
Security Consultant
- Wrocław, dolnośląskie
- Stała
- Pełny etat
- Understanding of Full Technology Stack, with emphasis on application security, vulnerability management, network security, etc.
- Define end to end security architectures and provide pragmatic security guidance that balance business benefit and risks.
- Engage technology teams in order to evaluate and prescribe security controls at all touchpoints throughout the technology architecture
- Define security configuration standards for platforms and technologies
- Provide knowledge sharing and technical assistance to other team members
- Act as Subject Matter Expert (SME) in responsible technologies and have deep technical understanding of responsible portfolios
- Perform risk assessments of information systems and infrastructure
- Maintain and enhance the Information Security risk assessment methodology
- Develop appropriate risk treatment and mitigation options to address security risks identified during security review or audit
- Translate technical vulnerabilities into business risk terminology for business units and recommend corrective actions to customers and project stake-holders
- Application Security is a MUST.
- Understanding of full application/product development lifecycle.
- Cloud technologies (MS Azure specifically)
- Strategic skills to analyze technology architectures and software solutions, identify security risk and prescribe mitigating security measures in accordance with the firm's risk tolerance level.
- Five or more years working experience with the architecture, design and engineering of web-based multi-tier information systems or network infrastructures
- Experience with security architecture, design and assessment of accounting and auditing systems.
- Ability to appropriately balance firm security needs with business impact & benefit
- Ability to facilitate compromise to incrementally advance security strategy and objectives
- An overall understanding of the business objectives of EY with an ability to build relationships with business partners and across EY IT
- Ability to team well with others to facilitate and enhance the understanding & compliance to security policies
- Experience facilitating meetings with multiple customers and technical staff, including building consensus and mediating compromise
- High degree of tolerance for ambiguity
- Experience conducting risk assessments, vulnerability assessments, vendor and third party risk assessments and recommending risk remediation strategies
- Experience working with common information security standards, such as: ISO 27001/27002, NIST, PCI DSS, ITIL, COBIT
- Five or more years of experience in security architecture, application security, networking, data center configuration, cloud technology, and the management of a significant Information Security risk functions
- 8 or more years of experience in an Information Security or Information Technology discipline
- Experience in the Agile development lifecycle
- Experience in managing the communication of security findings and recommendations to IT project teams and management
- Exceptional judgment, tact, and decision-making ability
- Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change
- Outstanding management, interpersonal, communication, organizational, and decision-making skills
- Strong English language skills are required
- Experience with cloud technology solutions, particularly MS Cloud
- Experience in technologies such as AI, MCP, block chain, RPA a plus.
- Knowledge of the Scaled Agile Framework
- Continuous learning: You'll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We'll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We'll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You'll be embraced for who you are and empowered to use your voice to help others find theirs.