Avenga is a global IT and digital transformation champion. We deliver strategy, customer experience, solution engineering, managed services, software products and outsourcing services like: staff augmentation, team leasing and permanent employment.
Together, we are more than 2500 professionals with over 20 years of experience. We are present in Europe, Asia and the USA.
IT Security and Compliance Manager
Miejsce pracy: Warszawa
Nr ref.: APD/ITSCM/WAR/02/P
Nr ref.: APD/ITSCM/WAR/02/P
Job description:
- Lead our Information Security & Compliance function and team
- The role holder is responsible for managing the process of gathering, analyzing & assessing the current & future compliance, information security and privacy threats to ensure constant monitoring of the information security best practices as they develop
- Ensure IT systems meets requirements regarding 21 CFR Part 11, data integrity, Gamp 5, GMP, annex 11 (Computer Systems Validation).
- Ensure design, development, and operation of secure & privacy-centric software, infrastructure, policies, and programs that balance best practices, business needs, and risks to continuously improve security posture and reduce the possibility of a data breach
- Oversee our network and application vulnerability scanning and penetration testing programs and coordinate remediation efforts in partnership with Infrastructure and Engineering teams
- Contribute as a member of the Incident Response Team by conducting forensic analysis and troubleshooting to assist in the containment and remediation of security incidents and further identify compensating controls related to security findings
- Managing compliance and security projects, providing expert guidance on compliance matters for other IT project but staying abreast of regulatory changes including cybersecurity developments and their impact on IT requirements, including relevant data privacy requirements.
- Qualify partners and vendors by assessing their security programs meet needs of PolBio and Pharma Standards
- Establish and deliver annual training programs
- Assess regulatory compliance (GDPR, etc.) and enact new programs or changes as regulations evolve and ensure compliance with existing laws
Requirements:
- Extensive experience (10+ years) in Information Security, Technology Risk Management, IT Audit, and/or IT Compliance functions
- Experience within the Pharmaceutical industry GAMP 5 and working within a GxP environment
- Ability to clearly articulate security and risk-related concepts to technical and non-technical stakeholders at various business levels
- Solid grasp of security standard methodologies; securing network and enterprise cloud applications and privileged access management technologies
- Experience implementing cloud security standards for platforms such as O365, Azure.
- Understanding of international privacy and data protection regulations, such GDPR
- Ability to multitask, prioritize, coordinate, work well under pressure and meet deadlines
- Excellent written and verbal communication skills and the ability to construct well-founded, clear, and concise analyses and recommendations
- Critical thinking with strong problem-solving skills and a "can-do” attitude
- Fluent English (spoken and spoken and written)
- Pracę zdalną lub w jednym z naszych biur- do wyboru
- Stały rozwój kwalifikacji zawodowych, wymiana doświadczeń
- Stabilną pracę wśród profesjonalistów
- Urozmaicony zakres prowadzonych projektów
- Dofinansowania do szkoleń i certyfikatów
- Prywatną opiekę medyczną
- Pakiet rekreacyjno- sportowy