Technology Specialist - Security, Procurement
Digital & Technology Team (D&T) is an integral division of HEINEKEN Business Services Poland. We are committed to making Heineken the most connected brewery. That includes digitalizing and integrating our processes, ensuring best-in-class technology, and embedding a data-driven culture. By joining us you will work in one of the most dynamic and innovative teams and have a direct impact on building the future of Heineken!
Would you like to meet the Team, see our office and much more? Visit our website: Heineken (heineken-dt.pl)
The Cybersecurity Chapter in D&T Support Functions department is a cross-function security enablement team that helps D&T Support Functions Product Teams build, operate, and maintain secure and compliant platforms through security governance, risk management, standardization, awareness, and operational assurance, while acting as the bridge between D&T Support Functions and Global Information Security. Team goal is to enable sustainable growth and innovation by strengthening the security posture and resiliency of D&T Support Functions platforms.
Technology Specialist – Security will operate as member of D&T Support Functions Cybersecurity Chapter and support D&T Procurement team and work in close cooperation with specific architects, technical specialists, suppliers, TS&O Global Information Security partners and to a lesser extend Global P&CI and Global Audit. Ultimately to ensure Security by Design principles are applied across the board.
Your responsibilities would include:
-
coordinating D&T Procurement Domain Product Security-related activities, ensuring work is done OTIF in accordance with Heineken Cybersecurity Policy and Security by Design principles
-
supporting D&T Domain Product Functional and Technical streams in performing their work in accordance with Heineken Cybersecurity Policy
-
overseeing IT control activities to keep Procurement systems secure and in compliance with Heineken Security Standard and reporting it to D&T stakeholders.
-
managing Central IT Audits & Security Control Effectiveness Assessment (SCEA).
-
driving remediation and mitigation activities based on CITA, SCEA and internal audit / controls execution findings.
-
ensuring D&T SF Procurement works in line with the security roadmap defined by the TS&O Global Information Security team
-
ensuring operational user management and monitoring across the D&T Procurement systems (e.g. support with mapping MyAccess Enterprise roles to Procurement system specific entitlements roles, supporting user and role attestation process, SoD/CA reviews, etc.)
-
challenging D&T and business parties at the technical and functional level in case of potential security breaches
-
escalating to D&T MT level in case of (imminent) security breaches
-
regular alignment with global security governance bodies (e.g. Global Information Security Global Audit, P&CI and external auditors) on security governance, ownership and relevant HEINEKEN MT assurance topics, connecting the dots, translating the general requirements into actual practical solutions at Procurement level.
You are a good candidate if you:
-
Bachelor’s or master’s degree in business information technology or a related field
- relevant knowledge and certifications in the field of Security, e.g. CISSP / CCSP / CISM / CISA / CRISC / ISO27001 / COBIT 5
-
5+ years of working experience in the field of IT security
-
experience with IT suppliers and vendor management, including teamwork coordination
-
stakeholder management, including strong relationship-building and reporting skills
-
ability to translate technical security into business-related terms
-
practical work experience with GRC, IAM and SIEM solutions
-
general level of functional knowledge of business processes (Procurement), understanding their importance and relation with application security
-
knowledge of the NIST Cybersecurity framework and how this can be applied to application security
-
experience in working with auditors, knowledge of audit procedures, audit phases and techniques of risk management
-
excellent consulting and communication skills to be applied at a large range of different stakeholder levels
-
strong architectural skills (both software and landscape) to understand the impact of the different elements on each other and D&T in general
-
Fluent English.
At HEINEKEN Kraków, we take integrity and ethical conduct seriously. If someone has concerns about a possible violation of legal regulations indicated in Polish Whistleblowing Act or our Code of Business Conduct, we encourage them to speak up. Cases can be reported to global team or locally (in line with the local HBSP Whistleblowing procedure) by selecting proper option in this tool or by communicating it on hotline.
This role allows you to apply 50 % copyright tax-deductible costs up to 80% of your tasks. (Koszty Uzyskania Przychodu)
Job Segment:
Risk Management, Procurement, Compliance, Internal Audit, Information Security, Finance, Operations, Legal, Technology