Białystok, Bialystok, Podlaskie Voivodeship, Polska
WHITESTONE TALENT SOLUTIONS sp. z o.o.
14. 5. 2025
Informacje o stanowisku
technologies-expected :
AWS
GCP
Azure DevOps
communication
technologies-optional :
CISSP
CISA
CISM
CCSP
about-project :
Were looking for a Cybersecurity Specialist to take the lead in the security compliance initiatives for a company in the US — helping meet and maintain high standards such as SOC 2, ISO 27001, and other critical frameworks. You’ll work closely with engineering, product, and leadership to ensure our systems are secure by design as the project scales.
This is a high-impact role for someone who values autonomy, collaboration, and real influence across the business.
responsibilities :
Own and manage our SOC 2 certification process — including gap assessments, audit preparation, documentation, and ongoing reporting.
Design, implement, and maintain security policies, standards, and procedures that align with ISO 27001, NIST, GDPR, and other frameworks.
Work closely with engineers to build secure systems and cloud infrastructure (AWS, GCP, Azure).
Lead security risk assessments, vulnerability management programs, and incident response plans.
Conduct internal audits and collaborate with external auditors and consultants.
Educate internal teams on security best practices and compliance requirements.
Continuously monitor and improve the company’s security posture and readiness.
requirements-expected :
3–5+ years of professional experience in cybersecurity, risk management, or compliance roles.
Proven, hands-on experience leading SOC 2 audits and managing the certification process.
Familiarity with compliance frameworks: ISO 27001, NIST, PCI DSS, GDPR, etc.
Technical understanding of cloud security and secure infrastructure design (AWS, GCP, Azure).
Experience conducting security assessments, working with auditors, and leading policy implementation.
Strong cross-functional communication skills — able to translate security goals into business-friendly language.
Relevant certifications are a plus: CISSP, CISA, CISM, CCSP, or similar.
Must be based in Poland — this role is remote-first but limited to candidates legally residing and working in Poland.
offered :
Own and shape the company’s security architecture and compliance roadmap.
Work with a smart, ambitious team that values quality, curiosity, and clear thinking.
Remote-friendly culture with trust, flexibility, and autonomy.
A role that has real influence across teams — not just box-checking, but building systems that matter.