.
IT Risk & Compliance Analyst @ Galderma
  • Kraków
IT Risk & Compliance Analyst @ Galderma
Kraków, Kraków, Lesser Poland Voivodeship, Polska
Galderma
12. 12. 2025
Informacje o stanowisku

Galderma is the emerging pure-play dermatology category leader, present in approximately 90 countries. We deliver an innovative, science-based portfolio of premium flagship brands and services that span the full spectrum of the fast-growing dermatology market through Injectable Aesthetics, Dermatological Skincare and Therapeutic Dermatology. Since our foundation in 1981, we have dedicated our focus and passion to the human bodys largest organ - the skin - meeting individual consumer and patient needs with superior outcomes in partnership with healthcare professionals. Because we understand that the skin, we are in shapes our lives, we are advancing dermatology for every skin story.

We look for people who focus on getting results, embrace learning and bring a positive energy. They must combine initiative with a sense of teamwork and collaboration. Above all, they must be passionate about doing something meaningful for consumers, patients, and the healthcare professionals we serve every day. We aim to empower each employee and promote their personal growth while ensuring business needs are met now and into the future. Across our company, we embrace diversity and respect the dignity, privacy, and personal rights of every employee.

At Galderma, we actively give our teams reasons to believe in our bold ambition to become the leading dermatology company in the world. With us, you have the ultimate opportunity to gain new and challenging work experiences and create an unparalleled, direct impact.

We’re looking for an IT Risk & Compliance Analyst to help shape and secure our global IT landscape.

In this role, you’ll work across departments to identify IT risks and policy deviations, assess vulnerabilities, and drive mitigation strategies. You’ll take ownership of risk management frameworks, produce actionable dashboards and reports, and ensure compliance with leading regulations like GDPR, HIPAA, and ISO standards. This is your chance to work hands-on with ServiceNow GRC and make a visible impact on a truly global scale.

What we offer in return:

  • You will be working for an organisation that embraces diversity & inclusion and believe we will deliver better outcomes by reflecting the perspectives of our diverse customer base.
  • You will receive a competitive compensation package with bonus structure and extended benefit package.
  • You will be able to work in a hybrid work culture.
  • You will participate in feedback loops, during which a personalized career path will be established.
  • You will be joining a growing company that believes in ownership from day one where everyone is empowered to grow and to take on accountability.

Next Steps:

  • If your profile is a match, we will invite you for a first virtual conversation with the recruiter.
  • The next step is a virtual conversation with the hiring manager.
  • The final step is a panel conversation with the extended team.

Our people make a difference

At Galderma, you’ll work with people who are like you. And people that are different. We value what every member of our team brings. Professionalism, collaboration, and a friendly, supportive ethos is the perfect environment for people to thrive and excel in what they do.


Location: 3 days/week in the Krakow office

Skills & Qualifications:

  • Minimum 3 years of experience in IT risk management, ideally in the pharmaceutical or healthcare sector.
  • Experience participating in TPRM (Third-Party Risk Management) activities or internal control assessments on applications level.
  • Working knowledge of tools like ServiceNow, or similar for incident handling/risk management and vulnerability management.
  • Ability to support risk assessments and compliance checks on TPRM or application level.
  • Hands-on experience with ServiceNow Integrated Risk Management (IRM).
  • Understanding of regulatory frameworks such as GDPR, GxP, HIPAA, ISO 27001, NIST.
  • Excellent analytical and problem-solving skills with a structured, detail-focused mindset.
  • Strong communicator, able to collaborate effectively across global and cross-functional teams.
  • Fluent in English (written and spoken).

Galderma is the emerging pure-play dermatology category leader, present in approximately 90 countries. We deliver an innovative, science-based portfolio of premium flagship brands and services that span the full spectrum of the fast-growing dermatology market through Injectable Aesthetics, Dermatological Skincare and Therapeutic Dermatology. Since our foundation in 1981, we have dedicated our focus and passion to the human bodys largest organ - the skin - meeting individual consumer and patient needs with superior outcomes in partnership with healthcare professionals. Because we understand that the skin, we are in shapes our lives, we are advancing dermatology for every skin story.

We look for people who focus on getting results, embrace learning and bring a positive energy. They must combine initiative with a sense of teamwork and collaboration. Above all, they must be passionate about doing something meaningful for consumers, patients, and the healthcare professionals we serve every day. We aim to empower each employee and promote their personal growth while ensuring business needs are met now and into the future. Across our company, we embrace diversity and respect the dignity, privacy, and personal rights of every employee.

At Galderma, we actively give our teams reasons to believe in our bold ambition to become the leading dermatology company in the world. With us, you have the ultimate opportunity to gain new and challenging work experiences and create an unparalleled, direct impact.

We’re looking for an IT Risk & Compliance Analyst to help shape and secure our global IT landscape.

In this role, you’ll work across departments to identify IT risks and policy deviations, assess vulnerabilities, and drive mitigation strategies. You’ll take ownership of risk management frameworks, produce actionable dashboards and reports, and ensure compliance with leading regulations like GDPR, HIPAA, and ISO standards. This is your chance to work hands-on with ServiceNow GRC and make a visible impact on a truly global scale.

What we offer in return:

  • You will be working for an organisation that embraces diversity & inclusion and believe we will deliver better outcomes by reflecting the perspectives of our diverse customer base.
  • You will receive a competitive compensation package with bonus structure and extended benefit package.
  • You will be able to work in a hybrid work culture.
  • You will participate in feedback loops, during which a personalized career path will be established.
  • You will be joining a growing company that believes in ownership from day one where everyone is empowered to grow and to take on accountability.

Next Steps:

  • If your profile is a match, we will invite you for a first virtual conversation with the recruiter.
  • The next step is a virtual conversation with the hiring manager.
  • The final step is a panel conversation with the extended team.

Our people make a difference

At Galderma, you’ll work with people who are like you. And people that are different. We value what every member of our team brings. Professionalism, collaboration, and a friendly, supportive ethos is the perfect environment for people to thrive and excel in what they do.

,[Conduct regular IT risk assessments to identify vulnerabilities and security threats across global systems., Evaluate and enhance the effectiveness of existing IT controls and recommend improvements., Perform security audits and assessments of applications, networks, and IT infrastructure., Develop and implement risk management frameworks, policies, and processes., Maintain and update the IT risk register, and track remediation efforts to ensure timely resolution., Collaborate with compliance and legal teams to interpret and implement evolving regulations (e.g., GDPR, HIPAA, GxP)., Prepare and deliver clear, data-driven risk analysis reports, dashboards, and presentations to stakeholders., Ensure the company’s IT environment aligns with industry best practices and regulatory requirements., Document all assessments, controls, and mitigation actions with strong evidence and audit readiness. Requirements: risk management, ServiceNow, Problem-Solving, Analytical skills, IRM, GDPR, GXP, HIPAA, ISO 27001, NIST Tools: . Additionally: Sport subscription, Private healthcare, Flat structure, International projects, Free coffee, Playroom, Free snacks, Free beverages, Mobile phone, In-house trainings, Modern office, Startup atmosphere.

  • Praca Kraków
  • Administrator IT Kraków
  • Specjalista ds. bezpieczeństwa IT Kraków
  • Kraków - Oferty pracy w okolicznych lokalizacjach


    125 008
    18 328