on work, applying appropriate documentation standards
Able to effectively prioritize and execute tasks in a high-pressure environment