Apply now »

Technology Specialist - CDO, Threat Monitoring Operational Coordinator

Digital & Technology Team (D&T) is an integral division of HEINEKEN Global Shared Services Center. We are committed to making Heineken the most connected brewery. That includes digitalizing and integrating our processes, ensuring best-in-class technology, and embedding a data-driven culture. By joining us you will work in one of the most dynamic and innovative teams and have a direct impact on building the future of Heineken!

 

Would you like to meet the Team, see our office and much more? Visit our website: Heineken (heineken-dt.pl)

 

Threat Monitoring Operational Coordinator is part of the CDO Threat Monitoring team, reporting to the Chapter Lead with a dotted line to the Product Owner. The role combines 30% product development (agile work on Threat Monitoring capabilities) and 70% operations (Change & Incident Management) in close cooperation with ENGaAS (Engineer as a Service). You are responsible for process quality, flow, and continuous improvement, while driving operational maturity by improving ownership, enabling engineers, and enhancing service quality—shifting the team from reactive to proactive operations.

 

Your responsibilities would include: 

 

1. Change Coordination

  • own the end‑to‑end change approval process up to “Approved – Ready for Implementation”
  • act as the single point of accountability for CSO, TM, and TR approvals
  • validate change quality, assess risks, and proactively drive approvals via direct communication and review calls
  • focus on reducing approval delays, rejections, and unnecessary SNOW notifications.

 

2. Incident Coordination

  • ensure correct and fast assignment of incidents to appropriate ENGaAS groups and track them to closure.
  • maintain proper status usage (e.g., Pending Customer) and prevent long-running “In Progress” tickets.
  • monitor SLA compliance, trigger early escalations at risk of breach, and coordinate with OpCos on dependencies and maintenance windows.

 

3. Continuous Improvement & Ownership

  • analyze escalated incidents to identify root causes, repeated handovers, and resolution gaps
  • highlight cases of unnecessary escalation and opportunities for ENGaAS to fully resolve tickets
  • drive improvements through SOP updates and stronger ownership practices.

 

4. Service Quality Assessment

  • assess ENGaAS service quality across incident handling, closure accuracy, and communication
  • track key trends (e.g., reopened tickets, ownership delays, customer vs. engineering blockers) and provide data‑driven insights
  • recommend concrete improvement actions to enhance overall performance.

 

You are a good candidate if you have:

 

  • Bachelor’s degree in a related field or equivalent experience 

  • at least 5 years of working experience in IT cybersecurity-related roles 

  • operational mindset to efficiently coordinate incidents and change management

  • ability to bring together expertise from other Engineers and use that to guide operational teams to do the right thing, and to do things right

  • understanding and you have practiced Agile ways of working

  • some coding experience (KQL, Python), ‘cheating’ by leveraging GenAI is fine

  • operational experience Logs Ingestion Management or Application Security

  • knowledge and experience of Microsoft security products and ServiceNow operations is a BIG pre, but if your experience is with other similar products that is okay

  • basic knowledge of industry standard security frameworks for information systems (NIST, ISO 27001/2, CSA, IEC 62443), the Cyber Kill Chain & MITRE ATT&CK framework
  • ability to work together with people of many different cultures and backgrounds (we are quite a diverse organization
  • ability to translate technical language into a story that can be understood, and cohesively present it back to different stakeholders with a clear message
  • fluent English level both spoken and written. 

 

At HEINEKEN Kraków, we take integrity and ethical conduct seriously. If someone has concerns about a possible violation of legal regulations indicated in Polish Whistleblowing Act or our Code of Business Conduct, we encourage them to speak up. Cases can be reported to global team or locally (in line with the local HGSS Whistleblowing procedure) by selecting proper option in this tool or by communicating it on hotline.

#LI-AK1 #LI-HYBRID


Job Segment: Compliance, Engineer, Information Systems, Change Management, Network, Legal, Engineering, Technology, Management

Apply now »