About Company
A fast-growing international SaaS group is redefining how the world's most ambitious real estate companies run their operations. Their unified CAFM platform powers the daily operations of over 250 million m² of real estate worldwide, supporting more than 500,000 professionals across 100,000+ buildings in 35+ countries.
Requirements
- Led information security and compliance, ideally as the most senior security person in the business
- Taken ISO 27001 through at least one full audit cycle and know where the bodies are buried
- Applied GDPR in practice, in more than one country
- Matured security across businesses at different stages, ideally in a group built by acquisition
- Builds programmes pragmatically — can tell the difference between real risk reduction and theatre, and protects business velocity while cutting the latter
- Credible in front of customers, auditors, and the board; can hold a technical line without becoming the reason a deal dies
- CISSP, CISM, or equivalent
- Strong professional English; Polish is useful, not essential
Duties
- ISO 27001 and Cyber Essentials Plus across every entity: scope, evidence, audits, recertification, and pulling newly acquired businesses in; if SOC 2 becomes commercially necessary, you make that call and lead it
- The ISMS and the policies behind it — current, genuinely used, and credible to an auditor
- GDPR across three jurisdictions — processing records, DPIAs, transfers, subject requests, breach notification
- Customer security assurance — questionnaires, due diligence packs, and security terms in contracts and DPAs; you join the calls where deals are won or stalled on security
- Incident response, end to end — you own the plan, you run the response, and you make sure the post-mortem actually changes something
- Business continuity and disaster recovery for group systems, tested at least annually, plus tabletop exercises with the leadership team
- Security baselines for endpoints and internal systems (CRM, ERP, email, collaboration) — IT Operations implements, you set them and verify them
- Risk register, access reviews, and control testing, reported straight to the executive team
- External partners — MSPs, penetration testers, security vendors, and the cyber insurance relationship
- Security awareness that people absorb rather than click through
Conditions
- Full ownership of security for an international SaaS group, with direct access to the executive team
- A programme you shape rather than inherit — real problems, real budget, and the mandate to fix them properly
- Security here enables revenue; it is a visible commercial role, not a back-office one
- Competitive salary, aligned to the seniority of the role
- Private medical care, sport card, life insurance, annual training budget, team integration budget
- Krakow or Warsaw, hybrid
Oops! Something went wrong while submitting the form.
